Privacy Policy
LiveWithLove ("we," "us," or "our") builds OnTrack (the "App"), a baby- and toddler-tracking app that helps parents and caregivers log feeds, diapers, sleep, growth, milestones, and related notes. This policy explains what information the App handles, how it is used, who it is shared with, and the choices and rights you have.
We designed the App to be privacy-first. The caregiving data you enter about your child is end-to-end encrypted (see End-to-end encryption), which means that even when it is backed up to our cloud, we cannot read it.
By using the App you agree to this policy. If you do not agree, please do not use the App.
1. Who can use the App
The App is intended for parents and caregivers who are adults (18 or older). It is not directed to children and is not intended for use by children to create accounts or enter their own data. The App stores information that is about a child, but the account holder and user is an adult. See Children's privacy.
2. Information we handle
a. Information you provide
- Account information. If you create an account, we collect your email address and a display name. If you sign in with Google, we receive your email address and basic profile name from Google (per the permissions you grant); we do not receive your Google password.
- Caregiving data about your child. Data you choose to enter — such as a child's name, date of birth, sex, growth measurements, feeding/diaper/sleep/potty/food/milestone logs, and any health, medication, or free-text notes, and optional photos you attach. This data is end-to-end encrypted before it leaves your device (Section 3).
- Family invitations. If you invite a co-caregiver or join a family, we process the invite code and family membership needed to link your accounts.
b. Information collected automatically
- Push notification token. If you enable co-caregiver notifications, we store a device push token (via Google Firebase Cloud Messaging) so we can send a contentless "new activity" signal to your co-caregiver's device. The notification itself carries no child data; the receiving device pulls and decrypts the update locally.
- Advertising identifier and ad-related data. The free App is supported by ads served through Google AdMob, which may access your device's advertising ID and limited device/ad-interaction data to serve and measure ads. See Advertising and your choices.
- Basic technical/diagnostic data. Standard information needed to operate and secure the service (e.g. coarse request metadata, error/crash signals). We do not currently use a third-party product-analytics SDK.
c. Purchases
- If you buy ad removal, the purchase is processed by Google Play Billing (or the Apple App Store on iOS). We receive a confirmation that your purchase is valid so we can turn off ads for your account. We do not receive or store your payment card details.
What we do not do
- We do not sell your personal information.
- We do not use your child's caregiving data to serve ads, and we cannot read that data because it is end-to-end encrypted.
- We do not require an account to use the App's core logging — see Guest mode.
3. End-to-end encryption (E2EE)
The caregiving data you enter (child profiles, log entries, notes, and any photos you sync) is encrypted on your device using a key derived from a family passphrase that you choose. That key — and your passphrase — are never sent to our servers. As a result:
- When your data is synced or backed up to our cloud, it is stored only as ciphertext we cannot decrypt, and it can only be read on a device that has been unlocked with your family passphrase (or your one-time recovery key).
- If you lose both your family passphrase and your recovery key, your encrypted cloud data cannot be recovered by us or anyone else. Please store your recovery key somewhere safe.
4. How we use information
We use the information above to:
- provide core features (logging, growth charts, reminders, multi-caregiver sync, backup/restore);
- authenticate you and keep your account and family data secure;
- deliver co-caregiver push notifications you've enabled;
- serve and measure ads (for users who have not purchased ad removal) and apply your ad-removal purchase;
- provide customer support and respond to your requests; and
- comply with legal obligations and enforce our terms.
