Privacy
Privacy policy
BabyName is an app for couples choosing a baby name together. Here is what data the app uses and what it does with it, in plain language.
Controller
Ing. Miloš Hynek
Sedlářova 1156/4, 197 00 Prague 19, Czech Republic
Company ID (IČO): 03978231
VAT ID (DIČ): CZ9104060680
Contact: support.milos.hynek@gmail.com
1. What the app remembers on your phone
The app stores the following data locally on your device:
- your settings — theme, language, layout and sorting, onboarding status and notification choice,
- the name you entered in your profile,
- your name selections — their title, the child’s surname, gender, selected name lists, filters and exact name order,
- your ratings and swipe history, selection progress, matches and related timestamps,
- your eight-character session code and pairing state,
- a local cache of your Premium status and the time of the last successful sync.
Most of this data stays only on your phone. The next section explains exactly what is sent to the server and when. You can erase everything in Settings → Delete all data.
2. What gets sent to the internet
On first launch, the app signs in anonymously to Google Firebase and stores a technical invitation there, ready for future pairing. It contains:
- an anonymous identifier — an identity created for the app; it does not require a name, email address or phone number,
- your eight-character session code, the session creation time and the invitation’s technical state,
- your profile name and, after pairing, the participants’ anonymous identifiers so the app knows who belongs to the session.
This lets a partner join when you give them the code. If you never pair with anyone, no name ratings or selections are uploaded. Optional purchase verification and a push token may be sent independently, but only if you buy or restore Premium or enable notifications.
After pairing, the app synchronizes how and when you rated individual names: the first name, gender, a local selection identifier, swipe direction and time. The server also creates a technical match record containing the first name, gender, anonymous identifiers and time, so it does not send the same notification repeatedly.
Ordinary ratings do not upload the child’s surname, the full selection, its lists or filters, your statistics or swipe progress. The exception is Share selection: when you explicitly use this feature, the selection title, gender, surname, selected lists, exact name order and any filters are temporarily uploaded so your partner can import the selection. The shared selection is deleted after it is accepted or declined.
Crash reporting: if the app crashes or encounters an error, it may send a technical report to Sentry through its European ingestion endpoint. The report may include the device model, operating-system and app versions, and a technical description of the error. BabyName does not attach your profile name, surname or ratings. User and network-request data are removed before sending, eight-character session codes are redacted from error text, and technical metadata are limited to a fixed allowlist. We use these reports only to fix bugs.
Premium purchase (optional): Apple processes the payment through the App Store; we do not see your card details. RevenueCat manages purchase verification, restoration and refunds. It processes its own anonymous user identifier and transaction details such as the product, time and status. BabyName does not send it your profile name, email address, selections or ratings. Settings shows a Support ID, which you may voluntarily send us for purchase support. If you are paired, the Premium holder’s anonymous identifier is also stored with the session so the partner can temporarily use Premium. It is removed when the pair disconnects or the entitlement ends.
New match notifications (optional): if you enable New match alerts in Settings, the server stores your device push token and app language. The server sends notifications through Expo Push, which forwards them to Apple APNs or Google FCM. The visible text contains the matched first name and your partner’s profile name; it may appear on your lock screen. The technical payload also contains the session code, first-name identifier and gender so the app can open the correct match. The child’s surname is not included. You can delete the token by disabling the setting or using Delete all data; no token is stored unless you enable this feature.
3. What the app does not do
- it does not show ads,
- it does not measure your behaviour with analytics tools,
- it does not use advertising tracking or follow you across other apps,
- it does not require sign-up, an email address or a password,
- it does not use cookies — it is a mobile app, not a web service.
4. Sharing and clipboard
At your request, the app can copy the session code to the system clipboard or open the system Share sheet, for example to send a name by text message. A shared name may include the surname if you entered one. Once you hand data to the operating system or another app, that system or app controls what happens next, not BabyName.
Never share your session code publicly. Anyone who knows it can try to join your pairing session.
5. Children
The app is intended for adults choosing a name for a child. We do not collect information about the child itself, such as a date of birth, photos or health information.
6. Your rights
Under the GDPR, you have the right to:
- access your data,
- correct it,
- erase it,
- restrict its processing,
- data portability.
The quickest way to erase your data is inside the app: Settings → Delete all data. Deletion requires an internet connection. The app first asks the server to remove cloud data and erases data on the phone only after cleanup is confirmed. If the server cannot confirm deletion, data on the phone are kept so you can safely try again. For a request or question, email support.milos.hynek@gmail.com.
7. How long we keep data
- Data on your phone remain until you delete them in the app or remove the app’s data from the device.
- Pairing-session data are updated when you disconnect and when you use Delete all data. On disconnection, participants and profile names are updated and the app attempts to remove the related swipes. Delete all data also attempts to remove the current device’s session participation and push token. After an ordinary disconnect, the host’s invitation may remain ready for future pairing.
- Technical match records remain in the session to prevent repeated notifications for the same match. They are deleted with the session.
- A shared selection is deleted after acceptance, rejection or disconnection; the Premium-holder field is removed on disconnection or loss of entitlement; a push token is removed when notifications are disabled, data are erased, the delivery service marks it invalid, or automatically after 90 days without a refresh (inactive device).
- Abandoned sessions with no active participants are deleted during the server’s daily automated cleanup once they are more than seven days old, including any remaining swipes and technical match records.
8. Security
- Communication between the app and the cloud goes over an encrypted connection.
- Access to data in the cloud is limited to the participants of your pairing session. The listed providers still process the data technically as infrastructure operators.
- The app uses an anonymous identity without an email address or password. After successful data deletion, it discards that identity and creates a new one.
- The app and server verify that requests come from the genuine app, not a fake one.
9. Changes to this policy
We will notify you of material changes the next time you open the app. The current version is always available at https://babyname.miloshynek.cz/en/privacy.
10. Contact
Controller: Ing. Miloš Hynek, Sedlářova 1156/4, 197 00 Prague 19, Czech Republic, Company ID (IČO): 03978231.
Email for any questions: support.milos.hynek@gmail.com.