Privacy
The short version. Hodierna stores what you write about your baby so that you and the people you invite can read it back. Nothing is sold, nothing goes to advertisers, and nothing is used to train anybody's models. The logbook itself is stored in the EU. The optional AI features are the exception and say so below — two of them send photographs, and the chat keeps a page of notes about your baby that everyone on the logbook shares. We do collect product analytics, which record that something happened but never anything you wrote. You can export all of it or delete all of it yourself, at any time, without asking us.
Who is responsible
Hodierna is made and run by Nurhak Altın, in the Netherlands, who is the data controller for everything described here. There is no company behind it and no third party who gets to decide what happens to your data.
One exception, and it is real: if a kraamzorg organisation or midwifery practice uses Hodierna as part of the care they are paid to give you, that organisation has its own legal duties about the records it keeps, and it decides what its staff record and for how long they must keep it. For that part they are a controller in their own right and we act on their instructions. Everything else on this page is us.
What we store
The logbook
Everything you write about your baby: feeds, nappies, sleep, temperatures, weights and lengths, medication, vaccinations, milestones, moods and free-text notes. Photos you attach. Appointments, with their date, place and any note you add. A feed timer while it is running, so the other parent's phone can see it.
About the baby: first name, date of birth, gender, and a profile photo if you add one.
Notes written by a professional carer
A kraamverzorgende or verloskundige with access can record what she observed during her visit. Some of those notes are about the mother rather than the baby — a temperature, a weight, an observation about recovery. This is health data about an adult, and it is treated differently from the rest:
- It is stored separately from the logbook entries, and it does not replicate to every phone that can see the logbook.
- Only the account owner, a partner, and professionals with current access can read it. Family members and anyone on a custom permission set never see it.
- There is no screen in the parent app that shows it today. It is written and read on the professional side. It is nonetheless part of your household's record, so it is included in full in your export and it is destroyed when you delete your account.
- What can be recorded is a fixed, short list — a measurement or an observation, as typed. The app stores no judgement about any value: no flag, no severity, no "normal" or "high".
Documents, if you use Premium
The files you upload — hospital discharge papers, the municipality registration, growth charts — along with the text extracted from them, so they can be searched. To make search work, short passages of that text are converted into numeric vectors and stored in a search index.
Your account
Your email address, your name if you give one, your profile picture if your sign-in provider supplies one, and a phone number if you choose to add one so the people sharing your logbook can reach you. Sign-in is handled by Clerk; we never see or store your password.
Alongside it: which plan you are on, your AI credit balance and the history of how it changed, your notification preferences, your reminder settings including any quiet hours you set, and a token for each device that receives notifications.
Sharing and access
Who has access to which logbook, what they may do, when their access ends, and how it was granted. Invitations you send are stored with the recipient's email address until they are accepted, revoked or expire. Requests for access from a professional are stored with their name and the practice they said they work for.
Payments
What you bought, when, in which currency and for how much, and the identifiers the store uses for the transaction. This comes to us from RevenueCat after Apple or Google has taken the payment.
Product analytics and error reports
We use PostHog, on their European servers, to know whether the app works. This is the one place where the rule needs stating precisely, because it is where a health app usually goes wrong.
- Analytics may know that something happened, never what it said. An event records that an entry was logged and which sort it was — a feed, a nappy. It never carries a name, a measurement, a note, a photo or a document. Properties are on a fixed list checked before anything leaves your phone, so a new field cannot slip out by being added somewhere in a hurry.
- No session recording and no autocapture. Both would record screen contents, which in this app means a health record.
- You are identified in analytics by your sign-in id, which is a random string that means nothing outside our own database. No email, no name.
- You can switch it off. Settings → Privacy → Do not send usage statistics. The choice is remembered on the device and applied before the first event of a session, so switching it off stops the next launch reporting anything at all — including that the app was opened.
- Crash and error reports include the error message and the technical stack trace. These are written by the app rather than by you, but an error message can occasionally quote a value it was choking on, so we treat them as possibly containing content and keep them out of anything else.
- PostHog derives an approximate location from your IP address — country, and also city, postal area and coordinates — and attaches it to events. It is not used for anything, and whether it should be attached at all is under review.
- There is no advertising, no advertising identifier, and no cross-app tracking anywhere in Hodierna, and there never will be.
