Imma App Privacy Policy
This policy covers the Imma mobile app only. It is a different document from the Haven AI website privacy policy, which covers visitors to haven-ai.eu and our consulting business. Nothing on this page describes the website, and nothing in the website policy describes the app.
Effective date: 28 August 2026
Imma ("Imma AI: Baby Tracker", "the app") is a baby-tracking app operated by Haven AI Solutions UG (haftungsbeschränkt), Reekamp 34, 22415 Hamburg, Germany ("we", "us"). This policy explains what data the app handles, why, and the choices you have.
The short version: your baby's records are stored on your device, and they stay there unless you turn on a feature that sends them somewhere. Cloud Sync, AI processing, automatic weekly AI reports, usage analytics and crash reporting are all optional. Before the first AI disclosure, Imma asks for a separate account-level AI permission that you can withdraw in Settings. We show no ads and do no cross-app tracking.
1. Who is responsible
Haven AI Solutions UG (haftungsbeschränkt) is the data controller for the processing described here. Contact: privacy@haven-ai.eu. Company details are in our Legal Notice.
We have not appointed a data protection officer. Under § 38(1) BDSG an appointment is required where at least 20 people are constantly engaged in the automated processing of personal data, and we are well below that threshold. The headcount-independent cases in § 38(1) sentence 2 BDSG turn on whether the processing is "large scale" within the meaning of Art. 37(1)(c) GDPR; on the size of our user base, that test is not met today. Because Imma processes health data, we keep this under review as the app grows, and we will appoint a data protection officer and say so here if the position changes. For any data protection matter, write to privacy@haven-ai.eu.
2. What the app collects, and where it goes
2.1 Account data
To use Imma you need an account. We process your email address and, if you sign in with Google or Apple, the basic profile that provider shares (name, email). Sign in with Apple lets you hide your real address, and we work fine with a relay address. Sign-in and account management are operated by Firebase Authentication (Google LLC); passwords are handled entirely by Firebase and never reach our servers. Firebase Authentication also processes user-agent and IP-address information for security and abuse prevention, and says logged IP addresses are kept for a few weeks. Firebase processes Authentication data in the United States. Your account is identified internally by an opaque user ID.
Firebase App Check is separate from user sign-in. It obtains app/device-attestation material to help establish that requests come from an authentic app or device; it does not grant AI permission or replace our own server-side access checks. Imma's custom backend does not currently enforce App Check tokens.
2.2 The records you enter
Feeding, sleep, diaper, growth, medicine and medicine adherence, pumping, temperature, activity, notes, calendar events and milestones, and your baby's profile (name, birth date, sex, feeding type, and — where you have provided them — weeks of pregnancy at birth, birth weight and birth length) are written to a database on your device.
Some of this is health data about your child, and some of it is health data about you. It is treated as special-category data under Article 9 GDPR throughout this policy.
By default these records stay on the phone. Three things can send them off the device, and each is described below: Cloud Sync, the AI assistant, and weekly AI reports. If you use none of them, your records never leave the phone. In that case, if you delete the app without exporting first, the data is gone, because we hold no copy.
2.3 Photos
Baby photos you add are stored on your device. The image files themselves are never uploaded, including when Cloud Sync is on. Only the record that a photo exists, and the details you attach to it such as the date and caption, is synced.
2.4 Cloud Sync (off by default)
Cloud Sync is a switch in Settings → Cloud Sync. It is off when you install the app. Before it can be enabled for an account on a device, Imma shows the same confirmation in Settings and during onboarding. It identifies the baby profile and every logged record category uploaded to your account: sleep, feeding, diaper changes, growth, pumping, medicines, medicine dose logs, temperature, activity, meals, water intake, notes, appointments, milestones and photo metadata. Photo metadata is included; photo files stay on your device. It also identifies the settings that sync: unit system, activity level, stored pre-pregnancy weight, stored height, stored daily calorie goal, medical-disclaimer acceptance, medical-disclaimer acceptance time, daily reminder setting and daily reminder time. Nothing is uploaded unless you affirmatively select Turn on Cloud sync.
When you turn it on, those records and settings are copied to your account on our backend, which runs on Amazon Web Services in the United States (N. Virginia). They are linked to your opaque user ID; we do not attach your email address or name to the synced records.
