MamaCare — Privacy Policy
Last updated: June 19, 2026
MamaCare ("we", "us", "our") is a pregnancy companion mobile app combining private week-by-week tracking with an optional shared community. Pregnancy data is among the most personal information you'll ever record, and we treat it that way. This Privacy Policy explains what we collect, why, who we share it with, and the choices you have.
1. Information you give us directly
If you use MamaCare offline (no sign-in):
- Profile — name, age, weeks pregnant, due date, last menstrual period, whether this is a first pregnancy.
- Health logs — symptoms, weight, water intake, vitamin/medication intake, sleep, blood pressure, contractions, kick counts, mood, meals, exercise.
- Bump photos and ultrasounds — images you upload, stored locally inside the app's sandbox on your device.
- Journal entries — text and photo notes.
All of the above stays on your device unless you choose to sign in.
If you sign in (Settings → Cloud Sync):
- Account — email address and a password (the password is never stored in plain text; we use the authentication system provided by Supabase, our backend provider).
- Display name and profile photo — what you choose to show on your posts, comments, stories, and DMs.
- Posts, comments, reactions, polls, pinned comments — content you create in the Community feed, visible to other signed-in users.
- Direct messages — text and photos sent in 1-on-1 conversations, visible only to you and the recipient.
- Stories — 24-hour ephemeral photos with optional captions and interactive stickers (polls, questions). Story views and hearts are tracked.
- Photo uploads — community post photos, story photos, DM photos, and your profile photo are stored on our backend's object storage so other users can render them.
- Pregnancy week and trimester — when you opt to show this on your community profile.
- Reports — if you report a post or comment, we record what you reported and the reason for our moderation review.
2. Information collected automatically
- Push notification token — when you grant notification permission, your device's push token is sent to our backend so we can deliver notifications when someone DMs, comments, or hearts your story.
- Read receipts — when you open a chat thread, the last-read timestamp is recorded so the other participant can see whether their message has been read.
- Crash and error reports — anonymized diagnostic data (stack trace, device model, OS version) is sent to our error-monitoring provider, Sentry, when a crash occurs. No content of your posts, messages, or health logs is included.
- Local notifications — if you grant permission, the app schedules reminders entirely on your device (kick counts, vitamin reminders, etc). We don't see when they fire.
3. What we do NOT collect
- We do not sell, share, or rent your personal data to third parties.
- We do not use third-party advertising trackers.
- We do not access your contacts, calendar, or location.
- We do not see your private journal entries, locally-tracked health logs, or photos that you have not explicitly posted to the community or sent in a DM.
- We do not link your account to any social network.
4. Third-party services we use
- Supabase (database, authentication, file storage, realtime, push delivery infrastructure) — hosted in the United States. Their privacy policy: supabase.com/privacy.
- Expo Push Notification service — your push tokens and notification payloads (title, short body, e.g. "Sarah commented on your post") pass through Expo's infrastructure to reach Apple/Google. Their privacy policy: expo.dev/privacy.
- Sentry (crash and error monitoring) — anonymized error reports only. Their privacy policy: sentry.io/privacy.
- Apple App Store / Google Play Store — handle subscription processing (if you ever buy premium). We only see the entitlement status (subscribed / not), never your payment details.
None of these providers use your data for their own advertising.
5. How long we keep your data
- Local-only data — kept until you uninstall the app or sign out and clear local storage.
- Cloud account data — kept indefinitely until you delete your account.
- Stories — automatically expire and become inaccessible 24 hours after posting. Their underlying rows are retained up to 7 days before deletion.
- Crash reports — retained by Sentry per their default retention (typically 90 days).
6. Your rights
You can:
- Export everything — Settings → "Export all data" creates one JSON file of everything you've logged locally.
- Delete your account permanently — Settings → Cloud Sync → Delete Account. Immediately removes your auth record, all your posts, comments, reactions, polls, chat messages, stories, sticker responses, push tokens, and uploaded photos from our servers. No recovery.
- Opt out of notifications by category — Settings → Notifications → toggle off DMs / comments / story hearts independently.
- Block another user — long-press a post → Block. Their posts and chats vanish from your view immediately.
- Report content — long-press a post or comment → Report. Reports go to our moderation review queue.
- Sign out — local data stays on your device, but new cloud activity stops.
- Request a copy of your cloud data — email us at the address below.
7. Health data
MamaCare collects pregnancy-related health data because that's our entire purpose. We treat this data with extra care:
- Local health logs (kicks, water, vitamins, mood, etc.) never leave your device unless you opt into Cloud Sync.
- Cloud health-data syncing is a feature for restoring your own logs across devices — your logs are never shown to other users.
- Pregnancy week / trimester is displayed on your community posts ONLY if you toggle "Show my week on posts" on; otherwise it is hidden from other users.
- We do not use your health data for research, training AI models, or any other secondary purpose.
8. Community content and moderation
Content you post in the community (posts, comments, polls, stories) is visible to all other signed-in MamaCare users. Direct messages are visible only to you and the recipient. We have a reporting + review system for content that violates our Terms of Service. We may remove content or restrict accounts that violate these terms.
9. Children's privacy
MamaCare is intended for adults (16+). We do not knowingly collect data from anyone under 16. If you believe a child has provided us data, please email us and we will delete it.
10. International data transfers
Our backend (Supabase) is hosted in the United States. By using MamaCare with Cloud Sync enabled, you consent to your data being processed in the US, where data protection laws may differ from your country of residence.
11. Security
All connections to our backend use HTTPS. Passwords are hashed using industry-standard algorithms (Argon2 via Supabase Auth). Storage objects are protected by per-user access policies enforced at the database level. We follow security best practices but no system is 100% impervious; report any suspected vulnerability to the email below.
12. Changes to this policy
We'll update the "Last updated" date above whenever this policy changes. For material changes, we'll surface a notice in the app the next time you open it. Continued use after a change means you accept the updated policy.
13. Contact us
Questions, deletion requests, complaints, or anything else: privacy@mamacare.app