Privacy Policy • BabyShield

1 Who we are

Cureviax Research LLC ("we", "us", "our") operates the BabyShield mobile apps and website.

Company Information

2 Scope

This policy covers the BabyShield mobile apps (iOS/Android) and our public website babyshield.cureviax.com.

Important Notes
  • BabyShield is an informational tool that aggregates official recall/safety data
  • It is not medical advice and not a medical device
  • Our website functions without analytics or advertising cookies

3 Data we collect

Account & Authentication

We store: Internal user_id (UUID) and provider's subject identifier (sub)
We don't store: Your email address from Apple or Google
?

App Telemetry

Crash reporting: Optional/opt-in anonymized crash logs
Performance logs: Aggregated metrics without personal identifiers

Support Communications

Only when you email us: your email address, message content, and attachments for support purposes
📱

Device & Technical Data

IP address and user agent in server logs for security. Camera used on-device for barcode scanning only.

5 Sharing & disclosures

We do NOT sell or share your personal information for advertising

We may disclose data to:

🔧

Service Providers

Sub-processors under contract (cloud hosting, error monitoring) who process data only on our instructions
⚖️

Legal Authorities

When required by law or to protect rights, safety, or security
🏢

Business Transfers

In case of merger or acquisition, with notice and appropriate safeguards

6 Data retention

👤

Account Identifiers

Kept until you delete your account (in-app or via Data Deletion page)
📧

Support Records

Up to 3 years unless longer period required by law
📊

Server Logs

Typically 30-90 days for security and diagnostics
💾

Backups

Encrypted backups may retain data for 30-90 days on rolling basis

7 Your rights & choices

In-app controls

🗑️
Delete Account
Settings → Privacy → Delete my account
📦
Export Data
Settings → Privacy → Export my data
🐛
Crash Reports
Opt in/out in Settings (off by default)

Region-specific rights

Depending on your location, you may have rights to access, correct, delete, or receive a copy of your data (GDPR/UK GDPR; CCPA/CPRA).

How to exercise your rights
  • Use the in-app controls above, or
  • Email support@babyshield.cureviax.com with your request
  • We'll ask you to re-authenticate via Apple/Google to verify ownership

California residents: we do not "sell" or "share" personal information as defined by CPRA. We honor deletion, access, and correction requests.

🔒 Security

🔐

Encryption

HTTPS/TLS in transit and industry-standard encryption at rest via our cloud provider
🛡️

Access Control

Least-privilege access, rate limiting, input validation, and structured error handling
🏗️

Infrastructure

Environment separation and periodic backup restore drills

See Security & Responsible Disclosure for technical details and how to report vulnerabilities.

🌍 International transfers

We are based in the United States. If you access BabyShield from outside the U.S., your information may be processed in the U.S. or other countries where our service providers operate.

Data Protection
  • We use appropriate safeguards (standard contractual clauses) for international transfers
  • All transfers comply with applicable data protection laws

👶 Children's privacy

BabyShield is intended for general audiences and is used by parents/caregivers. We do not knowingly collect personal information from children under 13 (or under the age of digital consent in your jurisdiction).

If you believe a child has provided personal information
  • Contact us immediately so we can delete it
  • We take children's privacy very seriously

🍪 Cookies, tracking & "Do Not Track"

Our Approach
  • Our website operates without analytics or advertising cookies
  • We don't track users across third-party websites for advertising
  • DNT/GPC signals don't change site behavior because we don't use trackers

See Cookie Policy for more details.

📝 Changes to this policy

We may update this Privacy Policy to reflect operational, legal, or regulatory changes.

How We Handle Updates
  • Material changes will be notified in-app or on our website before they take effect
  • Continued use after changes take effect constitutes acceptance

📊 Summary table (for reviewers)

Category Collected Linked to user Purpose Retention
Identifiers Internal user_id, provider sub Yes (functional) App functionality, security Until account deletion
Contact info Only if you email support Yes (support thread) Customer support, compliance Up to 3 years
Diagnostics Crash logs (opt-in), performance metrics No direct identifier App stability Short, per vendor defaults
Sensitive data Not collected
Tracking/ads Not used

Apple/Google forms: mark "Identifiers (User ID)" collected (for functionality), not shared; "Contact info" only for support; diagnostics optional/consent.

Contact us

Cureviax Research LLC
1111B S Governors Ave STE 34726, Dover, DE 19904, United States
Email: support@babyshield.cureviax.com
Website: https://babyshield.cureviax.com