Privacy Notice
This Privacy Notice explains how KERNELICS LLP, a limited liability partnership registered in England and Wales under company number OC448443, acts as controller for Growing Years. Our registered office is 27 Old Gloucester Street, London, United Kingdom, WC1N 3AX. The Notice applies from 21 August 2026 wherever Growing Years is available.
Growing Years is an adult-operated child health diary with optional AI features. It is not intended for a child to create or operate an account independently. For privacy questions or requests, email legal@kernelics.com. For product support, email support@growing-years.com.
Information we collect and why
We collect information that you provide or generate when using Growing Years:
- Account and authentication information: email address and display name when supplied, Apple or Google account identifiers, verification and session information, and account recovery state. We use this to create, secure, and operate your account and to perform our contract with you.
- Child profile, diary, and planner information: a child's name, date of birth, sex, measurements, allergies, conditions, medicines, health history, notes, laboratory values, dates, reminders, and other text you enter. We use this to provide the health diary and planning features you request. Because health information receives additional legal protection, we rely on your explicit consent where applicable in addition to the basis used to provide the service.
- Attachments and AI material: photos, PDFs, filenames, extracted text or rows, voice clips and transcripts, AI requests and responses, summaries, and related processing status. We use these only to store the records you choose and, after separate AI consent, to perform the AI action you request.
- Calendar and notification information: planner titles, notes, times, timezone, selected calendar identifiers, push tokens, device identifiers, locale, and delivery information. We process these when you enable the corresponding optional feature or device permission.
- Subscription information: an opaque customer identifier, products, entitlements, purchase, renewal and refund status, and store transaction references. We use this to provide and reconcile paid access and to meet accounting or legal obligations.
- Analytics and diagnostics: an opaque linked account identifier, allowlisted interaction names, timestamps, enums and counts, safe app, device and build context, and sanitised diagnostic categories. We use this for our legitimate interests in measuring and improving the service. The enforced analytics allowlist excludes names, email addresses, child identifiers, health content and values, free text, attachments, raw URLs, and raw errors.
- Security and operations information: opaque user or resource identifiers where necessary, timestamps, rate limits, action and outcome categories, and provider request metadata. We use this for our legitimate interests in protecting accounts, preventing abuse, operating the service, debugging, and responding to incidents.
We also receive limited information from Apple or Google for the authentication or calendar features you choose, from RevenueCat and Apple for purchases and subscriptions, and from Expo and APNs when notifications are enabled.
How and where information is stored
Core account, diary, planner, subscription, notification, AI history, and service state are stored through our production Convex backend. Private photos, PDFs, voice files, analysis artefacts, and temporary export packages are stored in Cloudflare R2 and retrieved using signed links. Limited preferences, unfinished input, calendar copies, and credentials may also remain on your device or with the calendar provider you select.
Growing Years is available internationally and our providers operate infrastructure in multiple countries. We do not promise that Convex, Cloudflare R2, OpenAI, or another provider stores your information only in the United Kingdom or European Economic Area. Information may therefore be processed in the United States and other countries whose laws differ from those where you live. Applicable law may require safeguards or other protections for an international transfer. This Notice does not state that a particular provider contract, transfer mechanism, residency option, backup rule, or provider-side deletion control applies when it has not been verified for our account.
We use access controls, private object storage, signed attachment and export links, secure device storage for tokens, ownership checks, rate limits, and data-minimised logging. No online service can guarantee absolute security.
AI processing and your consent
AI features are optional. Before an AI request is sent, Growing Years requires a separate affirmative AI Processing Consent. If you consent and ask for an AI action, we send OpenAI the material needed for that request, which may include your prompt, selected child or diary context, photos, PDF-derived content, voice audio or transcript, and previous relevant conversation. Growing Years may also create embeddings, summaries, memories, and safety or quality signals needed to provide the requested feature.
OpenAI is the active AI recipient for text and multimodal responses, embeddings, and audio transcription. Responses API requests are configured with store: false, which prevents provider application-state storage for that endpoint. This setting is not a promise of zero data retention and does not prove that ordinary provider safety or abuse-monitoring records are absent. We do not promise a particular OpenAI processing region.
You may refuse or withdraw AI consent without losing non-AI diary, planner, account, legal, deletion, and subscription-management features. Withdrawal stops future AI requests and disables new AI processing. It does not by itself erase diary records or past chat kept in your account, and it cannot recall processing already completed. A materially changed AI purpose, recipient, data scope, provider retention statement, or international-processing disclosure requires a new version and a fresh affirmative choice before further AI processing.
Service providers and recipients
We disclose only the information needed for the mapped purpose to these active or conditional recipients:
- Convex provides the production backend, authentication, database, server functions, scheduled work, and recent operational logs.
- Cloudflare R2 stores private attachments, analysis artefacts, and temporary exports using a standard global service and signed-only retrieval.
- OpenAI processes the bounded text, image, document, audio, and selected account context needed for an AI action you request after consent.
