Covers: the ParentTrap iPhone app (bundle id com.parenttrap.app) and the website at parent-trap.com Operated by: ParentTrap, United States ("we", "us") Effective: September 18, 2026 Last updated: September 18, 2026
This policy says what ParentTrap collects, why, who else touches it, how long it is kept, and how to delete it. It is written for parents, not lawyers. Where it is specific, that is on purpose. The section on health information is also our consumer health data privacy policy for the states that require one.
1. Who we are and who ParentTrap is for
ParentTrap is a chat assistant for parents. You describe your family once, and from then on every answer is about your own children rather than a generic child. It is available as an iPhone app and as a website; both use the same account and the same data.
ParentTrap is for adults. Children do not use it, and we never collect information from a child. Everything about a child in ParentTrap is written, uploaded, or approved by the parent using the account.
2. What we collect
2.1 Your account
| Data | Where it comes from |
|---|---|
| Email address | Sign in with Apple (which may give us a private relay address), Google sign-in, or the email you type |
| Display name | Apple or Google, when they provide one; otherwise derived from your email |
| Sign-in identifier | A unique id from Apple, Google, or our sign-in provider. If you create an account with a password, only a salted hash of it is stored, never the password itself |
| Google sign-in tokens (website only) | When you sign in to the website with Google, the tokens Google issues are stored with your account and used only to confirm it is you |
2.2 What you tell us about your family
Every field is optional. The app works with an empty family.
| Data | Purpose |
|---|---|
| Your first name, your role (Mom, Dad, or what you type), and your relationship status | So answers are written to you and fit your household |
| For each child: name, birth month and year (or an exact birthdate if you enter one), gender, school type, and grade | So advice is right for that child's exact age and stage. We never store an age; it is computed from the birthdate each time |
| A photo of each child, if you choose to add one | Shown next to that child in the app so you can tell them apart. Nothing else. See photos |
| The notes you write yourself about a child or the household | Treated as authoritative. The assistant may never rewrite them |
2.3 What the assistant writes down
As you talk, the assistant records durable facts it learns (a pattern, what worked, a temperament, a constraint, a medical or developmental detail you mentioned) and keeps a short prose profile per child, for you, and for the household. Each fact records when it was learned and, if it is later replaced, when it stopped being true. These are stored with your account so the next conversation starts informed. You can see them on the Family tab, delete any single fact, clear everything learned about a child with "Forget what I've learned", and edit or delete anything you wrote yourself.
2.4 Conversations
Every message you send and every answer you receive is stored so you can return to a conversation, and so the assistant can read recent turns. A title is generated from your first message. If the assistant looked something up while answering, the sources it read are not stored with the message. You can delete any conversation.
2.5 Notifications and device (app only)
| Data | Purpose |
|---|---|
| Your device's push token, the app version, and whether it is a test or store build | To deliver the evening check-in through Apple's push service. Only stored if you allow notifications |
| Your time zone (from the phone) and the check-in time you choose | So the check-in arrives in your evening |
| A record of each check-in: the question sent, when it was scheduled, whether it was delivered, and whether you opened it | So we can tell whether check-ins work and stop sending them when they fail |
2.6 Usage
In the app we record a small set of product events (the app opened, which sign-in method was used, the notification permission answered, a check-in opened, the intake form finished or skipped) with a timestamp, the app version, and your account.
On the website each page view is recorded with the page, the page that linked to it (the referrer), your browser's user agent string, and a random id stored in a cookie named pt_anon for one year. That cookie is the only cookie we set for analytics; it tells us whether two visits came from the same browser and nothing else. The website also sets the cookies needed to keep you signed in.
There is no advertising SDK, no third-party analytics, no tracking across other apps or websites, no fingerprinting, and no advertising identifier. Because we do not track, we do not need to respond to "Do Not Track" or Global Privacy Control signals, and we treat every visitor as if they were sent.
Abuse protection. The number of requests per account and per network (IP) address is counted in short windows so a script cannot run up our bills. Those counters are deleted after two days. Our hosting providers keep routine server logs, which can include IP addresses, for a short period for security and debugging.
2.7 What we do not collect
Location. Contacts. Your photo library beyond the single photos you pick. Microphone audio (dictation happens on your phone's keyboard and reaches us as text). Payment details (ParentTrap is free). Biometric data. Anything from a child directly.
3. Photos of your children
Adding a photo is optional and does nothing except show that child's face in the app.
- You pick the photo through the iOS picker; the app never sees the rest of your library.
- Before upload the app crops it square, shrinks it to at most 512 pixels, and re-encodes it. That strips the file's metadata, including the location the photo was taken.
- It is stored in a private bucket that only our server can read. The app receives a temporary link that expires within an hour.
- A photo is never sent to OpenAI or any AI model, is never analyzed, and is never used for face recognition or anything biometric.
- Replace or remove it any time on the child's profile. Removing a child or your account deletes it.