Four things worth knowing:
- It is per device. Turning Cloud Sync on for one phone does not turn it on for any other device on the same account. Each device asks separately.
- It only runs while the app is open. Imma does no background syncing, so changes travel when you next open the app, not while it is closed.
- It does not authorize an automatic weekly report. Reports require the separate choices described in 2.6.
- Turning it off stops future uploads but does not delete what was already uploaded. Your records stay on your device and stay in your account. To remove the copy we hold, delete your account (section 7).
2.5 AI assistant
AI processing is optional. Before the first message or other AI use can disclose anything, Imma asks for an account-level AI processing permission. It applies to every baby profile in that account and is not part of accepting the Terms or mandatory onboarding. If you decline, ordinary baby tracking remains available and nothing from the attempted AI use is persisted to our backend, retrieved for AI context or sent to a model. You can later allow or withdraw it under Settings → Privacy & data → AI processing. Missing, expired or unverifiable permission is treated as no permission.
When you send a message after granting that permission, up to four things happen. The three model-processing steps use Amazon Bedrock. The relevance classifier and the model that writes the reply use Bedrock's United States cross-region inference service, which can process a request in N. Virginia, Ohio or Oregon depending on capacity. The retrieval-embedding step runs only in N. Virginia. This is separate from our backend and database storage location, which remains N. Virginia. AWS operates model execution in Bedrock-controlled deployment accounts and states that model providers do not have access to customer prompts or completions.
First, only the text of your new message is sent to a small relevance and abuse classifier. It receives no earlier conversation, baby records, account details or email address. If it classifies the message as off-topic or abusive, the later retrieval and reply-writing steps do not run and the app stores a fixed reply instead.
Second, if the message continues, its text is converted to a numerical embedding to work out which parts of our own reference material are relevant to your question. Only the text of your message is sent to the embedding model for this: not your baby's records, not your account details, not your email address. Your baby's age is used alongside it to narrow that reference material to the right age range, but it stays inside our own systems and is not sent on.
Third, your message and the context needed to answer it are sent to the model that writes the reply. The automatically constructed context does not include your baby's name, raw birth date, your email address, account identifiers, record or conversation IDs, photo URLs or photo files. It can include computed age; where you have provided them, sex, feeding type, weeks of pregnancy at birth, birth weight and birth length; recent feeding, sleep and diaper summaries; temperature readings, including the most recent reading, the highest reading of the last seven days and how many readings there were; growth measurements; the names of active medications, together with how many doses were taken, skipped or missed in the last seven days; and the text of your five most recent notes. Your earlier messages in the same conversation are sent as well, so the assistant can follow the thread.
This context is minimised, not anonymous. Messages and notes are text you enter yourself and may contain names or other identifiers. We do not attempt to guess and remove every possible identifier from that user-entered text.
Fourth, your messages and the assistant's replies are stored in your account on our backend, and a copy is kept on your device. The History screen in the app shows you the copy on your device.
That distinction matters when you clear your history: clearing chat history in the app removes the copy on your device, not the copy in your account. The copy we hold is removed when you delete your account (section 7).
This happens whether or not Cloud Sync is on, only when you use the assistant, and only while current AI permission remains granted. Withdrawing AI permission blocks future AI processing immediately but does not delete earlier conversations or replies. The assistant is a subscriber feature.
2.6 Weekly AI reports
Automatic reports require two account-level choices: current AI processing permission and the separate Automatic weekly AI reports toggle under Settings → Privacy & data, which is off by default. Cloud Sync alone does not authorize a report. The report toggle cannot be enabled without current AI permission. Withdrawing AI permission switches automatic reports off; granting AI permission again does not silently switch them back on.
When both choices remain on and eligible records have been uploaded through Cloud Sync, our backend can generate a weekly report automatically, once a week, without another action at that moment. It sends the reply-writing model on Amazon Bedrock a bounded structured summary of the current week, with limited comparison figures from the previous week where available. The supported record categories are sleep, feeding, diaper changes, pumping, medicines and medicine-dose logs, growth and temperature. The timeline can include bounded text and metadata from notes, calendar events, milestones and photo records: dates, titles or text, categories, completion state, intensity, photo captions and photo milestone tags. Activity, meal and water-intake records are not included in the report input. The image files themselves, your baby's name or raw birth date, account or record identifiers, internal IDs and photo URLs are not sent. The profile context can include computed age and — where you have provided them — sex, feeding type and weeks of pregnancy at birth. Birth weight and birth length are not included. Reports use neutral wording such as “your baby.” Text you entered in notes, captions or calendar items can still contain identifiers, so this model input is minimised rather than anonymous. The resulting report is stored in your account.
