Privacy
Privacy, in plain words
Last updated: September 12, 2026
This policy covers leelalu.com and the LEELALU app.
This policy covers three different things, and it says which is which. The first is leelalu.com: an introduction to LEELALU, a library of reviewed guides, free tools, and a waitlist. The second is the waitlist itself. The third is the LEELALU app, which is open by invitation to a handful of families while we test it, and which holds a family's own record. Here is everything each one collects, where it goes, how long it stays, and who can read it.
Who we are.
Leelalu, Inc., 1301 N Broadway STE 93372, Los Angeles, CA 90012. Write to hello@leelalu.com and a person answers.
We are not a clinic and not a doctor's office, so we are not a covered entity under HIPAA and neither is your record here. What protects it is this policy, the design choices below, and the consumer health data laws of the state you live in. We treat the health-adjacent parts of your record under the strictest of those rules rather than the loosest.
Where the product actually is today.
LEELALU is an invited beta on iOS, distributed through Apple's TestFlight. A stranger cannot sign up. There are four ways in and no fifth: the public gate is open, which today it is not; your account is on our internal testing list; the email address you sign in with is one we wrote down when we invited you; or somebody already inside a family sent you an invitation and you redeemed it. Nothing here is charged. There is no payment path in the app at all, so we hold no card details and no payment records.
Signing in.
You sign in with your email address and a one-time code. There is no password, so there is no password for us to hold or to lose. Your email address lives with our database and authentication provider and is used to send you the code, to recognise your account, and to reach you about the beta. The list of addresses we invited is stored where no interface can read it: the table has row-level security enabled and no read policy, so only a trusted internal function can consult it.
You can also use the app signed out. Signed out, the care log, the guides, Ask Lu and the emergency card all run on your device and nothing is stored on our servers. An account buys one thing: other adults in your family see the same record you do.
What the waitlist collects.
The waitlist asks for your email address and your consent, nothing else. With it we record the consent time, the policy version (waitlist-2026-08-v1) and which page you joined from. No due date, no stage, no child's name, no browser language.
How the waitlist form reaches us.
When you press Join, a form delivery service (Web3Forms) relays your entry to our inbox. Your email address passes through that service on the way to us. It exists to deliver the entry; the list itself lives with us.
The website's analytics.
Our guide, tool and blog pages use cookieless analytics: a PostHog script served from our own domain, which counts page views with no cookie, no stored identifier and no autocapture, and Vercel's performance beacon, which measures loading speed. The counts themselves are sent to PostHog, which therefore sees the page you looked at and the network address you looked at it from. Neither receives your email, any date you typed, or anything you wrote. The pages of the new site, this one included, run no analytics at all and load no script from any other company.
Free tools and date calculators.
Our free tools include date calculators (wake windows by age, a contraction timer, a due-date week calculator). Dates you type into a calculator are processed in your browser and may be kept in your browser's local storage so the tool remembers you. They are not sent to us.
The data map
Everything an invited family's account can hold.
This table is the whole inventory, kept in step with the file our release checks read. If something is not in this table, the app does not collect it. Every row of every table below is isolated by row-level security in the database itself, so one family's record is unreachable from another family's session, and inside your family the roles, the visibility scope and the access window you set decide who sees what.
| What | Where it goes | How long | Who can read it |
|---|---|---|---|
| Your email address and the one-time codes you sign in with | Our authentication and database provider | While your account exists | You, and our team for support |
| The address we invited, plus who invited it and a short note | Our database, in a table with no read policy at all | Until we clear the list | Nobody through any interface; one internal function consults it |
| Your family circle, its name, and the seats in it: role, capabilities, visibility scope, access window, status | Our database | While the family exists | The family's adults; a caregiver sees the family only inside their own access window |
| Confirmed facts about an adult: the name you want used, a due date, a birth date, feeding mode, solids status | Our database, one active fact per kind, superseded rather than overwritten | While the family exists, or until you remove the fact | Your family, by the visibility you set |
| The child as a person: a record identifier, a creation time, a guardian, a household. No name, no birth date, no due date | Our database, which refuses the three identity kinds for a child at the table itself | While the family exists | Your family |
| Care events: feeds, sleeps, diapers, times, and a short note you type | Our database | While the family exists, or until you remove the entry | Your family, by role and access window |
| Tasks, the family calendar, care plans and handoff summaries, including the free text in them | Our database | While the family exists | Your family, by role and access window |
| The family chat: message text, and a reference to any photo or video attached | Our database; the file itself rides the Vault | While the family exists. Deleting your own message blanks the text and leaves a visible mark | Every active member of your family, the caregivers you invited included |
| The Family Vault: the words of a moment, and photographs and video | Our database for the words, our provider's media storage for the files | While the family exists, or until you remove the item | Exactly the audience you set per item: only you, owners only, active caregivers, chosen members, or the whole family |
