Hodierna
Prices

Privacy

Last updated 30 September 2026. Controller: Nurhak Altın, the Netherlands. Contact: hallo@hodierna.app

The short version. Hodierna stores what you write about your baby so that you and the people you invite can read it back. Nothing is sold, nothing goes to advertisers, and nothing is used to train anybody's models. The logbook itself is stored in the EU. The optional AI features are the exception and say so below — two of them send photographs, and the chat keeps a page of notes about your baby that everyone on the logbook shares. We do collect product analytics, which record that something happened but never anything you wrote. You can export all of it or delete all of it yourself, at any time, without asking us.

Who is responsible

Hodierna is made and run by Nurhak Altın, in the Netherlands, who is the data controller for everything described here. There is no company behind it and no third party who gets to decide what happens to your data.

One exception, and it is real: if a kraamzorg organisation or midwifery practice uses Hodierna as part of the care they are paid to give you, that organisation has its own legal duties about the records it keeps, and it decides what its staff record and for how long they must keep it. For that part they are a controller in their own right and we act on their instructions. Everything else on this page is us.

What we store

The logbook

Everything you write about your baby: feeds, nappies, sleep, temperatures, weights and lengths, medication, vaccinations, milestones, moods and free-text notes. Photos you attach. Appointments, with their date, place and any note you add. A feed timer while it is running, so the other parent's phone can see it.

About the baby: first name, date of birth, gender, and a profile photo if you add one.

Notes written by a professional carer

A kraamverzorgende or verloskundige with access can record what she observed during her visit. Some of those notes are about the mother rather than the baby — a temperature, a weight, an observation about recovery. This is health data about an adult, and it is treated differently from the rest:

Documents, if you use Premium

The files you upload — hospital discharge papers, the municipality registration, growth charts — along with the text extracted from them, so they can be searched. To make search work, short passages of that text are converted into numeric vectors and stored in a search index.

Your account

Your email address, your name if you give one, your profile picture if your sign-in provider supplies one, and a phone number if you choose to add one so the people sharing your logbook can reach you. Sign-in is handled by Clerk; we never see or store your password.

Alongside it: which plan you are on, your AI credit balance and the history of how it changed, your notification preferences, your reminder settings including any quiet hours you set, and a token for each device that receives notifications.

Sharing and access

Who has access to which logbook, what they may do, when their access ends, and how it was granted. Invitations you send are stored with the recipient's email address until they are accepted, revoked or expire. Requests for access from a professional are stored with their name and the practice they said they work for.

Payments

What you bought, when, in which currency and for how much, and the identifiers the store uses for the transaction. This comes to us from RevenueCat after Apple or Google has taken the payment.

Product analytics and error reports

We use PostHog, on their European servers, to know whether the app works. This is the one place where the rule needs stating precisely, because it is where a health app usually goes wrong.

What we never store

Why we are allowed to store it

Different parts rest on different legal grounds under the GDPR, and it matters which is which — so here they are one by one rather than as a list of all the possibilities.

WhatGround
The baby's health record: entries, growth, temperatures, medication, documents, and professional notes about the babyYour explicit consent (Art. 9(2)(a)), given by you as the child's parent, on top of the contract between us. You are asked for it once, with an unticked box, at the moment you create the first logbook — which is when there is a health record to consent to. We record which version of this policy you were shown. You can withdraw it by deleting the data or the account.
Notes a professional records about the motherExplicit consent where the mother holds the account. Where a professional records them in the course of care, they are processed for the provision of health care under the carer's professional duty of confidentiality (Art. 9(2)(h)), and the organisation employing her is the controller for that content.
Your account, sync between your devices, sharing with the people you invite, and the invitation emails that make sharing workPerformance of the contract (Art. 6(1)(b)) — this is the service you asked for.
Subscriptions, credit purchases and the balance behind themPerformance of the contract, and for the records kept afterwards, a legal obligation (Art. 6(1)(c)) under Dutch tax law.
Keeping the service working and safe: rate limits, abuse prevention, error reports, product analyticsLegitimate interests (Art. 6(1)(f)) — knowing whether the app is broken, without knowing what anybody wrote. You can object; see below.
Notifications you switch onPerformance of the contract, plus the permission you grant your phone's operating system, which you can take back there at any time.

