Privacy
Privacy policy
Last updated: 2026-05-07
Founding principle: collect the minimum, be transparent about use, return control to the user. Privacy is the default.
What we collect
Anonymous visitor
- Access logs (IP, user-agent, path, timestamp) — for operation, security, debug. Retained for 90 days.
NEXT_LOCALEcookie — only to remember your language preference.- Aggregate metrics (self-hosted Plausible) — no fingerprinting, no cookie by default.
Authenticated user (when community is enabled)
- Email, name, photo — for identification and communication.
- Posts, comments, reactions — community features.
- Approximate baby’s birth date (optional) — to personalize the guide phase shown.
We don’t collect health data about the baby. If you share sensitive data in a post, moderation may suggest editing to remove specific identifiers.
Your rights
- Access to everything we know about you
- Export in structured JSON
- Correction of incorrect data
- Anonymize your account (keeps posts, swaps name/photo)
- Delete your account — soft-delete for 30 days, then hard-delete
- Granular consent revocation (analytics, emails, optional cookies)
To exercise any right, contact us at the email below. Response within 15 business days. Critical requests (deletion, export) are processed automatically in under 24h when the account system is available.
Cookies
- Necessary (session, locale): no opt-out, required for the site to work.
- Analytics: only privacy-first Plausible without cookie by default. GA4 optional via explicit consent.
- Marketing: none by default. When AdSense is enabled, only with consent.
We don’t use cookie walls or dark patterns.
Children
The terms require age 18+ for accounts. We don’t collect data on minors. Accounts created by minors are closed when identified.
Sharing
We never sell data. Subprocessors:
- Google Cloud Platform — hosting, database, auth, storage
- Resend — transactional emails (when enabled)
- Perspective API — toxicity moderation (when community is enabled)
- Self-hosted Plausible — privacy-first analytics
Data Protection Officer (DPO)
Currently, Daniel Garcia: privacy@mildias.life.
Changes
Material changes to this policy will be notified by email to registered users and flagged on the site for 30 days before taking effect.