Privacy Policy
Bubbi is white noise for sleep, plus a shared feed and sleep log. Playing a sound collects nothing extra. An account is only so two phones can share one log.
This policy describes what the Bubbi iOS app stores, what it can copy off the device if you ask it to, the note you can send us from Support, and how to delete all of it. It applies to the app and to this website.
Who we are
Bubbi is developed by the maker of the Bubbi iOS app
(bundle identifier com.bubbi.Bubbi). Questions about this
policy: hello@bubbisleep.com.
The short version
- You can use Bubbi with no account at all. The app still sends a tiny “this happened” ping so we can see which parts are being used — which screen, which of the six sounds, never the baby’s name or your notes. If you type your own name on first run, we store it with the phone’s install id.
- An account is only for sharing the family's log between two parents' phones. It uses Sign in with Apple, and nothing else.
- Sharing is off until you sign in. Signing in turns it on — the screen says so before you tap the button — and you can turn it back off in Settings at any time.
- What sharing covers: sessions (times, durations, the settle curve, your notes), feeds and sleeps, and your baby's name and birth date. Never a photo. Memory Wall looks at your camera roll on this iPhone and never uploads a picture.
- There is no advertising SDK and no tracking of you across other apps. Paid ads, when they run, are measured by Apple — SKAdNetwork for the product step, and AdServices for which Apple Search Ad bought the install. We do not read an advertising identifier.
- You can log out or delete your account from Settings inside the app.
What the app stores on your iPhone
All of the following stay in the app's sandbox on that device.
| What | Why | Where |
|---|---|---|
| Optional voice note after a session | So you can say how a night went instead of typing it | Application Support on this iPhone. Never uploaded. |
| Session summaries, cry bouts, and settle-curve blocks | History, the night-to-night guidance clock, and the curve you already saw | SwiftData on this iPhone. Copied to your family's account only if sharing is on. |
| Your name | So the log can say who wrote a feed or a sleep | SwiftData on this iPhone. Copied with the shared log if sharing is on. If you skip an account, the name is stored with this phone’s install id. |
| Your baby's name, optional birth date, optional due date, and optional photo | To address you both about the same baby, and to match the day plan to age. A due date is only asked if they were born more than three weeks early, and it never leaves this phone. Without a birth date, Bubbi uses the most cautious advice. | SwiftData on this iPhone. Name and birth date may copy to the other parent. Due date and photo stay here. |
| Memory Wall identifiers | To put photos of your baby on a week-by-week wall. Bubbi looks at photos taken since the birthday, on this iPhone, and keeps only a list of which ones belong on the wall. Turning the wall off empties that list. The camera roll is never changed. | SwiftData on this iPhone. Never uploaded. Not shared with the other parent. |
| Labelled sessions you export | Only if you tap Export. A copy of the audio and labels is written where you can move it to a Mac. | Files → On My iPhone → Bubbi → eval-corpus |
Accounts
Bubbi works completely without an account, and choosing “Just use it on this phone” is a normal way to use it. Every feature except the second phone works the same.
If you do sign in, the only method is Sign in with Apple. We receive a stable identifier for your Apple ID, the name you choose to share, and an email address — which is a relay address if you use Apple's Hide My Email. First run also asks for your name if Apple did not hand one over, including when you skip the account. We never see your Apple password. There is no other way to create an account, so there is no password for us to store.
Two parents join one “family” by one of them generating a four-digit code in the app and the other typing it in. Codes expire after two days, work once, and are rate-limited on the server. Joining a family means both phones read and write one shared log for each baby in the family.
The usage ping, with or without an account
Each time you open Bubbi, start or finish a sound, log a feed, meal, sleep or activity, correct or delete one of those, open the player, the day plan, the log, Journey, the memory wall, the ideas or the settings, reach one of the first-run screens, see a note asking for an App Store review, sign in, sign out, turn sharing off, or delete your account, the app tells our server that it happened. If a sleep or play is still open when you open the app, that is sent too, as the same yes it sent when it started. That is how we know the app is actually being used, and which parts of it are.
