A baby tracker seems like the most innocent software imaginable — it's weights and diaper counts. But step back and look at what a typical cloud-connected parenting app can hold: your child's full name, exact birth date, sex, photos, growth measurements, health notes, your email, your location, and a minute-by-minute log of your family's daily routine. That is a remarkably complete dossier on a person who cannot consent to anything, assembled starting at age zero. It's worth choosing the app that holds it deliberately.
What's actually at stake
Three properties make children's data different from ordinary app data:
- It's permanent. A leaked password gets rotated; a leaked birth date, name, and growth history are facts about your child forever. Data collected now can follow them for decades.
- It's identity-grade. Name plus exact date of birth is the raw material of identity theft, and children are attractive targets precisely because nobody checks a toddler's credit file.
- It's intimate. Feeding struggles, growth worries, and health notes are the kind of information families used to share only with their pediatrician.
Where the data goes in cloud-first apps
Independent reviews of the parenting-app category — such as Mozilla's *Privacy Not Included project and academic studies of pregnancy and parenting apps — have repeatedly found broad patterns worth knowing about: analytics and advertising SDKs embedded in family apps, data shared with third parties in ways users didn't expect, vague retention policies, and privacy policies that permit far more than the app's marketing implies. Regulators have acted against children's services often enough (under COPPA in the US, GDPR in Europe) that this isn't hypothetical. None of this requires malice — a free app has to be paid for somehow, and an account-plus-cloud architecture means your data sits on someone else's servers, subject to their security, their business model, and their acquirer's business model when the startup is sold.
The practical point is not that any particular app is bad. It's that every account-based app requires trust in a company, and the only architecture that requires no trust is the one where the data never leaves your device.
A parent's privacy checklist
Reading a privacy policy at 2 a.m. is nobody's plan, so here are the questions that separate the architectures quickly:
- Does it work without an account? If yes, there is probably no server-side profile of your child at all. This single question does most of the work.
- Where is data stored? "On your device" and "in the cloud" are different risk categories, whatever the encryption claims.
- Check the store privacy labels. Apple's privacy "nutrition labels" and Google Play's data-safety section state declared collection plainly — "Data not collected" is a rare and meaningful label.
- Does the price make sense? A one-time purchase or paid app has an obvious business model. A free app with a server bill has a less obvious one.
- Can you get your data out? A local export (PDF, backup file) means you're never locked in — and never hostage to a shutdown notice.
- Does it ask for permissions it doesn't need? A growth tracker has no business with your location or contacts.
If you're switching from a cloud app
Already have months of history in an account-based tracker? Before you leave, export whatever the app allows — many offer a CSV, PDF, or email report — so the record travels with you. Then do the two steps people skip: delete the data in-app if a deletion option exists, and request account deletion rather than just uninstalling, since uninstalling removes the app from your phone but not your child's data from their servers. Under GDPR (and several US state laws), companies must honor a deletion request; a short email to the address in the privacy policy usually suffices. It's ten minutes of admin that meaningfully shrinks your child's data footprint.
The trade-off, honestly stated
Local-only storage does give something up: automatic multi-device sync and effortless cloud restore. A private app has to compensate with deliberate, user-controlled exports — a backup file you save where you choose, and shareable reports for the people who genuinely need the data, like your pediatrician. For a tracker whose real job is a weigh-in every week or two, that trade is small; for parents, whether it's the right trade is a personal call — but it should at least be a visible one, made by you rather than by a default setting.
How Baby Weight handles it
Baby Weight picks the no-trust-required architecture: all measurements are stored locally on your device, there is no account, no cloud upload, no analytics SDK, and no advertising identifier. Getting data out is explicit and user-controlled — a PDF growth report for the pediatrician and a local backup file you keep wherever you like. Launching soon on the App Store and Google Play.
Sources
- Mozilla Foundation: *Privacy Not Included — independent privacy reviews of consumer apps and devices.
- FTC: Children's privacy (COPPA) guidance and enforcement.
- FTC consumer guidance: Child identity theft.