| Your conversations with Lu: your question and Lu's reply | Our database, in a store with no read path for anybody else | Until you delete the conversation. Temporary Chat keeps nothing, and switching a live chat to Temporary erases what was already saved | You alone. No owner, guardian or caregiver read path exists |
| The facts you switched on for Lu, on the What Lu Remembers screen | Our database, and from there into a Lu request as quoted data | Until you switch the fact off | You and your family, by the visibility you set |
| Your consent answers, each with the exact text you read, a fingerprint of that text, its version, its language and the app build | Our database | Kept as the record of what you agreed to | You and our team |
| Outing Mode: an outing, its viewers, and, only while you choose live location, raw route points | Our database, raw points in a short-retention store with no interface view | Raw points and unkept routes: 30 days at most, purged by a daily job. Sooner if you stop or delete | The adult on the outing and the viewers they picked |
| Push registration: the notification token your phone issues, and the platform | Our database, and Expo's push service to deliver | Until you sign out or turn notifications off | Our sending job |
| Queued notifications, carrying a generic line and never message text | Our database | 30 days, then purged | Our sending job |
| Audit rows: who did what, when, to which kind of thing | Our database, under an allowlist that admits no free text | While the family exists; content-free rows survive an erasure as its record | Our team |
| Lu safety records, when the safety ledger is switched on: a response identifier, which route answered, the policy and model version, which sources were cited, the language, and whether it was an emergency | Our database | 90 days, then purged by a daily job | Our team |
| Server logs for the Lu endpoint: a request identifier, the route taken, a rule identifier when something was withheld | Our hosting provider's logs | Per our hosting provider's retention | Our team |
Your child, and the honest version of it.
Your child exists in our database as a person with no name, no birth date and no due date. That is not a promise we keep by being careful: the table refuses those three values for a child on every path and for every role, ours included. The date you give the app stays on your own device, in the phone's own secure keystore, and what leaves the device is a derived label like "child age 3 months".
Here is the part a shorter policy would leave out. Your family's own words are free text, and free text can contain anything you type. A care note, a task, a handoff summary, a chat message or a Vault moment will hold your child's name if you write it there. Those are your words and we do not scan them, but you should know they are on our servers rather than only on your phone. Two of them behave differently when a single child's record is erased: entries keyed to that child go with them, while a Vault moment is erased with its author or with the whole family, so a moment whose words mention a child can survive that child's individual deletion. Deleting the family deletes all of it.
Lu, and what leaves your device.
When you type a question to Lu, this is what travels: your message and the recent turns of that conversation, whether you are expecting or already a parent, whether it is night, the derived stage label described above, your language, and the facts you explicitly switched on for Lu. Those facts come from a short allowlist that carries no raw date for anybody, and there are hard limits on how many and how long they can be.
What never travels: your child's name, your exact due date and your exact birth date.
Our server does not store your question. It checks the emergency corpus first, and when that matches you get a fixed reviewed card with real phone numbers and no model is called at all. Otherwise it forwards the request to OpenAI, which processes it to produce the answer. We send every request with storage switched off on our side of that contract, and your family's content is not used to train AI models. The provider may still retain content for up to 30 days for its own abuse monitoring; a zero-retention agreement has been requested and is not signed, and we will change this sentence the day it is. Our own logs for that request hold an identifier and which route answered, never your words.
Your conversation is saved in your private Lu history unless you choose Temporary Chat or delete it. Nobody else in your family can read it.
The family chat and the Vault.
Your family has one shared chat. There are no private side-channels, which is the point: what the family says lives where the family lives. Every active member reads and writes it, the caregivers you invited included. Deleting your own message blanks the text and leaves a visible mark rather than silently rewriting your family's history. Photographs and video you attach are Vault items shared with the whole family, and they travel through the same audited pipeline as everything else in the Vault. A push notification about a new message carries a generic line and never the text.
Every other Vault item carries its own audience, chosen by you when you save it: only you, owners only, active caregivers, specific people, or the whole family. Removing a photograph removes the file itself within ten minutes, and on the ordinary path within the same request as your tap. Nothing about a face is ever measured or matched, and no Vault item is ever given a public link.
Consumer health data.
Some of what this app holds is health data about you and your child: a pregnancy stage, feeds and sleeps, a question you asked at three in the morning. Washington's My Health My Data Act, and the similar Nevada law, cover exactly this kind of information, and Washington's reaches its residents wherever the company operates. We treat that as our standard everywhere rather than only for people in those states, and we have written it out separately, as those laws expect.
Read the Consumer Health Data Privacy Policy.
There are no analytics in the app.
