Effective date: 1 December 2025
Last updated: 28 September 2026
This Privacy Policy explains how Buslovskyi Pavlo, trading as OBRIY soft ("OBRIY soft," "we," "us," or "our"), collects, uses, stores, and discloses personal data when you use the Caring Mother mobile application for Android or iOS and related support services (together, the "Service").
Controller/contact: Buslovskyi Pavlo, Brovary, Ukraine. Email: pavlo.buslowski@gmail.com. Website: https://caring-mother.pages.dev/.
Please read this Policy before entering information about yourself or a child. Caring Mother is intended for parents, guardians, and other adult caregivers. It is not directed to children and must not be used independently by a child.
The app creates a Firebase account so it can associate records with the correct user. This may initially be an anonymous account. If you register or sign in, we process information such as:
Firebase user ID;
name, email address, profile image URL, email-verification status, and account type;
authentication credentials or tokens. Passwords are handled by Firebase Authentication; we do not receive them in readable form;
the sign-in method you choose, including email/password, Google Sign-In on Android, or Sign in with Apple on iOS; and
password-reset and account-management requests.
Google or Apple processes sign-in information under its own privacy terms when you choose its sign-in service.
You may enter a child’s:
name;
sex;
date of birth;
profile-photo reference; and
internal profile and account identifiers.
A selected profile image stays in storage on your device, while the cloud profile stores only a reference to that file. The app does not upload the image itself to Firebase Cloud Storage. We will update this Policy before adding cloud photo upload.
The Service stores the records and notes you choose to create, which may include sensitive health or consumer-health data about a child, including:
feeding, formula, breast milk, solid food, breastfeeding, and pumping sessions, amounts, sides, durations, and related tags;
sleep, falling-asleep, walk, play, bath, and massage records and timers;
diaper changes, bowel movements, consistency, color, and related notes;
weight, height, head circumference, and growth history;
temperature readings;
medicine names, amounts, units, times, and free-text notes;
vaccine names and vaccination records;
dates, times, duration, quantity, units, active-timer state, and free-text notes for events; and
personalized medicine, vaccination, and solid-food suggestion terms that you save.
We do not obtain these records from a medical provider or connected medical device. They are entered by you. We do not use them to diagnose, treat, or make automated medical decisions.
The app stores preferences on your device, such as language, theme, metric/imperial units, selected child, sleep day/night thresholds, last sleep sound, onboarding state, prompts shown, purchase-attempt state, and some editor defaults. Firebase SDKs may also maintain authentication and Firestore offline caches on the device.
Firebase Analytics records app interactions chosen by us, such as onboarding progress and selected goals or struggles, screen views, authentication method, paywall source, selected subscription plan, purchase outcome, and export actions. Depending on platform and SDK configuration, analytics and Firebase services may also process app-instance or installation identifiers, device and operating-system information, language, app version, approximate region derived from IP address, and interaction timestamps.
Firebase Crashlytics is included in the Android app and may collect crash traces, Crashlytics and Firebase installation identifiers, device state, operating-system and app information, and diagnostic context when a crash occurs. The iOS app uses Firebase Analytics but does not use Crashlytics.
We do not intentionally send child profile fields, care records, or free-text notes as custom analytics parameters. Diagnostic records can nevertheless contain information present in an error context, so we restrict access to diagnostic systems.
Apple App Store or Google Play processes payment details. We do not receive your full payment-card information. We receive or process subscription product/plan identifiers, entitlement status, price and currency used for analytics, purchase status and time, and—on Android—a Google Play purchase token stored under your Firebase user account. On iOS, StoreKit may use an app-account token derived from the Firebase user ID to associate a transaction with an account.
The app may request permission to:
select one image through the Android system photo picker or Apple Photos picker;
show notifications for active care timers and audio playback;
run foreground timer and media-playback services on Android; and
play sleep sounds in the background on iOS.
Exports are created as CSV or PDF files in temporary app storage and shared only when you choose a destination through the operating-system share sheet. Once shared, the recipient application or person controls that copy.
If you email support, your email provider and ours process your address, message, attachments, and related metadata. Do not include child health information unless it is necessary to resolve your request.
We collect information:
directly from you when you create profiles, records, accounts, exports, or support messages;
automatically from the app, operating system, and Firebase SDKs when you use the Service;
from Google or Apple when you use their sign-in service; and
from Apple App Store or Google Play for purchases and subscription status.
We do not purchase personal data from data brokers.
We use personal data to:
create and secure anonymous or registered accounts;
save, synchronize, display, filter, chart, and export child-care records;
provide timers, notifications, sleep audio, growth information, and user-selected preferences;
provide, restore, verify, and manage premium access;
respond to support, privacy, and deletion requests;
maintain, troubleshoot, secure, and improve the Service;
understand aggregate feature use and app performance;
detect fraud, abuse, security incidents, and violations of our Terms of Use;
comply with law and protect users, children, our rights, and the rights of others; and
establish, exercise, or defend legal claims.
We do not use child health data to serve targeted advertising, build advertising profiles, determine insurance or employment eligibility, or train general-purpose artificial-intelligence models. The app contains no advertising SDK and displays no third-party ads. We do not sell personal data for money. If our practices change, we will update this Policy and obtain consent where required before the new processing starts.
Where the EU GDPR, UK GDPR, or similar law applies, we rely on the following bases:
Account creation, sync, care-record features, exports, and subscriptions: performance of our contract with you (Article 6(1)(b)).
Security, fraud prevention, essential diagnostics, service improvement, and limited product analytics: our legitimate interests (Article 6(1)(f)), after balancing those interests against your rights; consent where local law or store policy requires it.
Legal compliance and lawful requests: legal obligation (Article 6(1)(c)).
Optional communications or processing specifically presented as optional: consent (Article 6(1)(a)).