The ping is a yes/no and, for a finished sound, sleep or activity, a duration. A few of them name one more thing, from a fixed list: which of the first-run screens you reached, which of the six sounds you played, and which review note you saw. The server refuses any word that is not on those lists.
It does not include audio, the baby's name, your notes, how much they ate, which meal it was, what the activity was, the times of anything, or the settle curve. A code that did not work is counted, never stored.
If you type your name on first run, or later in Settings, that name is stored with the install id so we can tell phones apart when there is no account. It is not the baby’s name, and it is not a word on the ping’s closed list — it labels the phone, the same way a Sign in with Apple name labels an account.
The phone is identified by a random install id stored on that iPhone. If you later sign in, we can attach that ping to your account so the two sides of the log match. Deleting the app, or deleting your account, starts that id over.
A note from Support
Settings has a Support screen at the top. If you write a note there, the words you type are sent to us so we can reply in that same screen. We may also write first — a reply, or a short note such as an App Store review link. The note can leave the phone with or without an account. We store the words, when they were sent, a random install id for that iPhone, the app version, and — if you are signed in — the account the token names. We do not ask for audio, and the composer cannot attach any.
Replies we write are stored on the same thread so they can appear on your phone. A https or mailto link in a note is tappable. Only the people who run Bubbi can read the thread. It is not part of the shared family log, and the other parent cannot see it.
Opening Support, or already allowing reminders, lets this iPhone send Apple a push token so we can wake you when a new note arrives. The alert shows a short preview of the note, not the baby's name or the log. The token is stored against that install id and is not used for ads.
Deleting your account removes support notes written while you were signed in. A note written signed out stays until you ask us to remove it. Email hello@bubbisleep.com.
What is copied off the device, and only if you ask
The shared log is not copied without an account, and signing in is what asks. The screen that offers Sign in with Apple states, above the button, that signing in copies your log; the same is true of the pairing code in Settings. Either way there is a single switch — “Share nights with the other parent” in Settings — that turns it back off and stops any further copying. With sharing on, each finished session, feed, sleep, solid or play is copied to your family's private area of our database so the other parent's phone can show it. That copy contains:
- When the session started and ended
- Total crying time, longest quiet stretch, and time to first settle
- The start and end of each cry bout
- The settle curve as 30-second aggregates — average and peak cry level, loudness, and the fraction of the block spent crying
- The moments you tapped “go check”
- Where the baby was put down and what you tried, if you filled that in
- How the night felt, any “unusual night” tags, and your typed note
- Each feed: when, which side or bottle, and the amount if you typed one
- Each solid: when, and whether it was breakfast, lunch, dinner or a snack
- Each sleep: when they went down, how long, and whether Bubbi was playing when they settled
- Each play: when it started, how long, what it was (tummy time, play, outdoors, bath, storytime or skin-to-skin), and a note if you typed one
- Your account identifier and display name, so the log can show who settled them
- Which baby the night belongs to, and each baby's name and birth date so both phones agree on who they are
It does not contain audio, and it cannot be turned back into audio: a 30-second average of a cry level is not a recording. Voice notes and raw recordings are never copied, and neither is your baby's photo or optional due date.
Nobody outside your family can read any of it. Access is enforced by server-side rules keyed to your family, not by the app.
Paid ads
When Bubbi is advertised, two Apple systems measure it. Neither is an advertising SDK, and neither reads the advertising identifier.
SKAdNetwork: the app tells Apple which step of using the app this install reached — that it opened, that first-run finished, that a sound played, that something was written in the log, or that an account was created. Apple may pass that fact to the ad network in aggregate, without naming you. The value never says which sound, what was logged, or anything about your baby.
