App Privacy Policy
Effective date: 31 August 2026
Policy version: 2.8
Application: Cub & Compass (Baby Tracker) (com.cubandcompass.app)
App version at time of writing: 1.36.1
Publisher: Cub & Compass
1. Overview and our core promise
Cub & Compass is an offline-first, on-device infant tracker. Sensitive health and
routine data about your baby belongs to you and stays on your own devices.
- We collect nothing. We do not collect, transmit, store, or sell any of your data or your child’s data. We operate no servers, no databases, and no back end of any kind, and nothing you enter is ever sent to us.
- No developer-run server, ever. The app can sync data directly between two phones a parent has paired themselves, but that link always runs phone-to-phone: over your own wifi, or directly between the two devices when wifi will not reach. No server we operate, and no internet host of any kind, is ever part of that path. See section 4a, “Syncing directly between your paired devices”, for the full explanation, including why Android still requires the app to declare an internet permission despite this.
- No tracking or analytics. The app contains no advertising, no analytics, no crash reporting, and no third-party tracking of any kind.
- No accounts. You do not register, sign in, or create an account to use the app.
Under UK GDPR, a developer’s data-protection duties as a controller or processor
apply only when personal data actually reaches the developer. Because Cub & Compass
never sends your data off your device to us, we do not receive it and we do not act
as a controller or processor for the data you keep in the app. This stays true even
though the app can now sync data between your own paired devices: that copy goes
only to the other device you paired, never to us. You remain in control of your data
on your own devices.
2. What is stored on your device
All data you enter is stored locally, in storage that only this app can read.
Timezone with each entry. So that times stay honest when you travel, each entry
also records your phone’s timezone at the moment you logged it (for example
“Europe/London”), and you can set a home timezone in Settings that all times are shown
in. This is read from your phone’s own clock settings, not from any location sensor,
but be aware a timezone name does indicate the general region you were in. It is used
only to display an entry’s time correctly and to mark entries logged while you were
away. Like everything else here it stays on your device, and syncs only to phones you
have paired.
If the app ever finds your saved data unreadable (for example after a storage fault),
it keeps a copy of the unreadable data on your device rather than discarding it, so
nothing is lost while you decide what to do. That copy lives in the same app-only
storage and is removed along with everything else if you reset the app’s data.
Technical diagnostics
To help you investigate an app problem, Cub & Compass keeps a small history of
technical diagnostics on your device for seven days. The history is capped at 300 KB
and contains only allow-listed technical categories, event stages, counts, approved
reason codes and sanitised error types. It deliberately excludes family data,
including family records, names, notes, child data, phone and device identifiers,
sync identifiers, network addresses and raw error messages.
This history is never uploaded automatically. A diagnostics report is created and
sent through Android’s share sheet only when you choose to share it. You choose the
recipient, and Cub & Compass does not receive a copy.
Care and health records (structured data)
- Child profiles: first name, date of birth, and due date.
- Parent profile: the parent or carer name you enter.
- Feeds: bottle feeds (amount made and drank, notes) and breast feeds (side, timed duration), with timestamps.
- Sleep: nap and night sleep start and end times and durations.
- Nappies: wet and dirty nappy entries, with optional notes and an optional photo.
- Medication: medication type and dose, with timestamps.
- Mood and activity: mood tags and free-text notes.
- Weaning and allergies: foods introduced, exposure counts, reaction symptoms, reaction notes, and any custom foods you add.
- Emergency and carer card: the names and phone numbers of up to two emergency contacts and a GP name and phone number, if you choose to fill these in.
Photos (special-category health data)
- Photos of skin reactions, rashes, or nappy contents that you choose to attach, taken with your device camera.
- Milestone photos taken through the Monthly Photo Ritual (see below).
- These photos can capture health information about a child, so we treat them as special-category data. They are stored only in this app’s private files area on your device (
Directory.Data) and are never uploaded anywhere by the app.
