Skip to policy
Baby Bothie Join the waitlist

Baby Bothie Privacy Policy

TestFlight beta · United States and Canada

Effective date: August 24, 2026
Who we are: PHILIAPHILE INC., operating Baby Bothie ("Baby Bothie," "we")
Mailing address: PHILIAPHILE INC., 56A Mill St E, Unit 314, Acton, Ontario L7J 1H3, Canada
Contact: hello@babybothie.com

Baby Bothie is an iPhone app for adults. A parent captures a photo of their baby with the back camera and a photo of themselves with the front camera, and the app combines those two real photos into one image of them together. The combining is AI-assisted, and every combined image is disclosed as such.

The short version

  • Your photo library lives only on your iPhone. Our servers keep no copies of your images.
  • To combine two photos, they pass through our server's memory only to a named AI image provider. We tell you exactly who, and exactly how long they can retain photos — the real number, even when it isn't a flattering one.
  • We do not train AI models on your photos. Google and OpenAI state that their paid/API content is not used for training. Written no-training confirmation from fal is still pending and is disclosed as a limited-beta residual risk rather than presented as settled.
  • Children never use Baby Bothie and we never collect data from children. You must be 18+ and the parent or legal guardian of every child in a photo you submit.
  • You can delete your account and data in the app. We state plainly what deletion cannot reach.
  • No ads. No selling or sharing your data. No tracking you across apps. No face-recognition databases.

1. Who the service is for

Baby Bothie is a general-audience app directed to adults (18+) — parents and legal guardians. Children never operate the app, have no accounts, and we never knowingly collect personal information from a child. Children appear only as subjects of photos their own parent or guardian chooses to submit, with that adult's explicit consent (see §6).

2. Information we collect

DataSourceWhyWhere it lives
Name and email address Sign in with Apple (you may use Apple's private relay email) Account creation, beta invitations, deletion requests Firebase Authentication (Google Cloud)
User ID A Firebase account identifier (UID) created at sign-in Ties your account, consent record, and analytics together; enforces per-user beta limits Firebase; also used as your analytics identifier
Photos you capture (the two source photos) and the combined images You, in the app Solely to create your combined image (see §3 for the full journey) Your iPhone; transiently in our server's memory and with the enabled provider(s) listed in §4
Usage analytics The app, via PostHog, from first launch — recorded under a persistent random app-installation ID (pseudonymous, not linked to your account) until you sign in and accept the consent screen, which links your usage to your user ID. You can turn this off anytime in Settings → Share usage analytics Beta research: which features are used, which model versions people prefer, where errors happen PostHog. We instruct PostHog to discard IP addresses at ingestion and disable geolocation; events are restricted to an approved allowlist; session replay and autocapture are off. Analytics never contain photos, image data, names, or GPS.
Crash reports The app, via Firebase Crashlytics, when the app hits a crash or fatal error after its startup initialization — this runs from first launch so we can fix crashes that happen before sign-in. Some failures are outside its reach: crashes in the first instants of launch, terminations by the system watchdog, and low-memory kills may not produce a report Diagnosing and fixing crashes during the beta Google Firebase. A crash report contains the technical error and stack trace, device/OS details, and a random installation identifier used to group crashes. We assign no account identity to crash reports; they never contain photos or image data.
Feedback text (optional) The in-app feedback box (1–2,000 characters) Improving the beta PostHog, linked to your UID. The form asks you not to include names, medical details, or other personal information.
Consent and processing records Created server-side when you consent or generate Proof of consent; request status, error and cost accounting — metadata only, never image data Firestore (Google Cloud); generation records auto-delete no later than 45 days after the request finishes
Waitlist email address (website only, before the app exists) You, if you submit the waitlist form on our website — never from the app To send you one invitation to the TestFlight beta, and nothing else Buttondown (our email provider), together with the wording of the consent you gave, the page you gave it on, and the date. We use double opt-in: the address is only added once you click the link in our confirmation email. Unsubscribe from any email to erase it. Our website analytics record only that a signup happened — the address itself is never sent to PostHog.

What we do not collect: contacts, location/GPS, microphone audio (the app has no microphone permission), health data, advertising identifiers, browsing history. We do not track you across other companies' apps or websites, and there are no third-party ad or tracking SDKs in the app.

During the beta, usage analytics run from first launch so we can diagnose crashes and drop-offs. If you do not accept the consent screen, your events stay pseudonymous — recorded under a random installation ID, never linked to an account or identity. You can stop analytics at any time with Settings → Share usage analytics (this also deletes any events queued on your device), and deleting your account additionally starts deletion of your analytics data on our side.

3. Your photos' exact journey

  1. Capture, on your iPhone. Both photos are taken in the app. Before anything leaves your device, the app strips photo metadata (no location, no device serial data — pixels only) and normalizes the images.
  2. Both originals are saved to your on-device library first (see §5). If that fails, nothing is sent.
  3. Encrypted upload to our server. The two photos travel over an encrypted connection to our processing function on Google Cloud (US). The function holds image bytes in memory only — it never writes your photos to our storage, logs, or databases.
  4. Sent to the enabled AI provider(s). The function forwards the two photos to each provider currently enabled in the app (§4) to create the combined image(s).
  5. Returned to your iPhone. Combined images stream back to your device and are stored in your on-device library. Our server keeps no copy of any image — not the originals, not the results.
  6. What remains server-side is metadata about the request (status, timing, error category, cost) with no image content, deleted no later than 45 days after the request completes.

The app asks you to keep it open during combining; some versions can take up to 3 minutes.

4. The AI providers we use (our processors)

We name every processor and disclose the retention and training posture we currently rely on, including unresolved beta risks. Our internal, dated processor checklist records the evidence and any narrow founder-approved exception. The in-app consent screen always lists the providers currently enabled and their current windows; if the list or the terms materially change, the app asks for your consent again before any further processing.

