🍼

MyPeke Privacy Policy

Last updated: July 9, 2026 Β· Version 1.1

Leer en espaΓ±ol


MyPeke is an app for keeping a daily record of a baby β€” feeding, sleep, diapers, growth, developmental milestones, teeth, vaccines, and reminders β€” designed to be shared between both parents. This policy explains, in as much detail as possible, what information is collected, how it is stored, who can access it, and what control you have over it. There's no fine print: if something isn't here, we don't do it.

1. Who is responsible for this app

MyPeke is developed by Bernardo Bohorquez Lairet, as an individual developer (not a company). For any question about privacy or your data, you can write to bblairet2@gmail.com.

2. What information the app collects

All the information you record in MyPeke is associated with the child profile you create in the app. In detail:

We do not collect contact information (there's no need to create an account or provide your email, name, or phone number to use the app), we do not use advertising identifiers, we do not include any third-party analytics or advertising SDK, and we do not track your activity across other apps.

3. Where this information lives and how it's protected

MyPeke has no server of its own. All data is stored using CloudKit, Apple's iCloud infrastructure, inside your own personal iCloud account β€” just like your photos or notes. We, as developers, do not keep a separate copy of your data on any server of ours, because no such server exists.

In addition, the fields containing sensitive information about the child β€” name, date of birth, sex, amounts, notes, and the date of each event β€” are individually encrypted (CloudKit "field-level encryption") with a key tied to your own device/iCloud account. This means that neither Apple nor we can read the actual content of those fields, not even using CloudKit's internal administration tools.

Technical note, for full transparency: as with any app that uses a cloud database, the developer has, at the infrastructure level, administrative access to Apple's CloudKit Dashboard for debugging purposes. Fields marked as encrypted (see above) cannot be read even from there β€” but non-sensitive technical identifiers (such as a record's internal ID, or an event's type without its content) are technically visible at the administration level, as with any cloud backend. We don't look at or use them for anything β€” we mention this because we prefer to be explicit even about what is technically possible, not only about what we actively do.

4. Who your information is shared with

By default, with no one. A child's data lives only in your own private iCloud database. It is only shared with someone else if you, explicitly, use the app's "Share" feature to invite someone (typically the other parent) β€” in that case, that specific person will be able to view and edit that child's data from their own iCloud account, and only them. You can revoke that access at any time.

We do not sell, rent, or share your information with advertisers, social networks, or any other third party. There is no data flow out of Apple/iCloud.

5. Optional permissions on your iPhone

MyPeke may ask your permission for the following β€” always optional, and explained at the moment it's requested:

6. In-app purchases

MyPeke offers voluntary "tips" (coffee, croissant, breakfast) as an optional thank-you β€” they don't unlock any feature and aren't required for anything. These purchases are processed directly by Apple (StoreKit); we do not receive or see your payment information, only a notice that the purchase was completed successfully.

7. Minors

MyPeke is designed to be used by adult parents/guardians, not by children themselves. Information about the child is entered by the responsible adult; it is not collected directly from a minor. If you have any question about how we handle your child's information, write to us.

8. Your control over this information

9. European Economic Area (GDPR) β€” additional information

If you're located in the European Economic Area or the UK, the following additional information applies to you under the General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR").

9.1 Our role as data controller β€” and why our relationship to your data is still unusually limited. We treat ourselves as the data controller for MyPeke, out of caution and transparency: GDPR Recital 18 makes clear that even where an end user's own activity (a parent keeping their own family's records) falls outside GDPR's scope as a "purely personal or household activity," that exemption never extends to "controllers or processors which provide the means for processing personal data for such personal or household activities" β€” that's us, as the app's developer, since we decide what data the app records and why. We are not relying on any argument that storing or structuring your data on our behalf falls outside GDPR merely because it happens through your own iCloud account.

What is genuinely unusual here is how little access we have, not whether GDPR applies to us. MyPeke has no server: every recording/storing/retrieving operation happens on your own device, writing to a CloudKit database scoped to your own personal iCloud account, with sensitive fields individually encrypted (Section 3). We have no technical ability to view, query, export, or aggregate your data, across your account or anyone else's. In practice, this means we fulfil our controller obligations in an unusual way: instead of processing access/rectification/erasure requests against a central database we control (none exists), the app itself gives you complete, immediate, self-service control over all of your own data at all times, as described in Section 9.5 below β€” and Apple's iCloud/CloudKit infrastructure, governed by Apple's own commitments, is the technical service that actually stores it.

9.2 Apple's role. Apple operates the iCloud/CloudKit infrastructure that stores your data. Apple may process and store data on servers located outside the European Economic Area, including in the United States. Where that happens, Apple relies on its own safeguards for such transfers (such as the EU-US Data Privacy Framework adequacy decision and/or Standard Contractual Clauses, as applicable). Because we have no contract or data-sharing relationship with Apple regarding your content β€” your relationship for iCloud storage is directly with Apple, under your own Apple ID β€” we point you to Apple's own privacy and legal documentation (available at apple.com/legal/privacy) for the specifics of how Apple safeguards international transfers.

9.3 Special category (health-related) data. Some of what you record β€” growth measurements, vaccines, medication, symptoms β€” constitutes "data concerning health" under GDPR Art. 9 / Art. 4(15). Our legal basis for this processing is your explicit consent (Art. 9(2)(a)): the Growth, Vaccines, and Medication/Symptom sections of the app are optional, clearly labeled, and only record data when you affirmatively choose to open them and enter something β€” using the app's core diary features (feeding, sleep, diapers) does not require this. You can decline to use these specific features at any time, and can delete anything already entered (Section 9.5). This data is, in any case, encrypted at the field level and never accessible to us in any form, within your own iCloud account.

9.4 Children and Article 8 GDPR. MyPeke is offered to, downloaded by, and operated by an adult parent or guardian β€” never directly to a child as the app's user. Because Article 8 GDPR concerns "the offer of information society services directly to a child," and MyPeke is not offered directly to children, Article 8 does not apply to this app. The parent or guardian, as the person with legal responsibility for the child and as the sole holder of the iCloud account where the data lives, is the one who exercises any rights concerning the child's data described below.

9.5 Your rights. Because your data lives exclusively in your own iCloud account, most of the rights below are already in your own hands directly through the app and your Apple ID β€” you don't need to submit a request to us to exercise them, though we're glad to help if you're unsure how:

Providing your child's data is entirely voluntary and is not a statutory or contractual requirement β€” declining simply means reduced functionality (Art. 13(2)(e)).

9.6 Right to lodge a complaint. You have the right to lodge a complaint with a supervisory authority, in particular in the EU member state of your habitual residence, place of work, or place of the alleged infringement (GDPR Art. 77). You can find your national supervisory authority via the European Data Protection Board: edpb.europa.eu.

9.7 Data Protection Officer. A Data Protection Officer is not legally required for this app under GDPR Art. 37: we are not a public authority, we do not carry out systematic large-scale monitoring, and we have no technical ability to aggregate or process special category data at scale across users, since each user's data is siloed within their own iCloud account with no visibility on our part. For any privacy question, contact bblairet2@gmail.com directly.

10. Changes to this policy

If this policy changes significantly, we will update the date at the top of this document. We recommend reviewing it from time to time.

11. Contact

For any question, concern, or request related to your privacy or your data: bblairet2@gmail.com.