BabyEvent Privacy Policy
How BabyEvent handles private family memories, AI processing, sharing, retention, and account deletion.
Last updated: 2026-08-11
Who this service is for
BabyEvent is a private memory service for parents and legal guardians. It is not directed to children, and children must not create their own accounts. An adult account holder decides what information about a child is added, who may see it, and when it is deleted or shared.
Information we process
Depending on the features you use, BabyEvent processes:
- account and authentication information, such as your name, email address, locale, sign-in provider, and security records;
- child-profile information entered by an adult, such as a nickname, birth or due date, time zone, language, and optional avatar;
- private family content, including photos, original videos, voice notes, captions, parent notes, confirmed facts, stories, cards, books, and reels;
- consent, family membership, invitation, sharing, export, deletion, and support records;
- subscription, order, entitlement, credit, and transaction identifiers. A payment processor handles payment credentials; BabyEvent does not store full card numbers;
- technical and security information needed to protect the service, such as session, device, request, rate-limit, error-category, and coarse usage data.
We do not sell private family content or personal information.
How information is used
We use this information to provide the private timeline, story, card, book, reel, sharing, export, support, account, and billing features you request; to enforce permissions and entitlements; to prevent abuse; and to diagnose and secure the service.
AI suggestions are drafts. BabyEvent separates parent-entered facts from AI observations and requires parent confirmation before confirmed facts are used in a final story. Standard Reels use the media you select and do not synthesize new actions by a child.
AI and service processors
BabyEvent uses service providers only for a defined operational purpose. The active provider depends on the feature and administrator configuration:
- Cloudflare may provide application hosting, private object storage, database, queue, security, and network services;
- Kie.AI may process the text or media submitted for an AI feature using the configured model after the required consent and authorization checks;
- an email provider may deliver account, sharing, deletion, export, job, and payment messages;
- Creem may process checkout, subscription, invoice, and payment events after paid checkout is enabled;
- an analytics provider may receive only allowlisted, coarse conversion events.
We do not send a child's nickname, birth date, story text, transcript, media URL or key, prompt, or extracted fact value in analytics events. Aggregate analytics may be retained without a fixed expiration until the operator deletes it or changes the analytics retention policy.
Premium synthetic video remains disabled unless its processor terms, data handling, safety controls, retention, quality, and cost have been reviewed. BabyEvent does not use face swap, voice cloning, or identity recreation, and does not send child reference media to a premium video provider under the current product policy.
Private storage and sharing
Saved family content is private by default and stored in private object storage. Access is checked against the account, child membership, and task or share authorization. A share link may be password protected, time limited, and revoked. Shared pages and application pages are excluded from public sitemaps and marked not to be indexed.
The owner may invite an additional parent editor. That person can access the content permitted by their current family role until the invitation, role, or access is revoked. Do not invite or share with anyone you do not trust.
Retention and deletion
- An unsigned guest preview and its uploaded media expire after 24 hours if they are not claimed into an account.
- Saved family content remains available while the account keeps it. Ending a subscription changes access according to the plan but does not by itself delete saved child content.
- Deleting an individual item removes it from normal access and schedules its database and private-object cleanup.
- Requesting account deletion makes the account and family content inaccessible and schedules physical cleanup. Cleanup jobs are recorded so completion can be audited.
- Security, transaction, consent, deletion, and legal records may be retained only as long as reasonably required for fraud prevention, accounting, dispute handling, or applicable law.
You may export supported profile, fact, story, book, and media data before deletion. Some deletion or export operations are asynchronous because private files and derived artifacts must be processed safely.
Security and sensitive-content boundaries
BabyEvent uses encrypted transport, private storage, short-lived capabilities, role checks, idempotent task handling, and redacted operational records. No Internet service can guarantee absolute security. Please use a strong account credential, protect share passwords, and revoke access you no longer intend.
Your choices and rights
Subject to applicable law, an adult account holder can review and edit family content, manage sharing and collaborators, export supported data, delete individual items, or request account deletion. You may also disable non-essential lifecycle messages. Use the in-product support ticket from an authenticated account for privacy, access, correction, export, or deletion requests.
Changes
We may update this policy when the product or its processors change. We will update the date above and provide additional notice when required. A material new use of private family content will not be enabled merely by silently changing this page.
Contact
Use Settings → Support Tickets in BabyEvent to contact the service operator. The operator's legal identity, mailing address, and dedicated privacy contact must be added here before public indexing or commercial launch.