Milson is a baby tracking app for parents and caregivers. This policy applies to the Milson app, website, and related services.
Information we collect
Account information
When you create or sign in to a Milson account, we collect the information needed to authenticate you and operate your account. This may include:
- Your email address.
- Authentication provider identifiers from Sign in with Apple or Google.
- Name information shared by your sign-in provider, when available.
- Password authentication data if you choose email and password sign-in. We do not store your password in plaintext.
Baby and family tracking information
Milson stores the information you choose to enter, including:
- Child profile details, such as name and date of birth.
- Family and caregiver membership information.
- Baby care logs, such as feeds, naps, diapers, potty or accident events, meals, medicine, temperature, growth, notes, and related timestamps.
- App preferences, such as units, theme, and saved defaults.
Technical information
We may collect limited technical information needed to run and protect the service, such as authentication, sync, and server logs; device and app version information; error information; and email delivery metadata for account messages.
Optional product analytics
Product analytics is off unless you turn on Share product analytics in the Milson app. If you opt in, Milson sends a deliberately limited set of data to PostHog. This may include your internal Milson caregiver account identifier; fixed app screen names; broad workflow, feature, and care-log categories; timing and count buckets; app release information; and limited error information, such as a general error category and code, plus a technical stack with locations and other sensitive details removed.
In analytics-enabled versions of Milson, after you sign in and complete family and child setup, Milson presents a one-time choice if that account has no recorded choice for the current analytics consent version on that device. Choosing Share product analytics grants consent; choosing Not now records a denial. Either choice leaves Milson fully functional. The choice is account-specific on that device and can be changed later in Settings → Privacy & analytics. Milson does not collect, buffer, or backfill product analytics from before you opt in.
Optional product analytics does not include your email or name as profile properties; child or family identifiers; family composition; care-record identifiers; names; notes; meal descriptions; food, medication, or symptom names; exact care values or timestamps; invite codes; raw error messages; screenshots; audio; video; or session replay. PostHog’s default device, locale, and timezone properties are disabled, IP geolocation is disabled, and the PostHog project is configured to discard IP addresses. The public Milson website does not load PostHog or another product analytics tracker.
How we use information
We use information to:
- Create, authenticate, and secure your account.
- Sync your baby tracking data across your devices.
- Show your logs, summaries, and app settings.
- Send account-related emails, including reset or verification messages.
- Diagnose bugs, prevent abuse, and keep the service reliable.
- Understand, when you opt in, whether core app workflows work and where broad usability or reliability problems occur.
- Comply with legal obligations.
Service providers
Milson relies on service providers to operate the app. These may include Supabase-compatible backend services for authentication, database, and API access; PowerSync for local-first sync; PostHog for optional, consented product analytics and sanitized app error reporting; Resend for transactional account email; Apple and Google when you choose their sign-in options; and hosting, logging, monitoring, and backup providers used to operate Milson.
These providers process information only as needed to provide their services to Milson.
Account deletion
You can initiate account deletion directly in the Milson app:
- Open Milson.
- Go to Settings.
- Tap Delete Account.
- Confirm the deletion prompts.
Deleting your account removes your Milson account from active systems and signs you out. If you are the only member of a family, Milson deletes that family and its associated child profiles and care logs. In a shared family, Milson removes your membership only when another parent remains. If you are the last parent while caregivers or other members remain, deletion stops so you can make another member a parent, remove the remaining members, or delete the family first. Milson never silently promotes a caregiver.
After deletion, you may create a new account with the same email. A new account will not automatically regain access to data deleted with the previous account.
Account deletion also removes the account-specific analytics preference from that device and stops future analytics collection for that account. Product analytics already received by PostHog may remain under the internal caregiver identifier until it expires under the retention settings then in effect. To request access to or deletion of analytics associated with an active account, email support@milson.app before deleting the account so Milson can verify the request and locate the internal identifier. After account deletion removes the account record, Milson may no longer be able to associate retained analytics with your email address.
Some information may remain temporarily in backups, security logs, or records we are legally required to keep. Backup copies are retained only for operational continuity and deleted according to our backup retention schedule.
If you used Sign in with Apple, Milson requests Apple authorization during account deletion and revokes the app’s Sign in with Apple token before deleting your Milson account.
For help, visit account deletion support or email support@milson.app.
Your choices
You can:
- Update app preferences in Settings.
- Turn optional product analytics on or off in Settings → Privacy & analytics after the initial optional choice. The choice is account-specific on each device. Choosing Not now or turning analytics off stops collection of new product analytics; neither choice affects core app features or baby tracking data.
- Sign out at any time.
- Delete your account in Settings.
- Contact us about privacy questions or data requests.
Children and caregiver data
Milson is intended for parents and caregivers to track information about children in their care. It is not intended for children to create accounts or use Milson without a parent or caregiver. Parents and caregivers are responsible for entering information they are authorized to share and manage.
Security and retention
We use reasonable administrative, technical, and organizational safeguards to protect information. No system can be guaranteed completely secure, but we work to protect accounts, authentication, and synced data from unauthorized access.
We keep account and baby tracking information while your account is active or as needed to provide the service. When you delete your account, active account data is deleted as described above. Backups and security logs may remain for a limited period.
Changes to this policy
We may update this policy as Milson changes. If we make material changes, we will update the effective date and provide notice where appropriate.
Contact
Questions about privacy or data requests can be sent to support@milson.app.