Duckaby

What leaves your phone

Last updated 28 September 2026. This is the claim in the privacy policy made checkable: every feature that talks to a server, and exactly what that request contains.

The short version

There is no analytics SDK, no ad SDK, and no crash reporter in the app. Nothing is sent in the background. A request only happens when a feature you’re actively using needs the network, and every request below is the whole list.

FeatureWhen it talks to a serverWhat the request containsWhat the server can read
Family sync (parents/caregivers sharing one baby’s log)Whenever a log entry changes, while a family is set upPOST /v1/nest/<id>/ops — a proof header derived from your invite secret, and one or more encrypted blobsOnly the request’s size and timing, and your IP address in the standard web server log. The blob is ciphertext sealed on your phone with a key the server is never sent; the nest id itself is a one-way hash of your invite secret, not your baby’s name.
Daycare day-sheet share linkOnly if you tap “Share today” to hand a daycare a linkAn encrypted snapshot of that one day, published under a random id; the decryption key lives only in the link’s #fragment, which browsers never send to a serverAn opaque blob and the random id. Whoever holds the full link (fragment included) can decrypt it — the server itself cannot.
Waitlist form on this websiteOnly if you check the consent box and press “Notify me”POST /v1/waitlist — your email address (lower-cased), the option you picked, and consent:trueYour email in plain text, the option, and the time — because you asked to be emailed. Nothing else on the site can do this; there’s no other form. See what we do with it.
Anonymous “how many people want this” counterWhen you view or interact with a demand-test prompt in the appPOST /v1/interest — one word naming which feature (e.g. sleep_coach)A tally per feature. No email, no device id, no IP is stored against it.
Nursery Listener (on-device sound classification)Never. Classification runs on the phone; nothing is sent—Nothing. No audio is stored or sent anywhere, not even to us. See the consent note below.
Everything else — logging feeds, naps, growth, memories, assistant answers, mom’s health notes, predictorsNever, unless it’s part of family sync above—Nothing. These run entirely on your phone.

Nursery Listener: tell anyone in the room

The Nursery Listener classifies sound on the device to guess sleep/awake state. No audio is ever recorded to a file, stored, or sent anywhere — not to Duckaby, not to any other server. Classification happens locally and only the resulting event (e.g. “asleep”) is saved. Because a microphone is listening even though nothing is transmitted or kept, tell any caregiver, nanny, or visitor in the room that it’s on.

Check it yourself

Two scripts in the Duckaby codebase make this checkable rather than just stated: site/check.mjs opens every page on this site and fails if any page makes a request off-site, and relay/it.mjs runs the sync + waitlist protocol end-to-end against a live relay and asserts the server only ever holds ciphertext or the fields listed above. Ask support@duckaby.com for the source if you’d like to run them.