Version 1.3 | Last updated: April 17, 2026 | Effective date: February 21, 2026
HannaH ("we," "us," "our," or the "App") is operated by MV Studio ("Company", "Data Controller"). This Privacy Policy describes how we collect, use, store, share, and protect your personal information when you use the HannaH mobile application, available on iOS and Android.
By using HannaH, you acknowledge that you have read, understood, and agree to this Privacy Policy. If you do not agree, please do not use the App.
MV Studio
Email: hannah@mv-studio.net
For data protection inquiries, contact us at the email address above.
| Data Type | Purpose | Retention |
|---|---|---|
| Account Information Name, email address, profile photo | Authentication, account management, personalization | Until account deletion |
| Authentication Tokens Google Sign-In, Apple Sign-In | Secure login | Session duration |
| Child Profiles Name, date of birth, gender | Age-appropriate tracking, milestone recommendations | Until you delete them |
| Period & Cycle Data Cycle dates, period length, symptoms, flow intensity | Period tracking, cycle predictions, fertility window estimation | Until account deletion |
| Fertility & TTC Data Ovulation dates, fertility indicators | Fertility window tracking, conception planning | Until account deletion |
| Pregnancy Data Due date, week-by-week progress, kick counts, contraction timers, pregnancy notes | Pregnancy tracking, milestone reminders, health monitoring | Until account deletion |
| Baby Tracking Data Feeding logs (breast/bottle/solids), sleep sessions, diaper changes, growth measurements (weight, height, head circumference) | Daily care tracking, growth charts, pattern analysis | Until account deletion |
| Health Conditions Selected allergens, medical conditions, health notes | Personalized product safety warnings, health awareness | Until you delete them |
| Milestones & Achievements Custom milestones, developmental achievements | Developmental tracking, memory keeping | Until account deletion |
| Photos & Memories Photos uploaded by you, associated captions | Memory keeping, photo timeline, milestone documentation | Until you delete them or your account |
| AI Chat Messages Messages sent to the AI companion | Contextual parenting support, conversation continuity | Until you delete them or your account |
| Hospital Bag Checklist Checklist items and completion status | Birth preparation tracking | Until account deletion |
| Appointments Doctor appointments, reminders | Schedule management, reminders | Until account deletion |
| Allergen Profiles Selected allergens for product scanning | Personalized product safety warnings | Until you delete them |
| Gratitude Journal Journal entries | Parent wellness feature | Until account deletion |
| Data Type | Purpose | Retention |
|---|---|---|
| Camera Images Barcode scans, product label photos | Product identification, ingredient scanning | Processed in real-time, not stored on our servers |
| HealthKit Data (iOS) Data you explicitly choose to share (e.g., weight, heart rate) | Health data integration, growth tracking | On-device only; synced per your HealthKit permissions |
| Device Information Device model, OS version, app version | App compatibility, crash diagnostics | 90 days (analytics), 180 days (crash logs) |
| Usage Analytics Screens viewed, features used | App improvement, feature prioritization | 14 months (Google Analytics default) |
| Advertising Identifiers IDFA (iOS), GAID (Android) | Personalized advertisements (free tier) | As per Google AdMob policy |
| Subscription Data Purchase status, plan type | Entitlement verification | Until account deletion |
| IP Address Approximate location | Fraud prevention, regional content | Not stored by us; processed by Firebase |
The following data is stored exclusively on your device in a local database (Hive). It is never transmitted to our servers unless you have cloud sync enabled:
| Purpose | Lawful Basis (GDPR) |
|---|---|
| Provide baby, pregnancy, and period tracking features | Contract performance (Art. 6(1)(b)) |
| Authenticate your account | Contract performance |
| Display personalized health insights and milestone reminders | Contract performance |
| Generate AI lullabies and bedtime stories | Contract performance |
| Provide AI companion chat responses | Contract performance |
| Scan products for ingredient safety and allergen detection | Contract performance |
| Sync data across your devices via cloud backup | Contract performance |
| Show advertisements (free tier) | Legitimate interest (Art. 6(1)(f)) |
| Process subscription payments | Contract performance |
| App analytics and crash reporting | Legitimate interest |
| Prevent fraud and abuse | Legitimate interest |
| Comply with legal obligations | Legal obligation (Art. 6(1)(c)) |
HannaH integrates with the following third-party services, each with their own privacy policies:
| Service | Provider | Data Shared | Purpose |
|---|---|---|---|
| Firebase Authentication | Google LLC | Email, name, auth tokens | User login |
| Firebase Firestore | Google LLC | User data (tracking logs, profiles) | Cloud data storage and sync |
| Firebase Storage | Google LLC | Photos, profile images | Photo and media storage |
| Firebase Analytics | Google LLC | Usage events, device info | App analytics |
| Firebase Crashlytics | Google LLC | Crash logs, device info | Crash diagnostics |
| Firebase Remote Config | Google LLC | None (config download only) | Feature flags |
| Firebase Cloud Functions | Google LLC | Product images (temporary), song generation requests | AI features processing |
| Google AdMob | Google LLC | Device ID, ad interactions | Advertising (free tier) |
| RevenueCat | RevenueCat Inc. | Purchase receipts, user ID | Subscription management |
| OpenAI | OpenAI Inc. | Chat messages, product images (via Cloud Functions) | AI companion chat, product identification |
| Suno AI | Suno Inc. | Song generation prompts (child name, theme, style) | AI lullaby and song generation |
| Perplexity | Perplexity AI Inc. | Product queries (via Cloud Functions) | Product scanner AI-powered web search |
