Just published Baby Tracking Field Guide Skip to main content

Wobble Privacy Policy

Last updated: 12 September 2026
Effective: 12 September 2026

Wobble provides parenting support through Coach and baby tracking through the Track iPhone app. This policy explains what data we collect when you use either product, why we collect it, who receives it, how long we keep it, and the rights you have over it. If anything is unclear, email hello@wobblelabs.uk and we’ll explain.


The short version


Who we are

Wobble is operated by Wobble Labs UK Ltd (“Wobble”, “we”, “us”), registered at 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom.

For the purposes of the UK GDPR, the EU GDPR, and similar laws, we are the data controller for the data described in this policy. You can reach us at hello@wobblelabs.uk.


What this policy covers

This policy applies to the Wobble iPhone app distributed through the Apple App Store and TestFlight, the backend services that power it, Coach at coach.wobblelabs.uk, and our website at wobblelabs.uk. It does not cover websites or services we do not operate, even if we link to them.


What we collect and why

1. Your account

Coach lets you sign in with your email address and a six-digit code, or choose Sign in with Google. Supabase Auth identifies your Wobble account across products. Resend delivers sign-in codes in the message body and subject. Older iPhone app versions use email and password; code and Google sign-in are being introduced in an app update.

If you choose Google, Google shares your account identifier, email address and basic profile with Supabase to authenticate you. We do not request access to your Google mail, contacts or files. A basic profile may include your name and picture. We do not ask for your phone number or postal address.

Cloudflare Turnstile processes browser and connection signals during Coach’s security check to help prevent automated abuse. Coach stores an authentication session in your browser so you can stay signed in; signing out removes that session from the browser. This necessary session storage is separate from the marketing website analytics described below.

2. Your baby’s profile

You give us:

This profile is stored locally and synced to our database. Anyone you authorise as a caregiver for that baby can see it.

3. Baby-care and parent logs

These are the records you create in the app: nursing, bottles, sleep, diapers, solids, pumping, and medications for the baby or, where available, for you. A log can include timestamps, amounts, durations, categories, optional notes, and identifiers showing which baby and account created or last edited it. Those identifiers let us sync changes and show shared caregivers what happened.

Manual logging is local-first and can continue without an internet connection. Pending changes sync after a connection returns. Signing in, inviting caregivers, Ask Wobble, Babble, and account deletion need a connection.

4. Feedback you send us

If you use Send Feedback, we receive your account ID, release channel, app version and build, iOS version, device model, and the message you write. If you rate an Ask Wobble answer, we also receive whether you found it helpful, its broad topic, and any explanation you choose to send after a thumbs-down. We do not include the question or answer text in that feedback. TestFlight or other pre-release builds may also include the current screen, active baby ID, recent synced log IDs, and a screenshot if you choose to attach one. This helps us understand the report and fix the problem.

Feedback is stored in Supabase and sent to our support inbox through Resend. Free-text feedback and screenshots can contain whatever you choose to include, so avoid adding information that is not needed for the report.

5. Feature and reliability telemetry

We keep limited operational records so we can enforce usage limits, diagnose failures, and understand whether features work:

6. Product analytics

We use PostHog to understand how people start using Wobble, which features they use, and where they encounter problems or upgrade to premium. Events include opening the app, onboarding steps, creating a profile or care log, receiving an Ask answer, finishing a Babble session, opening a paywall, and purchase or restore outcomes.

These events can include your Wobble account ID, an installation-level analytics identifier, event time, app version and build, device and operating-system information, feature or log category, and subscription product ID. A log event can include a record-derived identifier to avoid counting the same event twice. We link analytics to your account after sign-in and reset the analytics identity when you sign out or change accounts. An account ID is not a name, but we can connect it to your account; these records are not anonymous.

We do not send baby nicknames, dates of birth, care-log amounts or notes, question or answer text, audio, transcripts, names, or email addresses as PostHog event properties. Session replay, automatic screen and interaction capture, and automatic crash capture are disabled. We configure events to disable IP-based location enrichment. Network providers still receive connection information needed to deliver the service.

