Privacy Policy
Last updated: 3 August 2026
Damiano is a shared baby-care log. Several adults — parents, grandparents, a nanny — keep one record about one child, and that record is some of the most sensitive information a family owns. This page says exactly what we hold, why, who else ever sees it, and how you get rid of it.
We do not sell your data, we do not advertise, and there is no analytics or tracking of any kind in this app.
1. Who is responsible
| Controller | Abrahan Romero Alvarez |
|---|---|
| Address | Locarno, Switzerland |
| Contact | support@damiano.app |
Write to that address for anything on this page, including any of the rights in §8.
2. What we collect, and why
Everything below is data you or another member of your family entered, or that the app needs to function. Nothing is inferred about you, and nothing is bought from anyone.
| What | Examples | Why we have it | Legal basis |
|---|---|---|---|
| Account | Email address, password (stored only as an Argon2id hash), your app language | To create your account, sign you in, verify your email, and reset your password | Contract |
| Your family profile | Your display name and relationship label in each Family Space (“Ana — mother”) | So the family can see who recorded what | Contract |
| Baby profile | Name, date of birth, optional due date, sex, home time zone, free-text health notes | It is the subject of the record | Contract |
| Care record — health data | Feeds, nappies, sleeps, medication doses, growth measurements, temperatures, notes, appointments, vaccination records | This is the product: the shared log your family keeps | Contract |
| Document vault | PDFs and photographs of paperwork you upload — discharge summaries, prescriptions, insurance documents | So a family can find the paperwork when a doctor asks | Contract |
| Coordination data | Care shifts, tasks and routines, shopping list, invitations you send | The coordination features | Contract |
| Device registration | A random identifier created on your device, the device’s name as the operating system reports it, the app version, the platform, and — if you allow notifications — a push token issued by Apple or Google | To send this device notifications and to sign it out cleanly | Contract |
| Subscription state | Whether your family has an active subscription, which product, and when it renews or expires | To unlock the paid extras. We never see your payment details — Apple and Google take the payment, and we are told only that a subscription exists | Contract |
| Technical logs | IP address, timestamp, requested URL, response code and user agent, kept by the web server; application logs of request outcomes | To keep the service running and to detect abuse. Authorization headers, cookies, passwords and refresh tokens are stripped before anything is written | Legitimate interest |
We do not collect: location, contacts, advertising identifiers, usage analytics, crash reports, biometrics, or anything at all from the child as a user. The child is not a user of Damiano and has no login (§6).
Face ID, Touch ID or the Android biometric prompt, if you turn on the app lock, is checked by your phone. The result — unlocked or not — never leaves the device, and we never receive a fingerprint or a face.
3. Where your data lives
- On your phone. Damiano works offline, so your family’s log is kept in a database on the device. That database is encrypted with SQLCipher (AES-256). Its key is generated on the device, stored in the iOS Keychain or the Android Keystore, marked device-only, and therefore never travels in an iCloud or Google backup. Signing out erases the database and the key.
- On our servers. Your family’s record is stored in a Postgres database and your documents in an object store, both of which run in our own containers. Neither is reachable from the public internet: the only thing exposed is the API, and every request to it travels over TLS. Your documents are fetched and uploaded through short-lived links that expire.
- Nowhere else. There is no data warehouse, no analytics pipeline, no advertising network, and no third party we hand your family’s record to. §4 is the complete list of anyone who touches any of it.
4. Who else is involved
These are the only third parties in the path of your data, and each is limited to the narrow role described.
| Who | What they get | What for |
|---|---|---|
| Our hosting provider | Runs the servers holding the database and the document store | Compute, storage and network. They have no access to the application’s login and act only on our instructions |
| Apple / Google | Your purchase, and the fact that it renewed or lapsed | They take the payment. We never receive your card details or your Apple/Google account |
| RevenueCat | Your Damiano user identifier and your subscription’s state | Turns a store purchase into “this family is subscribed”. No health data, no email address, no names |
| Our email provider | Your email address and the text of account emails (verification, password reset, invitation) | Sending those emails. Nothing about the baby is ever in them |
| Apple / Google push services | A push token and the notification’s contents | Delivering a notification to your phone. Notification payloads carry short generic text and identifiers — never a medication name, a measurement, or anything you typed |
| Have I Been Pwned | The first five characters of a SHA-1 hash of a password you are choosing | Warning you if that password appears in a known breach. Your password, your email and your full hash never leave our server; the service learns only that somebody, somewhere, is using a password from a bucket of roughly eight hundred. If it is unreachable, we simply skip the check |
We update this list before adding anyone to it. Nobody on it is permitted to use your data for their own purposes.