Live camera preview (Monthly Photo Ritual)
When you use the Monthly Photo Ritual to take this month’s milestone photo, the app
can show a live camera preview with a faint outline of last month’s photo overlaid
on top, so the two line up. This needs direct access to your device’s camera, so the
Android camera permission is requested the first time you open this screen, in
context, not at app start. If you decline the permission, or a live preview is not
available on your phone, the app falls back to opening your phone’s own camera app
and lets you compare before-and-after photos afterwards instead. Either way, the
photo you take is stored on your device exactly like every other photo in this app,
and it is never uploaded anywhere.
3. Where your data is stored
Everything the app stores lives in app-private storage on your device that other apps
cannot read:
- Structured data is stored in Capacitor Preferences (Android
SharedPreferences) under the keycub_compass_data_v1. - Photos are stored as JPEG files in the app’s private files directory (
Directory.Data). - Device sync pairing details (which phones you have paired, and the secret used to authenticate a sync between them) are also stored locally on each device, and are never sent anywhere except to the specific paired phone during a sync exchange (see section 4a).
- Your light or dark theme choice is additionally kept in the app’s own browser storage under the key
cub_compass_theme_v1, so the app can colour its very first screen correctly instead of flashing the wrong theme while it starts up. It holds only the wordlightordark, nothing else, and nothing at all if you leave the theme on Automatic. It never leaves your device, is not included in backups or sync, and clearing the app’s data removes it.
4. What leaves your device, and when
Nothing leaves your device automatically to us. Data only leaves your device when
you choose to send it, when you sync it to a phone you have paired (section 4a),
or through Android’s own backup (section 5).
PDF reports for a midwife or doctor
When you export a PDF report, the file is created on your device in a temporary cache
folder and then handed to the Android share sheet. Any leftover export files in that
cache folder are deleted automatically the next time you open the app, so exported
copies do not build up on your device. You choose where it goes (for
example email or a messaging app). It reaches only the app or person you pick.
A PDF report can include the photos attached to the records in the report’s date
range, for example a skin-reaction photo on a weaning entry or a photo on a nappy log.
This is deliberate, so a clinician can see the evidence, and it happens only when you
choose to export and then choose who receives the file. If you would rather not share
a photo, remove it from the record before you export, or share a date range that does
not include it.
JSON backups
When you use Settings -> Backup Data, a JSON file of your structured records is
created in the temporary cache folder and handed to the Android share sheet for you to
save wherever you choose. The JSON backup contains your structured records and the
photos those records reference (nappy and skin-reaction evidence), embedded in the file
so a restore on a new phone keeps your photos. Because the photos are included, the
backup file is larger than your records alone. It is created only when you tap Backup
Data, and it leaves the device only through the share destination you pick, exactly like
a PDF report.
Both of these are actions you start yourself. The app never shares a file without you
tapping export or backup first.
4a. Syncing directly between your paired devices
Cub & Compass can keep two phones in step, for example both parents, or a parent and
a grandparent who does regular childcare, so everyone sees the same feeds, sleep,
nappy, and other entries. This only ever happens between phones that a parent has
actively paired using an on-screen code. It is not automatic and not with strangers.
Local wifi sync (the usual path)
Once two phones are paired, syncing happens directly between them over your own wifi
network. No developer-run server is ever involved, and no internet host is ever
contacted. The data goes phone to phone, on your own local network, the moment both
paired devices are reachable on it. This includes any photos attached to your entries – they travel the same encrypted phone-to-phone path between your paired devices, never through any server. The exchange also carries your family’s Family Sync trial and unlock status, so one purchase on any of your paired phones unlocks all of them – this status is the only licensing detail shared, and only ever between your own paired devices.
Why the app requests an “Internet” permission despite this. Android has no
separate permission for “local network only”. Opening any network connection, even
one that stays entirely inside your own wifi router and never reaches the wider
internet, requires the same android.permission.INTERNET permission Android would
require for a connection to the open internet. Cub & Compass requests INTERNET,
ACCESS_NETWORK_STATE, ACCESS_WIFI_STATE, CHANGE_WIFI_STATE and
CHANGE_WIFI_MULTICAST_STATE for exactly this reason: to open a local connection to
your paired phone, to let Android create the direct phone-to-phone wifi link, and to
find the other phone on the wifi network you are both using. The app does not use
any of these permissions to reach the wider internet, and it never attempts to. If your router’s internet
connection is switched off, or your phones are on a wifi network with no internet
access at all, sync between two paired phones on that network still works exactly
the same, which is the practical proof of what these permissions are and are not
used for.