5. How information is shared
We share information only as needed to run the service:
| Recipient | Purpose | What they receive |
|---|---|---|
| Amazon Web Services (AWS) | Cloud hosting, authentication, encrypted storage, sync | Account identifiers; encrypted (unreadable) caregiving data; optional encrypted photos |
| Google (Firebase Cloud Messaging) | Delivering push notifications | Your device push token + a contentless wake signal (no child data) |
| Google (Sign-In) | Optional Google login | Authentication request; we receive your email + basic profile from Google |
| Google AdMob | Serving and measuring ads (free users) | Advertising ID + limited device/ad data |
| Google Play Billing / Apple App Store | Processing the ad-removal purchase | Purchase/validation data (no card details reach us) |
| Service providers / legal | As required to operate, protect, or comply | Limited data as necessary |
We may also disclose information if required by law, to protect rights and safety, or in connection with a corporate transaction (with notice where required). We do not sell personal information or share it for cross-context behavioral advertising beyond the ad serving described above.
6. Advertising and your choices
The free App shows ads via Google AdMob. You can control ad-related data collection:
- Remove ads. Purchase ad removal in the App to turn off all ads for your account.
- Reset or limit your advertising ID in your device settings (Android: Settings → Privacy → Ads).
- Consent (EEA/UK). Where required, we will request your consent for personalized ads before they are shown and honor your choice.
- Learn more about how Google uses data from apps that use its services at policies.google.com/technologies/partner-sites.
Because the App is used in a family context, ads are configured to be non-personalized / not child-directed where applicable, consistent with Google Play's Families policy.
7. Children's privacy
The App is for adult parents and caregivers and is not directed to children. We do not knowingly allow children to create accounts or use the App directly, and we do not knowingly collect personal information from children. The child information in the App is entered by an adult and, for cloud sync, is end-to-end encrypted so that we cannot read it.
If you believe a child has used the App to provide information to us directly, please contact us at ontrack.app.support@gmail.com and we will take appropriate steps.
8. Data retention
- Account and cloud data are retained while your account exists, so your data is available across your devices and to caregivers you've invited.
- When you delete your account (Section 9), we delete your associated cloud data as described below.
- Encrypted backups/photos are stored only as ciphertext we cannot read, and are deleted as part of account/family deletion or when you turn off cloud photos.
- On-device data stays on your device until you delete it or uninstall the App. Uninstalling does not by itself delete cloud data tied to your account.
9. Your rights and choices
Depending on where you live (e.g. EEA/UK under GDPR, California under CCPA/CPRA, and similar laws), you may have the right to access, correct, delete, or export your personal information, to withdraw consent, and to not be discriminated against for exercising these rights.
You can exercise key rights directly in the App:
- Delete your account and data. Use the in-app account-deletion option, or the web form at withlove-ontrack.com/delete-account. This removes your family membership and, if you are the last member, deletes the family's children, entries, entitlements, encrypted photos, and your login credentials, and revokes your sessions. If other caregivers remain in your family, they keep access to the family's shared data unless you removed them first.
- Export your data. Use the in-app export to obtain a copy of your data. (Availability per app version.)
- Manage notifications and ads in the App and your device settings.
For any request, or to reach us about your rights, contact ontrack.app.support@gmail.com. We will respond within the timeframe required by applicable law. You may also have the right to lodge a complaint with your local data protection authority.
10. Guest mode (no account)
You can use the App's core logging without creating an account. In guest mode your data is stored only on your device and is not synced to our cloud. If you later create an account, you can choose to upload your existing local data so it becomes part of your encrypted account.
11. Security
We use industry-standard measures to protect information, including end-to-end encryption of caregiving data, encryption in transit (TLS), platform-secure storage of credentials on the device (Android Keystore-backed storage), and access controls on our backend. No method of transmission or storage is 100% secure, but we work to protect your information and to limit what we are even able to access (which, for your caregiving data, is nothing readable).
12. International data transfers
We operate using cloud infrastructure that may process and store data in the United States and other countries. Where required, we rely on appropriate safeguards for international transfers.
13. Changes to this policy
We may update this policy from time to time. We will revise the "Last updated" date and, for material changes, provide additional notice as required by law. Your continued use of the App after an update means you accept the revised policy.
14. Contact us
LiveWithLove
Email: ontrack.app.support@gmail.com