1. Who is responsible
Alexis Sotomayor, an individual is responsible for Daisy’s handling of personal information. Daisy is designed for adult parents and caregivers; children do not create accounts or use the community independently.
2. Information Daisy handles
- Account: Apple account identifier, Apple relay email if shared, display name, authentication/session records, and account status.
- Family and child profile: family membership and role, child preferred name, birth date, optional due date, and adjusted-age preference.
- Parent-entered records: feeds, sleep, diapers, moods, activities, routines, milestones, and memory text. Version-one memory photos remain on the device and are not uploaded to Daisy.
- Ask Daisy: the question, limited recent-turn context, and age/phase context are processed to answer the request. Daisy version one does not offer a readable chat-history feature. Daisy retains a salted usage fingerprint and account identifier for up to 90 days for quota and abuse controls—not a readable copy of the question or answer.
- Community: profile display name, posts, comments, reactions, reports, blocks, and moderation decisions.
- Purchases and notifications: Apple transaction identifiers, product and entitlement status, device installation identifier, push token, notification authorization, preferences, app version, locale, and time zone.
- Support and security: information a person chooses to include in a support request plus limited technical/security logs needed to investigate misuse or failure.
3. Why Daisy uses information
Daisy uses this information to authenticate adults; provide, synchronize, personalize, secure, and support the app; operate purchases and notifications; answer parenting questions; moderate the community; prevent abuse; honor deletion requests; and meet legal obligations. Daisy does not sell personal information or use child-profile information for targeted advertising.
4. Service providers
Apple processes sign-in, purchases, and push delivery. Supabase provides authentication, database, and server functions. With explicit in-app permission before a question is sent, OpenAI processes Ask Daisy and automated community-safety screening under Daisy’s server credentials. Daisy requests non-persistent response processing; however, OpenAI states that default API abuse-monitoring logs may retain prompts, responses, and related metadata for up to 30 days. Each provider processes information under its own terms and Daisy’s configuration.
5. Sharing inside a family
Adults invited to the same family can see the shared child profile and synchronized records allowed by their role. Owners control invitations and can revoke access. Daisy does not make these records public.
6. Retention and deletion
Account and family data are kept while the account is active. Deleted records may be retained briefly for synchronization, security, dispute, or legal purposes, then removed or de-identified. AI metering records expire after 90 days. Verified transaction and moderation-audit records may be retained longer where needed for fraud prevention, financial records, safety, or legal compliance.
An adult can request deletion inside Daisy at Settings → Account → Delete Daisy account. A family owner must first transfer ownership or remove other active adults; Daisy does not silently transfer a household. The request deletes the authentication account and personal app data, subject to narrow legal, financial, safety, or content-integrity exceptions explained at confirmation. Deleting Daisy does not cancel an Apple subscription; subscriptions are managed in Apple settings.
7. Choices and rights
Adults can edit child details, control notification categories, leave a family where permitted, delete posts or records where available, block community accounts, report content, decline Ask Daisy processing, and request access, correction, export, or deletion. Rights vary by location.
8. Security and international processing
Daisy uses encrypted transport, Apple identity, device-protected sessions, database row-level authorization, role separation, server-held secrets, moderation controls, and purchase re-verification. No system can guarantee absolute security. Service providers may process data in the United States and other locations where they operate.
9. Children’s privacy
Daisy is for adults and is not directed to children under 13. Child-profile information is supplied and controlled by an adult caregiver. Do not post identifying child information in the Circle.
10. Changes
Material changes will be dated and, when appropriate, shown in the app before they take effect.
Daisy is in pre-launch development. The public support address must be supplied and activated before TestFlight or public release; no support request is accepted by this preview site yet.