Privacy, in plain language.
What CribClock stores, where, and why. Last updated October 4, 2026.
The short version
- CribClock works without an account. Until you share, your baby's record stays on your iPhone.
- Sharing stores the household's record on CribClock's service, so the iPhones of the caregivers you invite can sync it.
- No ads, no trackers, and we never sell data. Names, notes, and medicine details never go to analytics.
- You stay in control. Export your data, leave a household, or delete your account from inside the app.
On your iPhone
Everything you record (entries, notes, saved medicines, your baby's name, and caregiver names) is saved on your iPhone first. Without sharing, nothing leaves it. You can export a spreadsheet (CSV) or erase all CribClock data on the iPhone from Settings.
When you share with other caregivers
Sharing needs Sign in with Apple, so only people you invite can see the record. To make sharing work, the CribClock service stores:
Your account
A private identifier from Sign in with Apple, and the random caregiver ID your iPhone created. CribClock asks Apple for this ID only, never your name or email.
Sign-in sessions
A token that keeps your iPhone signed in. We store only a one-way hash of it, and it expires after 180 days without use.
Households and members
Which accounts belong to each household, whether each is the owner or a caregiver, and when they joined or were removed.
Invitations
A one-way hash of the invitation code, when it expires, and, only if you add them, the names shown on the invitation page (for example, yours and your baby's). Those names are stored on the invitation only and deleted with it.
The shared care record
The entries caregivers record and correct, such as feeds, diapers, sleep, and doses, with their times and details. That can include anything you type, like names, notes, medicine names, and amounts. It is encrypted in transit and stored on the service so every member's iPhone can sync it. The service puts changes in order and passes them on; it does not analyze them.
Device tokens
Apple push notification tokens for your iPhones, so the service can quietly tell them that the shared record changed. These are silent background notifications, not alerts.
Waitlist emails
If you join the early access list on this website, your email address, used only to tell you when CribClock is available.
About encryption: everything travels over encrypted connections (HTTPS), but the shared record is not end-to-end encrypted. It is stored so the service can deliver it to your household, and it is used for nothing else.
Who can see the shared record
Only the active members of the household. Every entry shows who recorded it. When a member is removed or leaves, their iPhone stops receiving the record and removes its copy; entries they already recorded stay in the household.
What we never do
- Show ads, or use advertising or tracking SDKs, in the app or on this website.
- Sell care data, or share it with anyone for marketing.
- Send names, notes, medicine names, or dose amounts to analytics or crash logs.
- Log request contents. Service logs record only the kind of error, never names, notes, medicine details, email addresses, tokens, or care entries.
- Set cookies on this website. It has no analytics and loads nothing from third parties.
Deleting your data
- Delete your account from the Sharing screen in CribClock. This deletes your account, sessions, devices, memberships, and the invitations you created or accepted. Households you own are deleted from the service with their shared records, and everyone you invited loses access. Your own iPhone keeps its copy.
- Leave a household to remove its record from your iPhone. Entries you recorded stay with the household.
- Erase data on this iPhone from Settings removes every entry, medicine, and setting from that iPhone.
- Waitlist emails are deleted on request; write to us at the address below.
One thing we keep after an account is deleted: the random caregiver ID it used, with nothing attached to it, so that no one else can ever appear in a household as you.
Service providers
The CribClock service runs on Vercel (hosting) with a Neon Postgres database. Apple provides Sign in with Apple and delivers push notifications. They process data only to provide those services.
Children
CribClock is for the adults caring for a baby. It holds information about a baby that caregivers choose to record, and is not directed at children.
Changes and questions
If this policy changes, we'll update this page and the date at the top. Questions or requests: support@cribclock.app.
Placeholder contact address: replace before launch.
See also: Support.