Privacy Policy

Last updated: October 8, 2026

Honey Bun is a baby-care tracker that helps caregivers log feedings, diaper changes, sleep, medicine doses, growth and the rest of a baby's day, and share that record with the other people who care for the child. It covers the iPhone app (with its widgets and Apple Watch app), the web app at honeybun.family, and the Alexa skill. We built it to be useful at 3 AM with one hand free, and we treat your data the same way we'd want ours treated. This policy explains exactly what we collect, why, where it lives, and how to get rid of it.

What we collect

  • Account information. When you sign in with Apple or Google, we receive your email address and a unique user identifier from that provider. We do not receive your Apple or Google password. If you sign in with an email address and a password instead, Firebase Authentication keeps the password in protected form; we cannot read it, and we send that address a verification email.
  • Your profile (Pliske ID). Your Honey Bun sign-in is a Pliske ID, the account system the developer of Honey Bun runs for all of his apps. It holds your email address, the name you go by, and, if you add them, a profile photo, a handle and a short bio, along with the list of his apps you have used. The same sign-in works in those other apps. Treat your name, handle and photo as a profile that other signed-in people in these apps can see; in Honey Bun they are shown to the caregivers who share a child with you.
  • Baby details you enter. Your baby's name, birth date and sex, the feeding windows, feeding schedule and medicine list you set up, and your pediatrician's details if you add them (practice, doctor, phone, address and website).
  • Care logs you create. Feedings (bottle amounts and type, nursing durations), diaper changes (type, size, color, consistency, rash), sleep, medicine doses, weight, baths, play and tummy time, and notes: goals, doctor-visit notes and questions, and milestones with an optional photo. Each entry carries its time and the name of the caregiver who logged it.
  • Caregivers and sharing. The connect code you share, requests to join a child's care team (with the requester's name, email address and photo), each caregiver's role label and access level, and the sitter schedule.
  • Chat. The messages, photos, videos and GIFs sent in a child's family chat, with reactions, who has read what, and edits.
  • Conversations with the AI assistant. The questions you type to Ask Honey Bun and its answers, @honeybun questions and answers in Chat, and the weekly summary it writes. See the AI assistant section.
  • Rewards. Your streaks, honey drop balance, quests, and the items you have collected or put on show.
  • Purchases. If you subscribe to Honey Bun Premium, Apple tells our server which plan you bought, Apple's identifier for the purchase, when it renews or ends, and whether it was refunded. We also keep the dates of your free trial and how many free questions you have used. We never receive your card or other payment details.
  • Device information and push tokens. For each device you sign in on: a push token from Firebase Cloud Messaging (and, on iPhone, a token from Apple for the Lock Screen Live Activity), an app-specific device identifier, your device model or browser, OS version, app version and time zone. These let us send notifications, work out what "today" is for you, and identify your device when you contact support. We do not see your phone number.
  • Alexa linking. If you choose to link Honey Bun with Amazon Alexa: a short-lived pairing code, your linked status, the identifiers Amazon gives the skill for your Amazon account and Echo device, and the name of the caregiver who linked it.
  • Pediatrician records. Only if you connect MyChart; see the MyChart section.
  • Help & feedback. The messages you send from Help & feedback in the app, any screenshot you attach, and your app version and device model. These are answered by an AI support assistant and read by the developer, who may copy a summary of a problem (without your email address or screenshot) into his issue tracker on GitHub.
  • Usage analytics. Which screens you view and which buttons you press in the app, plus named events describing feature use (e.g., AI assistant opened, settings toggled, sign-in method), via Google Analytics for Firebase, linked to your account in the phone app. The website uses the same service for page views and a few events. We do not collect the contents of your care logs or your AI conversations here — only screen names, button/element names, and basic event parameters describing app behavior. This is used only to improve the app — it's not used for advertising, not sold, and not used to track you across other companies' apps or websites.
  • App Store ads. If you installed Honey Bun after tapping an App Store ad, Apple tells us which of our ads it was. We use that to see which ads work. We never tell Apple or any ad network anything about your family or your baby.
  • Crash diagnostics. When the app crashes, Firebase Crashlytics sends us a report containing the stack trace, your device model, OS version, app version, and a short trail of recent in-app events ("breadcrumbs") leading up to the crash. No care log contents, AI conversations, or other personal information are included in crash reports. This data lets us find and fix bugs faster.

