Privacy Policy
Effective date: July 11, 2026 · Last updated: July 22, 2026
This Privacy Policy describes how Don't Buy That Yet (“we”, “us”, or “our”) collects, uses, and shares information when you use the Don't Buy That Yet: Baby mobile application (the “App”) and the websites we operate (together, the “Services”). We built the Services around a simple idea: help you buy less, not learn more about you. We collect the minimum we need to run the audit you ask for.
1. Information we collect
Information you provide
- Your registry or shopping list. The product names you paste or type into the App so we can audit them. The list should contain product names only — please do not include names, addresses, or other personal details in it. We apply automated filtering to the text you submit, but the best protection is not to paste personal information in the first place.
- Household answers. Your answers to the App’s short questionnaire — for example expected due date or baby age range, home and storage type, budget range, and buying preferences. These exist only to shape the audit.
- Your check-in answers. Some time after an audit, the App may show a short check-in asking what actually happened with the items it suggested you cut, delay, or buy used — for each one, whether you bought it, didn’t buy it, or are still deciding, and whether you kept something we suggested cutting. Answering is optional and you can dismiss the check-in in one tap. We ask because it is the only way to know whether our advice was any good, and it is what lets us tell future users things like “most people who delayed this never ended up needing it.”
- Messages you send us. If you contact us (for example by email), we receive your email address and the contents of your message.
Information collected automatically
- An anonymous session identifier. The App signs in anonymously to our backend. This identifier is a random value; it is not linked to your name, email address, or phone number — the App never asks for any of those, and there are no user accounts.
- Basic technical data. App version, device platform and OS version, request timestamps, and IP addresses in our server logs, used for security, rate limiting, and debugging.
- Crash and diagnostics data. The App includes Firebase Crashlytics, a crash reporting tool provided by Google. When the App crashes, it sends Google a diagnostic report so we can find and fix the bug: the crash’s technical stack trace, the App version, your device model and operating system version, and basic device state at the moment of the crash (for example, whether the device was low on memory). Each installation of the App is given a random Crashlytics installation identifier so that multiple crash reports from the same install can be grouped together. That identifier is generated by Google, is not linked to your name, email address, or advertising identifier, and is reset if you delete and reinstall the App. We use crash data only to fix crashes. We do not use it to build a profile of you, to track you, or for advertising, and we do not attach your registry text, household answers, or session tokens to crash reports.
- Two actions inside the App. When you mark a suggestion “Keep Anyway”, and when you copy your family summary to share it, the App tells our backend that it happened, attached to that audit. That is the complete list — two actions, both of which you take on purpose. Disagreeing with an audit is useful signal, and we would rather learn it from the button you actually pressed than by guessing.
- Website logs. Our websites are served by Cloudflare and produce standard server logs.
What we do not run
We do not run advertising trackers, and we do not use advertising identifiers. We do not run behavioral or product analytics SDKs — nothing in the App reports which screens you visit, how long you spend, or where you drop off. Crash reporting, described above, is the one third-party SDK in the App that reports anything automatically, and it reports only crashes.
The check-in answers and the two actions described above are the exception, and we want to be straight about it rather than hide behind “we don’t do analytics”: those are things you did in the App that we record. The distinction we are drawing is between measuring you and measuring our own advice. We are not building a profile of your behavior, and we are not watching you use the App. We are checking whether the recommendations we gave were right, using answers you chose to give and two buttons you chose to press.
Information we do not collect
We do not collect your name, email address (unless you email us), phone number, contacts, photos, precise location, health records, payment details, or advertising identifiers. We do not sell personal information, and we do not share it for cross-context behavioral advertising.
2. How we use information
- To generate your registry audit and savings plan — the service you asked for.
- To find out whether our recommendations were actually right, and improve the guidance every future audit gives, using de-identified check-in results as described below.
- To operate, maintain, debug, and improve the reliability of the Services.
- To protect the Services, including rate limiting, abuse prevention, and security.
