This policy page is published in English only. The English text is the authoritative version; the rest of the app follows the language you choose below.
Privacy policy
Effective September 12, 2026. Rongduan Zhu operates Cozibud at https://cozibud.com.
Cozibud records what a caregiver chooses to log about a baby. That is family data about a child who cannot consent, so this policy describes exactly what is stored, who can reach it, and how to get it back or remove it.
What we collect
Only what you enter or what the service must record to work:
- Account. Your email address and a hash of your password. We never store the password itself.
- Household. A household name and timezone, and the membership linking each caregiver to it.
- Children. The name, date of birth and sex you enter for each child.
- Tracking records. Feeds, sleeps, nappy changes, growth measurements, activities, medications and symptoms, timers, and any notes and tags you attach, each with its time and the caregiver who entered it. Corrections keep the previous version so a record's history stays auditable.
- Access. API keys you create and assistant connections you authorise, including which permissions you granted.
- Operational records. Request logs, sanitized browser-error fingerprints and per-household counts of operations, used to run the service and enforce plan limits. These record route templates, machine categories and counts, not messages, stacks, full URLs, the contents of your records or anything you said to an assistant.
Product analytics
When product analytics is enabled, we use it to understand signup completion, broad feature adoption and retention. Signed-in events use a stable pseudonymous caregiver identifier. We create it with HMAC-SHA-256 and a secret held byCozibud; PostHog receives neither the original account ID nor the secret. This reduces identification risk, but the linked events are pseudonymous personal data, not anonymous data.
Events can say that a caregiver completed signup or baby setup, saved a feeding, sleep, diaper, pumping, growth, activity or other broad record category, opened the calendar, used invitations, connected an assistant, changed language, or reached a subscription step. Properties are limited to interface language, product surface, input method, broad category, invitation status, billing interval and the time the product event was completed. We never send caregiver or baby names, email addresses, household or baby IDs, record contents, notes, health values, care-record start or end times, full URLs, assistant messages, bug messages or stacks. Medication, symptom and temperature records do not generate analytics events.
Automatic click capture, session replay, advertising profiles and PostHog error tracking are disabled. Anonymous marketing and pre-signup analytics require an affirmative browser choice. Your account may start with analytics on. Settings shows your current choice, and you can turn it off at any time. Turning it off stops future collection and clears the browser analytics ID. PostHog can retain events for up to one year. Deleting your account schedules its linked analytics history for deletion after the 30-day recovery period. We do not sell personal information or share it for cross-context behavioural advertising.
Children's data
Cozibud is a tool for caregivers. Accounts are held by adults; the service is not offered to children and children do not use it. Records about a child are entered by their caregiver and are visible only to members of that child's household. We do not use them to train models and do not disclose them for any purpose other than running the service.
Assistant connections
You can connect an AI assistant, which then reaches your records through our Model Context Protocol interface. Connecting requires your explicit consent on a screen that names the assistant, the household and the permissions requested. Read access and write access are granted separately, and you can revoke any connection at any time from Settings; revocation takes effect immediately, including for a connection already open.
The assistant interface does not expose medication or symptom records: it will neither record them nor return them, whatever the assistant asks. Those records remain available to you in the app. Everything else your household tracks — including growth measurements and temperatures — is reachable by an assistant you have connected.
When you use an assistant, whatever it sends or receives is also handled by that assistant's provider under their own privacy policy, which we do not control. Consider that before asking one about your child's health.
Who else processes your data
We run Cozibud on services that necessarily handle data on our behalf:
- Google Cloud (Cloud Run, Secret Manager, Cloud Logging). Runs the application and stores operational logs. Hosted in us-west1, United States.
- Neon. Hosts the Postgres database holding all tracking records. Hosted in United States.
- Resend. Delivers account email: verification, password recovery and invitations. Hosted in United States.
- Stripe. Processes subscription payments. Card details go to Stripe and are never stored by us. Hosted in United States.
- PostHog. Processes limited pseudonymous product analytics when analytics is enabled. Hosted in United States.
Your records are stored in the United States. Each household's data is isolated in the database itself, so a request authorised for one household cannot read another's.
Getting your data out
A household owner can download the complete tracking archive as JSON at any time from Settings, including archived children, deleted records and correction history. It is your data and it leaves in a form you can read.
Deletion and retention
We keep your records for as long as your account exists. When you delete an account or a household, access is revoked immediately — sessions, API keys, invitations and assistant connections all stop working — and the data is held for 30 days so you can restore it with the recovery code shown at deletion. After that window it is permanently removed from the live database.
Encrypted database backups are kept for disaster recovery and expire on their own schedule, so a deleted record can persist in a backup for a period after it is gone from the service. Restoring a backup replays deletions before the service accepts traffic. Records required for tax and accounting, such as payment history, are kept as long as the law requires.
Security
Traffic is encrypted in transit. Passwords are stored only as hashes, API keys only as digests, and assistant access tokens are opaque and short-lived. Access to production systems is limited to the operator. No service can promise it will never be breached; if one affects your data we will tell you.
Your rights
You can access, export, correct and delete your data using the controls in the app, without asking us. Depending on where you live you may also have the right to object to or restrict processing, or to complain to a data protection authority. Write to rongduan.zhu@gmail.com and we will answer.
Changes
If this policy changes materially we will say so in the app before the change takes effect. The effective date above always reflects the current version.
Contact
Rongduan Zhu — rongduan.zhu@gmail.com
Cozibud