Location, camera and photos. The iPhone app asks for your location only to open the pediatrician map on your area. Your location stays on your phone and is not saved; the map area you are looking at is sent to Apple Maps to search for practices. The camera is used to scan a caregiver's connect code and to take photos for Chat. We only receive the photos and videos you choose to add.

We do not collect: your contacts, your location on our servers, the rest of your photo library, advertising identifiers, tracking across other apps for advertising, or any data we don't actively need for the features above.

How we use it

  • To show you your own care logs and the history view.
  • To sync your data across the devices signed into your account (your phone, your partner's phone) in real time.
  • To share a child's record and chat with the caregivers the child's owner has added.
  • To send reminders, missed-feeding alerts, feed-logged and chat notifications, and lock-screen feeding banner updates. Notifications can include the child's name, the details of a feed, and the start of a chat message; they are delivered through Apple and Google.
  • To show the last feed and what's next on your widgets and Apple Watch. A small copy of that summary (the child's name, recent feeds and diapers, your streak) is kept on your iPhone and watch for this.
  • To run Rewards: streaks, honey drops, quests and the items you collect.
  • To know whether your family has Honey Bun Premium, a trial, or neither.
  • To send you a welcome email when you join and one getting-started email a couple of days later. Both have a one-click unsubscribe. We send no marketing email.
  • To answer you in Help & feedback.
  • To answer questions you ask the AI assistant, grounded in your real care logs.
  • To log entries and answer questions when you use Alexa, Siri or Shortcuts.

We do not use your data for advertising. We do not sell, rent, or share your data with marketers. We do not train AI models on your data.

Where it's stored

Your data lives in Google Firebase and Google Cloud (Firestore database, Cloud Storage for photos and videos, Firebase Authentication, Firebase Cloud Messaging, Cloud Functions and Cloud Run) on servers operated by Google Cloud in the United States. Honey Bun's records are in Honey Bun's own Firebase project; your sign-in and profile are in the Pliske ID project, which the same developer runs. Access is scoped to your authenticated account and the caregivers on the same child, and our database security rules enforce this server-side.

Who else can see it

Each caregiver has their own account. A child's owner adds other caregivers with a connect code and gives each one a role. Other Honey Bun users cannot see your data, with these exceptions for people on the same child:

  • Every caregiver on a child can see that child's details, care logs, notes and milestones, the family chat with its photos and videos, the sitter schedule and the weekly summary.
  • They can also see each other's name, photo, email address, role, and Rewards (streak and the items on show).
  • Caregivers with restricted access (for example a sitter, nanny or grandparent) can change only the entries they logged themselves, and never see pediatrician records from MyChart.
  • Your Ask Honey Bun conversation is private to you. Answers to @honeybun in Chat are posted in the chat, where every caregiver on the child sees them.

Third parties we share with

Honey Bun relies on a small number of service providers to function. We only share the minimum data each needs:

  • Google Firebase — hosts your account, your care logs, chat, photos and videos, the messages that deliver notifications, usage analytics (Firebase Analytics), and crash diagnostics (Firebase Crashlytics). Firebase App Check (Apple's App Attest in the iPhone app, Google reCAPTCHA Enterprise on the web) confirms that requests come from the real app. Firebase privacy.
  • Google Sign-In, Apple Sign In and email with a password — used to authenticate you. The email and user ID returned by these providers are stored on our side, in your Pliske ID and in your user record in our database, so we can identify you when you contact support.
  • Apple — delivers push notifications and Live Activity updates, processes Honey Bun Premium purchases through the App Store and tells us their status, runs the map search for the pediatrician finder, and handles Siri and Shortcuts requests on your device.
  • Anthropic — its Claude models power the AI assistant. See the dedicated AI assistant section below for the full disclosure (what's sent, what's not, your consent, your revocation).
  • Amazon Alexa — if you link Alexa, Amazon keeps a token that identifies your Honey Bun account, and sends us what you asked for as text (for example the amount, the type of feed or the medicine name), not the audio. Our spoken answers go back through Amazon and can include your child's name and log details. If you use the Echo Show widget, your child's name and recent feeds and diapers are sent to Amazon to show there each time one is logged. Amazon Alexa privacy.
  • Epic MyChart and your clinic — only if you connect a chart; see the MyChart section.
  • KLIPY — the GIF search in the iPhone app's chat. What you type into the GIF search goes to KLIPY; nothing about your child or your account is sent with it.
  • Resend — sends Honey Bun's emails (the welcome and getting-started emails) from honeybun.family. Resend receives your email address, your first name and the email's text; nothing about your child or your care logs is in these emails. Resend privacy.
  • On the public website only — the chat bubble on the home page uses Cloudflare Turnstile to keep out bots and Anthropic's Claude to answer. Messages typed there are not stored by us.

