bebem — Privacy Policy
Effective date: 2026-08-25
The short version. Your records stay on your device and in your own iCloud — they never reach us. We operate no server that could read them, there are no user accounts, and we cannot see, access, or recover what you write, not even if you ask us to. No ads, no advertising tracking, no behavioural analytics. Two things can reach us, and neither contains your records: content-free crash and sync-trouble reports that carry no name or account (on by default — switch them off any time in Settings → "Share diagnostics"), and email you choose to send us.
1. Who we are
bebem is published by Merve ALTIN-SARIYILDIZ, operating as BIZMESMER (registered trade name / nom commercial of an entreprise individuelle, France).
- Address: 7 Chemin des Sources, 38240 Meylan, France
- Contact: [email protected]
To the extent the General Data Protection Regulation (GDPR) applies to us at all — see section 5 — Merve ALTIN-SARIYILDIZ is the data controller.
2. What bebem handles, and why
bebem is a notebook for your child's day. Everything in it is written by you or by the family members you invite:
- feeding and meal records (times, amounts, foods, where the meal happened)
- breastfeeding records (which side, how long, feeds grouped into one session)
- sleep records (start, end, duration)
- diaper changes, including what was in the diaper
- drinks (water, milk, juice)
- activities, with your own notes
- health notes: medicines given (name, dose, time), body temperature and where it was taken, symptoms, and doctor visits — see section 8
- vaccinations: the names and dates you copy from your child's own health booklet, whether each one has been given, and your notes on it
- growth measurements (height, weight, head circumference), your child's measurements at birth, and the length of the pregnancy
- free-text notes, including the one moment a day you can star
- a family food list (food names, portion sizes, calorie values)
- your child's first name, birth date and sex
- caretaker names you create ("Mum", "Grandpa", a nanny's name) — each entry records which name wrote it
- app settings (language, notification preferences, units), stored on the device
- for each entry, the time zone it was written in and how precisely the time is known
That is what the app is built to hold, and section 11 tells you how you will learn if it ever changes. bebem records no photos, no audio, no location, no contacts, and nothing from other apps.
Health information, and why it gets special care. Some of what you write is health information about a child: medicines and doses, body temperature, symptoms, doctor visits, vaccinations, and growth. European law treats health information as a special category of personal data (Article 9 GDPR); Turkish law treats it as özel nitelikli kişisel veri (KVKK art. 6). Our position is short, and it is a consequence of how the app is built rather than a promise about our conduct: we never receive it. It is written on your device and kept on your device. If you use iCloud it is synchronised inside your own iCloud account, and when you invite someone, inside the private share you create — with the health fields encrypted so that only your family's own devices can read them. There is no bebem server it passes through, no bebem account it is attached to, and no copy we hold. There is nothing for us to look at, lose, sell, or be compelled to hand over. You are keeping a record for your own household (Article 2(2)(c) GDPR); what you do with it, and who you show it to, is yours to decide.
Two things you can send out of the app, both by your own hand. The visit summary (a PDF) and "Export all data as JSON" are both built on your phone, with no network connection of any kind. Each exists as a file only around the sharing sheet you opened; the app deletes the summaries it made the next time you open it, and in any case within the hour. Where the file goes — a message, an email, a printer, a doctor — is your choice, and once it has left the app it is outside bebem's protection. The summary carries your child's full name in the document and in its filename, together with the health information listed above, including vaccinations. The JSON archive carries everything in the list above.
Diagnostics (on by default, with an off switch). So that crashes and sync failures get found and fixed, bebem sends diagnostics: if the app crashes or hangs, a technical report (stack traces, thread state) goes out, together with the device model, OS version, app version and build, timestamps, and short app-launch/session pings that tell us which release is stable. If iCloud sync or sharing fails, a report of the failure goes out the same way — error codes and their structure only, never the contents of a record, a name, or an identifier. These reports carry a random installation identifier and a hash derived from your device — neither is linked to any user identity, and bebem has no accounts to link them to. They are configured to be content-free: no session replay, no automatic breadcrumbs, no network-request tracking, no screenshots, no view hierarchy. They never include anything you write, child data, names, iCloud identifiers, or location. Turn this off at any time in Settings → "Share diagnostics".
