Privacy Policy
This policy explains what Napverse keeps on your device; what the iPhone app sends for product analytics, diagnostics, attribution, optional personalization, subscriptions, support, and security; which providers process that information; and your choices.
1. Controller and contact
Napverse is operated by LLAPPS LTD, EIK 208492694, Bacho Kiro 1 street, floor 8, office 8-3, 9000 Varna, Bulgaria. LLAPPS LTD is the controller for the processing described in this policy unless a listed provider acts as an independent controller under its own terms.
For privacy questions or requests, use Contact Support in the app or email support@napverse.app.
2. Information kept on your device
Napverse stores the information you enter and the views it calculates locally so ordinary tracking can work quickly and offline. Depending on the features you use, this can include:
- Baby profiles: name, birthday or expected due date, gender, profile color, and birth measurements.
- Daily care: sleep, breastfeeding, bottles, pumping, diapers, temperature, growth measurements, times, durations, amounts, sides, moods, and notes.
- Memories and Time Capsules: journal entries, ratings, recipients, photos, videos, audio, documents, and related metadata.
- Settings and calculated views: reminders, notification preferences, schedules, widgets, Live Activities, summaries, charts, pattern segments, and prediction state.
Local information may also be included in an iPhone backup if you enable Apple backup features. Some security or installation identifiers stored in the iOS Keychain can survive an app reinstall.
3. Information sent by the iPhone app
App usage analytics
Napverse uses Amplitude and Google Analytics for Firebase to understand feature use and improve the app. Custom events can describe app launches, screens and features used, taps and actions, activity categories, onboarding progress, subscription-flow interactions, whether an entry contains certain types of information, the selected analytics date range, derived age in days, and cumulative sleep hours logged. They can also include product, entitlement, renewal, trial, price, result, and error-state information.
Analytics SDKs can automatically add event timestamps, session information, app version, iOS version, device model or category, language or locale, network or carrier context, approximate region derived from an IP address, and provider-specific app-instance or device identifiers. Napverse does not intentionally add an entered baby name, exact birthday, raw notes, media, exact sleep timestamps, or raw feeding, temperature, or growth values to its custom analytics events.
Pseudonymous account and service identifiers
Napverse uses Firebase Anonymous Authentication to protect backend requests. The resulting Firebase user ID is assigned to Google Analytics for Firebase and Amplitude as a user ID and user property, and can also be shared with RevenueCat. RevenueCat can receive the Firebase user ID and Amplitude user and device identifiers so analytics and subscription records remain consistent.
Napverse also creates a first-party device identifier from Apple's identifier for vendor when available, or a random UUID otherwise. It stores that identifier on the device, includes it in authenticated backend requests, and uses it to seed a stable RevenueCat app user ID that is also kept in the iOS Keychain. These identifiers do not contain your name or Apple ID, but they can distinguish an installation, device, or anonymous account and associate activity over time. Pseudonymous identifiers are therefore not the same as anonymous data.
Crash, diagnostics, configuration, and security
Firebase Crashlytics may receive crash logs, stack traces, timestamps, app and iOS versions, device information, technical error details, and pseudonymous installation identifiers. Firebase Remote Config and Napverse backend services may process technical request information to deliver configuration, diagnose failures, prevent abuse, and protect the service.
Attribution
Napverse uses Apple AdServices, RevenueCat attribution features, and Meta App Events to measure whether an App Store campaign led to an install, app activation, or subscription. This can include an attribution token, campaign, ad group, keyword and ad identifiers, conversion type, click date, country or region, app and device information, and SKAdNetwork conversion information. Napverse disables collection of Apple's advertising identifier by the Meta SDK in the current configuration. We do not knowingly send baby names, raw routine entries, notes, or media to advertising platforms.
Optional personalized schedules
When you request a personalized or adaptive sleep schedule, Napverse sends the relevant baby identifier, age or age range, timezone, schedule context, and a selected history of exact sleep start and end times and durations to Napverse's Google Cloud backend. The backend uses OpenAI to help generate the requested schedule. Napverse requests that OpenAI not store the response for application-state purposes; OpenAI may retain limited data temporarily for abuse monitoring under its applicable service policies.
Support and cancellation feedback
If you contact support or send cancellation feedback, Napverse receives your message, the optional email address you provide, pseudonymous user and device identifiers, technical context, and any screenshot, video, document, audio, or diagnostic attachment you choose to submit. Support records are stored in private Google Cloud storage and Firestore. The support message, optional email, and private attachment metadata may be routed to LLAPPS LTD through Slack.
4. Purchases and subscriptions
Apple processes App Store payments. Napverse and RevenueCat may receive an app user ID, Apple receipt and transaction information, product identifiers, entitlement and renewal status, trial or offer information, purchase timestamps, last-seen time, attribution data, and technical app or device information needed to unlock and restore Napverse Plus. Napverse and RevenueCat do not receive your full payment-card details from Apple.
5. Website data and cookies
napverse.app does not set cookies, use local or session storage, run web analytics or advertising pixels, or embed third-party media. The hosting and security infrastructure can still process ordinary request logs such as IP address, user agent, requested path, timestamp, and response status to deliver and protect the website. Because the website uses no optional cookies, no consent choice is required. We display an informational no-cookies notice for transparency; dismissing it does not store a preference.
