Privacy Policy
The short version
Zen Otto stores your baby's care records on your iPhone. iCloud sync is enabled by default when available, and you can turn it off in the app. Sharing a baby's log with another caregiver is a separate choice. We do not operate a server that receives your care records, require a Zen Otto account, or include advertising. Versions with the Usage analytics setting also send app-usage information as described below.
Where your data lives
Everything you enter is stored on your iPhone.
With iCloud sync enabled and available, records are copied to your private iCloud database through Apple's CloudKit service. This uses your Apple Account and is subject to Apple's privacy policy. You can change the setting under Settings, then iCloud. A change takes effect on the next app launch; the screen shows whether sync is currently running.
Photos you select are stored with the log and can be included in iCloud sync and caregiver sharing. Apple's photo picker gives the app access to the pictures you choose, rather than your entire photo library.
Sharing with caregivers
If you choose to share a baby's log, CloudKit makes that log available to the people you invite. Sharing uses iCloud separately from the setting for syncing your own devices: turning that setting off does not stop an existing share. Use the baby's sharing controls to manage access or stop sharing. Only share with people you intend to give access to the care records.
Stopping a share does not delete your own private iCloud copy. It also cannot retract records that a recipient has already exported or copied outside the app.
What we collect
Full care logs, notes, photos and recorded measurements are not sent to us for analytics. Limited usage information and derived context are described below. The app connects to Apple services for enabled features such as iCloud sync, caregiver sharing and purchases. If you email support, we receive the information you choose to include in that message. Do not send sensitive care records unless they are needed for your support request.
Usage analytics
The upcoming 1.3.1 release includes usage analytics handled by PostHog in the United States. Earlier versions without a Usage analytics setting do not include this reporting. In versions that support it, reporting is on by default. Turn it off under Settings, then iCloud and privacy. The change stops reporting immediately, without waiting for another launch.
Events describe app actions, such as opening a screen, logging an entry, starting a timer, changing a setting or completing a purchase. They include the kind of action, but not your baby's name, date of birth, photos, notes, feeding amounts, durations, weights or temperatures. Events also have timestamps and technical identifiers used by the analytics service.
Limited context includes a coarse age band, whether you have one baby or more than one, enabled features, app version, device model and operating system. The service can derive approximate country, region and city from the network connection. This is not GPS location. No advertising identifier is requested, and analytics are not used for tracking across other apps or websites. Session replay and screen recording are disabled.
Turning reporting off stops future analytics. It does not automatically delete events already received. Contact hello@zenproducts.ai with privacy questions; do not include your care records unless necessary.
Payments
Subscriptions and the one time purchase are handled entirely by Apple. We never see your card, your billing address or your Apple Account. All we ever learn is whether this copy of the app is unlocked, and that answer comes from your device rather than from a server of ours.
Notifications
Care reminders are scheduled on your device by iOS. You can change them in the app and in iOS notification settings. CloudKit also delivers updates for enabled sync and caregiver sharing through Apple's services.
Children
Zen Otto is used by parents and caregivers to record information about a child. Those records are stored on the adult's device and, when enabled, in iCloud or a caregiver share as described above. We do not receive those records through an app-operated data service.
Deleting your data
Removing the app does not by itself remove copies held in iCloud or end a caregiver share. Manage sharing in the app before removing it, and manage its iCloud data in iOS Settings under your Apple Account, then iCloud and Manage Account Storage. Keep an export of any records you want to retain before deleting data. Copies you or a caregiver exported separately must be managed separately.
This app is not medical advice
Zen Otto shows you your own log, and it shows published reference ranges with the body that published them named on screen. It never compares the two, and it never draws a conclusion about your baby. It is not a medical device, it does not diagnose anything, and it is not a substitute for your doctor or health visitor.
Changes
If this policy changes, the updated version will be posted here and the date at the top will change.