The purpose is the one you can see on screen: keeping a private family record of your child's care, shown back to you as daily and summary views. The optional evening summary and the optional vaccination reminders are put together on your phone, by your phone — nothing is transmitted to schedule them and no one else is involved. But a notification is drawn on a screen anyone holding the phone can read, and your phone may repeat it on a paired watch or a Mac you are signed in to. So by default neither one shows your child's name or any words you wrote: the evening summary shows the day's counts, and a vaccination reminder says only that a vaccine is due. One switch in Settings turns names and your own words back on, for both, if you want them.
About children. bebem stores information about your child, entered by you. The app is directed at parents and caregivers — adults — not at children, and it is not intended to be used by children. You decide what to write; record only what you are comfortable keeping, and only about children in your care.
If you use the iOS keyboard's dictation feature to enter text, that is a feature of Apple's keyboard, governed by your device settings and Apple's terms; bebem receives only the final text.
3. Where your data lives, and who can access it
Three places, all of them yours:
- Your device. Records are stored in the app's local database on your iPhone.
- Your iCloud. If your device is signed in to iCloud, bebem keeps its records in your private iCloud database so they survive a lost phone and stay in sync across your own devices. This happens inside your own iCloud account, under your existing service relationship with Apple: Apple processes that data as your provider, under Apple's iCloud terms and Apple's privacy policy — not on our behalf. If you are not signed in to iCloud, everything simply stays on the device. You can manage which apps use iCloud in your device's iCloud settings.
- Family members you invite. You can share the family archive with people you invite through iCloud sharing. Shared records move only between the participants' own iCloud accounts. You control who is invited; you can remove a member at any time, and an invited member can leave the share (optionally keeping a copy of the records). A shared ledger also carries a subscription-status marker, visible to everyone in the share: it is how a participant's device knows whether the ledger owner's plan still covers it, which means invited participants can see whether the owner's subscription has lapsed. It travels the same iCloud path as the records themselves and never reaches us.
We have no access. We operate no server that receives, stores, or can read your records. We cannot view them, restore them, or hand them over to anyone — the technical means to do so simply do not exist in the app.
Beyond Apple's iCloud sync and Apple's App Store and subscription machinery, the only network traffic the app creates on its own is the optional, content-free diagnostics described in section 2 — and it stops the moment you turn the toggle off.
4. What we do receive
Little, and none of it your records:
- Subscription information from Apple. Subscriptions are bought through Apple's In-App Purchase. Apple is the merchant: we never see your name, your payment details, or your Apple Account. Apple makes anonymized transaction information available to us — enough to know that a subscription of a given tier exists, not who bought it.
- Diagnostics — if the toggle is on. The content-free crash, hang and sync-failure reports described in section 2. They are processed for us by Sentry (Functional Software, Inc. dba Sentry), a US company acting as our processor, and bebem's diagnostic data is hosted in Sentry's EU region (EU data residency). The reports contain no identity that could be linked to you.
- Email you choose to send us. The "Send feedback" row in the app opens your own mail app, addressed to [email protected]. If you send it — or write to us directly — we receive your email address and whatever you chose to include, and we use it only to answer you.
No accounts, no ads, no advertising tracking, no behavioural analytics. One third-party SDK exists in the app — the diagnostics SDK above, configured content-free, with its off switch in Settings — and no other.
5. Our role under the GDPR (legal basis)
The honest answer: for your records, we are not in the loop.
- Your family's records are processed on your own device and inside your own iCloud, under your exclusive control. We — the publisher — never receive them and never process them. For purely personal or household record-keeping, the GDPR generally does not apply to your family's own use either (Article 2(2)(c) GDPR).
- Health information about your child is a special category of personal data (Article 9 GDPR), and özel nitelikli kişisel veri under Turkish law (KVKK art. 6). We do not process it — we never receive it. Where the household exemption in Article 2(2)(c) GDPR does not cover your own use of it, the grounds are yours, not ours; we are not in a position to rely on any.
- Apple processes iCloud data as your own service provider, under your agreement with Apple.
- Where we do process personal data — a feedback or support email you send us, or the minimal anonymized transaction data Apple provides — we rely on the performance of our contract with you (Article 6(1)(b) GDPR) and on our legitimate interest in answering you and operating the business (Article 6(1)(f) GDPR).