Turning Cloud Sync off stops future synchronization from that device, but does not delete records already retained in your account. If AI permission and Automatic weekly AI reports remain enabled, an otherwise eligible report may use those retained records. Withdrawing AI permission stops future AI processing immediately and also turns the report toggle off, but does not delete an existing report, conversation or synced record. Deleting your account removes those records through the process in section 7.
2.7 Subscriptions
Payments are processed entirely by Apple; we never see your payment details. We use RevenueCat to know whether your subscription is active. RevenueCat receives your purchase receipts and your app user ID, which is the same opaque identifier used for your account.
2.8 Usage analytics (opt-in)
Only if you turn it on — at the first-run prompt or in Settings → Privacy & data — PostHog (United States) receives only these app-generated custom events: account_deleted without properties; app_error and app_crash, each with a fixed severity flag and a code-defined error-type label; and app_failure with a code-defined failure-type label. Automatic lifecycle, screen, session-replay, feature-flag, survey, push, rage-click, native-error and log capture are disabled. To operate its SDK, PostHog also receives an opaque Firebase account identifier, a random persistent app-install identifier, and technical app/device metadata such as app and operating-system version, device model/type/name, screen dimensions, locale, time zone and network type. Like any online service, it receives the network address used to connect; depending on the live project setting, it may retain that address or derive an approximate location from it. The app does not deliberately submit baby-record or chat payloads. Analytics are disabled by default and can be withdrawn independently at any time.
2.9 Crash reports (opt-in)
Crash reporting is a separate choice from analytics. Only if you enable it, minimised technical diagnostics such as stack traces, device model and OS version are sent to Sentry (United States) so we can fix bugs. Before sending, the app sanitises messages, exception values and other known sensitive fields, disables Sentry's default collection of personally identifying information, and does not deliberately attach your account identity. These controls reduce the risk of personal or health-related information appearing in a diagnostic report, but no sanitiser can guarantee removal of every sensitive value from every unexpected error. Crash reporting is disabled by default and can be withdrawn independently at any time.
2.10 On your device only
Reminders and notifications are generated locally on the device — the app has no push notification service. If you use the home-screen widget or Live Activity, your baby's name and recent sleep timings are shared with that widget on your own device, which means they can appear on your lock screen.
3. What we do not do
- No advertising and no advertising SDKs.
- No cross-app tracking, no device fingerprinting, and no use of Apple's advertising identifier. The app never shows Apple's tracking prompt because it does not track.
- No sale or rental of personal data.
- No sharing of your records with other users. Imma has no social or sharing features.
4. Legal bases (GDPR)
- Contract (Art. 6(1)(b)): creating and operating your account, managing your subscription, and delivering the non-AI features you have signed up for. Storing your records on your own device is part of providing the app.
- Consent (Art. 6(1)(a), and Art. 9(2)(a) where health data is processed): Cloud Sync; account-level AI processing; the separate, default-off automatic weekly-report choice; usage analytics; and crash reports. Each relevant control is off until you choose it. AI permission is obtained just in time before the first AI disclosure, recorded and enforced by our backend, and can be withdrawn under Settings → Privacy & data.
- Contract (Art. 6(1)(b)): RevenueCat processing needed to determine and restore the subscription access you bought through Apple.
- Legitimate interest (Art. 6(1)(f)): essential security, abuse prevention and service integrity on our servers, including privacy-minimised event-deduplication and deleted-account suppression records that prevent duplicate processing or re-creation of an erased account.
You can withdraw AI processing, automatic reports, analytics and crash-report consent in Settings → Privacy & data at any time; withdrawal does not affect the lawfulness of processing already carried out. AI withdrawal stops future AI processing immediately and automatically turns weekly reports off, but does not delete existing conversations, reports or synced records. Turning Cloud Sync off stops further synchronization from that device but does not remove records already retained on the server; while AI permission and the separate report toggle remain on, an eligible report may use those retained records. Delete your account to remove the server copy (section 7).