Phone-to-phone fallback, when wifi sync cannot reach the other phone
Some home routers stop phones finding each other on wifi even when they are on the
same network (a setting sometimes called “AP isolation” or “client isolation”), and
sometimes two paired phones are simply not on the same wifi at all, for example a
childminder handover in a car park. For those cases, Cub & Compass falls back to a
second, fully offline sync path built on Android’s Nearby Connections: the two
phones use Bluetooth Low Energy to find each other, then wifi-direct or a
locally-hosted hotspot to move the data. This fallback is only ever tried after wifi
sync has already failed to reach the other phone, and it is exactly as private as
wifi sync: still only between the two phones you paired, still no server, still no
internet host contacted at any point.
This fallback needs a further set of Android permissions: CHANGE_WIFI_STATE,
BLUETOOTH and
BLUETOOTH_ADMIN (older phones only), and BLUETOOTH_SCAN, BLUETOOTH_ADVERTISE,
BLUETOOTH_CONNECT and NEARBY_WIFI_DEVICES on newer ones. CHANGE_WIFI_STATE is
an ordinary install-time permission with no prompt. The Bluetooth and Nearby
permissions that need an Android prompt are requested only when the phone-to-phone
fallback is actually attempted, never speculatively when you open the app.
Why the app asks for a location permission it does not use for location
One further permission this fallback needs is Android’s precise location permission,
ACCESS_FINE_LOCATION. This exists only for phone-to-phone discovery, not for
anything to do with where you are. Android requires apps to hold this permission
before they are allowed to use Bluetooth-based device discovery at all, on every
version of Android this app supports, because the same radio hardware could in
principle be used by some other app to estimate a device’s position. Cub & Compass
does not do that: the app never reads your device’s location, never stores it, and
never transmits it, to us or to anyone else, and this permission is used for nothing
beyond finding the other phone you have paired. (Separately, and not from this
permission, the app does record your phone’s own timezone setting alongside entries
you log – see section 2. That is a setting your phone already holds, not a location
reading, though a timezone name does indicate the general region you were in.) The related Bluetooth-scanning
permissions on newer Android versions are separately declared “never for location”
in the app’s manifest for the same reason.
Keeping sync ready in the background (opt-in)
By default, the app only listens for a sync from your paired phone while it is open.
Settings -> Keep Sync Ready in the Background is an off-by-default toggle that,
if you turn it on, keeps that listener running for a while after you switch away
from the app, using a quiet, ongoing Android notification so the other phone can
still reach you. Turning this on does not change what is synced, who it is synced
with, or where it goes. It only keeps the existing listener reachable for longer.
It stops as soon as the app is fully closed, not just backgrounded, and needs no
permission beyond the two ordinary “run a background service” permissions
(FOREGROUND_SERVICE and FOREGROUND_SERVICE_DATA_SYNC) every app of this kind
needs, plus, if notifications are not already allowed, the same notification
permission covered in section 6a below.
5. Android’s own backup
Android has a built-in backup service that this app leaves enabled
(android:allowBackup="true"), with rules that decide exactly what is included:
- Structured data is backed up to your own Google account by Android. When your device has a screen lock (PIN, pattern, or password), Android end-to-end encrypts this backup, so Google cannot read its contents.
- Photos are excluded. The app’s files directory, where the photos live, is excluded from both cloud backup and device-to-device transfer, in
data_extraction_rules.xml(Android 12 and later) andbackup_rules.xml(Android 11 and earlier). Your infant photos never leave the device through Android backup.
This is a backup to your own Google account, run by Android. The developer never
receives it.
