Privacy policy
This policy covers LittlesLog, Challenge, and this public information website. LittlesLog is for adult parents and caregivers; children do not create LittlesLog accounts.
Account and Google sign-in information
Our shared authentication service, Supabase, receives a provider identifier and the email address, name and basic profile information made available by your chosen sign-in provider. Google may also provide a profile picture. We use this information to authenticate you, maintain your session, display account information and secure account actions. LittlesLog supports Sign in with Apple, including Apple private relay email addresses, and Google sign-in. The upcoming Challenge iPhone release also includes Apple sign-in. Your Apple or Google password is not collected by LittlesLog or Challenge.
Challenge also supports email links and email/password sign-in through Supabase. Resend delivers account emails for our shared authentication service. It processes recipient email addresses, message content (including sign-in links or verification codes) and delivery information. Email open and click tracking are disabled. We do not use Google account information for advertising or sell it. Our use and transfer of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.
LittlesLog data
We store the child profile and care information you choose to enter: name, birth date, optional profile photo, feeding and pumping records, sleep and diaper logs, foods and allergen tracking, growth measurements and information used for growth charts, daily notes, photos and other care records. Records include dates, child identifiers and, where applicable, the caregiver who created them. Family memberships, roles and access schedules determine access.
These records support logging, history, growth displays and synchronization between authorized caregivers. Some records can contain sensitive health information. Only enter information you are authorized to provide.
Current account-backed records are stored through Supabase and cached on your device. Older local or iCloud records may be imported into your account while preserving the originals during migration. iCloud continues to handle original records and any associated legacy sharing until that migration and cleanup are complete.
Challenge data
Challenge stores the profile details you provide, such as your display name, username and optional avatar, along with challenge details, invitations, participation, scores, verification status and results. Profiles help other Challenge users find and recognize you. Participants can see information shared through their challenges and leaderboards. Uploaded profile pictures are served through public image links; do not upload a sensitive image as your Challenge avatar.
If you enable health verification on a supported device, Challenge requests permission to read the activity information needed to calculate scores, such as steps, walking or running distance, workouts and active energy. It calculates scores from this information and sends the score and verification information to the backend for the challenge. Other participants can see your resulting scores. You can revoke health access in your device’s settings. Health information is not used for advertising.
Challenge can read permitted activity in the background to keep competition scores up to date. It stores a phone identifier and activity-source information to enforce one-phone scoring during a competition. Personal activity summaries and manual edits to those summaries stay on your phone. If notifications are enabled, device push tokens and preferences are stored so Apple Push Notification service or Firebase Cloud Messaging can deliver Challenge notifications.
When you report content or behavior, Challenge stores your report reason and description, the relevant account/challenge identifiers, and a limited snapshot of the reported profile or challenge. Reports are visible to their author and the app operator for investigation, not the reported competitor. Block choices are stored to control discovery, invitations and notifications. Limited safety evidence may be retained to investigate abuse after an account is deleted; contact support about privacy or deletion requests.
Who receives information
- Your authorized caregivers or challenge participants: information shared through the relevant app features.
- Service providers: Supabase processes account and synchronized app data; Resend delivers authentication emails; Apple and Google process sign-in information and notification delivery; Apple processes legacy iCloud data. This website is hosted through OpenAI Sites and its hosting infrastructure.
- Support: when you email us, we receive your email address and the information you include so we can respond.
LittlesLog and Challenge share authentication infrastructure, but app enrollment and access to app records are separate. Signing into LittlesLog does not make your baby’s records visible to Challenge users. We may disclose information when required by law or necessary to address abuse or a security incident.
Security, hosting and retention
We use encrypted network connections, secure session storage and backend access controls. These measures do not make the service end-to-end encrypted. Service providers may process information outside your country and keep operational logs, such as request time, IP address and error information, to operate and protect their services.
We retain account and app data while needed to provide the service, subject to your deletion choices. Deleted information may remain temporarily in provider backups or operational logs until those are rotated or expire under the provider’s retention settings. We do not promise immediate removal from every backup. Limited information may be retained when legally required or needed to resolve a security incident.
Delete your account and manage your data
In LittlesLog, open Family → Account → Delete account. Confirm deletion and verify your identity with your sign-in provider. This removes your LittlesLog account and caregiver memberships. If another caregiver still has access to a child, that child’s shared history is preserved for them and structured attribution to your account is removed. If you are the last caregiver, the child and associated account-backed records are deleted. Names written into shared free-text notes are not automatically erased.
Legacy iCloud cleanup may need a network connection and time to synchronize. Histories shared with other iCloud participants are preserved for those participants. Copies exported or saved by others are outside the app’s control.
If you also use Challenge, deleting LittlesLog preserves your Challenge account and the shared authentication identity that Challenge still needs. Deleting Challenge likewise preserves LittlesLog when it still needs that identity. When neither app needs it, the shared authentication identity is removed. Deleting an app account does not delete your Apple or Google account.
You can edit information through the app, export available LittlesLog activity logs, manage caregiver access, and contact us about access, correction, deletion or other privacy rights that apply where you live. We may ask for enough information to verify that you are authorized to make the request.
This website
These pages do not contain advertising, analytics scripts, tracking pixels, sign-in forms or file uploads. Hosting providers may process ordinary connection information to serve and secure the website. Email links open your own email app.
Updates and contact
We will update this page and its effective date when our practices change. Material changes that require additional notice or consent will be handled as applicable.
Privacy questions: ddbarron48176@gmail.com. Please do not send passwords, sign-in codes or sensitive child photos by email.