Early Days ("the app") is made by Huhu. "Huhu" is the name under which the app's developer — an independent developer based in California, USA — does business; when we say "we" or "us", that's who we mean. This policy explains what we collect, why, and what control you have. The short version: your baby's data belongs to you, we use it only to run the app for your family, we never sell it, and there are no ads.
Early Days is for parents and caregivers. You must be an adult to create an account. Children do not have accounts and cannot use the app themselves. The records you create are about your baby and are entered by you — see "Children's privacy" below for exactly what that means legally, and "Your baby's data" for how we treat it.
Account information. When you sign in with Apple or Google we receive your email address, display name, and an authentication identifier. We use these to create your account and let your family members recognize you. (If you use Apple's "Hide My Email", we receive the relay address Apple gives us — that works fine.)
Baby profile and care records. What you enter in the app: your baby's first name and birth date, your unit preferences, and the care events you log — feeds (method, sides, amounts, durations), sleep, diapers, pumping, medicine doses you record, weight and height, custom trackers and medicine presets you set up, optional notes, and timestamps including which caregiver logged each entry.
Family sharing. If you invite a partner or caregiver, your family is linked by an identifier, and everyone in the family sees the same baby records and each other's display names. That sharing is the point of the feature; only people you invite can join.
Notifications. If you enable reminders we store your device's push token (including Live Activity tokens), timezone offset, and your reminder preferences so we can deliver them.
Feedback. If you send feedback we receive your message, an optional screenshot you choose to attach, and your email so we can reply.
Usage analytics. We use Google Firebase Analytics to understand app usage (e.g., which screens are used, device model and OS version). This is standard product analytics tied to an app identifier — not advertising tracking, and we don't combine it with ad networks or data brokers (we work with none).
What we do NOT collect: your location, your contacts, your photo library (the only image we ever receive is a feedback screenshot you deliberately attach), advertising identifiers. We have no third-party trackers or ad SDKs. The app does not "track" you as Apple defines it, and it does not respond to browser "Do Not Track" signals because it has nothing to track and no third-party behavioral advertising in the first place.
Care records — especially medicine logs, weight, and height — are sensitive. In some places (for example under European law) records like these count as health data and get extra protection. Here is our position regardless of where you live: we treat every baby record as sensitive, we use it only to provide the app to your family, we never sell it, never share it for advertising, and never let a third-party AI train on it. You add these records by choice, and you can delete them (or your whole account) at any time.
The audio/video monitor connects your own two devices directly, peer-to-peer, on your own network. Audio and video are never recorded, stored, or routed through our servers. Our servers only carry the small connection-setup messages (and battery level) needed to link your devices. The white-noise player is generated on your device and transmits nothing.
Where GDPR-style laws apply, our legal bases are: performing our agreement with you (storing and syncing the records you ask us to keep, delivering the app), your consent for the optional things (reminders/notifications, feedback screenshots) — and, for care records that count as health data, your explicit consent, which you give by choosing to enter them and can withdraw at any time by deleting them or your account; and our legitimate interest in basic product analytics and keeping the service secure. We don't do automated decision-making with legal effects, and we don't profile you for advertising.
We may disclose information if the law genuinely requires it (a valid legal demand), to protect someone's safety, or to defend our legal rights — and if that ever happens we'll tell you unless the law forbids it. If the app is ever acquired or handed to a successor, your data goes only with the same promises in this policy, and we'll notify you before anything changes.
Your data is stored with Google Firebase on Google Cloud servers in the United States, and Google processes it on our behalf under Google's data-processing terms. If you use the app from outside the US, your data comes to US servers — we want to be plain about that. Google LLC participates in the EU-U.S. Data Privacy Framework and its data-processing terms for Firebase include the European Commission's Standard Contractual Clauses for onward processing; we rely on those Google commitments rather than pretending we've signed separate transfer paperwork with each user. Data is encrypted in transit and at rest.
Data is encrypted in transit and at rest, access is controlled by per-family security rules (only your family's accounts can read your family's records), and we keep the data we hold to the minimum the features need. No system is perfect: if we learn of a breach that affects your personal data, we will notify you without unreasonable delay — in the app or by email — and as required by applicable law.
We keep your records for as long as your account exists. Deleting your account deletes them. Push tokens are kept only while notifications are enabled for your device. Analytics data is retained under Firebase's standard limited retention period. Feedback messages are kept as long as needed to act on them, then removed.
The app is directed to adults — parents and caregivers — and we do not knowingly collect personal information from children, online or otherwise. The information about your baby is provided by you, the parent or guardian, and is used only to provide the service to your family. (US children's privacy law — COPPA — governs data collected from children using a service; Early Days is not designed for or usable by children, and no child interacts with it.) If we learn a child has created an account, we will delete it.
Depending on where you live, privacy laws give you rights to access, correct, export, delete, or object to processing of your data. Honestly: we're a small operation, and some of these laws (like California's CCPA) technically apply only to businesses far larger than us. We don't lean on that. We give the same controls to everyone, everywhere: the in-app export and delete cover access, portability, and erasure directly; editing covers correction; and for anything else — objection, restriction, a question, or exercising a right through an authorized agent — email us and we'll handle it within the timelines the strictest applicable law would set: app_support@meethuhu.com. We will never discriminate against you for exercising a privacy right (there's nothing to discriminate with — the app is free and the same for everyone). We do not sell or share personal information as California law defines those terms, so there is nothing to opt out of. If you're in the EU/UK and we can't resolve a concern, you also have the right to complain to your local data protection authority.
If we change this policy we'll update the date above and, for meaningful changes, tell you in the app before they take effect.
Huhu — app_support@meethuhu.com — meethuhu.com
Based in California, USA.