What we never store
- Card details. Payment happens entirely inside Apple's or Google's own checkout. We never see a card number or a name on a card.
- Your GPS location. The app does not ask for it and does not use it.
- Your contacts, your photo library, or anything else on your phone. Only the photos you pick, one at a time.
- Anything about a child as a user. The child has no account and never uses the app.
Why we are allowed to store it
Different parts rest on different legal grounds under the GDPR, and it matters which is which — so here they are one by one rather than as a list of all the possibilities.
| What | Ground |
|---|---|
| The baby's health record: entries, growth, temperatures, medication, documents, and professional notes about the baby | Your explicit consent (Art. 9(2)(a)), given by you as the child's parent, on top of the contract between us. You are asked for it once, with an unticked box, at the moment you create the first logbook — which is when there is a health record to consent to. We record which version of this policy you were shown. You can withdraw it by deleting the data or the account. |
| Notes a professional records about the mother | Explicit consent where the mother holds the account. Where a professional records them in the course of care, they are processed for the provision of health care under the carer's professional duty of confidentiality (Art. 9(2)(h)), and the organisation employing her is the controller for that content. |
| Your account, sync between your devices, sharing with the people you invite, and the invitation emails that make sharing work | Performance of the contract (Art. 6(1)(b)) — this is the service you asked for. |
| Subscriptions, credit purchases and the balance behind them | Performance of the contract, and for the records kept afterwards, a legal obligation (Art. 6(1)(c)) under Dutch tax law. |
| Keeping the service working and safe: rate limits, abuse prevention, error reports, product analytics | Legitimate interests (Art. 6(1)(f)) — knowing whether the app is broken, without knowing what anybody wrote. You can object; see below. |
| Notifications you switch on | Performance of the contract, plus the permission you grant your phone's operating system, which you can take back there at any time. |
You give consent for your child because your child cannot. If both parents use the logbook, either of you can withdraw it for the copy held in your own account.
Where it is stored
On Cloudflare's infrastructure, and deliberately so:
- The database was created with a Western Europe location, and the file storage for photos and documents with an EU jurisdiction. Both are fixed at creation and cannot be moved later. That means the logbook does not merely happen to sit in Europe — it cannot leave.
- The code that answers a request runs at the Cloudflare location nearest you, which for someone in Europe is in Europe.
- Two parts do not carry the same guarantee: the AI features and the document search index run on Cloudflare services that do not offer a region lock. What is sent to them may be processed outside the EU on Cloudflare's own network, under their standard contractual clauses. That is text for most of them and photographs of your baby for one of them — arranging the keepsake book — which is the furthest this guarantee is stretched anywhere in Hodierna, and the reason that feature never runs unless you press the button that says so. If it matters to you, do not use the AI features: nothing else in the app depends on them, and the book is still made without them.
Your phone also keeps a complete copy of the logbook so the app works with no signal. That copy is removed when you sign out.
Who can see it
You, and the people you invite. Every request is checked against your permissions on the server, not merely hidden in the app, and anything unknown or expired is refused rather than allowed.
When you invite someone you choose what they may do — view, log, comment, manage access — and when their access ends. Access given to a kraamverzorgende or verloskundige carries an end date by default and stops on its own. A professional cannot get in by searching for you: either you invite them, or they ask and you approve. An organisation rostering someone to your family produces a request, never access.
We do not read your logbook. We can technically reach the database in order to operate and repair the service, and we do not do so casually. The back office used to run the service can see account state — plan, credits, when someone signed up — and cannot open a logbook at all.
Who we share it with
Only the suppliers needed to run the service, each acting on our instructions under a data processing agreement:
| Who | What for | Where |
|---|---|---|
| Cloudflare | Hosting, database, file storage, email delivery, the AI features and document search | Database and files in the EU; AI and search on Cloudflare's global network under standard contractual clauses |
| Whoever makes the assistant you connect | Only if you connect one yourself — see Connecting an assistant below | Their terms, not ours |
| Clerk | Sign-in and account management | US, under EU standard contractual clauses |
| RevenueCat | Knowing what you bought and whether it is still active | US, under EU standard contractual clauses |
| PostHog | Product analytics and error reports | EU (Frankfurt) |
| TypeSafe | Only if you switch on Help test a smarter home screen — see The AI features below | US |
| Expo | Delivering push notifications and app updates | US, under EU standard contractual clauses |
| Apple / Google | Payments, and the final delivery of a notification to your phone | Per their own terms; outside the EU |
We do not sell personal data and we do not share it for advertising. We have never disclosed any to a government or law enforcement body. If we were compelled to, we would tell you unless legally prevented from doing so.