| Apple Sign-In | Apple Inc. | Apple ID token | Authentication |
| Google Sign-In | Google LLC | Google account token | Authentication |
| Apple HealthKit | Apple Inc. | Health data you choose to share | Health data integration (iOS only) |
| Open Food Facts | Open Food Facts (non-profit) | Barcode numbers (lookup only) | Product data retrieval |
Links to third-party privacy policies:
HannaH uses third-party AI services to power certain features. Before using any AI-powered feature for the first time, the app will ask for your explicit consent and clearly explain what data is shared. Below is a complete disclosure of all AI data sharing:
| What data is sent | Photos of product packaging and/or ingredient labels (camera images) |
|---|---|
| Who receives it | OpenAI, Inc. (San Francisco, CA, USA) — via our Firebase Cloud Functions (server-side relay, never client-direct) |
| Purpose | Identify product name/brand from packaging photo; extract ingredient text from label photo via OCR |
| Data retention by OpenAI | Images are processed in real-time and are not stored by OpenAI beyond the API request. OpenAI's API data usage policy confirms API inputs are not used for model training. |
| What is NOT sent | Your name, email, health data, tracking data, or any personal information — only the product photo |
| Data protection | OpenAI is certified under the EU-US Data Privacy Framework and maintains SOC 2 Type II compliance |
| What data is sent | Song description/prompt, child's first name (if provided), selected music style, and generated lyrics text |
|---|---|
| Who receives it | Step 1 — Lyrics: OpenAI, Inc. (generates song lyrics from your description) Step 2 — Music: MiniMax (via fal.ai, Inc., San Francisco, CA, USA) generates audio from lyrics |
| Purpose | Create a personalized lullaby or children's song using your child's name and chosen theme |
| Data retention | Neither OpenAI nor fal.ai/MiniMax store your data beyond the API request. Generated audio is stored in your private Firebase Storage account. |
| What is NOT sent | Your email, health data, tracking data, photos, or any data beyond the song prompt and child's first name |
| Content safety | All user input is moderated via OpenAI Moderation API before generation. Lyrics are generated with strict rules: "NO explicit, violent, or inappropriate content." MiniMax has built-in content safety filters. |
| Data protection | fal.ai maintains SOC 2 compliance. OpenAI is certified under the EU-US Data Privacy Framework. |
In compliance with Apple App Store Guidelines 5.1.1(i) and 5.1.2(i), we confirm that all third-party AI services used by HannaH provide the same or equal level of data protection as described in this Privacy Policy:
HannaH collects and processes health-related data that may be considered sensitive under various privacy laws, including:
The free tier of HannaH displays advertisements provided by Google AdMob. AdMob may collect device identifiers and usage data to serve personalized ads.
Your data may be transferred to and processed in countries outside your country of residence, including the United States, where our service providers (Google/Firebase, OpenAI, Suno AI, RevenueCat, Perplexity AI) maintain servers.
| Data Type | Retention Period |
|---|---|
| Account data | Until you delete your account |
| Child profiles and tracking data | Until you delete them or your account |
| Period, pregnancy, and health data | Until you delete your account |
| Photos and memories | Until you delete them or your account |
| AI chat history | Until you delete conversations or your account |
| AI-generated songs | Until you delete them or your account |
| Product scan history | On-device only; cleared when you uninstall or delete account |
| HealthKit data | On-device only; managed by iOS |
| Analytics data | 14 months |
| Crash logs | 180 days |
| Advertising data | As per Google AdMob retention policy |
| Subscription records | As required by tax/legal obligations (up to 10 years) |
You have the following rights regarding your personal data:
In the preceding 12 months, we have collected the categories of personal information described in Section 2. We do not sell personal information. We share data with service providers listed in Section 4 solely for the purposes described.
Brazilian residents have rights under the Lei Geral de Protecao de Dados, including access, correction, deletion, anonymization, data portability, and information about sharing. Contact us to exercise these rights.
Canadian residents have the right to access, correct, and challenge compliance. Contact us at the address in Section 1.
To exercise any of the above rights, contact us at hannah@mv-studio.net. We will respond within 30 days (GDPR) or 45 days (CCPA). We may need to verify your identity before processing your request.
You can delete your account at any time:
When you delete your account, the following cascade deletion is performed:
No system is 100% secure. If you discover a security vulnerability, please report it to hannah@mv-studio.net.
The HannaH mobile app does not use browser cookies. However:
Some browsers and devices offer a "Do Not Track" (DNT) signal. Due to the lack of a unified standard, the App does not currently respond to DNT signals. You can control tracking through your device privacy settings and our in-app consent mechanisms.
We may update this Privacy Policy from time to time. When we make material changes:
This Privacy Policy is governed by the laws of the Republic of Croatia, without regard to conflict of law principles. For EU/EEA residents, this does not affect your rights under GDPR. For California residents, CCPA/CPRA rights are preserved regardless of governing law.
If you have questions, concerns, or requests regarding this Privacy Policy or your personal data:
MV Studio
Email: hannah@mv-studio.net
Support: hannah@mv-studio.net
For EU data protection matters, you may also contact the Croatian Personal Data Protection Agency (AZOP) at azop.hr.
© 2026 MV Studio. All rights reserved.
HannaH — Where Hope Begins