Imma Consumer Health Data Privacy Notice
This notice covers the Imma mobile app only and supplements the Imma App Privacy Policy. It explains our practices for consumer health data under the Washington My Health My Data Act and similar US state privacy laws.
Effective date: 28 August 2026
Imma ("Imma AI: Baby Tracker") is operated by Haven AI Solutions UG (haftungsbeschränkt), Reekamp 34, 22415 Hamburg, Germany.
Categories of consumer health data
Depending on what you enter and which optional features you enable, Imma handles:
- baby profile information, including name, birth date, sex, feeding type, weeks of pregnancy at birth, birth weight and birth length;
- feeding, sleep, diaper, pumping, growth, temperature, activity, medicine and dose records;
- meals, water intake, notes, appointments, milestones and photo metadata or captions; photo files stay on your device;
- information about a parent or caregiver where it appears in pumping, medicine, note or other records;
- chat messages, AI answers and weekly AI reports; and
- account and device information used to link records to your account, operate subscriptions and protect the service.
Sources
We receive this information directly from you when you create an account, enter records, write messages or notes, and choose optional settings. If you enable Cloud Sync, we receive the records uploaded by your device. Imma also calculates limited information from what you enter, such as your baby's age and bounded weekly summaries.
Purposes
We use these categories to:
- store and display your records and, if you enable Cloud Sync, synchronize them with your account and your other devices;
- provide AI assistant answers after you grant the account-level AI-processing permission;
- generate automatic weekly AI reports only when that permission remains current and the separate default-off report toggle is also enabled;
- provide subscriptions, account support and data export; and
- secure the app, authenticate requests, prevent abuse and diagnose problems where you have enabled optional diagnostics.
Categories shared
The categories shared depend on the feature you choose:
- Cloud Sync shares the baby profile, selected settings and logged record categories listed in the Imma App Privacy Policy with our backend host. Photo files are not shared.
- AI features share your message and relevant, minimized baby-health context. Automatically constructed AI context does not include the baby's name or raw birth date, email addresses supplied by the app, account or record identifiers, photo URLs or photo files. It can include computed age and relevant health context. Text you type in messages, notes, captions or calendar items may itself contain identifiers, so the input is minimized rather than anonymous.
- Subscription, authentication and security providers receive the account, receipt, app/device-attestation or connection information needed for those functions, rather than baby-health records deliberately supplied by the app.
- PostHog and Sentry receive only the optional analytics or crash-diagnostic categories described in the main policy. The app does not deliberately include baby-health records or chat content in those transmissions.
Recipients
- Amazon Web Services hosts Imma's backend and database in N. Virginia and processes AI requests through Amazon Bedrock in the United States.
- Google provides Firebase Authentication for sign-in/account management and Firebase App Check for app/device attestation.
- RevenueCat receives subscription receipts and the opaque app user ID needed to determine subscription status.
- Apple processes App Store payments and distribution.
- PostHog receives usage analytics only if you enable them.
- Sentry receives minimized crash diagnostics only if you enable them.
We do not share consumer health data with corporate affiliates. We do not sell consumer health data, and we do not use geofences around health-care facilities to identify or track people, collect consumer health data, or send health-related messages.
Your rights and how to exercise them
You may ask us to confirm whether we collect, share or sell consumer health data about you; access that data; and provide a list of the third parties and affiliates with whom we shared it, together with a way to contact them. You may withdraw consent to future collection or sharing and ask us to delete consumer health data about you. We do not discriminate against you for exercising these rights.
- Submit a rights request: email privacy@haven-ai.eu. This is the secure request channel for confirmation, access, a recipient list, withdrawal, or deletion. You do not need to create a new account. We use proportionate steps to authenticate you and may ask for information reasonably necessary to do that. The in-app export is a convenient copy of profile and baby records, but email is the route for a complete server/provider request.
- Access or export in the app: Settings → App → Export data creates a PDF or CSV of your profile and baby records.
- Withdraw AI permission: Settings → Privacy & data → AI processing stops future AI processing immediately and turns automatic weekly reports off. It does not delete existing conversations, reports or synced records.
- Control weekly reports: Settings → Privacy & data → Automatic weekly AI reports is separate and off by default. It cannot be enabled without current AI permission.
- Stop future synchronization from a device: turn off Settings → Cloud Sync. This does not delete records already retained in your account.
- Delete the Imma account and retained records: use Settings → Danger zone → Delete account. This removes substantive data from Imma's backend and starts deletion of the Firebase sign-in identity, but it does not cancel an App Store subscription or automatically delete RevenueCat's separate customer profile. To make a complete consumer-health deletion request, including notification to processors and other recipients where required, email us before or alongside the in-app deletion. See the account-deletion page.
We respond without undue delay and within 45 days. If reasonably necessary, we may extend once by another 45 days and will tell you why during the first period. Responses are free up to twice per year; the law permits a reasonable fee or refusal for requests that are manifestly unfounded, excessive or repetitive.
If we refuse to act, you may appeal by replying to the decision or emailing privacy@haven-ai.eu with “Appeal” in the subject. We will decide the appeal in writing within 45 days and explain the result. If we deny the appeal, you may submit a complaint to the Washington State Attorney General.
When a verified deletion request covers data shared with a processor or other recipient, we notify them and require deletion where the law requires it. Imma's encrypted database backups normally expire within 14 days. Washington law allows deletion from an archived or backup system to be delayed when necessary for restoration, but not beyond six months after authentication of the request.
Contact
For questions or requests, email privacy@haven-ai.eu or write to Haven AI Solutions UG (haftungsbeschränkt), Reekamp 34, 22415 Hamburg, Germany.