Child health data and other special-category data: your explicit consent (Article 9(2)(a)).
By using the app and entering information about your child, including health-related records, you confirm that you are the child’s parent, legal guardian, or a person authorized by them, and you consent to our collection and processing of that information for the purposes described in this Policy.
You may withdraw consent at any time by deleting the relevant records or your account in the app, or by emailing pavlo.buslowski@gmail.com. Withdrawal does not affect processing already carried out lawfully, but some features cannot work without the data they require.
We disclose information only as described below:
Google/Firebase: Firebase Authentication, Cloud Firestore, Cloud Functions, Remote Config, Analytics, Firebase installation services, and Android Crashlytics provide account, hosting, configuration, analytics, diagnostics, and deletion functions.
Apple: Sign in with Apple, App Store, StoreKit, photo picker, notifications, and operating-system services provide features you request on iOS.
Google Play and Google identity services: Google Play Billing, Play in-app updates, Credential Manager, and Google Sign-In provide Android store, update, purchase, and sign-in features.
Your chosen recipients: We disclose an export or support email to the person or application you select.
Professional advisers and contractors: Lawyers, accountants, security specialists, or support contractors may receive limited data under confidentiality and data-protection obligations when necessary.
Legal and safety disclosures: We may disclose data if reasonably necessary to comply with law or valid legal process, respond to an emergency involving danger to a person, protect rights or security, or investigate fraud and abuse.
Business transfers: Data may be transferred in a merger, acquisition, financing, reorganization, insolvency, or sale of assets, subject to this Policy and applicable notice or consent requirements.
We require processors to use data only under our instructions, keep it confidential, apply appropriate security, and provide protections consistent with applicable law.
Firebase Authentication is operated from U.S. data centers, and other Firebase services may process data on global Google infrastructure. Apple and Google may also process information outside your country. Where required, we use appropriate transfer safeguards, such as an adequacy decision, the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, and supplementary measures. Contact pavlo.buslowski@gmail.com to request information about applicable safeguards.
We keep data only for as long as necessary for the purposes described above:
Account, child-profile, care-record, suggestion, and subscription-association data: while the account is active, then deleted or de-identified after a verified deletion request, subject to backups and legal exceptions;
Temporary CSV/PDF exports: the apps attempt to delete old export files from app cache after approximately 24 hours, but copies you shared are outside our control;
Locally selected profile images and local SDK caches: until removed by the operating system, app data is cleared, or the app is uninstalled; account deletion may not erase every locally stored file from every device;
Firebase Crashlytics data: under Google’s documented service retention, crash traces and associated identifiers are generally kept for 90 days before removal begins;
Analytics data: user-level and event-level data in Google Analytics for Firebase is kept for up to 14 months under our Google Analytics data-retention setting and then deleted automatically; aggregated reports that do not identify you may be kept longer;
Support records: for as long as needed to resolve your request and handle related follow-up, then deleted; and
Security, transaction, tax, and legal records: for the period required by applicable tax, accounting, and other laws, or for as long as reasonably needed to establish, exercise, or defend legal claims. Purchase records held by Apple App Store and Google Play are kept under their own retention policies.
Backups and provider systems may take additional time to cycle out deleted information. We isolate deleted data from ordinary use during that period where technically feasible.
We use safeguards designed for the sensitivity of the data, including authenticated Firebase access, per-user Firestore paths and security rules, encrypted network transport, platform-provided authentication and payment flows, iOS file protection for copied profile images, least-privilege access, and release logging controls. No method of storage or transmission is completely secure, and we cannot guarantee absolute security.
You are responsible for protecting your device, store account, email account, and sign-in credentials. Do not share exported health records unless you trust the recipient.
Depending on where you live, you may have rights to:
know whether and how we process personal data;
access and receive a copy of data;
correct inaccurate data;
delete data;
restrict or object to certain processing;
receive portable data you provided;
withdraw consent;
opt out of sale, sharing, targeted advertising, or qualifying profiling; and
appeal a refusal and complain to a privacy regulator.
The app lets you edit or delete individual records and profiles, export event history, and request account deletion under Settings → Delete account. You may also email pavlo.buslowski@gmail.com. We may verify your identity and authority over the account. We will respond within the period required by applicable law, normally one month under GDPR and 45 days under many U.S. state laws, subject to permitted extensions.
We do not sell personal data, use it for targeted advertising, or carry out profiling that produces legal or similarly significant effects. For consumer-health rights, see our Consumer Health Data Privacy Notice.
EEA users may complain to the data-protection authority where they live or work. UK users may complain to the Information Commissioner’s Office. U.S. residents may contact their state attorney general where applicable.
Caring Mother is a tool for adult caregivers and is not directed to children. You must be at least 18 years old or the age of legal majority where you live. Information about a child must be provided only by a parent, legal guardian, or person authorized by them. Do not permit a child to create an account or use the Service independently.
If you believe a child submitted information directly without appropriate adult involvement, contact pavlo.buslowski@gmail.com. We will investigate and delete it where required. Information entered by an adult about a child remains protected personal data even where a children’s-specific statute such as COPPA does not apply.
Caring Mother is not a healthcare provider, medical device, emergency service, or substitute for professional medical advice, diagnosis, monitoring, or treatment. Read the separate Medical Disclaimer.
We may update this Policy to reflect changes in the Service, providers, or law. We will update the date above and, when required, provide prominent in-app or email notice and obtain new consent before materially different processing begins. If you do not agree with a change, stop using the affected feature and request deletion before the change takes effect.
Privacy questions and rights requests: pavlo.buslowski@gmail.com
Support: pavlo.buslowski@gmail.com
Postal address: Buslovskyi Pavlo (OBRIY soft), Brovary, Ukraine