Website analytics

On wobblelabs.uk, we use PostHog to count page views and clicks through to Wobble’s App Store listing, links to Coach information and the Coach app, and selection of the Coach or Track features tab. Events include the public page path, event time, deployment environment, and campaign labels such as source, medium, campaign, and content when they are present in the link you follow. Feature-tab events contain only the fixed product label, Coach or Track. We accept only short campaign labels and exclude other query parameters, full URLs, referrers, form contents, and page text.

Website analytics uses a random identifier held in memory for each page load. It uses no cookies or browser storage, does not create a person profile, and does not link website visits to your Wobble account or App Store installation. The identifier lets us relate a page view to a product click or feature-tab selection on that page; it changes when another page loads. We respect your browser’s Do Not Track setting and disable IP-based location enrichment. PostHog still receives connection information needed to deliver the service.

7. Subscriptions and purchase history

Apple processes payments for Wobble’s monthly and yearly subscriptions. RevenueCat receives your Wobble account ID and App Store transaction information to validate purchases, restore access, and determine whether premium is active. This includes the product purchased, transaction identifiers, purchase and expiry dates, and subscription events such as renewal, cancellation, refund, or billing issues. We do not receive your payment-card or bank details.

We use RevenueCat’s subscription reports and send subscription lifecycle events to PostHog using the same Wobble account ID. This lets us understand how app use relates to subscriptions. We do not send baby-care content to RevenueCat.

Our database keeps your verified subscription status and account-linked Ask and Babble usage records to enforce free allowances across devices. Ask counts successful answers; Babble counts successfully issued voice-session access tokens, including sessions where no logs are saved. Failed answer or token creation does not consume the monthly allowance. The usage ledger does not contain questions, answers, audio, or transcripts.

8. Crash reports

If you choose to share crash reports with Apple in your iPhone settings, Apple may make crash and diagnostic information available to us through App Store Connect. We use it to find and fix bugs. Apple controls this collection and its settings.

What we do not collect for advertising

We do not use the advertising identifier (IDFA), advertising SDKs, or cross-app tracking. We do not collect your contacts, location, photo library, browsing history, search history, social graph, or Apple Health records. We do not run ads or profile you for advertisers.


Coach conversations and family context

Coach stores the messages and responses in your conversations, child and caregiver details, observations, parenting context, plans, courses, practice sessions and feedback you share or generate. These records are held in your household in Supabase so you can return to them. You can review and edit family context in Coach. Use a nickname and age where possible and avoid unnecessary identifying details in free text.

When you ask for help, OpenAI processes your message and relevant conversation and family context to generate guidance. Cloudflare hosts Coach and processes requests needed to serve the app. Operational records help us diagnose failures and enforce usage limits. AI guidance can be incomplete or wrong and is not a diagnosis or a substitute for professional care.

We keep Coach records while they are needed to provide your ongoing conversations and saved guidance, or until you request deletion, subject to lawful retention requirements. To request access, correction, export or deletion, email hello@wobblelabs.uk. Tell us whether your request covers Coach, Track or both. Provider copies may remain for security, abuse prevention or legal obligations under their terms.


Ask Wobble

When you submit a question through Ask Wobble:

  1. On your device, Wobble replaces the selected baby’s nickname and doctor names written in forms such as “Dr Smith” or “Doctor Patel”. This does not detect every name or piece of personal information. Do not include addresses, contact details, full names, or other unnecessary identifying information.
  2. The resulting question, your baby’s age and feeding method, and a topic-relevant summary of up to 14 days of recent logs are sent through a Supabase Edge Function to OpenAI or Anthropic. Supabase processes a numerical representation of the question to retrieve relevant guidance.
  3. Wobble retrieves relevant guidance and asks the configured AI provider to return an answer with sources. If the primary provider is unavailable, the request may be sent to the other provider. An AI answer can still be incomplete or wrong; Ask Wobble is not a diagnosis, medical device, or substitute for a healthcare professional.
  4. The question and answer are saved in chat history on your device. Wobble’s usage tables do not contain the question or answer text, but backend diagnostic logs can include a short excerpt of the processed question.