Data about your child is entered by you, as the parent or guardian exercising responsibility for that child, and is processed on that basis. Imma is intended for adults. We do not knowingly collect data directly from children, and the app is not directed at children.
5. Recipients and international transfers
We share data only with the providers needed to run the app:
| Recipient | Purpose | Location |
|---|---|---|
| Amazon Web Services | Backend and database hosting (account record, AI conversations, weekly reports, and — if you turn Cloud Sync on — your synced records) | US (N. Virginia) |
| Amazon Web Services (Amazon Bedrock) | Message classification and reply/report generation through US cross-region inference; regional message embedding for reference retrieval | US (N. Virginia for embedding; N. Virginia, Ohio or Oregon for classification and generation) |
| Sign-in and account management (Firebase Authentication); app/device attestation (Firebase App Check) | US (Authentication); attestation provider infrastructure (App Check) | |
| RevenueCat | Subscription status | US |
| PostHog | Opt-in usage analytics | US |
| Sentry | Opt-in crash reports | US |
| Apple | Payments and app distribution | per your Apple region |
Most of the above act as our processors under Art. 28 GDPR, on our instructions. Apple has a different role:
- Apple is an independent controller for payments and app distribution, under its own privacy policy.
We are established in Germany, so this processing is subject to the GDPR regardless of where you live. Our servers and most recipients above are in the United States, so personal data is transferred outside the EU/EEA. We rely on the safeguard applicable to each transfer, including an adequacy decision such as an applicable EU–US Data Privacy Framework certification or the European Commission's Standard Contractual Clauses incorporated into the provider's data-protection terms. You can ask privacy@haven-ai.eu for information about the safeguard relevant to your data. Amazon Web Services states that its Data Processing Addendum incorporates the Standard Contractual Clauses automatically for transfers outside the EEA.
Model training and provider access. Amazon Web Services states that neither it nor the providers of the models hosted on Bedrock use customer inputs or outputs to train models. AWS also states that model providers cannot access Bedrock's deployment accounts or the logs, prompts and completions held there. That deployment isolation is not the same as every retention mode: AWS's provider_data_share mode can permit retained inference data to be shared with a provider for models that require it. Section 6 therefore describes retention and sharing conservatively until the effective mode of each active AI path has been verified. If this position changes, we will say so here before it takes effect.
6. Retention
Records on your device are kept for as long as you keep the app installed. You control them, and deleting the app removes them from the device.
Server-side data is kept while your account exists. That data is your account record, your AI conversations and reports, and — only if you have turned Cloud Sync on — the records synced from your devices. Because a synced copy lives in your account rather than on one phone, deleting the app or switching Cloud Sync off does not remove it; deleting your account does.
Two details worth being precise about:
- Deleting a single entry in the app does not erase it from our servers. When Cloud Sync is on, a deleted entry is marked as deleted rather than removed, because that marker is how your other devices learn about the deletion. The underlying content is erased when you delete your account.
- Deleted data may remain in encrypted database backups until their normal 14-day expiry. Backups are used only for disaster recovery, not ordinary processing. Server logs, which contain request metadata and your internal user ID but no record content, are kept for 30 days.
Amazon Bedrock documents a zero-operator-access model under which service operators cannot access model inputs or outputs, and a zero-data-retention default except for models named in its abuse-detection exceptions. On 28 August 2026 we read the live account setting in N. Virginia, Ohio and Oregon: each region was inherit, so the model's own policy applies. None of Imma's three enabled models — the Claude Haiku relevance classifier, Cohere Embed retrieval model, or Claude Sonnet reply/report model — was named in AWS's published retention exceptions. Under that applied state, AWS says model inputs and outputs are not stored or shared with model providers. We re-check this when an enabled model or retention setting changes. The optional reranking model remains disabled and must be reviewed before it can be enabled.
Opt-in usage analytics are kept under PostHog's plan-defined retention and can be associated with the opaque account identifier and the SDK's persistent app-install identifier. Crash-report retention is governed by Sentry.
7. Deleting your account and data
In the app: Settings → Danger zone → Delete account. You will be asked to sign in again to confirm. This removes your account and the substantive data we hold server-side, including your AI-permission and report preferences, records synced via Cloud Sync, your AI conversation history and weekly reports, and requests deletion of your Firebase sign-in identity. It also attempts to wipe Imma's own local database, settings and files from your device. If a local cleanup step fails, the app warns that data may remain; uninstalling the app removes any remaining app-container data. The limited exceptions and provider-retry state are set out below.
