Skip to content
Chloe: Nursery Ledger

Privacy

Privacy for Chloe: Nursery Ledger

Last updated October 5, 2026

Chloe: Nursery Ledger is designed to keep newborn logging practical and low-friction. This page explains how the app handles personal logs, shared care teams, and account data.

Data stays useful without an account

Chloe: Nursery Ledger is designed to work on-device first. Parents can log care without creating an account, and the app remains usable even when cloud features are turned off.

Cloud sync is optional

Personal logs stay on this iPhone until you choose cloud sync. Supabase provides account authentication and synced storage. Joining a shared care team or publishing a baby for shared care enables automatic sync for that baby's log while the app is open. Independent local babies are not automatically attached to an account when you sign in.

You choose access for each baby

Each care-team member uses their own account. Full-access members can read all logs and insights and manage the baby's profile and team. Caretakers can read all raw entries, add entries, and correct their own; Viewers can read raw entries. Team members see author names and relationship labels. Invitation emails are visible only to full-access members. Permission to one baby does not grant access to another baby.

Cloud data and iPhone data can be managed separately

Signing out hides account and shared logs while leaving independent local logs available. Removing a care-team member keeps their contributions in the shared history. Account deletion retains a shared baby when another full-access adult remains and changes the deleted account's author label to Former member. If you are the last full-access adult, you must add another full-access adult or explicitly delete that baby and its history. Erase data on this iPhone clears device data without deleting the server copy.

Offline access and shared files

Shared logs may remain available offline for up to 24 hours after membership was last verified. Server access stops on removal, and the app clears the shared cache when it detects removal; a disconnected device cannot learn about a change immediately. Handoff files and other exports are copies shared by their sender. Removing membership cannot recall copies already shared or saved elsewhere.

Choose local or online voice

Experimental Apple voice processes speech and replies on your supported iPhone and uses your private local records. It does not send those conversations to ElevenLabs; speech assets may need downloading first. When you select online voice, relevant audio and request context are sent to ElevenLabs and its configured language-model provider to process the conversation. Care-team sync is a separate online feature. Switching voice providers does not delete cloud records or turn a shared log into a local-only log.

Support requests should include only what helps us fix the issue

When you email support, share the minimum information needed to reproduce the problem quickly, especially for sync troubleshooting and device-specific bugs.

Chloe ChatGPT Site and plugin

The Chloe ChatGPT Site is a separate private preview for adult caregivers. Website screenshots use sample records. ChatGPT sign-in identifies the Site account. Babies, entries and caregiver permissions are held in the Site’s hosted storage, independently from the iPhone app. The Site does not connect to Supabase or import your iPhone records.

When enabled and used, OpenAI processes conversation messages, voice audio, and the authorized care records needed to answer a request. The Site does not save audio recordings. API requests set store to false; applicable provider abuse-monitoring retention still applies. Your personal OpenAI API key is encrypted on the server and linked to your ChatGPT identity. It is never returned to the browser. Temporary voice context and encrypted assistant retry results are stored to support safe logging; expired results are cleaned up on later requests.

The Chloe plugin uses the Site’s ChatGPT identity, records and caregiver permissions. Requested records appear in your ChatGPT conversation and its history settings apply. Language, voice, quiet delivery and bottle milk defaults are stored separately for each caregiver and baby. An explicit request such as “always formula” saves that default across chats; change it or clear it with Ask each time in the Site’s Settings. Plugin tool calls do not use your personal Site API key.

Removing your API key disables model-backed features for your Site account; it does not delete baby records. Contact support for Site data or account requests. The iPhone app’s deletion controls, storage and voice providers operate separately. Chloe is a care ledger, not a clinical service.

Questions

If you have a privacy question or want to request account-related help, contact support@nurseryledger.com.