Nanny Notes/Privacy Policy
Privacy Policy
Last updated: August 1, 2026
1. Scope and operator
This Privacy Policy explains how Sam Ships (“Sam Ships,” “we,” “us,” or “our”) handles information when you use the Nanny Notes iOS app, a temporary caregiver session, our website, or support services (together, the “Service”).
Operator: Sam Ships, Colorado, United States
Privacy and support: nannynotessupport@gmail.com
2. Who Nanny Notes is for
Nanny Notes is a parent- and caregiver-facing handoff tool. A parent or guardian prepares care information and chooses what to share in a temporary session pack with a nanny or babysitter. It is not intended for children to create accounts or submit information themselves.
3. Information we process
Depending on what you enter, share, or enable, we may process:
- Parent or caregiver name, phone number, email address, profile photo, and notes
- Child names, nicknames, birthdays or ages, photos, preferences, comfort items, allergies, medications, and care notes
- Pet profiles, photos, and care instructions
- Home address, Wi-Fi details, alarm codes, house instructions, emergency contacts, and routine steps
- Voice recordings, photos, short videos, titles, and related metadata
- Temporary session identifiers, hashed invite credentials, access events, timeline status, and abuse-prevention records
- A device-based anonymous authentication identifier. The current app does not ask for an account password
- An Expo push token when a parent enables sitter-join notifications
- Limited crash diagnostics, such as app and operating-system versions, device model, error type, stack trace, request time, and network information received by our infrastructure providers
- Aggregate website usage information, such as page, referrer, browser, device, and approximate location derived from network data
Do not enter information you are not authorized to provide. Share only what the caregiver needs for the specific sit.
4. Local storage and temporary sharing
The parent’s care information is local-first. Structured app data and access credentials are stored in iOS Keychain-backed secure storage. Voice recordings and selected media are stored in the app’s private files area and protected by iOS. Device backups, a compromised or shared device, screenshots, and exports can create copies outside our control.
Information is not uploaded merely because it was entered. When a parent confirms an invite, the selected session pack and its media are uploaded to private Supabase storage for that sit. The pack may include child and household information, emergency details, credentials, photos, video, and voice recordings.
The browser caregiver experience keeps its authentication token, pack, and media in memory and does not intentionally save them in browser cookies or persistent browser storage. The installed app may download a private offline copy and attempts to remove it when the caregiver leaves nanny mode or the app detects expiry.
A recipient can still copy, photograph, record, or retain information they receive. Revocation and expiry prevent future access through Nanny Notes but cannot recall copies already made by a recipient or included in a device backup.
5. How we use information
- Store and display care information on the parent’s device
- Create and deliver a session pack when the parent shares one
- Let the invited caregiver view the pack and complete or skip timeline steps
- Authenticate devices, enforce access controls, prevent invite abuse, expire or revoke access, and secure the Service
- Send an enabled sitter-join notification
- Diagnose crashes and maintain reliability
- Respond to support, privacy, safety, and legal requests
- Understand aggregate website traffic
We do not sell personal information. We do not use household, child, emergency, photo, video, or voice data for advertising, and the app contains no third-party advertising or behavioral advertising SDK.
6. Who receives information
- The caregiver selected by the parent, who receives the session pack the parent chooses to share
- Supabase, for authentication, Postgres, Edge Functions, and private session-pack storage. The production project is hosted in Canada Central
- Expo and Apple Push Notification service, when join notifications are enabled. Notification text is general and does not include a child name, medical information, address, or invite code
- Apple, as the iOS, App Store, and payment platform
- Sentry, for limited production crash diagnostics. We disable default PII, screenshots, view hierarchy, request capture, breadcrumbs, and performance tracing in the reviewed app configuration
- Vercel, for website hosting and aggregate Web Analytics
- Professional advisers, service providers, authorities, or other recipients when reasonably necessary to comply with law, protect safety or rights, investigate misuse, or operate the business
Session-pack content is not sent to Sentry or Vercel Analytics by design. Providers process information under their own terms and our applicable service agreements.
7. Retention
- Parent local data remains until the parent deletes it or uses More → Start fresh, subject to operating-system and backup behavior. Uninstalling alone may not erase iOS Keychain-backed values, so use Start fresh before uninstalling when you want to clear local data
- A cloud session can remain active for no more than 24 hours. Revoked session media and metadata are scheduled for deletion by the next hourly cleanup. Expired data is scheduled for deletion within approximately 25 hours after expiry
- Join-attempt and timeline rate-limit records are scheduled for deletion after 24 hours. Session progress is deleted with the session
- A session push token is cleared on revocation or expiry and deleted with session metadata
- Anonymous device identity/profile records, support communications, security records, and provider logs remain only as long as reasonably needed for their stated purpose, legal obligations, dispute resolution, or security
- Backups may take additional time to age out and are not ordinarily available through the Service after deletion
Cleanup is automated, but no deletion system is instantaneous or infallible. We monitor cleanup and investigate failures.
8. Your choices and privacy rights
You can edit local information, remove media, revoke a live invite, leave nanny mode, or use More → Start fresh. Starting fresh does not cancel an App Store subscription.
Depending on where you live, you may have rights to access, correct, delete, obtain a copy of, restrict, or object to processing and to appeal a privacy decision. Email nannynotessupport@gmail.com. We may need to verify the request and your relationship to the device or session. See our Data Deletion instructions.
9. Children’s information
Parents or guardians control information entered about children and authorize disclosure to their selected caregiver. Nanny Notes is not intended for children to use independently. If we learn that a child submitted personal information directly without required authorization, contact us so we can investigate and delete it as required.
10. Sensitive information and recordings
Allergies, medications, addresses, household credentials, and recordings can be sensitive. Share the minimum needed for a sit, verify critical details, and change credentials afterward when appropriate. You must obtain any consent required before recording or sharing another person’s voice or image. Do not use Nanny Notes for covert recording.
11. Website analytics
Vercel Web Analytics provides aggregate website measurements. The website does not use that analytics service to build advertising profiles.
12. Security
We use private file storage, row-level access controls, authenticated device identities, separate link and invite-code values, hashed invite codes, short session lifetimes, revocation, rate limits, bounded uploads, and automated cleanup. No security measure can guarantee absolute protection. Protect your phone and invite code and contact us promptly if you suspect unauthorized access.
13. International processing
Our providers may process information in countries different from where you live. Where required, we use appropriate contractual or other lawful transfer mechanisms.
14. Emergency and medical limitation
Nanny Notes is an information-sharing tool, not an emergency dispatch service, medical provider, or verified medical record. Information may be incomplete, stale, unavailable, or entered incorrectly. In an emergency, call the appropriate local emergency service directly and follow qualified professional guidance.
15. Changes and contact
We may update this policy as the product or law changes. We will change the effective date and provide any notice required by law. Questions or privacy requests: nannynotessupport@gmail.com.