6. Keeping, deleting, and resetting your data
Deleted entries are recoverable for a while. When you delete an entry it stops
appearing in the app straight away, but it is kept in a Recently deleted list so you
can restore it if you deleted it by accident, including if the deletion arrived from a
paired phone. After that period it is cleared for good. Resetting the app’s data
removes everything immediately, recoverable entries included.
Archiving a child is not deletion. If you archive a child, everything about
them is kept exactly as it is – every entry, photo and milestone stays on your
device and stays viewable. Archiving only stops the app being active about them:
reminders are cancelled, nudges and weekly summaries stop, and they move out of
your day-to-day screens. It syncs to phones you have paired so they fall quiet
too. You can undo it at any time.
You keep your data until you choose to remove it.
- Delete a single record. Deleting a feed, sleep, nappy, medication, or other log removes it immediately. If that record had a photo, the photo file is deleted from disk at the same time.
- Remove a reaction photo. Removing a photo from a weaning reaction deletes the image file from your device.
- Reset everything. Settings -> Reset Application Data erases all profiles, logs, photos, and sync pairing details. It clears the stored data and then deletes every photo file. You can also use Android’s own Settings -> Apps -> Cub & Compass -> Storage -> Clear storage.
- Uninstall. Removing the app deletes all of its on-device data, including stored records, photo files, and any sync pairing.
6a. Reminders and notifications
If you turn on feed, sleep, or nappy reminders in Settings, or the background sync
notification described in section 4a, the app schedules a local notification
directly on your phone using Android’s own notification system. Every one of these
is switched off by default and is only ever turned on by you, in Settings, at which
point Android may ask you to allow notifications, the same in-context request
pattern used for every other permission in this app. No notification content, and no
information about whether or how you use reminders, is ever sent anywhere. It is
entirely local scheduling, on your own device.
6b. Purchases
Cub & Compass offers two ways to unlock Family Sync for your whole household once
its free trial ends: an optional one-time purchase, or an optional monthly
subscription. Everything else in the app is free and stays free either way. Both are
handled entirely by Google Play: your payment method, purchase history, and receipt
are processed by Google, not by Cub & Compass. The app only ever learns whether your
purchase or subscription is currently active, so it knows which features to unlock,
it never sees your card details, billing address, or any other payment information.
A subscription can be cancelled at any time from the Play Store – Family Sync simply
pauses at the end of the period you’ve already paid for, and nothing is ever
deleted. See Google’s own Play Store terms and privacy policy for how they handle
that data.
7. Third parties, ads, and analytics
- No ads. The app shows no advertising.
- No analytics. We do not track usage, screens, taps, or performance.
- No third-party SDKs that send data. No advertising, social, or analytics SDKs are included.
- Google Play is the one third party involved anywhere in this app, for the optional purchase (section 6b) and for Android’s own backup service (section 5). Neither receives any of your child’s health or routine data.
8. Keeping store text and app text in step
The wording in this pack matches the copy shown inside the app, so the two never
contradict each other:
- The Settings screen tells the parent: “Your logged data may also be backed up to your Google account by Android, and is end-to-end encrypted when your device has a screen lock. Photos are never included and stay only on this device.” (matches section 5).
- The export screen describes its purpose as: “Create a summary PDF to share with midwives or doctors.” (matches section 4).
- The paired-device sync section tells the parent: “Directly between your phones, never the internet – no servers, ever. Works over your wifi, or phone-to-phone direct if that’s not available.” (matches section 4a).
- The background sync toggle tells the parent: “Uses a quiet, ongoing notification so the other phone can reach you even when this app isn’t open.” (matches section 4a).
If either in-app string changes, update this policy in the same change.
9. Contact
If you have any question about this policy or how the app handles your data, contact:
- Support:
cubandcompass@gmail.com
This policy describes Cub & Compass (Baby Tracker) as built at version 1.36.1,
dated 31 August 2026. Every technical claim is checked against the app’s manifest and
source code as of that date.
This policy covers the Cub & Compass baby tracker app. For our website, blog and downloadable resources, see the website privacy policy.