Privacy Policy
Your camera and microphone streams are sent between your own phones and are never recorded or stored by us. Here's exactly what we do — and don't — process.
Last updated: August 29, 2026
This Privacy Policy explains how Masofi d.o.o. ("we", "us", "our") handles information in connection with the Ninna mobile application (the "App") and our website at ninnaapp.com (the "Website"). We are based in Slovenia, and you can contact us at privacy@ninnaapp.com.
We built the App to be private by design: it turns two of your own phones into a baby monitor. Your camera and microphone streams are sent between your devices in real time and are never recorded or stored by us.
1. Summary
| What | Do we collect it? |
|---|---|
| Your name / email | No for sign-in — Apple and Google sign-in are configured to use only an opaque account identifier. If you voluntarily add an email to a support message, we use it only to reply. |
| Video / audio of your room | No — streamed live between your devices, never stored. |
| A pseudonymous account identifier | Yes — an opaque Apple or Google user ID. It doesn't reveal who you are, but it does identify your account consistently. |
| Subscription status | Yes — via Apple or Google Play and RevenueCat. |
| Crash reports & basic usage analytics | Yes — to keep the App working and improve it. |
2. Information we process
Account data. When you sign in with Apple or Google, we receive an opaque user identifier (a random string). We do not request your name or email for sign-in. On our servers we store only: this identifier, your account creation date, your subscription tier, and a "last seen" timestamp.
Subscription data. Purchases are processed by Apple or Google Play. We use RevenueCat to verify and manage your subscription entitlement. RevenueCat receives the pseudonymous account identifier and purchase information from the relevant store. We never see your payment card or store credentials.
On-device data. A session token is stored securely in your device Keychain, and your preferences (mode, alert sensitivity, notification settings) are stored in the device's local storage. These stay on your device.
Live streams. Audio and video are transmitted in real time between your devices. Local mode connects the phones on your network. Remote Pro mode uses an end-to-end encrypted relay; the relay passes encrypted media through to deliver it and does not record or persist it.
Alerts. Noise and motion detection runs on your camera device. Only small event messages (e.g. "noise detected" with a timestamp) are sent to your viewer device(s). These are not stored on our servers.
Diagnostics & analytics. To keep the App reliable and understand how it's used, we process:
- Crash and error diagnostics (via Sentry): device model, OS and app version, and technical error data.
- Product analytics (via PostHog): in-app events such as app opened, signed in, paywall viewed, and subscription started. Before you sign in these are tied only to a random identifier generated on your device. After you sign in they are linked to your pseudonymous account identifier, so we can tell whether the same person completed a step rather than counting anonymous events twice.
- Install attribution (via Apple's AdServices framework, iOS only): when the App is first opened, Apple can tell us whether the download came from an Apple Search Ads campaign, and if so which campaign, ad group and keyword (as numeric identifiers). This is Apple's own privacy-preserving attribution — it does not involve the advertising identifier (IDFA), cross-app tracking, or any data broker, and we use it solely to measure which of our own ads work. It is processed together with the analytics data above and is covered by the same "Share usage analytics" switch.
- Install attribution (via Google Play Install Referrer, Android only): Google Play can pass us the non-identifying campaign labels attached to the store link, plus click and install timestamps. We use them only to understand which Ninna content led to an installation.
- Campaign measurement on our website: when you open our download page (ninnaapp.com/get), we record the non-identifying campaign labels in the link, your device type (iPhone/Android), and a salted one-way hash of your IP address. The raw IP address is never stored. On iOS, if the App is first opened within a short window (about an hour) from the same network, we use the matching hash to connect that installation to the campaign the click came from — this tells us only which of our own posts and ads work. No advertising identifier, no cross-site or cross-app tracking, no data brokers, and the hash is useless outside this single purpose.
Website cookies & analytics. On the Website we use Google Analytics to understand how visitors find and use our pages — but only if you agree. When you first visit, a banner asks for your choice; until you click Allow analytics, no analytics run and no analytics cookies are set. If you agree, Google Analytics sets first-party cookies (_ga and _ga_*) and we receive aggregated usage statistics; advertising features and ad personalization are permanently disabled. If you decline, the Website works exactly the same without any analytics. Your choice is stored in your browser and you can change it at any time, which also removes the analytics cookies.
Network data. Your IP address is processed transiently by our servers and sub-processors to establish connections and to prevent abuse (rate limiting). We do not use it to build advertising profiles.
3. Why we process it (legal bases under GDPR)
- To provide the service (performance of a contract): accounts, streaming, subscriptions.
- Legitimate interests: security, abuse prevention, and improving the App (diagnostics and analytics), balanced against your rights.
- Consent, where required by your jurisdiction (e.g. certain analytics). This includes Google Analytics on the Website, which runs only after you accept the cookie banner. You can withdraw consent at any time — in the App’s settings, or on the Website by changing your cookie choice.
Usage analytics and crash reports are controlled separately in Account → Privacy, so you can keep crash reporting on while switching product analytics off. Turning either off takes effect immediately.
4. Sharing and sub-processors
We do not sell your personal data. We share data only with service providers who process it on our behalf:
| Provider | Purpose | Location |
|---|---|---|
| Apple | Sign in with Apple, App Store payments and attribution | EU/US |
| Google sign-in, Google Play payments and install attribution | EU/US | |
| RevenueCat | Subscription management | US |
| Hetzner Online GmbH | Server hosting | EU (Germany) |
| Google Workspace | Support and privacy email | EU/US |
| Sentry | Crash/error diagnostics | US/EU |
| PostHog | Product analytics | US/EU |
| Google (Google Analytics) | Website analytics — only with your consent | EU/US |
Where data is transferred outside the EEA/UK, we rely on appropriate safeguards such as Standard Contractual Clauses. Our core account data is hosted in the EU.
5. Retention
We keep account data until you delete your account, at which point it is removed from our servers (see Section 7). Raw product telemetry and research attribution links are kept for no more than 90 days, then deleted or aggregated. Provider backups and diagnostic retention may take additional time to expire under the relevant provider schedule.
6. Your rights
Depending on where you live, you may have the right to access, correct, delete, port, restrict, or object to the processing of your personal data, and to withdraw consent. EEA/UK users may lodge a complaint with their data protection authority. California residents have rights under the CCPA/CPRA, including the right to know and to delete; we do not sell or "share" personal information for cross-context behavioral advertising.
To exercise any right, use the in-app Delete Account option or contact us at privacy@ninnaapp.com.
7. Deleting your account
You can delete your account at any time: Account → Delete Account. This permanently erases the account data we hold for you. App Store and Google Play subscriptions are managed by the relevant store and must be cancelled separately in its subscription settings.
8. Children
The App is intended for use by parents and caregivers (adults). It is not directed to children, and we do not knowingly collect personal data from children. While the App may show a sleeping child via your own live stream, that video is never recorded or transmitted to us.
9. Security
We use encryption in transit, store secrets only on our servers (never in the App), keep the session token in the device Keychain, and apply server hardening and rate limiting. No method of transmission or storage is 100% secure, but we work to protect your information.
10. Changes
We may update this Policy. We will revise the "Last updated" date and, for material changes, provide notice in the App or by other appropriate means.
11. Contact
Masofi d.o.o.
Slovenia
privacy@ninnaapp.com
masofi.si