Privacy Policy

Published: 2026-09-10 · Effective: 2026-09-10

Baby Flow (the "Service") establishes and discloses this Privacy Policy under Article 30 of the Personal Information Protection Act ("PIPA") of the Republic of Korea, so that data subjects can have their personal data protected and any related grievances handled promptly. The Service is operated by an individual developer, and this policy applies equally to the app and to the website at https://babyflow.studiohwi.kr.

Article 1 (Purposes of processing personal data)

The Service processes personal data for the purposes below. It does not use personal data for any other purpose, and if a purpose changes it will take the necessary steps, such as obtaining separate consent under Article 18 of PIPA.

1. Membership sign-up and management: identifying and authenticating members, maintaining membership, preventing fraudulent use, sending notices, and handling grievances.

2. Providing the baby-tracking service: storing and displaying feed, sleep, diaper and other activity logs, sharing and syncing records between family members, providing statistics and growth charts, providing Smart Flow predictions, and generating handover reports.

3. Sending notifications: push notifications for the predicted next feed and sleep window, logging reminders, and important service announcements.

4. Providing paid services: checking subscription status, restoring purchases, validating store receipts, and determining free-trial eligibility.

5. Serving advertising: displaying ads to free users and measuring ad performance (personalised advertising applies only where the user has consented).

6. Improving the Service and keeping it stable: diagnosing crashes and errors, responding to support enquiries, and improving service quality.

Article 2 (Categories of personal data processed and how it is collected)

The Service processes the following categories of personal data.

1. Required — email address, display name, the member identifier issued by the social login provider, baby name, date of birth (or due date) and sex, activity records (feeding, pumping, solids, sleep, diapers, growth (weight, height, head circumference), medication, temperature, bath, notes, together with each record’s time, author and entry route), device push token, app version, operating system and device model, and purchase and subscription status.

2. Optional — profile photo, baby profile photo, the content of support enquiries and any files attached to them, and advertising identifiers (IDFA on iOS, Advertising ID on Android).

3. Automatically generated — access timestamps, app launch and error logs, and crash diagnostics may be generated and collected while the Service is used.

Collection methods: (a) entered or uploaded directly by the user in the app or on the website; (b) received from Apple, Google or Kakao within the scope the user consented to when signing in; (c) generated automatically while the app runs; and (d) provided by the user in the course of a support enquiry.

Baby information is third-party data that the user (the guardian) enters about their own child. The guardian warrants that they are entitled to enter that information and is responsible for its accuracy and for the decision to enter it.

Article 3 (Processing and retention periods)

The Service processes and retains personal data within the retention period required by law or the retention period consented to when the data was collected.

1. Member profile, baby information, activity records and uploaded photos: retained until the member withdraws (deletes their account), and destroyed without delay upon a deletion request.

2. Baby records shared by several guardians: retained while at least one guardian remains; when the last guardian withdraws, the baby information and activity records are destroyed with the account.

3. Push tokens: until notifications are turned off or the account is deleted.

4. Advertising identifiers: until the user withdraws tracking consent or resets the identifier in the device settings.

5. Crash and error diagnostics: up to 90 days from collection. This information is processed in a form that is not linked to an identified user.

6. Retention required by law: under the Act on Consumer Protection in Electronic Commerce, records on contracts and withdrawal of subscription for 5 years, records on payment and the supply of goods for 5 years, and records on consumer complaints or dispute resolution for 3 years; under the Protection of Communications Secrets Act, service use records for 3 months. Such records are stored separately from other personal data and destroyed when the period expires.

Article 4 (Provision of personal data to third parties)

The Service processes personal data only within the scope stated in Article 1, and provides personal data to third parties only where Articles 17 and 18 of PIPA apply, such as separate consent from the data subject or a specific provision of law.

The Service currently provides no personal data to third parties. It does not sell personal data or transfer it to third parties for advertising purposes.

Personal data may be provided only where an investigative authority makes a lawful request following the procedures and methods prescribed by law; even then, the Service verifies the legal basis and scope of the request and provides the minimum necessary.

When a user invites another guardian through the family invitation feature, that is record sharing chosen by the user and does not constitute provision of personal data to a third party by the Service.

Article 5 (Entrustment of personal data processing)

The Service entrusts personal data processing as set out below in order to operate the Service. In accordance with Article 26 of PIPA, the entrustment agreements specify in writing the prohibition on processing personal data beyond the purpose of the entrusted work, technical and administrative safeguards, restrictions on sub-entrustment, supervision of the trustee, and liability including damages.

Trustee: Supabase Inc. · Entrusted work: database, member authentication, file storage and serverless functions · Storage location: Amazon Web Services Seoul region (within the Republic of Korea) · Retention: until withdrawal of membership or termination of the agreement.

Trustee: RevenueCat, Inc. · Entrusted work: subscription status checks and validation of store payment receipts · Storage location: United States · Retention: until withdrawal of membership or termination of the agreement.

