What's changed — September 2026
This summary highlights the main changes from the Policy dated 22 August 2026. Please read the full Policy below.
- Siri and Shortcuts. A new section explains that Apple processes spoken requests under your Siri and Dictation settings. Requests may include information you say, such as names, medicines, doses or dictated keepsake text.
- Lock Screen visibility. The Policy explains what quick logging and Live Activities show while your device is locked, including running feeds, sleeps and feeding side. It also explains that VoiceOver may speak a child's first name.
- Controls for Lock Screen words. Settings → Data & Export → Lock Screen → Hide care words on the Lock Screen removes care words from quick logging and Live Activities and changes spoken names to initials. Icons and running timers remain.
- Private sharing invitations and ending access. The sharing section clarifies recipient-specific invitations through Messages or Mail, why a forwarded link does not grant access to someone you did not invite, and how to stop sharing. Access ends when sharing is revoked; another device removes its cached copy when it next reconciles.
- Care-team contacts. These are now expressly included among the information excluded from participant sharing.
The effective date has changed to 12 September 2026. This summary is explanatory; the full Policy below provides the complete details.
The short version This Privacy Policy explains what BloomBook (the iOS and Apple Watch app) does with your data. The short version: your baby's data stays on your devices and your private iCloud account; we never see it. We also keep the data we sync to a minimum — see “Sharing with co-parents and carers” below.
This Policy is written primarily under the UK General Data Protection Regulation (UK GDPR). It also reflects the Data Protection Act 2018 as amended by the Data (Use and Access) Act 2025.
Who is the data controller?
You are. As the parent, legal guardian, or carer logging information about your child, you are the data controller for that information under the UK GDPR. Stack & Stone Limited is the publisher of the App. We do not operate any server-side store of your child's data and have no ability to access, decrypt, or restore it; where data leaves your device (described below) we act only as a processor on your instructions.
Lawful basis for processing
To the extent that Stack & Stone Limited processes any personal data on your behalf (for example, facilitating CloudKit sync or processing a support request you send us by email), we do so on the following lawful bases under the UK GDPR:
- Performance of a contract — processing necessary to provide the App and its features to you under the Terms of Use.
- Legitimate interests — processing necessary for the security, stability, and improvement of the App, where those interests are not overridden by your rights and freedoms.
- Consent — where you voluntarily contact us, we process the personal data in your correspondence to respond to your enquiry.
The information you enter about your child may include health-related data, which is “special category data” under Article 9 of the UK GDPR. This data stays under your control: it is held solely on your devices and in your private iCloud account, and Stack & Stone Limited has no ability to access, read, decrypt, or retrieve it. We do not collect special category data onto, or process it on, any system we control. To the limited extent any processing occurs through the App — for example, the App invoking Apple's CloudKit to sync at your instruction — it takes place on your device, under your control, and without us accessing the content.
Children's best interests
The data subject is a child, even though you (the parent or carer) are the user. In line with the ICO's Age Appropriate Design Code (the Children's Code), now reinforced by the Data (Use and Access) Act 2025, we treat the best interests of the child as a primary consideration in the App's design. In practice this means: sharing is off by default and is opt-in only; we collect no location data anywhere in the App; there are no advertising, analytics, or tracking technologies of any kind; and the App's default settings favour privacy.
What we collect and where it lives
All data you enter in the App — tracker logs, photos, contacts, child profile details, and settings — is stored on your device. If you enable iCloud, it syncs to your private iCloud database via Apple's CloudKit. We do not have access to your iCloud data. If you disable iCloud or sign out, sync stops and your data remains on the device. If you uninstall the App, on-device data is deleted by iOS.
Home-screen widgets and the Apple Watch companion read a snapshot of recent tracker data (including the child's name, photo, and latest measurements) from a shared container on your device only — this is never synced to iCloud or transmitted off-device. Communication between your iPhone and Apple Watch is a direct peer-to-peer link and does not pass through any server.
What is visible without unlocking. Home-screen widgets and Apple Watch complications hide their contents while the device is locked, so a passer-by sees a blurred placeholder. The Lock Screen quick-log widget is the deliberate exception: so that you can record a nappy or a feed at three in the morning without unlocking, it stays readable while the phone is locked, and tapping a button records an entry.
What it shows is each child's first initial, its logging buttons, and, when a feed or sleep is running, that fact and which side you are feeding from. It never shows a name in full, a photograph, a measurement, a date, or anything from the journal. A running feed or nap also appears in the Live Activity on the Lock Screen and in the Dynamic Island, which shows the elapsed time and the side.
