๐ before you download
What baby-tracking apps actually do with your data, and how to check before you download
The Baby Suite team ยท Published 10 August 2026 ยท Last reviewed 10 August 2026
A feed log doesn't sound sensitive until you list what's in it: when your baby eats and sleeps
(so, when your home is asleep), your child's name and birth date, growth measurements, medicines
and doses, sometimes a note about a rough night written at 3am in your own words. Under European
law, most of this is health data, the most protected category there is. A baby app is asking you
to hand over more intimate information than your banking app ever sees.
The good news: you can learn most of what you need to know in about ten minutes, before
installing anything, from the app's own store page. Here's exactly where to look.
Step 1: find the Data safety section
On any app's Google Play page, scroll past the screenshots and ratings to the block called
Data safety, then tap See details. Every app has had to fill this in since 2022.
It has three parts, and they mean different things:
- Data shared: what the app passes to other companies. This is the one to read
first. For a baby app, ideally this section is empty or close to it.
- Data collected: what the app gathers and keeps on its own servers. A tracker will
legitimately collect a lot here; the question is whether each item has an obvious reason.
- Security practices: encryption, deletion, and whether you can ask for your data
to be removed.
๐ Google explains every label in its
Data safety help page.
It's worth a skim once, so the vocabulary is familiar.
Step 2: know what the labels actually promise
Three labels do less work than they appear to:
- "Data is encrypted in transit" promises only that data is encrypted on the way
to the server. That's table stakes; your connection to almost every website works this way.
It says nothing about how data is stored, who can query it, or what it's used for.
- "No data shared with third parties" uses a narrow definition of "shared". Data sent
to companies acting as the developer's service providers (analytics, crash reporting,
cloud hosting) can fall outside it. The privacy policy is where those names appear.
- "You can request that data be deleted": note the word request. It's weaker
than a delete button in the app that works on the spot. If deletion matters to you, look for
an in-app path, not an email address.
And one thing to know about the whole section: it is self-declared. The developer fills
in the form; Google doesn't audit every claim (the
developer-side rules
say as much). That doesn't make it useless (a false declaration is grounds for removal, so
developers have a real incentive to be accurate), but it does mean the section is the app's
claim, not a certificate.
Step 3: the two-minute cross-check
Because it's self-declared, spend two more minutes checking the claim against the two links
every store page must carry:
- The privacy policy (linked at the bottom of the listing). You're not reading all of
it. Search the page for three words: advertising, partners, and retention.
An app whose Data safety says "nothing shared" but whose policy mentions advertising partners
has answered your question, just not the way its store page did.
- The account deletion link (also required now). Tap it. If it leads to a working
page that explains what gets deleted, that's a good sign someone built the unglamorous parts
properly.
Red flags that should end the conversation
- Location or advertising ID under "Data shared" in a baby tracker. There is no
feature a sleep log needs your location for.
- A free app with no visible way of making money. Servers cost money; if you can't see
what pays for them (a paid tier, a subscription), the data often does. "Free" plus ad SDKs
plus health data is the worst combination on the store.
- "Data can't be deleted". The label exists, and some apps ship it. For a diary of your
child's first years, that's disqualifying.
Green flags worth noticing
- A named data location ("stored in the EU") rather than silence. It means the
developer thought about jurisdiction.
- Export that works without paying. Portability is your right in the EU regardless of
plan; an app that paywalls it is telling you how it thinks about your data.
- A changelog or "what's new" page that mentions privacy work. Teams that talk about
this in public tend to be the ones actually doing it.
- The app works before you create an account, or offers a demo. Collecting nothing is
the strongest privacy practice there is.
None of this requires trusting anyone's marketing, ours included. The point of the
ten-minute check is that it works on any app, and the apps that pass it tend to be the
ones built by people who expected to be checked. that's the real signal โ
Try it: the ten-minute check in ten seconds
We built a small free tool that runs this exact check for you: paste any Google Play link
and see the app's own Data safety declaration laid out under these headings, green and red
flags first. No score, no ranking: the reading is still yours.
Open the app privacy check →
โ How Baby Suite handles this
We build a baby tracker, so here is our own page held to the same checklist: our
Data safety section
declares health data collected, nothing shared with third parties for advertising, and in-app
deletion; data is stored in the EU; export and deletion are free on every plan and work from
inside the app, on the spot; there are no ads and no ad SDKs; Baby Suite is paid for by its
Premium subscription, so you can see what pays for the servers. The demo on
nest.babysuite.app runs entirely in your
browser with no account. Where we're not perfect: our AI features send the inputs a feature
needs to Google's Vertex AI when you use them (never for training), and that trade-off is
documented in our FAQ rather than hidden.