Effective August 12, 2026
Privacy Policy
All Their Days is a private family archive for adults who choose to preserve a child’s memories and personal records. This policy explains the information the website and app use, why it is needed, and the choices families have.
Who we are
All Their Days LLC (“All Their Days,” “we,” “us,” or “our”) provides the All Their Days website and app. Privacy questions and requests can be sent to privacy@alltheirdays.com.
Who the app is for
All Their Days is provided to parents, guardians, and invited adult family members. It is not directed to children and does not ask a child to create an account. An adult family steward decides what to preserve and who may enter the family archive.
Information we process
Account information includes an adult’s name, email address, authentication records, family role, and security events. Family information may include child names and dates, pregnancy or childbirth details such as expecting status and due date, optional height and weight observations, memories, notes, answers, landmarks, traditions, family relationships, authorship, and future handoff instructions.
When an adult deliberately chooses to add them, the archive may contain photographs, videos, voice recordings, documents, and related details such as filenames, dates, file types, sizes, integrity checksums, and upload status. Recent photographs remain on the device until the adult selects one; the app does not automatically import a camera roll.
Why we use information
We use this information only to authenticate adults, operate the private archive, preserve and retrieve selected originals, deliver requested reminders and account emails, enforce family permissions, provide exports, prevent abuse, respond to support requests, and maintain service reliability.
We do not sell family information, use it for targeted advertising, or publish it by default. The app can ask the device operating system to verify an adult with Face ID, Touch ID, or Android biometrics, but All Their Days does not receive or store the adult’s face, fingerprint, or biometric template. The app does not analyze family photographs for facial recognition, infer a child’s emotions, or send family content to a general-purpose AI system.
Family access and sharing
Every adult uses an individual account. A steward can invite an adult as a co-steward, contributor, or viewer, cancel an invitation, or revoke access. Invitations are email-bound and time-limited. Family-visible memories may be seen by adults with access to that family; restricted records are limited to stewards. Adults should add content only when they have the right and authority to preserve it.
Device permissions and reminders
Camera, photo-library, microphone, document, and notification access is requested only when needed for a feature the adult chooses. Landmark reminders are scheduled locally and use generic lock-screen wording without a child’s name or landmark details.
Service providers
We use service providers to operate the product, including Supabase for authentication, database, and private object storage; Vercel for the public website; Expo, Apple, and Google for building, testing, distributing, and billing the mobile apps; RevenueCat for subscription entitlement verification; Resend for transactional account email; and Sentry for privacy-restricted error and crash monitoring. These providers process limited information for the purposes described here and are required to protect it under their applicable agreements and security controls. RevenueCat receives the adult account’s random Supabase user identifier and store transaction state, not family archive content. We will update this policy and our Trust Center when that list materially changes.
Sentry monitoring is limited to diagnosing software failures. We disable session replay, screen and view capture, performance tracing, profiling, automatic logs, and automatic user identity. Before an error is sent, the app removes request bodies, headers, cookies, query strings, user details, breadcrumbs, custom context, and runtime variable values. Sentry is also configured to reject IP-address storage and apply server-side sensitive-data scrubbing. Family photographs, videos, audio, documents, memory text, health or school records, and search contents are not intentionally sent to Sentry.
Security
Family archives use access controls, private storage, expiring signed file access, encrypted network connections, role checks, and checksums recorded for completed originals. No service can guarantee absolute security. Report a suspected security issue to security@alltheirdays.com without attaching family content.
Retention, export, and deletion
We retain account and family content while the archive remains active and as needed to operate and secure it. Stewards can create structured and complete archive exports. Account deletion is available inside the app and removes an individually controlled family archive and its private originals after reauthentication. Shared archives may require a stewardship transfer or removal of other members so one adult cannot silently erase content belonging to the family.
When account deletion completes, the account and associated production archive data controlled solely by it are no longer available through the service. Limited transaction, security, fraud-prevention, or legal records may be retained only for the period required for those purposes, then deleted or de-identified. Residual encrypted backups may remain until they roll off under service-provider backup schedules and are not used to recreate a deleted account. Temporary export files are removed from app cache after the system sharing flow.
To request deletion help when unable to sign in, visit our account-deletion page or email privacy@alltheirdays.com from the account email address.
Health and school records
The vault is personal organization software, not a provider record system. All Their Days does not diagnose, interpret records, give medical or educational advice, or replace records maintained by a clinician, school, government agency, or emergency service.
Website, marketing measurement, and early access
If you join the founding-family waitlist, we collect your email address, request time, email consent, and limited attribution and technical logs needed for security, reliability, and understanding how people find us. You may optionally provide your name, family role, preservation interests, survey answers, interview consent, device type, and TestFlight interest. Do not submit children's names, birthdays, media, health or school information, or private family stories through these marketing forms. Waitlist and survey records are kept in a separate internal CRM and are not part of a family archive. We retain them while the program is active or until you ask us to remove them.
We use founding-family information to send requested product updates, invite optional research participation, manage pre-release testing, prepare for launch, and improve our public messaging. Every lifecycle email includes an unsubscribe option. Unsubscribing stops future marketing messages; you may separately request deletion through the account-deletion page or by emailing privacy@alltheirdays.com.
With your permission, the public website uses first-party browser storage to assign random visitor and session identifiers and remember advertising attribution for a limited period. We may record landing path, referring domain, campaign parameters and advertising click identifiers, device category, page views, engagement time, scroll milestones, calls to action, and whether an early-access request occurred. We use this information to understand acquisition, measure campaigns, improve the website, and support the founder-controlled Growth Agent.
When you allow measurement, the public website also loads Google Analytics and the Meta Pixel and sends each service a generic page-view event on approved public marketing pages. Google Enhanced Measurement, Google advertising storage and personalization, and Meta advanced matching are disabled. We do not send names, email addresses, form contents, child information, or private archive activity to either service. Google and Meta may process limited browser and device information under their own privacy terms.
Website growth data does not include a child's name, birthday, family relationships, memory text, photographs, videos, audio, documents, health or school records, archive searches, or the contents of an early-access form. We do not store an exact IP address in the first-party growth analytics tables or combine private archive content with advertising profiles.
You can allow or decline optional measurement from the website notice and change your selection at any time using Privacy choices in the footer. Do Not Track and Global Privacy Control signals keep optional measurement off. Declining does not affect access to the website or app.
Your choices
Adults can decline or revoke optional device permissions, change or remove archive entries where their role allows, revoke invited access, export the archive, change their password, or request account deletion. Depending on where you live, you may also have rights to access, correct, delete, or obtain a copy of personal information and to appeal a denied request. We may verify a request before acting on it.
Where information is processed
All Their Days is operated from the United States. Service providers may process information in the United States and other locations where they operate, subject to their contractual and legal safeguards.
Changes and contact
We will date material changes and provide notice when appropriate. Contact privacy@alltheirdays.com for privacy questions, support@alltheirdays.com for product help, or security@alltheirdays.com for security reports.