Where your baby's data goes in Plumi
Feeds, sleep, growth, health notes and photos are sensitive. Here is what stays on your phone, what changes when you turn on sync, and what Plumi cannot read.
A baby tracker ends up holding a very private picture of family life.
Not just feeds and naps. Growth measurements. Temperatures. Medications. Photos. Doctor visits. Notes about hard nights, new foods, diaper changes, milestones, and routines only your family understands.
So the important question is not “does the app have a privacy page?” It is simpler than that:
Where does this data go?
For Plumi, the default answer is: it stays on your phone.
You can use Plumi without an account
The core app does not need sign-up. You can add your baby, log feeds, start timers, track diapers, record sleep, save growth measurements, keep checklists, add milestones and use Plumi offline without creating a Plumi account.
That matters because an account usually means a server record. For everyday tracking, Plumi does not need one.
If you never turn on Pro sync or partner sharing, your baby logs are local to your device. They are not uploaded to Plumi’s servers in the background, and we do not have a copy we can browse, analyze, sell or hand to an ad network.
No third-party analytics, no ads
We do not build the app around advertising. We do not include third-party analytics SDKs. We do not sell or rent personal data.
That is not a slogan. It is a product choice. If the business model depends on ads or behavioral analytics, baby data becomes material for someone else’s system. Plumi is built the other way around: free local tracking, with Pro for sync, sharing and advanced family features.
What changes when you turn on sync
Some families want Plumi on more than one phone. Some want a partner, grandparent or nanny to log care too. That is what Plumi Pro sync and sharing are for.
When you choose to use those features, you sign in with Apple or Google so Plumi can connect your devices and your subscription. From that point, the app uses Plumi’s relay servers to move updates between the people and devices you invited.
The important part is what the server receives.
Your entries are encrypted on your device before upload. The server stores ciphertext and sync metadata, not readable baby logs. The keys needed to read a child’s history stay on devices that are allowed to see that child. We cannot open the database and read a feed note, a photo, a medication entry, or your baby’s name from the encrypted sync payload.
Sync is also optional. If you do not turn it on, there is no Plumi sync record for your baby.
Sharing is per child
Family sharing is not one big household switch.
Each child has their own encrypted record. When you invite someone, you choose which child they can see and what role they should have. A caregiver can see and log care for the child you shared with them. A parent has broader controls, such as managing lists, reminders, exports and profile details.
If you do not share a child with someone, their phone does not get that child’s data or key. That child is not merely hidden in the interface; there is nothing for that person to decrypt.
This is why Plumi asks you to choose carefully before sending an invite link. Sharing is private by design, but it is still sharing. Invite people you trust with that child’s information.
Backups are separate from sync
Sync is for keeping devices and caregivers up to date. Backup is for recovering your own data later.
Plumi can keep an optional iCloud Drive backup through your Apple account. That backup is not a Plumi server feature, and it is separate from Pro sharing. If you use it, the backup belongs to your iCloud account and is governed by Apple’s privacy and security model.
If you do not want backup, leave it off. If you do not want sync, leave sync off. The app is designed so local tracking still works.
What Plumi does store
Privacy-first does not mean “nothing exists anywhere.” It means the app should collect only what it needs, and it should be clear about when that changes.
For local-only use, your baby data stays on your device.
If you choose account features, Plumi stores a minimal account record, such as the sign-in provider identifier and email if provided, plus subscription status. If you enable sync or reminders, the service may also keep device push tokens needed to notify your devices. Payments are handled by Apple through the App Store; Plumi does not receive your card details.
For encrypted sync, the server stores the encrypted updates it needs to relay between authorized devices. Those updates are not readable by us.
Export and deletion stay in your hands
You can export your baby history to CSV. You can delete entries and babies in the app. If you created an account for Pro features, you can also delete the account from Plumi.
Because most baby data lives on your device, deleting the app removes the local copy from that device. If you use sync, deletions sync to the shared record. If you use iCloud Drive backup, any backups you created live in your own iCloud storage.
The practical version: Plumi tries to keep the sensitive stuff where parents expect it to be, and when a feature needs a server, it keeps the server from reading the baby record.
Privacy should be boring
Good privacy should not require a technical explanation before every feed.
You should be able to open the app at 3 a.m., log what happened, and know the default: this stays on your phone. If you later choose sync or family sharing, you should know the tradeoff: your devices can stay in step, the people you invite can help, and Plumi still cannot read the encrypted baby log.
That is the version of privacy we are building for: clear defaults, fewer hidden systems, and no business model hiding inside your baby’s day.
For the formal version, read the Plumi Privacy Policy. Questions go to privacy@plumi.app.