6. Why we process information
- To provide tracking, summaries, reminders, subscriptions, purchase restoration, support, and features you request.
- To generate personalized schedules and keep server-backed recommendations aligned with recent activity.
- To understand feature adoption, app performance, and campaign effectiveness.
- To diagnose crashes, fix bugs, secure requests, prevent fraud or abuse, and enforce our terms.
- To meet accounting, tax, consumer-protection, and other legal obligations.
7. Legal bases
Depending on the processing and the law that applies, LLAPPS LTD relies on:
- Performance of a contract: to provide requested app, subscription, personalization, and support functions.
- Legitimate interests: to keep Napverse secure and reliable, understand product performance, prevent abuse, and improve the service where those interests are not overridden by your rights.
- Consent: when iOS requests permission for notifications, microphone, camera, photos, or other device access. Non-essential analytics or attribution may also require separate consent; where it does, that processing must remain off until you choose it and must provide an effective withdrawal control. Withdrawing consent does not affect earlier lawful processing.
- Legal obligation: for records or disclosures required by law.
8. Providers and recipients
Limited information may be processed by the following providers for the stated purpose:
- Apple: App Store distribution and billing, notifications, device features, AdServices attribution, SKAdNetwork, ratings, and reviews.
- Google Firebase and Google Cloud: anonymous authentication, Analytics, Crashlytics, Remote Config, backend APIs, logs, website hosting, and private support storage.
- Amplitude: product-usage analytics and pseudonymous user or device measurement.
- RevenueCat: subscription, entitlement, receipt, identity, and attribution management.
- OpenAI: model processing for personalized schedules requested through Napverse's backend.
- Meta: automatic app events and campaign or install attribution, with advertising-identifier collection disabled in the current app configuration.
- Slack: restricted internal routing of support messages and private attachment metadata.
We do not sell personal information. A provider may process information under its own terms when it acts as an independent controller, such as Apple for App Store transactions.
When a provider processes personal data on our behalf, we require it to use the data only for the agreed service purposes, apply protections consistent with this policy and applicable law, and assist with security and data-subject obligations as required by our agreement.
9. Retention
- On-device data: remains until you edit or delete it, remove the app and its local data, or erase the relevant iPhone backup. Keychain identifiers can persist after reinstall.
- Analytics and attribution: retained under the applicable provider and project settings for as long as needed to compare product and campaign trends, then deleted or aggregated. We review retention against those purposes and applicable law.
- Anonymous authentication and linked service identifiers: may remain in Firebase, Amplitude, RevenueCat, and related service records until a verified deletion request is completed or the applicable provider or project retention process removes them. Removing the app alone does not delete these provider records; Keychain identifiers can survive reinstall.
- Crash, security, and backend logs: retained for the provider-configured diagnostic or security period, then deleted or aggregated unless a longer period is needed to investigate abuse, an incident, or a legal claim.
- OpenAI processing: requests are sent with storage disabled for application state; limited abuse-monitoring data may be retained by OpenAI for up to 30 days unless law or a security investigation requires longer.
- Support records: retained while a request is handled and for a limited period afterward to investigate recurring issues, protect the service, and maintain necessary business or legal records, then deleted or anonymized.
- Purchase records: retained as needed to provide and restore entitlements and meet accounting, tax, consumer, fraud-prevention, and legal obligations.
10. Your choices and rights
- You can edit or delete local entries in the app, choose whether to use server-backed personalization or support, and control notifications and device permissions in iPhone Settings.
- You can manage or cancel a subscription through Apple. Deleting Napverse does not cancel an active subscription.
- You can object to product analytics or request deletion of identifiable provider records by emailing support@napverse.app. Because records use pseudonymous identifiers, we may need an identifier or diagnostic information from the app to locate them.
- Deleting the app stops future collection from that installation but does not by itself erase information already sent to providers or cancel an App Store subscription.
Subject to applicable law, you may request access, correction, deletion, restriction, or portability of personal data, object to certain processing, and withdraw consent. We may need to verify your request and may retain limited information where law permits or requires it.
If you are in the European Economic Area, you may also lodge a complaint with your local supervisory authority or Bulgaria's Commission for Personal Data Protection (CPDP).
11. Children's privacy
Napverse is intended for parents, guardians, and caregivers, not for children to use independently. A user who enters information about a child must be authorized to do so. We do not use child routine information for targeted advertising. Contact us if you believe information was provided without appropriate authority.
12. Security
We use reasonable technical and organizational measures intended to protect information, including authenticated backend requests, encrypted network transport, restricted service access, and private support storage. No system can guarantee absolute security. Please avoid including unnecessary personal or medical details in free-text support messages.
13. International processing
LLAPPS LTD is established in Bulgaria. Providers may process information in the European Economic Area, the United States, or other countries. Where required, transfers rely on adequacy decisions, standard contractual clauses, or another lawful transfer mechanism.
14. Recommendations and automated processing
Napverse can calculate predictions and use model-assisted processing to generate sleep schedules. These outputs are informational planning aids. They do not make decisions that produce legal or similarly significant effects, and they are not medical advice.
15. Changes to this policy
We may update this policy as Napverse or its providers change. We will post the current version at napverse.app/privacy, update the date above, and provide additional notice where required by law.