4. Sensitive details
Parents share medical, developmental, and mental-health details about a child, and sometimes about themselves. Sometimes they share family circumstances: a separation, a diagnosis, a death, a religion. If you do, in a note or in conversation, it is stored like any other fact about your family and used only to answer you. We treat it as sensitive: it is never used for anything else, never shared beyond the providers in section 6, never sold, and never used for advertising. You can remove it at any time by editing the note, deleting the fact, forgetting a child's learned profile, deleting the conversation, or deleting your account. Section 8 has more on health information.
5. How we use it
- To answer your questions with the context of your family.
- To keep a memory of your family so you do not repeat yourself.
- To send one evening check-in a day, if you turn it on.
- To sign you in and keep your account yours.
- To find and fix problems, protect against abuse, and see, in aggregate, which parts of the product are used.
- To comply with the law, and to respond to you when you write to us.
We do not sell personal information, do not share it for advertising, and do not use your conversations, notes, or photos to train AI models. Nobody at ParentTrap reads your conversations as a matter of course. A human looks at an individual account only to answer a request you made, to investigate abuse, or when the law requires it.
5.1 How the AI works
When you send a message, the server assembles what the assistant needs (your message, the recent turns of that conversation, the family details, profiles, and facts on file, your own notes, and the current date) and sends it to OpenAI's API, which generates the answer. The same happens, with less context, when the assistant updates a profile, writes a conversation title, composes the evening check-in question, or reads the notes you typed during setup.
Looking things up. For questions about development, sleep, nutrition, safety, or milestones, the assistant can run a web search through OpenAI's search tool, restricted to a fixed list of public health and child development bodies (US federal health agencies, the American Academy of Pediatrics, the American Speech-Language-Hearing Association, Harvard's Center on the Developing Child, and Nemours). The search query is written by the model from your question. Search results are used to write the answer and are not stored. The assistant never opens a link on your behalf and never sends your name or your child's name to a search engine on purpose; if the model includes a detail from your question in its query, that query is handled under OpenAI's API terms like the rest of the request.
Under OpenAI's API terms, what we send is not used to train OpenAI's models. OpenAI may keep API inputs and outputs for up to 30 days to detect abuse, then deletes them. We have turned off OpenAI's optional longer storage of responses.
6. Who else handles your data
| Provider | What they do | What they receive |
|---|---|---|
| OpenAI (United States) | Generates the assistant's answers, memory profiles, conversation titles, and check-in questions; runs the assistant's web searches | Your messages, recent conversation turns, and the family details, profiles, notes, and facts needed to answer. Never photos, never your email or sign-in identity. openai.com/policies/privacy-policy |
| Supabase (hosted on AWS, US East) | Hosts the database, file storage, sign-in for the app, and the server code | Everything in section 2, encrypted in transit and at rest. supabase.com/privacy |
| Vercel (United States) | Hosts the website | Web requests to parent-trap.com, including IP address and browser details in routine logs. vercel.com/legal/privacy-policy |
| Apple | Sign in with Apple, push notification delivery, the App Store | Your Apple sign-in identity if you use it; your device token and the text of each check-in for delivery. apple.com/legal/privacy |
| Google sign-in, only if you use it | Your Google account identity. policies.google.com/privacy |
Each of these acts as our service provider under a contract that limits them to providing the service to us and holds them to protections at least as strong as this policy. Nobody else, with three exceptions that every service has: we will disclose data if a law, court order, or government request requires it and we believe the request is valid; to protect someone's safety or our rights, for example to investigate abuse of the service; and if ParentTrap is ever sold or merged, in which case this policy continues to apply and you will be told before anything changes. If the provider list changes, this policy changes first.
7. How long we keep it
| Data | Kept |
|---|---|
| Account, family, notes, photos, learned profiles, facts, conversations | Until you delete them in the app, or delete your account |
| Push token and check-in preferences | Until you turn notifications off, sign out, or delete your account |
| Check-in delivery records | Deleted with your account |
| Usage events | Deleted with your account, except counts that no longer identify anyone |
| Website page views | Tied to the pt_anon cookie id and, when signed in, your household; the household link is removed with your account |
| Rate-limit counters | Two days |
| Provider server logs | On the provider's routine schedule, typically days to a few weeks |
Deleting your account (app: Family tab, Settings, "Delete account") removes your family, photos, conversations, learned profiles, facts, devices, and check-in records immediately, and removes your sign-in identity, so the same email can no longer sign in until it creates a fresh account. The website does not yet have its own delete button; if you only use the website, email us and the account is deleted within 7 days. Copies in our hosting provider's routine backups expire on the provider's schedule, typically within 30 days. Data already sent to OpenAI expires under their 30-day retention.
8. Consumer health data
This section is our consumer health data privacy policy under the Washington My Health My Data Act, Nevada SB 370, and the Connecticut Data Privacy Act's health provisions. It applies to everyone, not only residents of those states.
