This Privacy Policy explains how Aku Online Ltd (“Weanify”, “we”, “us”, “our”) collects, uses, and protects information when you use the Weanify mobile application (the “App”).
Aku Online Ltd is a company registered in the United Kingdom.
Controller:
Aku Online Ltd
167–169 Great Portland Street, 5th Floor
London, W1W 5PF
United Kingdom
Email: support@weanify.com
Website: https://weanify.com
We are the data controller for purposes of the UK GDPR and EU General Data Protection Regulation (GDPR).
Who the App Is For
- Weanify is designed for parents and caregivers.
- It is not directed to children.
- Parents may enter information about a child (such as age, allergies, or dietary requirements) to personalize app functionality.
Information We Process
We follow a local-first architecture. Most data is stored only on your device.
A. Information Stored Locally on Your Device
The following information is stored only on your device (AsyncStorage / local database):
- Baby name or nickname (optional)
- Age or birth date
- Allergies
- Dietary requirements (e.g., vegetarian, gluten-free, nut-free)
- Feeding challenges
- Supplements
- Medical conditions
- Meal logs and reactions
- Saved recipes
- Notes and preferences
We do not sync this information to our servers.
B. Information Sent to Our Backend (Ephemeral Processing)
When you use AI-powered recipe generation, the App sends to our backend:
- Ingredients entered
- Baby age in months
- Allergies
- Dietary requirement flags
Our backend:
- Validates and sanitizes the request
- Sends relevant data to OpenAI
- Returns generated results
- Does not store prompts or generated content in a database
Generated recipes are saved only on your device if you choose to save them.
C. Special Category (Health-Related) Data
Allergy information, dietary requirements, medical conditions, and feeding reactions may qualify as health-related data under GDPR.
Legal basis for processing:
- Explicit consent (Article 9(2)(a) GDPR), provided when you voluntarily enter this information and use AI features.
- Provision of app functionality (Article 6(1)(b)).
- Legitimate interests in improving feeding insights (Article 6(1)(f)), where applicable.
You may delete this data at any time by clearing your profile or uninstalling the App.
D. Analytics Data (Mixpanel)
We use Mixpanel (EU data residency enabled) to understand usage and improve the App.
Analytics may include:
- Anonymous device identifier
- App version
- Device type
- Operating system
- Feature usage events
- Onboarding selections (including challenges, supplements, medical conditions)
- Approximate location inferred from IP address (IP anonymized where supported)
We configure Mixpanel to use pseudonymous identifiers and avoid collecting direct identifiers such as name or email.
Legal basis: Consent (Article 6(1)(a) GDPR) for EU/UK users. Where required by law, analytics collection should be based on user consent.
E. Backend Logs (Vercel)
Our backend runs on Vercel.
Function logs may contain:
- IP address
- Request ID
- Anonymous client ID
- Duration and performance metrics
- Allergy metadata (for AI request context)
- Error messages (sanitized)
We do not maintain our own log database. Log retention is governed by Vercel's retention policies.
Legal basis: Legitimate interests (security, abuse prevention, debugging).
F. AI Processing (OpenAI)
We use OpenAI API to generate recipes and analyze ingredients.
- Data sent includes ingredients, baby age, allergies, and dietary requirements.
- We use OpenAI's API under a policy where customer data is not used for model training.
- OpenAI may retain data temporarily in accordance with its policies.
OpenAI acts as our processor for AI functionality.
G. Subscriptions and Payments
Subscriptions are handled by:
- Apple App Store
- Google Play
- RevenueCat (subscription processor)
We do not receive or store payment card information. We receive only entitlement/subscription status necessary to unlock features.
H. Push Notifications
If enabled, we collect:
- Expo push token
Notifications are purely functional (reminders, milestones). They are not used for advertising.
Legal Bases for Processing (EU/UK)
Under GDPR and UK GDPR, we rely on:
- Contractual necessity (Article 6(1)(b)) — to provide core app functionality.
- Consent (Article 6(1)(a)) — for analytics and optional features.
- Explicit consent (Article 9(2)(a)) — for health-related data.
- Legitimate interests (Article 6(1)(f)) — security, fraud prevention, debugging, service improvement.
International Data Transfers
Some service providers (e.g., OpenAI, Mixpanel, RevenueCat, Vercel) may process data outside the UK/EEA.
Where required, transfers are protected through:
- Standard Contractual Clauses (SCCs),
- Adequacy decisions, or
- Other lawful safeguards.
Data Retention
- Local device data: Stored until you delete it or uninstall the App.
- Backend logs (Vercel): Retained according to Vercel's platform policies.
- Analytics data (Mixpanel): Retained according to Mixpanel retention settings.
We do not maintain a central user database.
Your Rights (EU/UK)
If you are located in the UK or EU/EEA, you have the right to:
- Access your personal data
- Rectify inaccurate data
- Request erasure
- Restrict processing
- Object to processing
- Data portability
- Withdraw consent at any time
- Lodge a complaint with your local supervisory authority
To exercise rights, contact: support@weanify.com
Because most data is stored locally, you can delete much of your data directly within the App.
California Privacy Rights (CCPA/CPRA)
If you are a California resident, you have the right to:
- Know what personal information we collect
- Request deletion
- Correct inaccurate information
- Opt-out of sale or sharing (we do not sell or share data for cross-context behavioral advertising)
- Non-discrimination for exercising rights
We do not sell personal information.
Canada (PIPEDA)
For Canadian users, we process personal information for identified purposes with consent, and you may request access or correction by contacting support@weanify.com.
Children's Privacy
- The App is not directed to children under 13 (or under 16 in certain jurisdictions).
- We do not knowingly collect personal information directly from children.
- Parents provide any child-related data voluntarily.
Security
We implement reasonable administrative and technical safeguards. However, no system is completely secure.
Changes to This Policy
We may update this policy periodically. We will revise the “Last updated” date accordingly.
Contact Us
Aku Online Ltd
167–169 Great Portland Street, 5th Floor
London, W1W 5PF
United Kingdom