The app names a closed list of events it would count, and today none of them go anywhere: there is no transport, so nothing leaves your device. When that changes, this page changes first, the list of events is published with it, and your question to Lu, your notes, your dates and your child are not on that list and will not be.
Because the beta is distributed through TestFlight, Apple gives us crash reports and basic usage counts for testers who leave that turned on in their own iOS settings. That setting is yours, in Settings, and not ours.
Who processes data for us.
These are the only companies that touch your data, each named with what it does. None of them may use your data for anything except providing that service to us.
- Supabase hosts the database, authentication and media storage. Your record, your files and your email address live here.
- Vercel hosts this site and our server endpoints, including the one Lu answers through, and keeps the request logs for it.
- OpenAI processes Lu questions, as described above, with storage switched off on our side and no training on your content.
- Expo issues the push token your phone uses, delivers our notifications to Apple and Google, and serves the app's over-the-air updates, which means it sees your device asking for one.
- Apple distributes the beta through TestFlight and, if you leave the sharing setting on, passes us crash reports and usage counts.
- Web3Forms relays waitlist entries from the website to our inbox.
- PostHog counts page views on the guide, tool and blog pages only. It never sees your family record, your account or anything you typed into the app.
If billing ever opens it will run through Apple, and this page will name that before anyone can pay. We will publish a new version of this list before adding anyone to it.
Getting your record out.
You can export from inside the app at any time. The archive is assembled with your own visibility, which means it can never contain a row you could not already see, and it is built and handed to your device in one go rather than queued for a worker. No export file is left sitting in storage anywhere: there is nothing to expire and nothing to leak. The archive lists every photograph and video with its details; the files themselves stay in the Vault, where you can save them.
Deleting, and how long it really takes.
Deletion works from inside the app. What happens next depends on what you are deleting, and these are the timings our code actually keeps.
Your own record.
Filing starts a grace period of 14 days in which one tap takes it back. After the grace, an erasure job that runs once a day removes your facts, your care entries, your consents, your tasks, your calendar items, your handoffs, your notes shared with Lu, your private Lu conversations and messages, your notification settings, your push tokens and your Vault items, and severs and deletes your sign-in account.
The whole family.
Filing freezes the family at once: no new writes, no sync, no AI, export only. The family's record is erased after a 30 day window that exists so everybody in it can take their copy first, and the same daily job does it.
What remains, and why.
A bare identifier with a deletion mark stays where your family's own record still points at it, because erasing that would erase your family's history rather than yours. The executed deletion request itself stays, because it is the legal record that the erasure happened. Audit rows stay, and they are content-free by construction. Tasks you created and calendar entries where you were the assigned caregiver stay with the family, because they are the family's workflow. Nothing in that list contains your words.
Backups, said plainly.
Our database provider keeps point-in-time backups, which is what makes a bad day survivable. We have not yet run a restore drill, and we have not yet built the step that would re-apply your deletion to a restored copy. Until both exist we will not print a backup window here, and we will not tell you your record is gone from every backup the moment it is gone from the live system. The executed deletion request is the durable record that would drive that re-deletion, and building the drill is on our list rather than in this sentence.
If you would rather write to us.
Email hello@leelalu.com and we will do it for you. We will answer within 30 days, and in practice much sooner: there are a handful of families in the beta today.
Correcting and limiting.
Facts are corrected by confirming a new one, which supersedes the old rather than editing it in place, so your record never quietly changes under you. You can take any fact away from Lu on the What Lu Remembers screen, and the change binds the very next answer: if a reply was already in flight when you revoked, it is thrown away rather than shown.
Deleting your waitlist data.
One email to hello@leelalu.com deletes your waitlist data within 7 days. Every waitlist email also includes a way to leave the list.
Children.
The site and the app are for parents and the other adults a family invites. We do not knowingly collect anything from children, a child never talks to Lu or to any free-form AI, and Lu is instructed to decline if a child is on the device. The child in a family's record is a subject the adults write about, with no name and no date on our servers. If we ever build a surface for children themselves, it will follow COPPA and stricter rules of our own, published before it launches rather than after.
Payments.
Billing is closed and checkout is closed. There is no payment path in the app, nobody has ever been charged, and we hold no payment records at all. If paid membership opens later, this page changes first and names the payment processor before anyone can buy.
What we never do.
We do not run ads. We do not sell your data. We do not share it with advertisers, and there is no advertising pixel or cross-context tracker anywhere on this site or in this app. We do not use your family's content to train AI models. These are founding vows of the company, not settings toggles, and they do not change without the founder saying so in public.
Changes to this policy.
When this changes in a way that matters, the date at the top changes with it, and anything you had already consented to gets a new version and a fresh ask rather than a quiet edit.
Questions? hello@leelalu.com. A person answers.