Trustee: Google LLC (Google AdMob) · Entrusted work: serving ads to free users and measuring performance · Storage location: United States · Retention: until withdrawal of membership, reset of the advertising identifier, or termination of the agreement.

Trustee: Google LLC (Firebase Crashlytics) · Entrusted work: diagnosing app crashes and errors · Storage location: United States · Retention: 90 days from collection.

Trustee: 650 Industries, Inc. (Expo) · Entrusted work: delivering push notifications and distributing over-the-air app updates · Storage location: United States · Retention: until withdrawal of membership or termination of the agreement.

Trustee: Apple Inc. and Google LLC · Entrusted work: processing in-app purchase payments and managing subscriptions · Storage location: United States · Retention: as set out in each store’s policy.

If the entrusted work or the trustee changes, the Service will disclose the change through this Privacy Policy without delay.

Article 6 (Transfer of personal data overseas)

To carry out the entrusted work described in Article 5, the Service transfers personal data overseas as set out below. Under Article 28-8(1)1 of PIPA a data subject may refuse consent to these transfers; refusing may limit the use of the related features (subscription payments, ad-supported free use, push notifications). Supabase, which stores the original member profile and activity records, is located within Korea (Amazon Web Services Seoul region), so it does not constitute an overseas transfer.

Recipient: RevenueCat, Inc. · Contact: support@revenuecat.com · Country: United States · Time and method of transfer: transmitted as needed over the network in encrypted form (HTTPS) whenever a subscription is checked, purchased or renewed · Data transferred: app user identifier, store purchase receipt, subscription status and expiry, device and app version · Purpose: verifying subscription status and validating payment receipts · Retention: until withdrawal of membership or termination of the agreement.

Recipient: Google LLC (Google AdMob) · Contact: dbd-google@google.com · Country: United States · Time and method of transfer: transmitted as needed over the network in encrypted form (HTTPS) whenever an ad is requested for a free user · Data transferred: advertising identifier (IDFA / Advertising ID), device and operating system information, approximate country of access · Purpose: serving ads and measuring performance · Retention: until withdrawal of membership, reset of the advertising identifier, or termination of the agreement.

Recipient: Google LLC (Firebase Crashlytics) · Contact: dbd-google@google.com · Country: United States · Time and method of transfer: transmitted as needed over the network in encrypted form (HTTPS) when the app crashes or raises an error · Data transferred: device model, OS version, app version, crash timestamp and stack trace and similar diagnostics (not linked to a user account) · Purpose: diagnosing the cause of crashes and errors and improving stability · Retention: 90 days from collection.

Recipient: 650 Industries, Inc. (Expo) · Contact: privacy@expo.dev · Country: United States · Time and method of transfer: transmitted as needed over the network in encrypted form (HTTPS) when a push notification is sent or an app update is checked · Data transferred: device push token, app version and platform · Purpose: delivering push notifications and distributing over-the-air updates · Retention: until notifications are turned off, membership is withdrawn, or the agreement ends.

Recipient: Apple Inc. · Contact: https://www.apple.com/legal/privacy/contact/ · Country: United States · Time and method of transfer: transmitted as needed over the network in encrypted form (HTTPS) when the user signs in with Apple or pays through the App Store · Data transferred: Apple account identifier, email address (to the extent the user chooses), purchase and subscription information · Purpose: social login authentication and in-app purchase processing · Retention: as set out in Apple’s privacy policy.

Recipient: Google LLC · Contact: dbd-google@google.com · Country: United States · Time and method of transfer: transmitted as needed over the network in encrypted form (HTTPS) when the user signs in with Google or pays through Google Play · Data transferred: Google account identifier, email address, profile name and photo, purchase and subscription information · Purpose: social login authentication and in-app purchase processing · Retention: as set out in Google’s privacy policy.

If you sign in with Kakao, your personal data is processed domestically by Kakao Corp. and is not transferred overseas.

Article 7 (Rights of data subjects and legal representatives, and how to exercise them)

A data subject may at any time ask the Service to give access to, correct, delete or suspend the processing of their personal data, and to withdraw consent. Where Article 35-2 of PIPA applies, the Service will also honour requests to transmit personal data.

You can exercise these rights directly in the app. Access and correction are available under Settings › Account, activity records can be edited or deleted on each record screen, and the account and all of its data can be deleted immediately under Settings › Account › Delete account. On the web, follow the instructions at https://babyflow.studiohwi.kr/account/delete.

If you cannot reach the app, you may make the request in writing or by email through the contact route published on the support page (https://babyflow.studiohwi.kr/support), and the Service will act on it without delay.

Where a data subject requests correction of an error in their personal data, the Service will not use or provide that data until the correction is complete.

These rights may also be exercised through a legal representative or an authorised agent. In that case you must submit a power of attorney in the form of Attachment 11 of the Notice on Methods of Processing Personal Information.