The website keeps a few settings in your browser's storage (your theme, the child you last viewed, a device identifier, whether notifications are on) and Firebase's sign-in session. It sets no advertising cookies.

AI assistant (powered by Claude)

When you use Honey Bun's AI assistant — Ask Honey Bun, @honeybun in Chat, or the weekly summary — Honey Bun sends the following data to Anthropic, PBC, the maker of Claude, over an encrypted HTTPS connection:

  • The text of each message you send, and the recent messages in that conversation. For @honeybun, that means the recent messages in the family chat, including other caregivers' names and what they wrote (photos are left out).
  • Your child's recent feeds and diapers: times, amounts, types, and diaper details such as color, consistency and rash.
  • For the weekly summary, also: the longest night-time sleep stretch, the number of medicine doses (not which medicines), the latest weight, and how many entries each caregiver logged, with their names and roles.
  • Your child's name, sex, birth date, and feeding-window settings, so the assistant can answer for their age.
  • Your time zone and the current time, and whether your family has Honey Bun Premium.

If you ask it to, Ask Honey Bun can also log a feed, a diaper or a medicine dose for you, using what you typed.

We do not send your password, payment information, your location, photos or videos, doctor-visit notes, or anything from MyChart (apart from the doctor's name, described below). We do not send your email address either, with one exception: a caregiver who has not set a name is labelled by their email address on the entries they log, and that label can be included in the weekly summary.

Where the conversations are kept. Your Ask Honey Bun questions and answers are stored in our database so the thread is there when you come back; only you can read it. @honeybun answers are stored in the family chat. The weekly summary is stored with the child's record, where every caregiver on the child can read it.

Other places Claude is used. The support assistant in Help & feedback is also Claude. It receives your messages, any screenshot you attach, your email address, how you sign in, when your account was created, your app version and device model, and a short account summary (your role, your plan, your streak and honey drop balance), but none of your care logs or your child's name. When you pick a pediatrician's practice on the map, the practice's website and the doctor's name (taken from MyChart if you connected it) are sent to Claude to look up the office's details.

Anthropic processes this data on its own servers under its own published privacy policy at anthropic.com/legal/privacy. Under Anthropic's commercial terms, data sent through its API is not used to train its models.

Consent. Ask Honey Bun, @honeybun and the weekly summary are off until you turn the AI assistant on: the iPhone app asks the first time you open Ask Honey Bun, and on the web it is a switch in Settings. Our server checks this before sending anything to Anthropic for those features. When a caregiver who has turned it on asks @honeybun in the family chat, the recent chat messages sent with the question can include ones written by caregivers who have not. The support assistant, the pediatrician lookup and the website's chat bubble are separate from this switch; they contact Anthropic only when you use them. If you decline, all other Honey Bun features (manual logging, Live Activity, Alexa integration, notifications, sync) continue to work normally.

Revocation. You can revoke consent at any time in Settings → AI Assistant. Revoking stops new transmissions for Ask Honey Bun, @honeybun and the weekly summary immediately. Data previously sent to Anthropic is retained according to Anthropic's policy; to request deletion on Anthropic's side, contact them directly.

Pediatrician records (MyChart)

If your pediatrician's office uses MyChart, a parent can connect a child's chart to Honey Bun from the pediatrician card on the app's Growth tab, or from Settings on the web. This is optional, and nothing here happens unless you choose it.

