Privacy Policy
We understand that infant feeding amounts, nappy output, and growth measurements are among the most sensitive information a family can record.
- NEVER Sold or Monetised: We never sell, rent, trade, or commercialise your child's data under any circumstances.
- Household Confidentiality: Your infant's routine care records are processed solely to provide routine tracking and sync within your household.
- Advertising & Analytics Disclosure: Milkstop does not currently deploy advertising or third-party analytics trackers. If advertising or analytics tools are introduced in the future, this policy will be updated, and Google user data will remain strictly protected under Google API Limited Use requirements.
1. Child & Minor Telemetry Transparency
Milkstop does not allow children to create accounts. The registered account holder is always an adult parent or legal guardian (18+) who voluntarily records information concerning a dependent infant (such as given name/nickname, date of birth, sex/color theme preference, feeding amounts, nappy records, and physical growth measurements).
All infant data is processed solely to calculate rolling 24-hour summaries, render local charts, and synchronise records across authorised members of your private household.
2. Categories of Information We Collect
Caregiver Account Data
Email address, given name, family name, and profile avatar supplied via Google Identity Services OAuth or email OTP authentication. We never handle or store raw passwords.
Infant Routine & Biometric Records
Feeding logs (breastfeeding latch scores, expressing side/volume in ml, bottle milk volume and type, NGT checks where enabled), nappy outputs (wet, dirty, stool consistency), physical growth measurements (weight in grams, length in cm, head circumference in cm), and personal care notes.
Technical & Network Telemetry
IP addresses, device user-agent headers, and security logs collected at the Cloudflare edge for DDoS prevention, rate-limiting, and error diagnosis.
3. Google User Data Policy & Limited Use Disclosure
Milkstop supports caregiver authentication via Google Identity Services OAuth 2.0. We adhere to the highest standards of data minimization and protection regarding Google user data:
Google Data Accessed
When you sign in using Google, Milkstop requests access strictly to basic identity scopes (openid, email, profile). We access your Google account email address, given name, family name, profile avatar URL, and Google subject identifier (sub). Milkstop never requests or accesses sensitive or restricted Google APIs, including Google Drive, Gmail, Google Contacts, Google Calendar, or device location data.
How Google User Data is Used
Google user data is used solely and strictly to:
- Authenticate your identity and create your caregiver user profile.
- Display your name and avatar to other authorised members within your private household so everyone knows who logged a feed or nappy change.
- Deliver critical security and policy notifications regarding your account.
Sharing, Advertising & AI Training Prohibitions
- We never sell, rent, or trade Google user data to any third party.
- We never transfer or share Google user data with data brokers, ad networks, or third-party marketing companies.
- We never use Google user data to serve retargeted or behavioral advertisements.
- We never use Google user data to build, train, or fine-tune generalized machine learning or artificial intelligence models.
- Google data is transferred only to our secure technical infrastructure sub-processors (Cloudflare D1 database and Cloudflare Pages/Workers compute) solely to host and execute the application.
Google API Services Limited Use Statement
Milkstop's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
4. Cookies & Client-Side Storage
Milkstop uses storage mechanisms solely for essential operational, security, and offline synchronisation functions:
| Storage Type | Purpose | Classification |
|---|---|---|
HTTP-Only Cookie (nourish_session) |
Maintains cryptographic session token over HTTPS; inaccessible to JavaScript. | Strictly Necessary |
IndexedDB (idb) |
Stores cached care events and offline outbox queue for network resilience. | Core Functional |
| LocalStorage | Stores active tab view and theme preferences. No tracking IDs. | Functional Preference |
5. Third-Party Sub-Processors
We rely on enterprise sub-processors bound by strict confidentiality and data protection agreements:
- Cloudflare, Inc.: Global edge network, web hosting (Pages), serverless execution (Workers), and managed encrypted relational database (D1).
- Google LLC (Google Identity Services): OAuth 2.0 authentication to verify caregiver credentials without password storage.
- Resend, Inc.: Transactional email delivery service used to dispatch one-time passcode (OTP) verification emails when logging in via email.
6. Data Retention, Self-Service Erasure & Google Data Deletion
Retention Duration: We retain your account details and care logs only for as long as your account remains active and registered, or as required to fulfill the purposes set out in this policy.
Self-Service Deletion: You have an absolute right to permanently delete your personal data, Google user data, and care records at any time:
- In-App Self-Service: Navigate to Settings > Danger Zone > Delete Account and confirm by typing
DELETE. - Sole-Member Households: If you are the only caregiver in your household, executing account deletion permanently purges your account, Google profile identifiers, registered infants, and all historical feeding, nappy, and biometric records from our primary Cloudflare D1 production database.
- Shared Households: If you share a household with another caregiver, your user profile and authentication credentials (including Google user ID) are permanently deleted and unlinked. Infant care logs remain accessible to surviving household members to ensure continuity of your baby's routine, with your personal identification completely removed.
- Client Wipe: Executing account deletion immediately wipes your browser's IndexedDB offline storage, local storage, and expires your authentication session cookie.
- Manual Request by Email: You may also email hello@milkstop.app at any time to request the complete deletion of your account and all associated Google user data. Deletion requests are processed and confirmed within 30 days.
7. Security Safeguards
We implement rigorous technical and organizational safeguards designed to protect personal and infant care data against unauthorized access, loss, alteration, or disclosure:
- TLS/HTTPS Everywhere: All data in transit between your browser and our edge servers is encrypted using modern TLS 1.3 cryptographic protocols with HSTS enforcement.
- Zero-Trust Edge Architecture: Compute and storage are managed on Cloudflare's serverless infrastructure with strict principle-of-least-privilege access controls.
- Encrypted Session Tokens: Authentication tokens are signed with HMAC-SHA256 and stored in secure,
HttpOnly,SameSite=Lax, encrypted cookies inaccessible to third-party client scripts. - No Password Storage: By utilizing Google Identity OAuth 2.0 and passwordless email OTPs, Milkstop never collects, stores, or handles plaintext or hashed user passwords.
8. Your Rights & Contact Information
Under the Australian Privacy Act 1988 (Cth), the European GDPR, and international privacy frameworks, you possess rights to access, correct, delete, or request data export of your records.
For privacy inquiries, data export requests, Google user data queries, or complaints, contact our Privacy Officer at:
Entity: Milkstop
Official Website: https://milkstop.app
Privacy Email: hello@milkstop.app
Jurisdiction: Queensland, Australia
Supervisory Authority: Office of the Australian Information Commissioner (OAIC) — oaic.gov.au