Privacy Policy — Pola

Last updated: October 1, 2026

Pola was created to help you care for your baby without worrying about where their data goes. This document explains what we store, why, and how we protect it.

1. Data controller

The controller of your data is Pola. Contact us regarding privacy athello@pola.baby

2. What data we collect

We collect only what is necessary to run the app: your email address, caregiver display name, child’s name and date of birth, and the entries you record (feeding, sleep, diapers, measurements, health notes). Child photos and videos remain strictly on your device and are never sent to our servers.

3. What we use your data for

Solely to provide the service: keeping the journal, syncing it between devices, sharing it with another caregiver and sending notifications. We do not build advertising profiles.

4. Where data is stored and how it is protected

Your data is hosted in the European Union (Hetzner, Finland). Offline entries on your device are encrypted with AES-GCM (iOS) or Tink (Android). Your data is encrypted and synchronised through our servers so that both caregivers see the current state in real time. We will never sell your personal data or your child’s to third parties.

5. Who processes data on our behalf

Pola’s own servers are hosted by Hetzner in Finland and carry your account and the whole journal. Alongside them we use: Firebase Analytics (Google) — events about how the app is used, with fixed names and values, plus an app-instance identifier, the device model, the operating system version and an approximate country derived from the IP address, never journal content and never an advertising identifier; Sentry (EU region) — crash and error reports, stack traces, the device model, the operating system version, the app version with its release and environment, the trail of the last network calls before a crash and a performance sample from roughly one session in ten, with identifiers, invitation codes, tokens and email addresses removed on the device before a report is sent; RevenueCat — purchase receipts and your subscription status, linked to your Pola user identifier, with no journal content; Sign in with Apple and Google — the sign-in itself, from which we receive a provider identifier and an email address, which may be a relay address; the App Store (Apple) and Google Play (Google Play Billing), through which purchases are made; and the Apple and Google push services, which deliver a notification and therefore see its text, including your child’s name. Our Pola newsletter runs on Listmonk, self-hosted on the same Hetzner server in Finland; it stores only the address you give us and the times of confirmation and unsubscribing, the emails are delivered through Resend, and each one carries an unsubscribe link. All of them act only on our instructions. We do not sell data and do not share it for other companies’ own purposes.

6. Analytics and crash reports — and how to switch them off

Anonymous usage analytics are on by default and you can switch them off at any time in the app: Settings → Account & Data → “Share anonymous usage data”. They record which screens and flows are used — never an entry, a name, a note, a dose or a measurement, because the events have no field that could carry one — and they are not linked to your account, because the app sends no user identifier with them. If you switch them off, everything stops, including Firebase’s own sessions, first opens and screen views, and the choice survives a restart. Crash reports are separate and keep running so that a crash can still be fixed. We use Firebase Analytics with no advertising identifiers and no personal data; crash reports via Sentry EU are anonymised with sensitive information scrubbed before delivery.

7. When you write to us from the app

The contact form in Settings prepares an email and hands it to your own mail app — you see the whole message and decide whether to send it. It contains only what helps us reproduce a problem: the app version and build number, your operating system version, the device model, the app language and the platform, plus the text you write. It never contains journal data, your user identifier or any token.

8. Your rights

You can export all your data (GDPR export) or delete your account at any time directly in the app settings under Account & Data, or on this website at pola.baby/delete-account. You can also write to us and we will permanently remove everything from our systems.

9. Website and news emails

The website stores your language in a cookie and your analytics choice in browser storage. Plausible measures visits and clicks only with your permission; you can withdraw it in the website privacy settings. We do not send form contents or URL parameters to analytics. The email address submitted in the form is used for news about new Pola features. Listmonk handles subscriptions and requires you to confirm your address by email. You can unsubscribe or ask us to remove your address. The pricing section estimates your country from your IP address using a DB-IP database stored on our server. The pricing service does not save your IP address or send it to DB-IP. Your selected country and store are kept in browser session storage.