5. Sharing inside a family
A Family Space is shared by design. Every member sees the care record, subject to their role: an admin manages the family and its members, a caregiver records care, and a viewer reads. Medical detail and the document vault can be hidden from viewers, and are hidden from them by default.
Two consequences worth stating plainly:
- What you record is visible to the rest of your family, attributed to your member name. That is the point of a shared log.
- A private note is private. A note you mark private is not shown to other members — including admins — and is not included in another member’s data export.
Anyone joining a family does so through an invitation somebody in that family sent. Nobody can find or join your family otherwise.
6. Children
The record is about a child. The users are adults. A baby has no login, no device, no notification, and cannot use Damiano; only the adults caring for them can. We do not knowingly let anyone under 18 create an account, we do not direct the app to children, and we do not build a profile of the child or make any automated decision about them. Damiano is declared to both app stores as an app for adults; the written determination behind that declaration is available on request.
We treat the child’s health record as the most sensitive data we hold and handle it accordingly (§3, §5).
7. How long we keep things
| Your care record | For as long as your family keeps it. We do not expire a child’s health history — that would be the opposite of what this app is for |
|---|---|
| Your account | Until you delete it. Deletion is immediate: credentials, sessions and device registrations are gone, and the app’s data on the device you deleted from is erased |
| A Family Space you delete | Erased permanently 30 days after the request. The delay exists so a deletion made in a difficult moment can be undone; any admin can cancel during it, and everyone is warned 7 days before |
| After erasure | The family’s rows, its documents’ bytes and its notifications are hard-deleted. What remains is a tombstone holding identifiers and timestamps only — no names, no content — as proof the erasure happened |
| Data export files | Deleted 7 days after the export is built |
| Technical logs | Kept only as long as needed to operate the service |
About backups. As of the date at the top of this page, the service keeps no long-term backup copies, so an erasure is complete once it runs — within 30 days of the request. If we add backups, this page will say so and will state how long an erased record can persist in them before expiring. We will not quietly widen the window.
Full detail: Deleting your account.
8. Your rights
Under the Swiss Federal Act on Data Protection (FADP), the GDPR and equivalent laws you can ask us to:
| Right | How |
|---|---|
| Access / take a copy | Family tab → Settings → Export data produces a complete machine-readable bundle of your family’s record, plus a printable Doctor Visit Summary. Export is a paid extra; if your family is on the free plan, email support@damiano.app and we will produce the same bundle for you at no cost — a right is not something we sell |
| Correct | Care entries are corrected by recording a correction, which keeps the original visible in the history rather than silently rewriting it. Profiles and settings are edited directly |
| Delete | Delete your account in the app, or ask an admin to delete the whole Family Space. See Deleting your account |
| Restrict or object | Turn off notifications, or write to us |
| Complain | You may lodge a complaint with your local data-protection supervisory authority — in Switzerland, the Federal Data Protection and Information Commissioner (FDPIC) |
One limit, stated openly: when you delete your account, the entries you wrote stay with the family, still shown under the member name you used, with no login attached. Removing one caregiver’s entries would tear holes in a child’s medical history that the other people caring for that child rely on and did not agree to lose. If you want specific entries gone, ask a family admin to retract them, or ask the family to erase the whole Family Space.
We answer requests within 30 days.
9. Where your data is processed
We are based in Switzerland, and our servers are located in the European Union — an arrangement both directions of which are covered: Switzerland is recognised by the EU as providing adequate protection, and the FADP recognises the EEA in return. Apple, Google, RevenueCat and our email provider may process the limited data described in §4 outside those countries under their own standard contractual safeguards.
10. Changes to this policy
If we change what we collect or who we share it with, we update this page and change the date at the top. Material changes will be shown in the app before they take effect.