OpenAI says its API inputs and outputs are not used to train its models by default unless the customer opts in. We disable storage of Ask responses as retrievable API conversation state, but this does not exclude provider retention for security, abuse monitoring, or legal requirements. See OpenAI’s business data explanation.

Anthropic says inputs and outputs from its commercial API are not used to train its models by default unless the customer explicitly opts in or submits feedback. Anthropic may retain or process data as allowed by its commercial terms for service operation, safety, abuse prevention, or legal requirements. See Anthropic’s commercial data-use explanation and Commercial Terms.


Voice logging with Babble

Babble is optional voice logging, available with limits on the free plan and without that limit on premium. You can always log manually instead.

Before the first session, Wobble explains the processing and asks for microphone permission and in-app consent. During an active session:

We rely on your consent for the microphone processing in Babble. You can decline it, stop using Babble, or revoke Wobble’s microphone access in iOS Settings; manual logging remains available.

Wobble not storing an audio recording does not mean Google never retains it. Google’s standard Gemini API terms allow limited retention of prompts and responses for abuse monitoring, security, and legal obligations. Voice audio is part of the input sent to that service, and we do not promise immediate deletion or zero retention by Google. Under Google’s paid-service data-use provisions, inputs and outputs are not used to improve Google’s products. Google requires paid services for apps made available to users in the UK and EEA. Processing may occur in countries where Google or its agents operate. See Google’s Gemini API terms and data-retention explanation.


Sharing with another caregiver

If you invite another caregiver to a baby profile, they can see that baby’s profile and logs, including entries you created. You can see their entries too. Local changes are pushed to our database, and the other device fetches changes when it signs in, returns to the foreground, or is manually refreshed; this is not a promise of instant real-time delivery.

Only invite someone you trust. Removing a caregiver ends their server access, but we cannot erase copies they exported or recorded while authorised.


We use your data only as needed to:

We do not use baby-care data for advertising, sell it to data brokers, or use it for marketing without your consent.


Service providers and other recipients

These are the current providers that receive data for the functions described above:

ProviderWhat they do for usData involved
SupabaseDatabase hosting, authentication, sync APIs, and Edge FunctionsAccount, Coach conversations and family context, saved guidance, baby profile, logs, feedback, feature telemetry, subscription status and usage allowances; hosted in Ireland (eu-west-1)
PostHogProduct funnels, website campaign measurement and subscription lifecycle analyticsAccount and installation identifiers for app events, app/device information, bounded feature and subscription events; website page paths, campaign labels and per-page random identifiers; we use PostHog’s EU cloud project
RevenueCatPurchase validation, premium access, restores and subscription analyticsWobble account ID, App Store transaction information and subscription status
OpenAIGenerates Coach guidance and processes Ask Wobble questionsCoach messages and relevant conversation/family context; processed Ask questions and relevant baby/log context
AnthropicProcesses Ask Wobble questions through the Claude APIThe processed question and relevant baby/log context described above
GoogleOptional Google sign-in and active Babble voice sessions through the Gemini Live APIAccount identifier, email and basic profile for sign-in; microphone audio and instructions during active Babble sessions
ResendDelivers sign-in, account, feedback and operational emailsEmail address, sign-in code/link and message content
CloudflareHosts the website and Coach; provides Turnstile abuse protectionRequests needed to serve Coach, including submitted content; browser, IP and connection signals for delivery and security checks
AppleDistributes the app and TestFlight builds and may provide opt-in crash reportsApp Store account, purchase/distribution, and diagnostic data under Apple’s terms

These providers may use their own subprocessors. We review our provider list and will update this section when it materially changes.