You give consent for your child because your child cannot. If both parents use the logbook, either of you can withdraw it for the copy held in your own account.

Where it is stored

On Cloudflare's infrastructure, and deliberately so:

Your phone also keeps a complete copy of the logbook so the app works with no signal. That copy is removed when you sign out.

Who can see it

You, and the people you invite. Every request is checked against your permissions on the server, not merely hidden in the app, and anything unknown or expired is refused rather than allowed.

When you invite someone you choose what they may do — view, log, comment, manage access — and when their access ends. Access given to a kraamverzorgende or verloskundige carries an end date by default and stops on its own. A professional cannot get in by searching for you: either you invite them, or they ask and you approve. An organisation rostering someone to your family produces a request, never access.

We do not read your logbook. We can technically reach the database in order to operate and repair the service, and we do not do so casually. The back office used to run the service can see account state — plan, credits, when someone signed up — and cannot open a logbook at all.

Who we share it with

Only the suppliers needed to run the service, each acting on our instructions under a data processing agreement:

WhoWhat forWhere
CloudflareHosting, database, file storage, email delivery, the AI features and document searchDatabase and files in the EU; AI and search on Cloudflare's global network under standard contractual clauses
Whoever makes the assistant you connectOnly if you connect one yourself — see Connecting an assistant belowTheir terms, not ours
ClerkSign-in and account managementUS, under EU standard contractual clauses
RevenueCatKnowing what you bought and whether it is still activeUS, under EU standard contractual clauses
PostHogProduct analytics and error reportsEU (Frankfurt)
TypeSafeOnly if you switch on Help test a smarter home screen — see The AI features belowUS
ExpoDelivering push notifications and app updatesUS, under EU standard contractual clauses
Apple / GooglePayments, and the final delivery of a notification to your phonePer their own terms; outside the EU

We do not sell personal data and we do not share it for advertising. We have never disclosed any to a government or law enforcement body. If we were compelled to, we would tell you unless legally prevented from doing so.

The AI features

The AI features are optional extras, paid for in credits. They are the only part of Hodierna that sends anything you wrote to be processed by a model.

The AI never interprets a health value. It reads what you wrote and turns it into entries; it does not tell you whether a number is good.

Connecting an assistant

If you have Premium you can connect an outside assistant — Claude, or anything else that speaks the Model Context Protocol — to one logbook, from Connected things in the app. This is the one place in Hodierna where you can hand your own data to somebody who is not our supplier, so it is worth being plain about what happens.

Notifications and email

If you turn on reminders, a token identifying your device is stored so a notification can reach it. What a notification may contain is a short fixed list: an actor's first name or role, your baby's first name, and what happened. Never entry contents, measurements or note text. Delivery goes through Expo and then Apple's or Google's push services.

Night Watch alarms are scheduled on your phone itself and involve no server at all.

We send transactional email only: an invitation when you invite someone, and messages about your account. An invitation email names you and your baby's first name, because the person receiving it needs to know what they are being invited to. There is no marketing email, no newsletter and no re-engagement nudging. That is a design decision, not a setting.

How long we keep it

If a professional carer recorded care in your logbook as part of her job, her employer may have a separate legal duty to retain that record. That duty is theirs, not ours, and they will tell you about it.

Your rights

Under the GDPR you may ask for a copy of your data, correct it, delete it, restrict or object to how it is processed, withdraw consent, or receive it in a portable form. Most of this you can do yourself, immediately, without asking anyone:

For anything else, email hallo@hodierna.app and we will answer within 30 days. If you are unhappy with how we have handled it you can complain to the Autoriteit Persoonsgegevens, the Dutch data protection authority, or to the authority where you live.

Children

Hodierna is used by adults to keep records about their own child. The child is not a user, has no account, and cannot sign in. The account holder must be 16 or older.

Security

Everything travels over TLS. Invitation tokens and the codes shown to professionals are stored hashed, never in the clear. Access is decided in one place on the server and fails closed: unknown, missing, unreadable or expired all mean no. If a breach ever affects your data, we will tell you and the Autoriteit Persoonsgegevens within the time the law requires.

Changes

If this policy changes in a way that matters, you will be told in the app before it takes effect — not by a silent edit to this page.