Baby Tracking Privacy: What Apps Do with Data

Baby Tracking Privacy: What Apps Do with Data

"A baby tracker holds a complete health record of a person too young to consent. What happens to that data depends less on the app's promises than on where it is hosted, and the law that governs it."

Storklet logo
Storklet Team
Published 2026-06-23 19 min read

Every baby tracker asks for the same thing: your child’s date of birth, their weight, their feeds, their sleep, their vaccines, and, in many apps, their face. Parents type it in several times a day, for the same reason they weigh before a feed and note the time: because the record matters.

What the record is worth to someone else is the part the app store never mentions. Health data about a child is among the most sensitive information a family holds. It is also, on the open market, valuable.

This post is about the gap between what apps say about privacy and the law that actually governs your data. The short version: where an app is hosted decides which law applies to it, and the two big hosting regions, the EU and the US, are not close to the same. Once you see the difference, app store promises become much easier to read.

Illustration of data flowing from a baby app on a phone toward a distant cloud with a target symbol, while the baby sleeps peacefully at home

What a baby tracker actually stores

Start with the inventory, because most people have never seen it written down. The same app you open at 2 a.m. to log a feed is quietly building this:

What the app storesExamplesWhy it matters
Feeding and sleep logsBottle amounts, nursing sessions, nap times, night stretchesA day-by-day record of a body’s rhythms, tied to a date of birth
Growth measurementsWeight, height, head circumferenceThe exact data a pediatrician uses to judge health, plotted on WHO curves
Health and vaccine recordsDoses given, symptoms, medication notes, doctor visitsA medical history in full, from a person with no say in it
Milestones and notesFirst roll, first word, diary entries, voice notesThe details that make a specific child identifiable, not a statistic
Photos and videosMoments, facesBiometric in all but name, linked to everything else in the profile
Account identifiersEmail, device ID, advertising IDThe key that joins the profile to ad networks, data brokers, and other apps
Location, in some appsGPS at log time, clinic visitsPrecise movement history, which is its own category of sensitive data1

None of these are new to you. You entered them. The question is what happens next, and the law treats the answer as serious because of two things about this particular dataset.

First, it is health data. Under the GDPR, data concerning health is a special category, and processing it is prohibited unless a specific legal basis applies, such as explicit consent.2 That is not a soft rule. It is the strictest tier of protection the regulation has.

Second, it is data about a child. The GDPR says children merit specific protection because they are less aware of the risks of sharing personal data, and it sets rules for when parental consent is required for online services, with the age threshold set by each member state between 13 and 16.3 In the US, the Children’s Online Privacy Protection Act (COPPA) reaches the same conclusion from a different direction: for apps directed at children under 13, even persistent identifiers like advertising IDs count as personal information, and collecting them requires verifiable parental consent.4

So the law agrees on the stakes. The disagreement is about who enforces it.

Where the data goes: the hosting question

The detail that changes everything is rarely explained: the GDPR applies to any company that processes the data of people in the EU, no matter where the servers sit.5 “EU-hosted” and “US-hosted” are not about whether EU law technically applies. They are about which regulator can actually reach the company, day to day, and what the company is required to do as a baseline.

A US-hosted app used by EU families. Data moving from the EU to the US crosses a legal border. Since 2023 the transfer route has been the EU-US Data Privacy Framework, which the European Commission found adequate in July of that year.6 That finding has history: the two frameworks before it, Safe Harbor and Privacy Shield, were both struck down by the EU’s top court.7 As of mid-2026 the current framework is still in force, and the EU’s General Court upheld the adequacy decision in September 2025, but an appeal is pending before the Court of Justice.8 Families are not asked to follow this drama. They just live with its consequences, because the stable answer keeps not arriving.

A US-hosted app used by US families. The GDPR may never touch it. What applies instead is the US patchwork, which is the next section.

