Duet is an iPhone app that helps two parents keep a shared record of their baby's sleep, feeds, diapers and pumping, and of medicines, baths, tummy time, growth and teeth. Duet is made by Roy Shavit ("we", "us"). This policy explains what the app collects, why, where it is kept, and how to delete it. It covers the Duet app, not the website it is published on, which sets no cookies and runs no analytics.
The short version
- We collect only what the app needs to work: your sign-in details, the care records you enter, and what it takes to deliver notifications to your phone. We also measure how the app is used, without any of your baby's care data.
- Only the parents in your household can see your baby's records.
- We don't sell your data, show ads, or track you across other apps and websites.
- You can delete your baby's history, your whole household, or your account, in the app, at any time.
What we collect
Your account. When you sign in with Apple, Google or email, we receive your name, your email address and an account identifier. If you use Apple's Hide My Email, we receive a private relay address instead of your real one. Your name is shown to the other parent in your household, next to the entries you log, and you can change it in Settings.
What you enter about your baby. Your baby's name and, if you add them, date of birth, the sex used to choose the right growth chart, and, for a baby born before 37 weeks, how early. The time zone your phone is set to, so each day and reminder falls at the right local time. The care entries you log: sleeps, breastfeeds (with the time on each side), bottles (milk type and amount), diapers (wet, dirty or both, and, if you add them, a rash, a blowout, and the stool's colour and texture), pumping sessions (duration and amount), medicine and vitamin doses (the medicine's name, the amount and unit, or that a dose was skipped), baths (how long, and whether hair was washed) and tummy time, with their times and which parent created or last changed each one. Any note you add to an entry.
Your baby's growth, teeth and medicines. Growth measurements (weight, length and head circumference, and whether each was taken at home or at a clinic); the dates each tooth came in or fell out, with any note; the medicines and vitamins you add, with their dose, schedule and end date; and a daily tummy time goal, if you set one.
Some of this, such as diaper details, medicines and growth, is information about your baby's health. It is used only to run Duet for your household.
Your household. The names of the parents in it, who created it, when each one joined or was removed, and invitation codes, which work once and expire after seven days.
Your settings. Your language, volume and growth units, your notification, reminder and Live Activity preferences, and which activities appear on your screens and in what order. Some settings, such as appearance and the night mode schedule, stay on your phone.
Your device. Push tokens that let us deliver notifications and Live Activity updates to your phone, with its model and iOS version, stored under an identifier Apple gives Duet on that phone. They identify the app on your device, not you.
How the app is used. Which features are used and where they fail — for example, that a diaper was logged from Home, that a timer was stopped, or that an entry was saved while offline — measured with Google Analytics for Firebase, with a random identifier for this installation of the app. It never includes your baby's name, your name, notes, amounts or times: only the kind of action and how it ended. It is not linked to your account, and it is not used for advertising.
When you write to us. If you choose Write to us in the app, the email it prepares includes your Duet version, iOS version, iPhone model and language, so we can help. You see all of it before you send it.
We don't collect your location, contacts, photos or Apple Health data, we don't use advertising identifiers, and we don't track you across other apps and websites. The app contains no advertising software.
How we use it
Only to run Duet and make it work better:
- to keep your household's records in sync between both parents' phones;
- to show who logged or changed each entry;
- to send notifications and Live Activity updates, such as a timer the other parent started;
- to send reminders, such as a medicine dose that's due or a growth check-in, which you can turn off in Settings;
- to keep you signed in, and to let you join or leave a household;
- to see which features are used and where they fail, so we can fix and improve them.
We don't use your baby's records for advertising, profiling, or anything else. Where data-protection law asks for a legal basis, ours is that the data is needed to provide the app you chose to use; for measuring how the app is used, it is our legitimate interest in keeping the app working well.
Where your data is kept, and who processes it
Duet is built on Google Firebase:
- Cloud Firestore stores your household, babies, care entries, medicines, growth measurements and teeth. Our database is in Google Cloud's
europe-west1region, in Belgium. - Cloud Functions, in the same region, save care entries, handle joining and leaving households, and send push notifications and reminders. Their logs record technical details, such as account and household identifiers and phone models, so we can fix problems.
- Firebase Authentication manages sign-in. Google may process sign-in data outside the European Union, including in the United States.
- Google Analytics for Firebase measures how the app is used, as described above. Google may process this data outside the European Union, including in the United States.
Other services:
- Apple runs Sign in with Apple, and delivers notifications and Live Activity updates through the Apple Push Notification service. Those messages carry what appears on your screen, such as your baby's name, a parent's name, a timer or a medicine's name. They never include notes or diaper details.
- Google runs Sign in with Google.
These providers process data on our behalf under their own terms and security measures. We don't share your data with anyone else, except where the law requires it.
Duet also keeps a copy of your household's records on your phone, so it works without a connection. Widgets, controls and Siri read a short summary from it, such as the time of the last feed or your medicines' names. Deleting the app removes that copy.
Who can see your baby's records
Only the active parents in your household. A parent who leaves or is removed loses access straight away, and each invitation code lets exactly one person join.
As the developer, we have technical access to the database that runs Duet. We look at a household's data only when you ask us to help with a problem, or when the law requires it.
Keeping and deleting data
- Records are kept for as long as your household exists.
- When you delete an entry, it disappears for both parents. It stays in the household's stored records until the baby's history is reset or the household is deleted. A deleted growth measurement works the same way, and stays until the household is deleted.
- Each time an entry is saved, our server keeps a receipt of the save, including the entry's details, so a save that is retried after a lost connection is recorded only once. Receipts can't be seen in the app, and they are kept until the household is deleted.
- The parent who created the household can reset a baby's history, which permanently deletes all of that baby's care entries. The baby's medicines, growth measurements and teeth are kept.
- A medicine you stop giving is archived rather than deleted, so its past doses still make sense.
- When the last parent leaves a household, the household, its babies, all of its entries and its invitation codes are permanently deleted.
- If you leave a household that still has another parent, the records stay with them, and your name stays on the entries you logged so the history still shows who did what.
- To delete your account, open Settings › Delete account. Your profile, your settings and your device's push tokens are deleted straight away, and if you signed in with Apple or Google, Duet gives up its access to that account too. Records in a household you shared stay with the other parent, with your name on the entries you logged, unless you are the last one in it, in which case the household is deleted too. Firebase Authentication keeps its sign-in record — your account identifier, name and email address — so signing in again starts afresh with nothing from before; email contact@royshavit.com and we'll remove that record too. If you can't use the app, email contact@royshavit.com from the address you sign in with, and we'll do all of this within 30 days.
Children
Duet is meant for parents and caregivers. It records information about a baby, entered by the baby's parents, but it is not designed for children to use, and we don't knowingly let children create accounts.
Security
Data travels between your phone and our servers encrypted, and Google encrypts it where it is stored. Server-side access rules let only your household's active parents read or change its records. No system is perfectly secure, but we limit what we collect and who can reach it.
Your rights
Depending on where you live, you may have the right to access the data we hold about you, correct it, receive a copy, have it deleted, or object to how it is used. You can correct most things in the app; for anything else, email contact@royshavit.com. If you're unhappy with our answer, you can complain to your data-protection authority, such as Israel's Privacy Protection Authority or the authority in your EU country.
Changes
If we change what Duet collects or how it is used, we'll update this page and the date at the top. Significant changes will also be mentioned in the app's release notes.