Privacy Policy

Effective date: July 11, 2026 · Last updated: July 22, 2026

This Privacy Policy describes how Don't Buy That Yet (“we”, “us”, or “our”) collects, uses, and shares information when you use the Don't Buy That Yet: Baby mobile application (the “App”) and the websites we operate (together, the “Services”). We built the Services around a simple idea: help you buy less, not learn more about you. We collect the minimum we need to run the audit you ask for.

1. Information we collect

Information you provide

Information collected automatically

What we do not run

We do not run advertising trackers, and we do not use advertising identifiers. We do not run behavioral or product analytics SDKs — nothing in the App reports which screens you visit, how long you spend, or where you drop off. Crash reporting, described above, is the one third-party SDK in the App that reports anything automatically, and it reports only crashes.

The check-in answers and the two actions described above are the exception, and we want to be straight about it rather than hide behind “we don’t do analytics”: those are things you did in the App that we record. The distinction we are drawing is between measuring you and measuring our own advice. We are not building a profile of your behavior, and we are not watching you use the App. We are checking whether the recommendations we gave were right, using answers you chose to give and two buttons you chose to press.

Information we do not collect

We do not collect your name, email address (unless you email us), phone number, contacts, photos, precise location, health records, payment details, or advertising identifiers. We do not sell personal information, and we do not share it for cross-context behavioral advertising.

2. How we use information

3. How artificial intelligence is used

The audit is generated with the help of large language model (“AI”) providers, such as Anthropic. When you run an audit, we send the product names from your list and your household answers to the AI provider through its commercial API so it can produce the keep / cut / delay / buy-used / buy-new recommendations.

4. How we share information

We share information only with:

We may use aggregated or de-identified information that cannot reasonably be used to identify you for any lawful purpose, such as understanding which product categories are most often overbought.

5. Data retention

Audit requests and results — including your registry text, household answers, and any check-in answers attached to that audit — are automatically deleted within 365 days of the audit completing. This is enforced by our database rather than by someone remembering to run a cleanup. Server logs are retained on shorter cycles. Crash reports are retained by Google on Firebase Crashlytics’ own schedule, after which they are deleted; deleting and reinstalling the App resets the crash reporting identifier described above. Because the App has no user accounts, deleting the App removes the anonymous session from your device; you can also delete your data from inside the App at any time, or ask us to delete server-side data associated with an audit by contacting us.

What outlives that window. When you answer a check-in, we separately keep a de-identified record of the outcome: a general product category, what the audit recommended, what you told us happened, and the item’s price if your list included one — for example “stroller · $340 · delay · didn’t buy”. These records carry no session identifier, no registry text, and nothing tying them to you or to each other beyond the single audit they came from, and that link is severed when the audit is deleted. We keep them because our advice only improves if we can see, in aggregate, how it turned out — and we would rather hold a category and an outcome indefinitely than hold your actual list and answers any longer than we do. Because they cannot be connected back to you, they cannot be individually retrieved or deleted on request, and they are not personal information.

6. Your choices and rights

Depending on where you live, you may have rights to access, correct, delete, or receive a copy of personal information, and to opt out of certain processing. Because we hold so little — and cannot link audits to a name or email address — some rights may be technically limited: we may not be able to locate data connected to you specifically unless you can provide the relevant session details. To exercise any right, contact us at the address below; we will not discriminate against you for doing so. Residents of the European Economic Area and the United Kingdom may also lodge a complaint with their supervisory authority.

7. Security

All traffic between the App, our servers, and our service providers is encrypted in transit using HTTPS/TLS. We use administrative and technical safeguards appropriate to the small amount of data we hold. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

8. Children’s privacy

The Services are for adults — expecting and new parents — and are not directed at children. We do not knowingly collect personal information from children under 16. If you believe a child has provided us personal information, contact us and we will delete it.

9. International users

The Services are operated from and processed in the United States. If you use them from outside the United States, you understand that your information is transferred to and processed in the United States and in the countries where our service providers operate.

10. Changes to this policy

We may update this Policy from time to time. When we do, we will revise the “Last updated” date above, and for material changes we will provide additional notice within the App or on this site. Continued use of the Services after changes take effect means you accept the revised Policy.

11. Contact us

Questions or requests about privacy: [email protected].