The AI features
The AI features are optional extras, paid for in credits. They are the only part of Hodierna that sends anything you wrote to be processed by a model.
- Turning a sentence or a photographed page into entries sends that text, or that photograph, to Cloudflare Workers AI. This works on the free plan too if you have credits — so it is not true that a free account never uses AI, and we would rather say that than let you assume otherwise.
- Indexing and questioning documents is a Premium feature. Your question and passages from your own documents are sent to be processed; answers are grounded only in your own documents.
- Arranging the keepsake book sends the photographs it is considering — the pictures themselves, up to forty of them — to Cloudflare Workers AI, which scores each one on focus, light and framing and returns two numbers. Apart from a picture you attach to the chat yourself, this is the only feature that sends a photograph of your child anywhere it is not already stored, and it happens only when you press a button on a dialog that says so and names the price. Nappy, illness and temperature photographs are excluded before anything is sent. The model is instructed not to describe what is in a picture and is given no room to; nothing it says about a photograph is kept, shown to you, or written into the book.
- Ask Hodierna sends the sentence you typed, and nothing else. No entries, no names, no dates, no summary of the logbook — because all it is doing is choosing which of the app's own screens or actions you meant. The answer it gives back is the name of an action and nothing more; your phone then does it, and anything that would be written down is shown to you first. The model never writes a sentence you read.
- The chat sends more than the other features, because it is answering about your baby: your message, the recent conversation (which is kept on your phone, not by us), a brief of the baby — first name, date of birth, the last days of the logbook — and, when you have them, passages from your own documents. It goes to Cloudflare Workers AI and the reply is the model's own, under its provider's terms; we do not screen it and it is not medical advice. Three things about it are worth knowing separately. Notes: at the end of each conversation the model writes itself a short page about what you told it that the logbook does not hold, and reads it at the start of the next; that page is stored in our database in the EU, one per baby, shared with everyone who has access to that logbook, shown in full on the chat's notes screen, and anyone who can write in the logbook can clear it. It is erased with the logbook. Pictures: a photograph you attach to a message is sent once to a vision model on Workers AI, which returns a written description; the description is kept with the message on your phone and goes up with later turns, the picture itself is not stored on our servers. Importing from another assistant: if you paste in what ChatGPT or another assistant knows about your family, that text is sent once to be folded into the notes page and is not kept in any other form.
- Help test a smarter home screen is off unless you switch it on, in Settings → Privacy, and it is free. While it is on, for logbooks you started, a summary of when things are logged is sent to TypeSafe, an AI company, so we can test whether their model (Jev) can tell which button you need next, for example on a weigh-in day. The summary is the baby's age in days, your country, the day of the week and time, how many entries of each kind today and in the last four weeks, hours since the last of each kind, the days between weigh-ins, and whether there is an appointment today. It never contains a name, a date of birth, a weight or any other value, a note or a photograph. It is sent at most twice a day, only when you have just used the app. Nothing in the app changes either way: the answers are only counted, to compare with the app's own rules, and the record of them is erased with the logbook or after ninety days. Switching it off stops it from the next check, within fifteen minutes. TypeSafe processes the summary in the United States, and states that it does not train its models on data sent to it.
- Nothing sent is used to train any model, ours or anyone else's.
- If an AI operation fails, its credits are returned to you automatically.
- If you never open these features, nothing you write is ever sent to a model.
The AI never interprets a health value. It reads what you wrote and turns it into entries; it does not tell you whether a number is good.
Connecting an assistant
If you have Premium you can connect an outside assistant — Claude, or anything else that speaks the Model Context Protocol — to one logbook, from Connected things in the app. This is the one place in Hodierna where you can hand your own data to somebody who is not our supplier, so it is worth being plain about what happens.
