Punn
  • Privacy
  • Terms
← Back to home

Privacy Policy

Last updated: March 2026

This Privacy Policy describes how Punn ("we", "us", or "our") collects, uses, shares, and protects your personal data when you use the Punn mobile application ("App"). This policy complies with the General Data Protection Regulation (GDPR) of the European Union and the Personal Data Protection Act B.E. 2562 (PDPA) of Thailand.

1. Data Controller

The data controller responsible for your personal data is:

  • Name: Punn
  • Contact email: hello@punnbaby.app

For privacy-related requests, please email us with the subject line "Privacy Request".

2. Data We Collect

a. Account Data

When you create an account, we collect your email address and display name through Supabase Authentication. You may sign in using Apple or Google OAuth, in which case we receive only the information you authorize those providers to share (typically email and name).

b. Baby Profile Data

You provide your baby's name, date of birth, and gender. This data is used to personalize app features such as age-appropriate tracking and growth charts.

c. Tracking Data

You manually log events including feeding times and amounts, sleep periods, diaper changes, growth measurements (weight, height, head circumference), health events (temperature, symptoms, medications), and pumping sessions.

d. Cry Analysis Results

When you use the cry analysis feature, audio is captured and processed entirely on your device using an on-device machine learning model. Only the classification result (e.g., "hungry") and confidence scores are stored. No audio recordings are transmitted to our servers or any third party.

e. Chat Conversations

When you use the AI chat assistant, your messages and relevant tracking context (such as recent feeding and sleep data) are sent to our chat server for processing. Chat messages are not persisted on our servers after processing -- they are handled statelessly. Baby names are not stored in server-side logs.

f. Feedback Data

If you choose to submit feedback on a cry analysis result (for example, correcting an incorrect classification), you may optionally upload the cry recording along with your correction. This requires your explicit consent via a data sharing toggle in the app. Feedback data is used solely for improving the machine learning model.

3. How We Use Your Data

a. Core App Functionality

We use your tracking data, baby profile, and cry analysis results to provide the core features of the app: event logging, reports, charts, insights, and growth tracking.

b. AI Chat Assistant

When you use the chat feature, your tracking context (recent events, baby age) is shared with OpenAI to generate personalized responses. No audio data is sent to OpenAI. Baby names are not persisted in server-side logs.

c. Cloud Sync

If you sign in, your tracking data and baby profiles are synced to the cloud via Supabase so you can access your data across multiple devices. Cloud sync is optional -- the app works fully offline.

d. Partner and Family Sharing

If you invite a partner, your baby profile and tracking data are shared with that person. Sharing requires explicit invite acceptance by the partner. You can revoke access at any time.

e. Model Improvement

If you submit feedback with your explicit consent, the feedback data (cry recording and correction) may be used to retrain and improve the cry classification model. This data is anonymized and cannot be linked back to your account.

4. Legal Basis for Processing (GDPR Article 6)

a. Consent

We rely on your consent for: feedback and recording uploads, data sharing toggle activation, and partner sharing invitations.

b. Contract Performance

We process your data as necessary to provide the core app features you signed up for, including tracking, cry analysis, reports, and cloud sync.

c. Legitimate Interest

We have a legitimate interest in improving our service quality, maintaining security, and preventing abuse.

5. Data Sharing with Third Parties

a. OpenAI

Chat context (recent tracking data, baby age) is sent to OpenAI for generating AI chat responses. No audio data is shared with OpenAI. Baby names are not persisted in server-side logs.

b. Supabase

If you enable cloud sync, your data is stored in Supabase (hosted on AWS). Data is encrypted at rest and in transit.

c. Apple and Google

If you sign in with Apple or Google, these providers handle authentication only. We do not share your app data with them.

We do NOT use any advertising SDKs, analytics tracking libraries, or data brokers. Your data is never sold or shared for advertising purposes.

6. Data Retention

a. Local Data

Data stored on your device is retained until you delete it manually or uninstall the app.

b. Cloud Data

Cloud-synced data is retained until you delete your account. You can request account deletion at any time by emailing hello@punnbaby.app.

c. Chat Messages

Chat messages are not persisted on our servers. They are processed statelessly and discarded after the response is generated.

d. Feedback Recordings

Feedback recordings submitted with your consent are retained for model training purposes. They are anonymized and cannot be traced back to your account.

7. Your Rights

Under the GDPR (Articles 15-22) and the Thai PDPA (Sections 30-36), you have the following rights:

  • Right to access your personal data
  • Right to rectification of inaccurate data
  • Right to erasure ("right to be forgotten")
  • Right to data portability in a machine-readable format
  • Right to restrict processing of your data
  • Right to object to certain types of processing
  • Right to withdraw consent at any time, without affecting the lawfulness of processing based on consent before withdrawal

To exercise any of these rights, email us at hello@punnbaby.app with the subject "Privacy Request".

You also have the right to lodge a complaint with:

  • Your local EU supervisory authority (for GDPR)
  • The Personal Data Protection Committee (PDPC) of Thailand (for PDPA)

8. Children's Data

Punn is designed for and operated by parents and caregivers. Baby data entered in the app is parental data about a child, not data collected directly from the child.

We do not knowingly collect personal data directly from children. The app does not target or enable use by children. If you believe a child has provided us with personal data without parental consent, please contact us at hello@punnbaby.app.

9. International Data Transfers

Your data may be processed in the following regions:

  • United States: OpenAI processes chat context for AI responses
  • Various AWS regions: Supabase stores cloud-synced data
  • Google Cloud (Asia): Our chat server is hosted on Google Cloud Run

Where data is transferred outside the EEA or Thailand, we ensure adequate safeguards are in place, including standard contractual clauses and reliance on adequacy decisions where available.

10. Security Measures

We implement the following security measures to protect your data:

  • Encryption in transit: All data transmitted between your device, our servers, and third-party services uses TLS encryption
  • Encryption at rest: Cloud-stored data is encrypted at rest in Supabase
  • JWT authentication: API requests are authenticated using Supabase-issued JSON Web Tokens
  • On-device audio processing: Cry analysis audio is processed entirely on your device and is never transmitted to any server
  • Role-based access: Partner sharing uses role-based access control to limit data visibility

11. Thai PDPA Compliance

In compliance with the Personal Data Protection Act B.E. 2562 (PDPA) of Thailand:

  • The data controller is identified per Section 23 of the PDPA (see Section 1 above)
  • Data subject rights are honored per Sections 30-36 of the PDPA (see Section 7 above)
  • Cross-border data transfers are protected per Section 28 of the PDPA (see Section 9 above)
  • Consent is obtained in accordance with Section 19 of the PDPA

For PDPA-related inquiries, contact us at hello@punnbaby.app.

12. Contact

If you have any questions about this Privacy Policy or wish to exercise your rights, please contact us:

  • Email: hello@punnbaby.app
  • Subject line for privacy requests: "Privacy Request"

We will respond to your request within 30 days, as required by GDPR and PDPA.

  • Privacy Policy
  • Terms of Service

Contact: hello@punnbaby.app

© 2026 Punn. All rights reserved.