Privacy

# I can't read a single entry. Not one.

On one phone there is nothing of yours to read. Once a second phone joins, what crosses between them is noise, and the thing that would make it readable never touches my server.

Not "I promise not to". I built it so I can't. Your entries are **end-to-end encrypted** on your phone, with a key only your phones have, before anything leaves.

## On one phone, I hold nothing

Not an encrypted copy of your log. Nothing at all. A phone logging on its own never contacts my server, so there is no row to point at, no arrival stamp, and nothing for anybody to ask me for. You could take the relay off the internet for a month and you would not notice.

That is the free version, and it is the most private this can be. Everything below is what changes when you add a second phone, because that is the only point at which anything of yours leaves.

## What my server holds once two phones are talking

Per sync code, that's the full list:

- Your entries, encrypted. I have no way to decrypt them.
- The order they arrived in, and when.
- A one-way fingerprint of the token your phones use to prove they're yours. Not the token itself.
- Whether this set of phones has paid. A yes or a no, nothing about who.
- Two dates about the phones, never about an entry: when they first reached the relay, and, if they've paid, when that went through.

No name, no profile, no analytics, no advertising anything. Not because I deleted them, but because I never built anywhere to put them.

What an entry says is hidden, and so is the time it records. A feed, a nappy and a temperature look identical to me, and one you write up the next morning tells me nothing about the night it belongs to.

What I do see is when your phone sent something, because I stamp that on arrival to keep the order straight. Log at 3am and I know something was logged at 3am. Not what, not for whom. I'd rather say that than pretend the stamp isn't there.

## Your email address, and the £2

- Buying it needs an email address, because a receipt has to go somewhere. It sits with Stripe. I can't look up a sync code from an email, or the reverse.
- Stripe holds the card details and sends the receipt. I never see the card.
- The one join I could have built and did not: my server knows a set of phones has paid, but not which payment did it. That link would have tied your email address to your entries.
- One count sits on the payment side: how many households a payment has set up, and when it was first used, so one £2 can't unlock an endless number. Keyed to the payment, never to a sync code.

## Getting your data out

Settings, one tap, and everything downloads as a file you keep. No request to me, no queue. It works whether or not I'm still here, which is the point.

## It gets deleted after 30 days

The server is a relay between your devices, not a backup. Each change sits there for 30 days from the moment it arrives, then is deleted, whether or not the other phone has been to collect it. Your phones keep the whole history.

Collecting it changes nothing, deliberately. Deleting on collection would mean recording which phone had fetched what, which is precisely what this relay is built not to hold.

The tradeoff: a phone left offline for more than a month misses whatever it didn't collect. In a house with two phones, that doesn't happen.

## The key is yours and I never see it

Your sync code does the encrypting, and it's generated on your phone. It isn't emailed, isn't attached to anything you buy, and isn't stored on my side in any form.

So I can't recover it, and there's no reset link because there's nothing to reset. Any phone you've set up can show it to you, so it's only gone if the code and every device go at once. [More on that](https://usebabybrain.app/setup).

The specifics, for anyone who wants them. AES-GCM with a 256-bit key, derived on your phone from your sync code by PBKDF2-SHA256 at 600,000 iterations, then HKDF-SHA256. That last step splits it into three: the encryption key, a token your phones show the relay, and the id your ciphertext is filed under. Standard Web Crypto, nothing hand-rolled.

## Things I don't do

- No accounts, so no password reset trail and no profile.
- No analytics. No "anonymous usage data". No cookies on this site.
- No trackers, ad networks or social login buttons.
- No selling your data, which would be a neat trick given I can't read it.

Nothing loads from anywhere else either. The interface uses the fonts already on your phone, so opening Baby Brain talks to nobody but the relay.

## Who else is involved

- **Cloudflare** hosts the site, the app and the relay. They hold the same encrypted blobs I do and, like any host, see your IP address and roughly when you connected. I can't tie that to your entries, but I won't pretend it isn't there.
- **Stripe** takes the £2, holds the card details and sends the receipt. There's no separate email provider, because nothing else on my side sends you anything.

## Asking me things

Anything at all, including your rights under UK GDPR: [allan@corbett.fyi](mailto:allan@corbett.fyi). I'm [Allan Corbett](https://superallan.com/), based in Edinburgh, and I'm the data controller, which mostly means there's one person to shout at.

I hold your email address and a payment record with Stripe, and I'll delete or hand over either on request. The encrypted entries aren't tied to you by anything on my end, so there's nothing to look up. Stop using it, wait 30 days, and they're gone by themselves.

Last updated: 2026-10-10.

---

Source: https://usebabybrain.app/privacy/