Where data is processed

Coach household records and synced account, baby-profile, log, feedback, subscription-status, and operational telemetry data is hosted by Supabase in Ireland (eu-west-1). We use PostHog’s EU cloud project for product analytics. RevenueCat processes subscription records, and OpenAI, Anthropic, Google, Cloudflare and Resend process the data needed for the services described above. Provider operations and subprocessors may involve transfers outside the UK or EEA; EU hosting does not mean every supporting operation takes place only within the EU.

Where data-protection law requires it, we rely on provider data-processing terms and recognised transfer safeguards such as the UK International Data Transfer Addendum, EU Standard Contractual Clauses, or an applicable adequacy framework.


How long we keep data


Account deletion

For Coach, email hello@wobblelabs.uk to request deletion of your conversations, context and saved guidance. Specify whether you want to remove Coach data or close your shared Wobble account across both products.

For Track, you can delete your account from Settings → Delete Account while connected to the internet. Deletion removes your authentication account, account-linked Ask Wobble and Babble telemetry, server subscription-status and usage-allowance records, memberships, and local Wobble data. It does not automatically delete your PostHog or RevenueCat records; see How long we keep data.

Deleting your Wobble account does not cancel an Apple subscription. Manage or cancel it through your Apple subscription settings to stop future renewals.

If you are the only caregiver for a baby, that baby profile and its logs are deleted from our servers. If another caregiver still has access, the baby profile and logs stay with them, your membership is removed, and entries you created no longer identify your account as the author. Feedback is handled as described in How long we keep data.


Exporting data and your rights

Depending on where you live, you may have rights to access, correct, delete, restrict, or receive a portable copy of your personal data; object to some processing; withdraw consent; and complain to a regulator. To exercise a right, email hello@wobblelabs.uk. We may need to verify that the request relates to your account.

The in-app Settings → Export Data option is a convenient export for one selected baby. It currently includes the baby nickname and birth date, nursing, bottle, sleep, diaper and solids logs for that baby, plus the signed-in user’s pumping logs, in JSON or CSV. It does not currently include medications, feedback, feature telemetry, PostHog analytics, RevenueCat subscription records, or every other item associated with the account. For a complete access or portability request, email us.

You can correct most profile and log information directly in the app. You can delete the account as described above. Withdrawing Babble consent does not affect processing that already occurred while consent was valid.

For California residents: you may have the right to know, correct, and delete personal information, to opt out of sale or sharing, and not to be discriminated against for exercising those rights. Wobble does not sell personal information or share it for cross-context behavioural advertising, and has not done so in the preceding 12 months.

If you are in the UK, you can complain to the Information Commissioner’s Office. If you are in the EEA, you can contact your local data-protection authority.


Children’s privacy

Wobble is a tool for adult parents and caregivers. We do not direct the app to children or knowingly allow a child to create an account. The information recorded about a baby is entered by a parent or guardian and is protected in the same way as the account holder’s data.

If you believe a child has created an account, contact us and we will investigate and close it where appropriate.


Security

We use TLS for data in transit and the encryption and access controls provided by our infrastructure providers for stored data. Supabase Auth handles authentication, and row-level security policies limit baby-profile and log access to the account and caregivers authorised for that baby.

No system is perfectly secure. If a personal-data breach affects you, we will notify you when required by law and explain what happened and what to do.


Changes to this policy

If we make material changes, we will update the date at the top. If a change meaningfully expands what we collect or how we use it, we will provide an in-app notice before it takes effect where required or appropriate.

The latest version is always available at wobblelabs.uk/privacy/.


Contact

For privacy questions, rights requests, support, or anything else, email hello@wobblelabs.uk.

Postal address:
Wobble Labs UK Ltd
71-75 Shelton Street
Covent Garden
London WC2H 9JQ
United Kingdom


This policy is written in plain English on purpose. If a section feels unclear or you would like more detail, please ask. We would rather explain than have you assume.