One thing is spoken rather than shown: if you use VoiceOver, it reads each button's child by first name, not by initial — with two children on the phone, two rows of identical buttons cannot be told apart otherwise. That is audible on a locked phone. Turning on the switch below changes it to the initial, matching what is on screen.
If you would rather no care words appeared there, turn on Settings → Data & Export → Lock Screen → Hide care words on the Lock Screen: the buttons keep working and the words go, on the quick-log widget and on the Live Activity alike — each keeps its icons and its running timer. Removing the widget from your Lock Screen, or turning off Live Activities for BloomBook in iOS Settings, removes each of those surfaces entirely. The Home-screen and Watch widgets are unaffected by any of this.
Siri and Shortcuts
If you use Siri or the Shortcuts app to log or ask about your child, Apple processes your spoken request under Apple's own Siri privacy terms, and may retain it according to your Siri and Dictation settings. What travels to Apple is what you say, which can include your child's name, a medicine and its dose, and any words you dictate for a keepsake moment. BloomBook receives only the resolved request and answers from the data already on your device. Nothing you say is sent to us, and nothing new leaves your device because of it. You can turn this off in Settings, under Apps, BloomBook, Siri and Search.
What we do not collect
We do not collect, transmit, or process: any identifier linking your child's data to you outside your Apple ID; analytics, crash reports, telemetry, advertising IDs, or attribution events (the App contains no third-party SDK); your location; your contacts, calendar, or other system data; or payment details (purchases are handled by Apple).
Health-system integration
BloomBook does not connect to any national or regional health system. It does not connect to any electronic health record system, hospital information system, or government health database in any jurisdiction. Records you enter are not transmitted to or from any healthcare provider automatically.
Sharing with co-parents and carers
You can share a child's record with another person — for example a co-parent, a grandparent, or a carer — using Apple's CloudKit Sharing. You invite participants from Settings → Family & Sharing and choose whether they can edit or only view. Invites are private to the person you choose: you send one through Messages or Mail and pick them from your contacts, which is how iOS identifies them. A share link cannot be forwarded and opened by someone you did not invite.
Every participant can see the child's records — growth measurements, feeds, sleeps, nappies, pumping, activities, medications, temperatures, immunisations, screenings, health reviews, doctor visits and milestones.
To keep the share to the minimum needed for shared care, some things never travel to participants, in any form:
- the child's name and photo — each participant names the child on their own device;
- all photographs, in any resolution — growth, milestone and journal photos stay on your own devices and in your own private iCloud;
- the keepsake journal and milestone stories — participants see which milestone was reached and when, never the story or the picture;
- the files attached to doctor visits — participants can see that an attachment exists, never its contents;
- your care-team contacts — the names, practices, phone numbers and your notes about your GP, health visitor or anyone else you record stay on your own devices and in your own private iCloud.
The role you choose sets what else a participant can do. Inviting or removing people, deleting records, and exporting data are reserved to the Owner.
- Owner — the parent who created the record; sees everything, can add and edit any record, can delete records and export the data, and is the only person who can invite or remove others.
- Co-parent — sees the shared records and can add and edit all of the child's records. A Co-parent cannot invite or remove others, delete records, or export the data — those actions stay with the Owner.
- Viewer — read-only; sees the records but cannot add, change, or delete anything, and does not see which participant logged each entry.
Reserving sharing, deletion and export to the Owner keeps a single accountable controller of who has access, keeps the shared log a stable record, and keeps destructive or bulk-disclosure actions with the original parent. Additions and edits a Co-parent makes sync to everyone on the share.
To minimise what is shared across iCloud accounts, the shared records carry only a random identifier, the data you log (never a photograph — see above), and the details needed to plot growth (sex, gestation, date of birth and age-at-measurement).
When you invite someone, the App confirms what the invitee will and will not be able to see for that share.
The read-only versus read-write boundary is enforced by Apple's CloudKit at the iCloud-account level: a Co-parent holds read-write access to the share and a Viewer holds read-only access. The further reservation of deletion and export to the Owner — and the hiding of contributor identity from Viewers — is applied by the App on top of that boundary.
Sharing is handled entirely by Apple between iCloud accounts. We have no part in inviting, accepting, granting, or revoking access and no ability to see who is on a share or what they can see.
You can change a participant's role or remove them at any time. When the owner removes a participant, the server revokes their access on the next successful save (which the App performs immediately). The removed participant's local cached copy of already-synced data clears the next time their device syncs while the App is open — usually within minutes, but if their device is offline or the App is not opened, the local copy can persist until it next reconciles. Each child has its own independent share.