AdServices, for Apple Search Ads: on first open the app asks Apple for an attribution token and our server exchanges it with Apple. If this install came from a Search Ad, Apple tells us the campaign, ad group, keyword and storefront — identifiers, not a name and not the words you typed. We keep those so we can see which search terms bring parents who stay. The token is discarded after the exchange. An install that did not come from a Search Ad is stored as not attributed.
We do not include an advertising SDK. We do not read the advertising identifier. We do not ask for App Tracking Transparency. We do not follow you into other companies' apps.
Reminders
If you sign in and turn on “the other parent” in Settings, this iPhone sends Apple a push token so we can wake the other phone when a feed, sleep or meal is logged. The alert says the kind, the clock, and the next window when the day plan has one. It does not say who logged it, how much, or the baby's name. A next-window clock may travel with the row so we can write that line, the same way a change timestamp does; it is not a log entry of its own. The token is stored on your account and is deleted when you turn the reminder off, sign out, or delete the account. The same token kind is also used for Support notes, stored against the install id, as described above.
If this iPhone has allowed notifications, Bubbi may also send short daytime notes: when a nap window is coming, when a sound may help them settle, to ask whether they slept, a weekly Journey card, a morning hello, or a quiet note if the app has sat unused. Those notes come from the windows this iPhone is already guessing. Never at night. When a name is saved on this iPhone, a nap, settle, sleep-check or Journey note may show it, including on the lock screen. The other parent's alert still does not.
Who processes it
Our backend is Google Firebase — Firebase Authentication, Cloud Firestore,
and Cloud Functions — acting as our processor. Data is stored in Google's
europe-west1 region (Belgium). Google may process it in other
regions for operational purposes under their own terms.
This website is static. It does not set tracking cookies and does not embed analytics.
What we never collect
- Audio, transcripts, or per-frame classifier scores
- Location, contacts, or HealthKit records
- Photos leaving this phone. Memory Wall may look at your camera roll on this iPhone. The pictures stay in Photos. Bubbi stores identifiers, not copies, and does not upload them.
- Advertising identifiers, or tracking you across other companies' apps
- Crash reports
Children
Bubbi is for parents, not for children to use. A birth date is stored only to choose age-appropriate timing, and stays on the device. We do not knowingly collect personal information from children off the device.
How to delete data
- Your account: Settings → Account → Delete account. This removes your account, everything it stored on our servers, support notes written while you were signed in, and every night, recording and voice note on that iPhone. Apple's sign-in permission is revoked at the same time. It cannot be undone.
- A signed-out support note: email hello@bubbisleep.com and we will delete that thread.
- Just sign out: Settings → Account → Log out. Nothing is deleted; the phone simply stops sharing.
- Memory Wall: Settings → Memory Wall off. The identifier list empties. Your camera roll is not changed.
- Raw recordings: Settings → Delete all recordings. Session summaries stay.
- A single night: delete that session in History. Its audio file goes with it, and it is removed from the shared log too.
- Exported labels: delete the files in Files → On My iPhone → Bubbi.
- Everything on the phone: delete the app. iOS removes the sandbox. If you had an account, delete it first — removing the app does not.
When the last member of a family deletes their account, the family's shared log is deleted with it. Nights the other parent already has on their own phone stay there; we cannot reach another person's device.
Your rights
If you are in the EU/UK or another region with access, correction, or deletion rights: almost everything lives on your iPhone, so you already have it, and the steps above delete it. For anything held on our servers under an account, deleting the account removes it. To ask for a copy, or if something above does not match what you see, email hello@bubbisleep.com and we will answer plainly.
Our lawful basis for the usage ping, and for the Apple Search Ads identifiers, is that we need them to run and improve Bubbi. Our lawful basis for the shared log is your consent, given by signing in on a screen that says what signing in copies, and withdrawable at any time by turning sharing off or logging out. Our lawful basis for a Support note is that you sent it so we could reply, or that we wrote first to reach you about the app.
Changes
If what leaves the device ever changes, this page will be updated before that ships, and the App Store privacy labels will change with it. The date at the top is the last revision.