You can also email privacy@haven-ai.eu to request deletion. An email address alone is not proof of identity, so we verify the requester before acting.
Full step-by-step instructions, including what happens to each category of data, are on the account deletion page.
The following limited data can remain after the deletion request, and we would rather say so than imply otherwise:
- Subscription/provider records. Our backend removes the account association and identifying content from subscription events it retains for duplicate prevention. Apple, as the App Store controller, keeps its own purchase and subscription records under its privacy terms. In-app account deletion does not automatically delete RevenueCat's separate customer profile. Email privacy@haven-ai.eu before or alongside deletion if you want us to submit a verified provider-side erasure request; RevenueCat states that deleting a customer through its dashboard or API clears that customer's data, but does not cancel an Apple subscription.
- Analytics events already collected, if you had opted in. These are pseudonymous and can be associated with an opaque account identifier and the SDK's persistent app-install identifier; they contain no health data deliberately submitted by the app. Tell us and we will submit an erasure request for the relevant identifiers and events.
- Firebase Authentication deletion. If Firebase cannot complete the provider deletion immediately, Imma temporarily retains only the provider identifier needed to retry; that retry period is our own pending-erasure state and is not Google's retention period. After we successfully request deletion of the associated Firebase Authentication user, Google states that the user's other Authentication information is removed from its live and backup systems within 180 days.
- Local analytics SDK state. If you enabled analytics and later withdrew it before deleting the account, PostHog's SDK can retain pseudonymous account and app-install identifiers inside the app container until a later consented activation resets them or you uninstall the app. Collection remains opted out and the app sends no custom analytics events after withdrawal.
- Deletion-prevention record. We keep a privacy-minimised technical record so delayed provider events or a still-valid sign-in token cannot recreate a deleted account. It does not contain an email address, baby record, conversation or provider-event content, and it is used only to prevent re-creation.
Deleting your account does not cancel an active subscription: subscriptions are managed by Apple. Cancel in Settings → Apple Account → Subscriptions.
8. Your rights
Under the GDPR you can request access, correction, deletion, restriction and portability, and you can object to processing. Where processing is based on consent, you can withdraw it at any time without affecting processing already carried out. Write to privacy@haven-ai.eu; we respond within one month.
US residents can also read the Imma Consumer Health Data Privacy Notice.
For portability, the app can produce your data directly: Settings → App → Export data generates a PDF or CSV containing your profile and your baby's records, which you can save or send anywhere you like. Treat that file carefully — it contains health data.
Right to object. Where we process personal data on the basis of legitimate interests (Art. 6(1)(f) GDPR), you have the right to object at any time, on grounds relating to your particular situation, to that processing. If you object, we will no longer process the data unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing serves to establish, exercise or defend legal claims. Send your objection to privacy@haven-ai.eu.
You may also lodge a complaint with a supervisory authority. Ours is:
The Hamburg Commissioner for Data Protection and Freedom of Information
Ludwig-Erhard-Strasse 22, 7th floor
20459 Hamburg, Germany
Telephone: +49 40 428 54-4040
Email: mailbox@datenschutz.hamburg.de
You may also complain to the authority where you live or work.
9. Security
Data is encrypted in transit with TLS, and the app refuses to make unencrypted requests. Our database is encrypted at rest, as are its backups. The database is not reachable from the internet: it accepts connections only from our application servers, inside a private network. Credentials are held in a managed secrets store, and access to production is restricted and authenticated.
Imma does not use end-to-end encryption. We can technically access the data stored in your account, and we access it only to operate the service, to support you when you ask, or where the law requires. That applies to the copy held in your account on our backend. The AI service described in 2.5 is a separate matter: its retention is governed by the effective setting described in section 6, and AWS documents zero operator access for model inputs and outputs.
No system is perfectly secure. Use a strong, unique password, and enable your device's screen lock.
10. Not medical advice
Imma is a tracking aid, not a medical device. Nothing in the app — including anything the AI assistant says — is medical advice, diagnosis, or treatment. AI responses can be wrong. Always consult a healthcare professional about your child's health, and in an emergency contact your local emergency service.
11. Changes
We will update this page when the policy changes and adjust the effective date above. Material changes will be announced in the app.
Status: August 2026