Privacy Policy

Last updated September 30, 2026

Baton: Baby Tracker (“Baton”) is an iOS app that parents use to record their child's feeds, sleep, diapers, growth and vaccinations. Baton is developed by Dao Van Thuong, an independent developer (“we”). This policy explains where the data you log is stored, who can see it, and what leaves your device.

Summary

  • Your baby's data is stored on your device and, if you use iCloud, in your own iCloud database through Apple's CloudKit.
  • Baton has no server and no accounts. We have no access to the data you log.
  • Baton has no analytics, no crash-reporting SDK, no ads and no tracking.
  • The only third-party service is RevenueCat, which processes Baton Plus purchases. It receives no data about your child.
  • Health and routine data about your child is never sold or shared.

What you enter

You may enter: your baby's name or nickname, birth date and sex (optional); entries such as feeds (side, duration, amount, milk type), pumping, solids, sleep, diapers, weight, length, head circumference, vaccine doses and notes; and your settings and reminders.

Baton does not ask for your real name, email, phone number or location, and does not access your camera, contacts or Apple Health. Baton never reads your photo library: when you add a photo to a Moment or a birth announcement card, you pick it with the iOS photo picker and only that photo is used, on your device. Baton saves to Photos only when you tap Save to Photos.

Where your data is stored

On your device: every entry is stored in Baton's private storage on your iPhone or iPad (shared only with Baton's own widgets and Live Activity).

In your iCloud: if you are signed in to iCloud, Baton syncs through CloudKit into the private database of your Apple ID. This data lives in your iCloud account, is governed by Apple's privacy policy and counts toward your iCloud storage.

Encryption: your baby's name and birth date, notes and the details of each entry are stored in CloudKit's end-to-end encrypted fields (encryptedValues) — only devices signed in to your iCloud, or to the iCloud of someone you invited, can decrypt them. The type of entry, its start and end times, the child's sex, the chosen vaccine schedule and the display name of the person who logged it are stored as standard iCloud fields, which Apple encrypts in transit and at rest.

We run no server and have no access to any user's iCloud private or shared database.

When you share with someone

When you invite your partner or a caregiver, Baton uses CloudKit sharing: your family's log is shared with their Apple ID, and they read and write it through the shared database in their iCloud. The person you invite can see and edit the whole shared log, including the display name of whoever logged each entry.

You can stop sharing or remove a participant at any time in More › Partner & sync; an invited person can also leave on their own. Share only with people you trust.

Purchases (RevenueCat)

Baton uses RevenueCat, Inc. to manage Baton Plus purchases. When the app starts and when you buy or restore, the RevenueCat SDK sends to its servers:

  • An anonymous app user ID generated by RevenueCat — not your name, email or Apple ID.
  • Your Baton Plus purchase history and subscription status, from the App Store receipt.
  • Technical details needed to validate purchases, such as the app version, iOS version and App Store country.

This data is used only to determine whether you have unlocked Plus. RevenueCat receives no data about your child. Payment is handled by Apple; we never see your card details.

Analytics and tracking

Baton contains no analytics SDK, no crash-reporting SDK and no advertising SDK, and does not track you across other apps or websites.

Apple may give developers aggregate, anonymous statistics (such as download counts) through App Store Connect, and crash reports only if you turned on “Share with App Developers” in iOS settings. These reports do not contain the data you log in Baton.

To offer you an update, Baton asks the App Store at most once a day which version is current. That request goes to Apple and carries only Baton's app identifier and your App Store country — nothing about you or your child.

If this ever changes, this policy and the App Store privacy label will be updated before that build ships.

Your child's data is never sold or shared

We do not sell, rent, trade or share health or routine data about your child with anyone — advertisers, data brokers, insurers or researchers — and we do not use it for advertising or to train AI models. In fact, we never receive it.

Notifications, exports and sharing you start

Reminders (the next nap window, vaccine doses, your own reminders) are local notifications scheduled on the device. iCloud may send silent notifications to signal that there are changes to sync; they are sent by Apple and contain none of your data.

When you export a CSV or a PDF report, the file is created on the device and goes wherever you choose in the iOS share sheet. If you email support, the email goes through your own mail app.

Children's privacy

Baton is made for parents and caregivers. It is not directed at children, is not intended to be used by children and is not in the App Store's Kids category. We do not knowingly collect personal information from children under 13 (or the equivalent age where you live).

Information about a child is entered by their parent or caregiver, is stored on that adult's devices and in their iCloud, and is never sent to us. We follow data minimization: a nickname is enough, no full name is needed. If you believe we have received personal information about a child, email us and we will delete it.

Retention and deletion

Data is kept until you delete it. You can delete a single entry or a child, or use Settings › Delete all data, which wipes the data on the device, deletes Baton's data zone in iCloud and stops sharing. You can also manage Baton's iCloud data in Settings › [your name] › iCloud.

Deleting the app removes only the copy on that device; the iCloud copy remains until you delete it as described above.

Your rights

Because there are no accounts and we hold none of your data, there is no record on our side to access, correct or erase — you have direct control in the app and in iCloud, and you can export everything to CSV at any time. This applies wherever you live, including under the GDPR, the CCPA and Vietnam's personal data protection rules. If you want RevenueCat to delete the anonymous ID linked to your purchases, email us.

Changes

When this policy changes, the date at the top of this page changes with it. Material changes will be mentioned in the App Store release notes.

Questions about privacy? Email vanthuong.dao2004@gmail.com