- To comply with legal obligations and enforce our terms.
- To respond when you contact us.
3. How artificial intelligence is used
The audit is generated with the help of large language model (“AI”) providers, such as Anthropic. When you run an audit, we send the product names from your list and your household answers to the AI provider through its commercial API so it can produce the keep / cut / delay / buy-used / buy-new recommendations.
- What is sent is anonymized. The request contains the list text and questionnaire answers only. It does not include your name, email address, phone number, device identifiers, or advertising identifiers. The crash reporting identifier described above is never sent to AI providers.
- Your data is not used to train AI models. We do not use your information to train AI models, and the commercial API terms we use with our AI providers prohibit them from training their models on data we send.
- Limited retention by providers. AI providers may retain API inputs and outputs for a limited period for abuse and safety monitoring under their commercial terms, after which they are deleted.
4. How we share information
We share information only with:
- Service providers that process it on our behalf and are authorized to use it only as necessary to provide services to us: cloud hosting and infrastructure (Google Cloud, in the United States), crash reporting (Google, via Firebase Crashlytics), website hosting (Cloudflare), and AI providers (such as Anthropic) as described above.
- Public authorities where required by law, subpoena, or legal process, or to protect the rights, safety, and security of our users, the public, or the Services.
- A successor entity in connection with a merger, acquisition, or sale of assets, in which case this Policy will continue to apply to previously collected data.
We may use aggregated or de-identified information that cannot reasonably be used to identify you for any lawful purpose, such as understanding which product categories are most often overbought.
5. Data retention
Audit requests and results — including your registry text, household answers, and any check-in answers attached to that audit — are automatically deleted within 365 days of the audit completing. This is enforced by our database rather than by someone remembering to run a cleanup. Server logs are retained on shorter cycles. Crash reports are retained by Google on Firebase Crashlytics’ own schedule, after which they are deleted; deleting and reinstalling the App resets the crash reporting identifier described above. Because the App has no user accounts, deleting the App removes the anonymous session from your device; you can also delete your data from inside the App at any time, or ask us to delete server-side data associated with an audit by contacting us.
What outlives that window. When you answer a check-in, we separately keep a de-identified record of the outcome: a general product category, what the audit recommended, what you told us happened, and the item’s price if your list included one — for example “stroller · $340 · delay · didn’t buy”. These records carry no session identifier, no registry text, and nothing tying them to you or to each other beyond the single audit they came from, and that link is severed when the audit is deleted. We keep them because our advice only improves if we can see, in aggregate, how it turned out — and we would rather hold a category and an outcome indefinitely than hold your actual list and answers any longer than we do. Because they cannot be connected back to you, they cannot be individually retrieved or deleted on request, and they are not personal information.
6. Your choices and rights
Depending on where you live, you may have rights to access, correct, delete, or receive a copy of personal information, and to opt out of certain processing. Because we hold so little — and cannot link audits to a name or email address — some rights may be technically limited: we may not be able to locate data connected to you specifically unless you can provide the relevant session details. To exercise any right, contact us at the address below; we will not discriminate against you for doing so. Residents of the European Economic Area and the United Kingdom may also lodge a complaint with their supervisory authority.
7. Security
All traffic between the App, our servers, and our service providers is encrypted in transit using HTTPS/TLS. We use administrative and technical safeguards appropriate to the small amount of data we hold. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
8. Children’s privacy
The Services are for adults — expecting and new parents — and are not directed at children. We do not knowingly collect personal information from children under 16. If you believe a child has provided us personal information, contact us and we will delete it.
9. International users
The Services are operated from and processed in the United States. If you use them from outside the United States, you understand that your information is transferred to and processed in the United States and in the countries where our service providers operate.
10. Changes to this policy
We may update this Policy from time to time. When we do, we will revise the “Last updated” date above, and for material changes we will provide additional notice within the App or on this site. Continued use of the Services after changes take effect means you accept the revised Policy.
11. Contact us
Questions or requests about privacy: [email protected].