  • What we read. Only what you tick on MyChart's own sharing screen, from these categories: immunizations, growth measurements (weight, length, head circumference and BMI, with their percentiles), allergies and reactions, medications and their instructions, clinical notes and visit summaries (including any attached PDFs), the child's name and date of birth, and the name of the child's primary-care doctor. We keep MyChart's identifiers for the child and for the parent who connected so we can refresh the record, which happens about once a day. We never write anything to the chart.
  • How it works. You sign in on MyChart's website, not in Honey Bun; we never see your MyChart password. MyChart gives our server a token for that one child, for the length of time you pick (one hour to one year). You can end it any time from MyChart's "linked apps" page or with Disconnect in Honey Bun.
  • Who can see it. Only the child's owner account and collaborators with full access (by default Mom, Dad and Co-parent). Sitters, nannies and grandparents with restricted access cannot see any of it, or that a chart is connected. The connection is made and removed only by the owner or a collaborator with full access.
  • What we do not do with it. We do not sell it, share it, or use it for marketing or advertising. It is never sent to Ask Honey Bun, @honeybun, the weekly summary, Alexa, or analytics. The one exception is the doctor's name, which is sent to Claude with the practice's website when you look up your pediatrician's office. It is not used to draw conclusions about anyone in your family beyond showing you the chart's own values and standard growth percentiles.
  • Where it is stored. On our servers (Google Cloud, United States), encrypted at rest; the MyChart tokens are additionally encrypted with a key held only by our server.
  • Deleting it. Disconnect (on the app's Pediatrician screen, or in Settings on the web) deletes everything the connection brought in and the tokens, immediately. Deleting the account that owns the child does the same. If a co-parent who made the connection deletes their own account, the tokens are deleted and the record stops refreshing, but what was already synced stays until someone disconnects. If MyChart access simply expires, what was already synced stays until you disconnect or reconnect.
  • Not covered by HIPAA, covered by the FTC. Honey Bun is not your healthcare provider and is not bound by HIPAA. Data you bring in from MyChart is protected by this policy and by the FTC's Health Breach Notification Rule: if it were ever accessed without authorization, we would notify you and the FTC as that rule requires.

Your rights and choices

  • Access. Your logs, profile and preferences appear in the app. Open Settings or History to see them.
  • Correction. Edit any care log, baby name, or preference from inside the app.
  • Deletion. In the iPhone app, open Settings, tap the (i) next to Account, then Delete account. You will be asked to sign in once more. This permanently removes your Pliske ID and, with it, your account in Honey Bun and in any of the developer's other apps you used it for. In Honey Bun it removes every child you own with all of that child's care logs, chat, photos and videos, MyChart data, rewards and AI conversations, for every caregiver on that child, plus your preferences, your device tokens and your Help & feedback messages. It starts at once, finishes within moments, and cannot be undone. See below for what stays. You may also email us at the address below to request deletion, or follow the steps at honeybun.family/delete-account.
  • Export. Request a copy of your data by emailing us at the address below; we will provide a JSON export within 30 days.

Children

Honey Bun is designed to be used by adults (parents and caregivers) to record information about a child. The app is not directed at children, and children are not the users. We do not knowingly collect information directly from anyone under 13. If you believe a child has signed up for an account, contact us and we will delete it.

Data retention

We keep your data for as long as your account is active. Deleting your account through the in-app flow removes the data described above right away. Server backups roll off within 30 days. Screenshots attached to Help & feedback are deleted 90 days after the conversation is closed.

What stays after you delete your account: entries, chat messages, photos and videos you added to a child that someone else owns remain part of that child's record, with your name removed. Questions you asked Ask Honey Bun about a child someone else owns stay stored with that child, readable by no one else, until its owner deletes the child or their account. If you ever subscribed, a record linking your former account's identifier to Apple's identifier for the purchase is kept. Deleting your account does not cancel a subscription; cancel it with Apple.

Security

Data is transmitted over HTTPS and stored encrypted at rest by Google Cloud. Access is gated by your account credentials and verified server-side on every request. The MyChart tokens are additionally encrypted with a key held only by our server. We do not store passwords ourselves; authentication is handled by Apple, Google, and Firebase Authentication.

Changes to this policy

If we change anything material about how Honey Bun handles your data, we will update this page and adjust the "Last updated" date at the top. For significant changes, we will also notify you in the app the next time you open it.

Contact

Questions, deletion requests, or anything else: support@honeybun.family.