Privacy Policy
Effective Date: August 21, 2025
Welcome to Napz ("we," "us," or "our"). This Privacy Policy describes how Napz collects, uses, processes, and protects your personal information when you use our mobile application and related services (collectively, the "Service").
Your privacy matters to us. We are committed to protecting your personal information and being transparent about our data practices. This policy explains what information we collect, how we use it, and your rights regarding your data.
Information We Collect
Personal Information
When you create an account or use our Service, we collect:
- Account Details: Email address, username, and securely encrypted password
- Profile Information: Optional details such as your name, baby's name, birth date, and profile photo
- Contact Information: Information you provide when contacting customer support
Baby Care Data
- Sleep Patterns: Bedtime, wake times, nap duration, sleep quality ratings, and sleep environment conditions
- Health Tracking: Feeding schedules, diaper changes, growth measurements, mood tracking, and developmental milestones
- Custom Activities: Any additional activities you choose to log within the app
Technical Information
- Device Data: Device type, operating system version, unique device identifiers, and app version
- Usage Analytics: App feature usage, session duration, crash reports, and performance metrics
- Location Data: Approximate location for timezone settings and regional features
Optional Data Collection
- Audio Analysis: If enabled, ambient sound analysis for sleep environment optimization (processed on our secure servers)
- Photos: Images you choose to upload related to your baby's activities or milestones
- Notes: Text entries, observations, and custom tags you add to tracking entries
Data Storage and Security
Storage Infrastructure
Secure Server Storage: Your data is stored on enterprise-grade servers with multiple layers of security protection, intrusion detection systems, and access controls.
Encryption and Protection
- In Transit: All data transmission is protected using TLS 1.3 encryption
- At Rest: Data stored on our servers is encrypted using AES-256 encryption
- Database Security: Multi-layer database security with encrypted backups and access logging
- Access Controls: Strict employee access controls with multi-factor authentication and regular access reviews
Security Monitoring
- 24/7 security monitoring and incident response
- Regular security audits and penetration testing by third-party security firms
- Automated threat detection and response systems
Data Sharing and Disclosure
We Do Not Sell Your Data
We never sell, rent, or trade your personal information to third parties for marketing purposes.
Authorized Sharing
Service Providers: We may share data with trusted third-party service providers who assist with:
- Cloud hosting and data storage
- Analytics and performance monitoring
- Customer support services
All service providers are contractually bound to protect your data and use it only for specified purposes.
Legal Requirements
We may disclose your information when required by law or to:
- Comply with legal processes, court orders, or government requests
- Protect our rights, property, or safety, or that of our users
- Investigate potential violations of our Terms of Service
- Respond to emergency situations involving potential harm
How We Use Your Information
Core Service Delivery
- Provide personalized sleep and health tracking functionality
- Generate insights, trends, and recommendations based on your data
- Sync data across your devices and maintain service continuity
- Send notifications, reminders, and alerts as configured by you
Service Improvement
- Analyze usage patterns to enhance app performance and user experience
- Develop new features and improve existing functionality
- Conduct research to better understand baby sleep and health patterns
- Troubleshoot technical issues and provide customer support
Communication
- Respond to your inquiries and provide customer support
- Send important service updates, security notifications, and policy changes
- Provide optional educational content and tips (with your consent)
Legal and Safety
- Comply with applicable laws, regulations, and legal processes
- Protect against fraud, abuse, and security threats
- Enforce our Terms of Service and other agreements
Data Retention and Deletion
Retention Periods
- Account Data: Retained while your account is active and for up to 2 years after account deletion
- Baby Care Data: Retained as long as you maintain an active account
- Technical Data: Log files and analytics data retained for up to 12 months
- Support Communications: Customer support interactions retained for up to 3 years
Data Deletion
- You may delete individual entries or entire data categories within the app
- Account deletion removes your personal data from our active systems within 30 days
- Some data may be retained in encrypted backups for up to 90 days for system recovery purposes
- Anonymized, aggregated data used for research may be retained indefinitely
Children's Privacy
Our Service is intended for use by parents, caregivers, and family members over the age of 18. We do not knowingly collect personal information from children under 16. If we become aware that we have collected data from a child under 16, we will take immediate steps to delete such information.
Your Privacy Rights
Access and Control
- View Your Data: Access all personal data we have collected about you
- Update Information: Modify or correct your personal information at any time
- Download Your Data: Export your data in standard formats (JSON, CSV)
- Delete Data: Remove specific entries or delete your entire account
Communication Preferences
- Opt-out: Unsubscribe from marketing communications at any time
- Notification Settings: Control which app notifications you receive
- Data Processing: Opt-out of non-essential data processing activities
Regional Rights
For EU Residents (GDPR):
- Right to access, rectify, erase, restrict, or port your data
- Right to object to data processing
- Right to lodge complaints with supervisory authorities
For California Residents (CCPA):
- Right to know what personal information is collected
- Right to delete personal information
- Right to opt-out of data sales (note: we do not sell data)
- Right to non-discrimination for exercising privacy rights
For Indian Residents (DPDP Act):
- Right to access and correction of personal data
- Right to data portability and erasure
- Right to grievance redressal
International Data Transfers
If you are located outside India, your data may be transferred to and processed in India or other countries where we or our service providers operate. We ensure appropriate safeguards are in place through:
- Standard contractual clauses approved by relevant authorities
- Adequacy decisions by data protection authorities
- Other legally recognized transfer mechanisms
Third-Party Services
Our app may integrate with or link to third-party services:
- App Stores: Apple App Store
- Social Media: If you choose to share content
- External Links: Educational resources and support materials
Each third-party service has its own privacy policy, which we encourage you to review.
Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect changes in our practices or applicable laws. We will:
- Post the updated policy in the app with a new effective date
- Notify you of material changes via email or in-app notification
- Provide a summary of key changes when significant updates are made
Your continued use of the Service after changes become effective constitutes acceptance of the updated policy.
Contact Us
If you have any privacy questions or requests, please reach us:
- Email: support@napz.app
- In-App Support: Settings → Help & Support → Contact Us
Response time commitment: all privacy inquiries receive a response within 24 hours, with resolution within 72 hours for complex cases.
Legal Framework
- Governing Law: This Privacy Policy is governed by the laws of India, including the Digital Personal Data Protection Act, 2023.
- Jurisdiction: Any legal proceedings will be subject to the exclusive jurisdiction of courts in New Delhi, India.
- Compliance: We comply with applicable international privacy laws including GDPR, CCPA, and other regional privacy regulations.