- PostHog US receives linked pseudonymous product analytics and sanitised diagnostics for first-party measurement. Turning analytics off stops future collection. Account deletion submits the linked person, events, and recordings for provider deletion, which may complete asynchronously and remains subject to provider or legal residual limits.
- RevenueCat processes opaque customer, product, entitlement, transaction, and subscription state. Account deletion requests removal of the Growing Years customer record but does not cancel the separate store subscription.
- Apple processes Sign in with Apple, App Store purchases, APNs notifications, and optional Apple calendar copies when you use those features.
- Google processes Google authentication and may store a calendar copy when you select a Google-backed device calendar.
- Expo and APNs process push tokens, notification content, and delivery receipts only when notifications are enabled.
We may also disclose information when reasonably necessary to comply with law, protect rights or safety, investigate abuse, or complete a corporate transaction, subject to applicable legal requirements. We do not receive money in exchange for child health information and do not use it for targeted advertising.
Your child's information and consumer health data
You must be at least 18 and be the child's parent, legal guardian, or another adult authorised to provide and manage the information you enter. Do not provide information that you are not authorised to use. The child is not the account holder; you exercise account controls for the records you manage, subject to the child's own rights under applicable law.
Child health and related diary information can qualify as health data, special-category data, sensitive data, or consumer health data depending on where you live. You provide explicit consent for the core processing of health information through the dedicated privacy choice shown before health records are collected. Optional AI disclosure is governed by the separate AI Processing Consent.
For US laws that require a consumer health data notice, this Notice identifies the health categories collected, their sources, purposes, recipients, and the rights route. We collect health information from you and from files or device features you choose; we use and share it only to provide requested diary, storage, calendar, notification, subscription, security, and consented AI functions. We do not sell consumer health data. You can withdraw consent for future consent-based processing and submit an access, correction, deletion, or appeal request at legal@kernelics.com.
Your rights and choices
Depending on where you live, you may have rights to access, correct, delete, restrict or object to processing, withdraw consent, receive portable information, or appeal a decision. You may also complain to your local data-protection authority. These rights may have legal limits, and we may need to verify that a requester is entitled to act for the account or child.
- You can edit or delete individual diary records in the app.
- You can create a machine-readable private export in Settings. It covers the account and directly owned service records, Anna conversations, and a manifest of private media links. The package and every link expire 24 hours after the request. Password secrets, refresh tokens, verification codes, and PKCE verifiers are excluded for security.
- You can turn off future PostHog US analytics collection in Analytics and Diagnostics. This choice is persistent, but it does not erase analytics already received by PostHog.
- You can withdraw AI consent in Settings. Non-AI features remain available.
- You can choose Delete now, which starts irreversible deletion immediately, or schedule deletion in 30 days. Both choices immediately freeze normal access and future AI, analytics, push, and calendar work. Only the scheduled choice can be cancelled, and only before the cutoff.
- At the cutoff, a resumable process erases the active account, directly owned Convex data, authentication sessions and credentials, Anna history and artefacts, private R2 media and exports, and scheduled application work. It also invokes applicable Apple, RevenueCat, and PostHog deletion boundaries. This installation removes managed calendar copies when device access remains available; copies on unavailable or other devices cannot be remotely guaranteed.
Recent authentication is required for in-app export and deletion. You may also email legal@kernelics.com; we will verify, assess, and respond under applicable law. Sign in with Apple revocation is triggered through the deletion process for supported accounts. Deleting a Growing Years account does not cancel an App Store subscription; manage it separately through Apple.
Retention
We keep active child, diary, planner, attachment, and AI-history information while the account is active or until you delete the corresponding content, subject to operational and legal needs. Unfinished system input is intended to expire sooner. A scheduled account deletion has a 30-day cancellation period. Private export packages and their signed media links expire 24 hours after the request and are cleaned up automatically.
After account deletion, we retain only minimal de-identified completion and legal-evidence records for six years. These records contain an opaque reference, document or action type, version, timestamp, locale, state, and integrity hash; they do not contain an account identifier, email address, child identifier, health content, or attachment. We do not maintain a separate recoverable application backup used to restore a completed deleted account.
Providers may keep operational, security, transaction, delivery, infrastructure-backup, or residual information under their own rules and legal obligations. We do not represent that every provider uses one common retention period or that account deletion immediately removes every offline, delivered, calendar-synchronised, provider-log, infrastructure-backup, or residual copy. Subscription and transaction information may be retained where required for accounting, fraud prevention, dispute handling, or law.
Changes and contact
We may update this Notice. Editorial corrections do not require a new acknowledgement. A material change to data categories, purposes, recipients, retention, or your rights receives a new Privacy Notice version and an in-app notice or acknowledgement; we request fresh consent when the law or the changed processing requires it. The effective date and version appear on every copy.
Controller: KERNELICS LLP, company number OC448443, 27 Old Gloucester Street, London, United Kingdom, WC1N 3AX. Privacy requests: legal@kernelics.com. Product support: support@growing-years.com. Public legal documents: https://www.growing-years.com/privacy.