What health data we collect. Only what you choose to type or say: a child's or your own physical or mental health conditions, symptoms, diagnoses, medications, allergies, therapies, developmental delays or differences, sleep and feeding details, and the assistant's notes summarizing what you said. We do not collect health data from any other source, do not infer health conditions from unrelated data, do not use precise location, and do not use geofencing.
Where it comes from. You, in the setup form, in notes, and in conversation.
Why we collect it. Solely to answer your questions with the context of your family, to remember it so you do not repeat yourself, and to compose the evening check-in if you turn it on. Collecting it is necessary to provide the service you asked for: an answer about your own child.
Who it is shared with. Only the service providers in section 6 that need it to operate the service: OpenAI to generate the answer, and Supabase to store it. It is never sold, never shared with advertisers, never shared with data brokers, and never shared with affiliates (we have none).
Your consent. You decide whether to share health details at all; ParentTrap works without them. Typing or saying a health detail is how you consent to our collecting it for the purposes above. You withdraw that consent by deleting the fact, note, conversation, or account, and we stop using it immediately.
Your rights. You can confirm whether we hold health data about you or your child, see it, get a copy, correct it, have it deleted (including from our backups on their expiry schedule and from OpenAI under their retention), withdraw consent, and get a list of the third parties it was shared with (that list is section 6). Almost all of this you can do yourself in the app, without asking. For anything else, email the address in section 14. We answer within 45 days and never charge for a first request in a year. If we refuse a request, we say why, and you can appeal by replying to that email; if the appeal is refused you may contact your state attorney general. We will never treat you differently for exercising a right.
9. Security
All traffic is encrypted with TLS. Data at rest, including photos, is encrypted by Supabase. The app never reads the database directly; every request goes through server code that checks who you are and only ever touches your own household. Photos are in a private bucket reached only by the server, with links that expire within an hour. Secrets used to talk to OpenAI and Apple never leave the server. Access to the production database is limited to the operator.
No system is perfectly secure. If we learn that your data was accessed or disclosed without authorization, we will tell you without unreasonable delay, and in any case within the time the law requires (at most 60 days), by email, with what happened, what data was involved, and what we are doing about it. If you think your account has been accessed by someone else, email us and we will help.
10. Your choices and rights
- See and edit everything about your family on the Family tab.
- Forget what the assistant has learned about a child, keeping your own notes, or delete any single fact.
- Delete any conversation, any photo, any child, or your whole account, in the app, without contacting us.
- Turn off the evening check-in in Settings or in iOS Settings, Notifications, ParentTrap.
- Ask for a copy of your data in a portable format, ask us to correct something, or ask a question about it, at the address below. We answer within 30 days (45 for health data, as section 8 says).
By state. If you live in California, Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, Virginia, or another state with a consumer privacy law, you may have the rights to access, correct, delete, and port your data, to opt out of sale, targeted advertising, and profiling, and to appeal a refusal. ParentTrap is below the size thresholds of most of these laws, but we honor every one of these rights for everyone, and there is nothing to opt out of: we do not sell data, do not advertise, and do not profile you for decisions. To appeal, reply to our answer; we respond within 45 days. You may use an authorized agent; we will ask them to prove you sent them. California residents: we have not sold or shared personal information in the preceding 12 months, and the categories we collect are listed in section 2 and the App Store label.
Outside the United States. ParentTrap is built for parents in the United States and its advice follows US medical guidance. The website can be reached from anywhere, and everything is stored in the United States, so if you use it from elsewhere your data is transferred there. If you are in the United Kingdom, the European Economic Area, or Switzerland: our legal basis is performing our contract with you (the account and the answers you ask for), your consent for health details and photos (which you withdraw by deleting them), and our legitimate interest in keeping the service secure. Transfers to our providers rest on their standard contractual clauses. You have the rights listed above, plus the right to object and to complain to your data protection authority. We do not use your data for automated decisions with legal or similarly significant effects.
11. Children
ParentTrap is not directed at children and does not knowingly collect information from anyone under 18. Information about children in the app is provided by their parent or guardian, which the Children's Online Privacy Protection Act does not cover; we hold ourselves to its spirit anyway, which is why children's information is never used for anything but answering the parent. If you believe a child has used the app directly, email us and we will delete the account.
12. Apple App Store privacy label
- Data used to track you: none.
- Data linked to you: contact info (email address, name), user content (messages, notes, family details, photos), identifiers (user id, device push token), usage data (product events), other data (time zone, check-in time).
- Data not linked to you: none.
13. Changes
If this policy changes in a way that matters, the app will say so before the change takes effect, and the dates at the top will move. Old versions are available on request.
14. Contact
Email: mayottekyle@gmail.com Post: available on request by email App: ParentTrap (com.parenttrap.app) Website: parent-trap.com