ProviderStatus in the betaTraining on your photosRetention
Google — Gemini API (paid tier) (models gemini-3-pro-image, gemini-3.1-flash-image) Enabled No. Google states paid-tier API content is not used to train its models. Google may retain submitted prompts and outputs in abuse-monitoring logs for up to 55 days, then deletes them. Zero-data-retention treatment has not yet been granted or verified; until it is, 55 days is the honest number and the one we disclose.
fal.ai (ByteDance Seedream image model, hosted by fal) Enabled for the consented friends-and-family staging beta. Broader use is gated on the remaining written confirmations. Written no-training confirmation is still pending. This unresolved risk is accepted only for the current limited beta. We call fal with its storage-off configuration: no stored request payload, results returned directly as data, short-lived object expiry, and retries disabled. We verified storage-off behavior on a tested endpoint; verification on every enabled route and written confirmation that no transient media persists and that ByteDance cannot access inputs remain pending.
OpenAI (gpt-image-2) Enabled for the consented friends-and-family staging beta under a limited founder-approved exception. Zero data retention has not been approved, and this exception must be revisited before broader distribution. No. OpenAI states that API content is not used to train its models by default. OpenAI may retain submitted images in abuse-monitoring logs for up to 30 days. It also scans image inputs for child-sexual-abuse material and may retain flagged images for human review and reporting. Those safeguards would remain even if zero data retention is later approved.

Things we deliberately do not use with these providers: no grounding/search features, no provider file-storage APIs, no context caching — each would carry its own retention.

All providers process data in the United States. If you use the beta from outside the US, your photos and data are transferred to and processed in the US.

5. Your on-device library

  • Your Baby Bothie library (originals and combined images) is stored only on your iPhone, in the app's protected storage, encrypted at rest by iOS.
  • The library is excluded from device backups — so "on-device only" stays literally true; it does not sync to iCloud through us.
  • Saving an image to Apple Photos is always your explicit choice (the app requests add-only Photos access). Once exported, that copy is governed by your Apple settings and may sync via iCloud Photos — see §7.
  • Signing out hides your library on that device; deleting your account removes it (§7).

6. Guardian consent — the gate in front of everything

Before your first combination, the app requires three explicit acknowledgements:

  1. You are 18 or older and the parent or legal guardian of every child whose photo you submit;
  2. You permit Baby Bothie to send the two selected photos to the processors listed on the consent screen (the enabled rows of §4, with their retention windows shown);
  3. You understand the combined output is AI-generated and that beta usage analytics are collected.

We record a consent receipt (consent version, processor configuration version, timestamp, app build). If the processor list or any disclosure materially changes, you must re-consent before further processing. You can withdraw at any time: turn off Settings → Share usage analytics to stop analytics on your device (this also purges locally queued events, while keeping your account and on-device library intact), and use Settings → Delete account to withdraw processing consent entirely — deletion blocks further combining and starts deletion of your analytics data.

7. Deletion

Delete your account in Settings. The flow re-confirms your identity with Apple, then: your Apple sign-in token is revoked, analytics stop, and all server-side data (account, consent records, request metadata) and your analytics identity are deleted. Your local library is removed from the device. If a combination is in progress, it is stopped as soon as technically possible; work already sent to a provider may briefly complete but its output is not delivered or kept.

Service levels: data on our servers (Firebase) is deleted within 24 hours; analytics data (PostHog) within 30 days. The app shows "deletion pending" until confirmed, and you receive a receipt code to check status without an account.

What deletion cannot reach — said plainly:

  • Copies you saved to Apple Photos. Those live in your Apple account and may have synced through iCloud Photos; delete them there.
  • Provider safety-retention windows described in §4 (e.g., Google's up-to-55-day abuse-monitoring logs age out on Google's schedule; any CSAM-flagged material at a provider is retained under that provider's legal obligations).
  • A minimal, non-identifying deletion record (not linked to you) kept up to 30 days so we can prove the deletion completed.

Other retention limits, regardless of deletion: server request metadata ≤45 days after each request; raw analytics no later than 90 days after the beta ends (after which only aggregate statistics, with free-text feedback excluded, are kept for research write-ups).

8. Children's privacy

COPPA governs data collected online from children. Baby Bothie is not directed to children, provides no child accounts, and collects no data from children; the user is always the parent or guardian, who provides the photos and the consent (§6). We honor the spirit of COPPA anyway: minimal data, short retention, verified processor terms, and parental deletion rights over everything we hold. If we learn a child has created an account, we will delete it.

9. What we never do

  • No advertising, and no advertising SDKs.
  • No sale of personal data; no sharing beyond the named processors above (plus our infrastructure providers, Google Firebase and PostHog, named in §2).
  • No tracking across apps or websites; no data broker anything.
  • No face-recognition or identification databases — we do not identify people; we combine two photos you chose into one image for you alone.
  • We do not train on your photos; each provider's current training posture, including fal's pending written confirmation, is disclosed in §4.

10. Security

Encryption in transit everywhere; on-device files protected by iOS encryption with backup exclusion; server functions verified by Apple App Check; image bytes confined to function memory; access to production systems restricted to the founder; provider requests authenticated and never logged with image content. No system is perfectly secure — if a breach affects your data, we will notify you promptly at your account email.

11. Your rights

Depending on your state or country, you may have rights to access, correct, delete, or export your personal data, and to non-discrimination for exercising them. The app provides analytics opt-out, account deletion, and on-device data controls. For anything else, contact hello@babybothie.com. We respond within 30 days.

12. Changes to this policy

We will post changes here with a new effective date. Material changes — especially anything touching §4 — additionally require fresh in-app consent before further processing (§6).