Invites are private to the people you choose: a share link cannot be forwarded and used by someone you did not invite, and removing a participant ends their access to it. To end a share for everyone at once — revoking all access and retiring the invite entirely — use Stop sharing. Settings → Shared links lists every link you have given out, for every child, with what you named it, whether it has been accepted and when, and a way to stop each one or all of them at once. Stopping a share takes effect immediately for access; the other person's copy is removed when their device next reconciles, on the same terms as removal above.
Bundled reference catalogue
The App bundles a catalogue of references compiled from publicly accessible government and public-health websites (including, in the UK, NHS, RCPCH, NICE, UKHSA, DfE, and WHO sources). Each entry links to the original publisher's page — when you tap it, your device opens the publisher's URL directly, not via us. The catalogue is read-only, ships inside the App, and contains no personal data.
The information displayed in the App has not been independently verified, reviewed, or approved by any medical professional for accuracy or clinical appropriateness. Stack & Stone Limited does not employ or retain medical professionals to curate or review this content. We are not the source of any clinical guidance.
UK public-sector content is reproduced under the Open Government Licence v3.0 where applicable, and under fair-dealing for RCPCH / NICE titles cited as references. Growth centiles are calculated from the WHO Child Growth Standards (© World Health Organization 2006, 2007), used under a non-exclusive licence from WHO (request ID 202609306); this adaptation was not created by WHO and WHO does not endorse BloomBook.
Data retention
We do not impose any retention period on your data. Your records remain on your devices and in your iCloud account for as long as you choose to keep them. When you delete data using the App (Settings → Delete Data), it is removed from the device and, where iCloud sync is enabled, from your CloudKit database within a short time.
Uninstalling the App is not the same as erasing your data. Removing the App deletes only the copy stored on that device. It does not delete your data in iCloud: that remains in your private iCloud (CloudKit) account until you delete it — from within the App before uninstalling, from another device signed in to the same Apple ID, or via iCloud — or until you close your Apple account; reinstalling on the same Apple ID restores it. Similarly, if you have shared a child's record with a co-parent or carer, uninstalling does not revoke their access — the share, and the copy synced to their device, remain until you stop the share or remove them (Settings → Family & Sharing). To erase everything you control — the device copy, your iCloud copy, and every share you own — use Settings → Delete Data before uninstalling.
We do not retain copies of your data on any system controlled by Stack & Stone Limited.
Your rights
Because the data lives on your devices and inside your own iCloud, you can exercise most data-protection rights directly without contacting us. Under the UK GDPR, these include:
- Right of access — use Settings → Data & Export to generate PDF and CSV copies of your records.
- Right to rectification — edit any record in-App at any time.
- Right to erasure — use Settings → Delete Data.
- Right to restrict processing — disable iCloud sync to stop syncing without losing on-device records, or uninstall the App to stop all processing.
- Right to data portability — the CSV export is structured per data type; the PDF export is print-ready.
- Right to object and rights related to automated decision-making — the App does not perform automated decision-making with legal or similarly significant effects. Centile calculations plot your entries against the licensed WHO Child Growth Standards; they are reference plots, not decisions made about you.
If you believe we have failed to respect your rights, you may complain to the Information Commissioner's Office at https://ico.org.uk.
Children's data
The data subject is your child. Under UK law, you exercise data-protection rights on behalf of a child too young to do so themselves. We do not direct the App at children, do not collect information from children directly, and do not allow children to create accounts. The same principle applies throughout: you are the user, not the child.
Security
We rely on Apple's platform security: the on-device database is encrypted at rest by iOS Data Protection, your iCloud account is secured by your Apple ID, and communication with Apple Watch is encrypted by Apple. We strongly recommend you set a passcode on your device and enable two-factor authentication on your Apple ID. If you use the sharing feature, ensure that all participants also secure their devices appropriately.
International transfers
BloomBook does not independently transfer your data internationally. CloudKit's choice of data centre is determined by your Apple ID region; BloomBook does not influence it. Apple may process or store iCloud data in data centres located outside the United Kingdom; Apple's transfer mechanisms govern any such transfers. For details, refer to Apple's iCloud Privacy Policy. Stack & Stone Limited does not make any independent international transfer of your personal data.
Changes
When this Policy materially changes, the effective date above will be revised. Where required by applicable law, we will seek your consent before applying material changes.
Contact
Questions, rights requests, or complaints:
Stack & Stone Limited
Registered in England and Wales, company number 17209745.
Registered office: 14/2E Docklands Business Centre, 10–16 Tiller Road, London E14 8PX, United Kingdom.
Email: customersupport@stackandstone.dev
If your enquiry is a UK-GDPR rights request, mark the subject line “GDPR” so we can route it. We aim to respond within one calendar month in accordance with UK GDPR.
This Policy is designed to be read alongside Apple's iCloud Privacy Policy and CloudKit terms, which govern the storage of any data you choose to sync.