- Diagnostics rest on our legitimate interest in keeping the app reliable (Article 6(1)(f) GDPR). Your right to object is built into the product: the "Share diagnostics" toggle in Settings stops all future sending, no questions asked.
We transfer none of your records anywhere (we do not have them), we make no automated decisions about you, and we have not appointed a data protection officer because none is required.
6. Your rights, and how they actually work here
Under the GDPR you have rights of access, rectification, erasure, restriction of processing, data portability, and objection. Because your data never reaches us, the rights that matter are satisfied directly in the app, by you, with immediate effect:
- Access: everything the app holds is visible in the app; nothing is held anywhere else.
- Rectification: open any entry and edit it.
- Erasure: delete any entry, any child, or everything — see section 7.
- Portability: Settings → "Export all data as JSON" produces a complete, machine-readable archive of everything, which the app can also import again.
For your records, the remaining rights (restriction, objection) have no practical object with respect to us, because we hold none of them: no copy exists for us to look up, correct, delete, or hand over. If anything is unclear, write to [email protected] and we will help you use the in-app paths.
Diagnostics are the one flow that does reach us, so to be precise about your rights there: turning off Settings → "Share diagnostics" stops all future sending immediately — that is your objection, honoured by design. Reports already sent carry no name and no account, but they do carry the two identifiers named in section 2. We cannot connect either to a person, and you have no way to read them off your phone to quote back to us — so we cannot single out "your" reports on request (Article 11(2) GDPR). They are deleted on schedule instead (section 9).
7. Deleting your data (and why there is no "delete account" button)
bebem has no accounts. You never sign up, there is no login, and no bebem account exists anywhere — so there is no account we could delete. (Apple's account-deletion requirement, App Review Guideline 5.1.1(v), applies to apps that let you create an account; bebem does not.) What exists instead is data on your device and in your iCloud, and you can remove all of it yourself:
- Export first, if you want a copy. Settings → "Export all data as JSON".
- Delete individual entries. Open any record and delete it. Deletions carry over to your other devices and to invited family members.
- Delete a child. In the baby switcher, edit a child and delete them — this removes the child's profile and all of that child's records. bebem always keeps at least one child profile; the last one disappears with the app itself (step 5).
- Handle sharing. If you invited others, remove them in Sharing — they lose access. If you joined someone else's archive, leave it (you can choose whether to keep a copy of the records).
- Delete the app. This removes everything stored on the device.
- Delete the iCloud copy. Deleting the app does not remove data already synced to your iCloud. On your iPhone: Settings → [your name] → iCloud → Manage Account Storage → bebem → Delete Data.
- Cancel your subscription separately. Deleting the app does not cancel a subscription. Go to Settings → [your name] → Subscriptions (or the App Store app → your profile → Subscriptions) and cancel bebem there.
After steps 5 and 6, nothing of your data remains anywhere — which is also why we cannot undo it for you. Export first.
8. Medicine entries
Medicine entries are your own notes, for your own record-keeping. bebem provides no medical advice, no dosing guidance, and no warnings — for anything concerning your child's health or medication, consult a healthcare professional.
9. How long data is kept
Your records: for as long as you keep them, and no longer. No server retains them, because no server has them: they stay on your device and in your iCloud until you delete them (section 7). Diagnostics are kept on our processor's systems for 30 days (the default retention period) and then deleted. Feedback and support emails are kept only as long as needed to handle your request.
10. What we never do
We do not sell your data. Your records we could not share with anyone even if asked — we do not have them. No advertising, no advertising tracking, no behavioural analytics, no profiling, no data brokers. The one piece of telemetry the app carries — content-free crash and sync reports — contains nothing you wrote and has an off switch. This is not a promise of good behaviour bolted onto the app; it is how the app is built.
11. Changes to this policy
If bebem's data flows ever change — for example, a future optional feature that processes text off-device — we will update this policy first, change the effective date at the top, and describe the change clearly before the feature ships. A new data flow will never be switched on silently.
12. Complaints
If you believe we have handled personal data in a way that violates the GDPR, you have the right to lodge a complaint with a supervisory authority — in France, the CNIL (Commission Nationale de l'Informatique et des Libertés, www.cnil.fr) — or with the authority of the EU/EEA country where you live or work. We would also appreciate the chance to resolve it directly: [email protected].