Privacy Policy

Last updated: July 21, 2026

Lulla ("we", "our", "the app") is built by Plainworks. This policy explains what information Lulla handles, why it is used, where it goes, and the choices available to you.

Information You Provide

Information Collected Automatically

How We Use Information

Local Storage and iCloud Family Sync

Your baby profile, sleep logs, chat history, and settings are stored on your device. If you use Family Sync, Lulla uses Apple CloudKit to place the shared baby profile, sleep logs, activity history, and shift details in an iCloud share. People who accept the invitation can view and update that shared information. They do not need to belong to the same Apple Family Sharing group.

Plainworks does not receive your CloudKit records through its own service. Apple stores and processes them under Apple's Privacy Policy.

AI Processing

When you request Coach, AI insight, or a short explanation for Tonight's Plan, Lulla sends the information needed for that request to a Plainworks service, which sends it to OpenAI. Depending on the feature, this can include baby profile details, recent sleep summaries, schedule information, and chat messages.

The Plainworks service does not write AI prompt or response content to a persistent application database. Hosting and AI providers may still process and retain request, connection, and diagnostic data under their service settings and policies. We use this content to return the feature you requested, not for advertising or to train models owned by Plainworks. OpenAI's handling of API data is described in its Privacy Policy.

Analytics and Diagnostics

We use PostHog for pseudonymous product analytics and Sentry for crash and error reporting. Sentry is configured not to send default personal identifiers, although diagnostic reports can contain technical error details. Standard network information, such as an IP address, may be processed by these services when the app connects to them.

Subscriptions and Contact Email

Apple processes App Store payments. We use RevenueCat to manage subscription status, entitlement checks, restores, and subscription lifecycle events. If you add an optional contact email in Settings, Lulla sends it to RevenueCat as a customer attribute for support and feedback follow-up. You can remove it in Settings; Lulla will ask RevenueCat to clear the attribute.

Service Providers and Disclosure

We share information only as needed with Apple, RevenueCat, PostHog, Sentry, OpenAI, and the hosting providers that operate Lulla's services. We may also disclose information if required by law, to protect users or the service, or as part of a business transfer subject to appropriate safeguards.

We do not sell or rent personal information. We do not use advertising trackers, build advertising profiles, or track you across other companies' apps and websites for advertising. Lulla does not request access to your precise location, contacts, photos, or browsing history.

Retention and Security

Local information remains on your device until you delete it or remove the app. CloudKit information remains under the control of the iCloud share owner and Apple. Subscription, analytics, diagnostics, support, and service records are retained only as needed for their stated purpose, legal obligations, security, and dispute resolution, subject to each provider's policies and configured retention.

We use encrypted network connections and reasonable administrative and technical safeguards. No storage or transmission method can be guaranteed completely secure.

Children's Privacy

Lulla is intended for use by parents and caregivers, not by children. Baby information is entered by an adult responsible for using the app.

Your Choices and Data Deletion

Settings > Delete Local Data removes the baby profile, sleep logs, chat history, schedules, and settings stored by Lulla on that device. It also asks RevenueCat to clear the optional contact email and resets Lulla's service identifier. This action does not delete Apple purchase records or records already stored in an iCloud family share.

Removing the app deletes its local app container but does not necessarily delete iCloud, App Store, support, analytics, diagnostic, or service-provider records. The owner of an iCloud share can manage or delete shared records through Apple services. To request access, correction, or deletion of information handled by Plainworks, email us at [email protected]. Depending on where you live, you may also have rights to object, restrict processing, or lodge a complaint with a data-protection authority.

Changes to This Policy

We may update this policy from time to time. Any changes will be posted on this page with an updated date.

Contact

If you have questions about this privacy policy, contact us at [email protected].