Requests for access or suspension of processing may be restricted under Article 35(4) and Article 37(2) of PIPA. Deletion cannot be requested where the personal data is expressly designated for collection by another statute.

The Service verifies that the person exercising the right is the data subject or a duly authorised representative.

Article 8 (Procedure and method of destroying personal data)

The Service destroys personal data without delay once it is no longer needed, for example because the retention period has expired or the purpose of processing has been achieved.

Procedure: when a user requests account deletion, the Service immediately begins deleting the profile, baby information, activity records and uploaded photos linked to that account. Where a retention period consented to by the data subject has expired but the information must still be kept under another statute, it is moved to a separate database or a different storage location.

Method: personal data held in electronic files is permanently deleted from the database and storage so that it cannot be recovered or reproduced, and any copies remaining in backups expire in turn once the backup retention cycle (up to 30 days) has passed. Personal data recorded on paper, if any, is shredded or incinerated.

Article 9 (Measures to secure personal data)

The Service takes the following measures to keep personal data secure.

1. Administrative measures: access to personal data is limited to the operator alone, and processing privileges are restricted to what the work requires.

2. Technical measures: all traffic between the app or website and the server is encrypted with TLS, and authentication secrets are stored in a form that cannot be decrypted. Row Level Security policies in the database ensure that only accounts registered as family members for a given baby can reach that baby’s records.

3. Access control: administrative console access uses least-privilege permissions and multi-factor authentication, and access logs are retained to prevent forgery, alteration, loss and theft.

4. Physical measures: the infrastructure that stores personal data is housed in data centres run by the cloud providers engaged as trustees, and physical access control follows those providers’ security policies.

Article 10 (Automatic collection devices, and how to refuse them)

The website uses only functional storage (local storage) to remember your language preference, and installs no advertising or analytics cookies.

The app may use the advertising identifier provided by the operating system (IDFA on iOS, Advertising ID on Android) in order to show ads to free users. Paid (Pro) subscribers see no ads, and no advertising identifier is collected from them.

On iOS, personalised advertising applies only where App Tracking Transparency consent has been given. You can use the app without consenting; you will simply see non-personalised ads.

How to refuse — iOS: Settings › Privacy & Security › Tracking, where you can turn off the app’s permission to request tracking. Android: Settings › Privacy › Ads, where you can delete the advertising ID or opt out of personalised ads. You can also remove ads at any time by subscribing to Pro.

Article 11 (Processing of children’s personal data)

The Service does not allow children under the age of 14 to sign up or use the Service. Any account confirmed to belong to a child under 14 is deleted without delay.

Baby information entered in the app is third-party data entered by the guardian into their own account rather than by the child, and the right and the responsibility to enter, correct and delete that information rest with the guardian.

A guardian can delete every record, including baby information, at any time through Settings › Account › Delete account.

Article 12 (Privacy officer and where to file access requests)

The Service has designated the privacy officer below to take overall responsibility for personal data processing and to handle complaints and remedies from data subjects.

Privacy officer — Name: [대표자] · Position: Operator · Contact: the email address published on the support page (https://babyflow.studiohwi.kr/support).

Department receiving and handling access requests — Department: Customer Support · Person in charge: [대표자] · Channel: the support page (https://babyflow.studiohwi.kr/support).

Data subjects may direct any question, complaint or request for remedy arising from their use of the Service to the privacy officer, and the Service will answer and act on it without delay.

Article 13 (Remedies for infringement of rights)

To obtain redress for an infringement of your personal data rights, you may apply to the bodies below for dispute resolution or advice. These bodies are independent of the Service; please contact them if you are not satisfied with the outcome of the complaint handling or remedy the Service provides, or if you need more detailed help.

Privacy Infringement Report Centre (operated by the Korea Internet & Security Agency) — Remit: reporting personal data infringements, advice · Phone: 118 (no area code) · Website: privacy.kisa.or.kr

Personal Information Dispute Mediation Committee — Remit: applications for personal data dispute mediation and collective dispute mediation · Phone: 1833-6972 · Website: www.kopico.go.kr

Supreme Prosecutors’ Office Cyber Investigation Division — Phone: 1301 (no area code) · Website: www.spo.go.kr

Korean National Police Agency Cybercrime Reporting System (ECRM) — Phone: 182 (no area code) · Website: ecrm.police.go.kr

A person whose rights or interests are infringed by a disposition or omission of the head of a public institution in response to a request under Article 35 (access), Article 36 (correction or deletion) or Article 37 (suspension of processing) of PIPA may file an administrative appeal under the Administrative Appeals Act.

Article 14 (Changes to this Privacy Policy)

This Privacy Policy takes effect on 10 September 2026.

If the policy changes because of a change in law, policy or the Service itself, the reason for and content of the change will be announced in the app and on the website at least 7 days before it takes effect. Changes that materially affect the rights of data subjects will be announced at least 30 days in advance.

Earlier versions of this Privacy Policy are available on request through the contact route on the support page.