- It is a wider key than a device gets. A key made for something in your house sees counts and timestamps. A key made for an assistant can read everything written in the logbook — the notes you typed at 3am, every measurement — and can add entries. An assistant that cannot read the logbook cannot answer anything about it, which is why the key is wide; the app says so before you make one.
- We send nothing to any model for this. The assistant runs wherever its maker runs it, asks us for data using your key, and does its own thinking. From our side it is an ordinary authorised request.
- What that assistant then does with what it reads is between you and whoever makes it, under their terms and in whatever country they operate. We cannot see it and cannot control it. Do not connect one you would not be willing to show the logbook to.
- Disconnecting works immediately. Revoking a key in the app stops the very next request; there is no cached permission and no window in which it still works. Only the person who made a key can see it, and any key stops working the moment its maker loses access to that logbook.
- An entry added this way is recorded as written by you, because you are the person who asked for it.
Notifications and email
If you turn on reminders, a token identifying your device is stored so a notification can reach it. What a notification may contain is a short fixed list: an actor's first name or role, your baby's first name, and what happened. Never entry contents, measurements or note text. Delivery goes through Expo and then Apple's or Google's push services.
Night Watch alarms are scheduled on your phone itself and involve no server at all.
We send transactional email only: an invitation when you invite someone, and messages about your account. An invitation email names you and your baby's first name, because the person receiving it needs to know what they are being invited to. There is no marketing email, no newsletter and no re-engagement nudging. That is a design decision, not a setting.
How long we keep it
- Your logbook is kept while your account exists, because the point of a logbook is that it is still there later.
- When you delete one logbook, it disappears for everyone who shares it at once. It is kept for thirty days in case it was deleted by mistake — write to hallo@hodierna.app within them and it can be restored — and is then erased for good: entries, photos, documents and notes.
- When you delete your account, the request waits seven days and you can cancel it at any point during them. After that everything is destroyed: entries, photos, documents, care notes, your account here and your sign-in account at Clerk. The columns that name a person are removed, not scrambled.
- If you choose to anonymise instead, the shape of the data survives — counts, timings, growth points — and everything identifying anybody is destroyed. Ids are regenerated, dates are shifted and coarsened, and nothing anywhere records how far they moved.
- Backups roll off within thirty days of the deletion running.
- Payment records are kept for as long as Dutch tax law requires, after every link to you has been destroyed: no account id, no store id, and the original message from the payment provider replaced. What survives is an amount, a currency, a product and a date — an accounting line about nobody.
- Invitations expire on their own; the codes a parent shows a professional last fifteen minutes and work once.
If a professional carer recorded care in your logbook as part of her job, her employer may have a separate legal duty to retain that record. That duty is theirs, not ours, and they will tell you about it.
Your rights
Under the GDPR you may ask for a copy of your data, correct it, delete it, restrict or object to how it is processed, withdraw consent, or receive it in a portable form. Most of this you can do yourself, immediately, without asking anyone:
- Access and portability — Settings → Your data → Export everything gives you one archive containing every entry, photo, document, care note, appointment and payment record, in formats that open without our app.
- Correction — every entry is editable in the app.
- Erasure — Settings → Your data → Delete everything. See deleting your account.
- Objection to the analytics — Settings → Privacy → Do not send usage statistics. It takes effect on the device immediately, and before anything is sent the next time you open the app. No email, no waiting for us.
- Withdrawing consent for the health record — Settings → Privacy shows what you agreed to and when. Withdrawing it means removing the record, because the logbook cannot be kept without it, so the link there takes you to export and deletion.
For anything else, email hallo@hodierna.app and we will answer within 30 days. If you are unhappy with how we have handled it you can complain to the Autoriteit Persoonsgegevens, the Dutch data protection authority, or to the authority where you live.
Children
Hodierna is used by adults to keep records about their own child. The child is not a user, has no account, and cannot sign in. The account holder must be 16 or older.
Security
Everything travels over TLS. Invitation tokens and the codes shown to professionals are stored hashed, never in the clear. Access is decided in one place on the server and fails closed: unknown, missing, unreadable or expired all mean no. If a breach ever affects your data, we will tell you and the Autoriteit Persoonsgegevens within the time the law requires.
Changes
If this policy changes in a way that matters, you will be told in the app before it takes effect — not by a silent edit to this page.