An EU-hosted app. The GDPR applies from day one, along with the ePrivacy rules that govern cookies and tracking on websites.9 The company answers to a data protection authority with the power to fine, and to individuals with enforceable rights. In the UK, the ICO adds the Children’s code, which requires online services used by children to put their best interests at the centre of design.10 None of this makes an EU-hosted app automatically good. It makes the rules the default, not the exception.

The legal gap: GDPR vs the US

The US has no comprehensive federal privacy law. That sentence is the whole story. Everything else follows from it. Instead there are state laws, and they differ.

California has the CCPA, amended by the CPRA, enforced by a dedicated agency. Virginia, Colorado, and Connecticut each passed their own comprehensive laws, effective in 2023, with their own scopes and rights. More states have followed, and the list keeps growing, with no two quite alike.11 A company processing data across the US may be juggling a dozen different regimes, each with its own definition of “sale”, its own rights, and its own enforcement. None of them is the GDPR.

Children are the partial exception. COPPA protects under-13s in specific ways: notice to parents, verifiable parental consent, and limits on collecting personal information, which includes persistent identifiers. The FTC enforces it, and it is the most protective children’s privacy law the US has.12

Now read the gap. COPPA does not bar the sale of children’s data. When California forced data brokers to register and disclose what they trade, 24 of the roughly 480 registered brokers stated that they sell data belonging to minors, 79 sell precise geolocation data, and 25 sell reproductive health information.13

After California made data brokers register, only 24 of roughly 480 disclosed that they sell data on minors — 79 sell precise geolocation, 25 sell reproductive health information (categories can overlap). COPPA does not bar the sale of children’s data.

The FTC’s own study of data brokers, a decade earlier, found files rich with health-related inferences, built without consumers’ knowledge or consent.14

The enforcement difference follows the law. In the EU, a parent can complain to a data protection authority, and the authority can fine up to 4% of global turnover.15 In the US, enforcement against the privacy harms of adults is agency-led and case by case. The FTC has been active, and the cases below show it, but it acts on what it can reach, when it chooses to.

The honest way to state this is not “US apps are bad”. Many US companies take privacy seriously, and some are held to the GDPR anyway because they serve EU users. The point is the default. In the EU, strong privacy is the legal baseline for every company, including the smallest. In the US, it is a business decision that varies by company, by state, and by app.

What has actually gone wrong

The pattern is not hypothetical. The following enforcement actions and studies are the ones with documents behind them. None, so far, is a baby tracker by name. They are the same data flows, and the same incentives, and that is the point.

Health apps sharing with advertisers. In 2021 the FTC settled with Flo Health, a period and fertility tracker, over charges that it shared users’ health data with Facebook and Google despite promising it would stay private. The order required consent before any future sharing, notice to affected users, and deletion of the data the third parties held.16

Ad SDKs in kids’ apps. An SDK is a software kit an app embeds from another company, and ad SDKs are how tracking data leaves the app. In 2020 the FTC settled with HyperBeard, maker of apps popular with children, over allegations that third-party ad networks collected persistent identifiers from children to serve behavioural advertising without parental consent. The penalty was $4 million, largely suspended; the company paid $150,000.17

Children’s health data collected without consent. In 2022 the FTC settled with the company behind the Kurbo weight-management app, marketed to children as young as eight, over allegations it collected children’s weight and food intake without verifiable parental consent. The order required deleting the data, including the models and algorithms trained on it, and limiting retention to one year.18

A connected toy that lied about encryption. In 2018 the FTC reached its first connected-toy settlement, with VTech, after a breach exposed children’s data. The complaint said the company collected children’s names, birth dates, and photos without parental consent, and that its privacy policy claimed encryption it did not provide. Penalty: $650,000.19

A platform fined for under-13s. In 2023 the UK’s ICO fined TikTok £12.7 million after finding it processed the data of an estimated 1.4 million UK children under 13 without parental consent and failed to remove underage users it knew about.20

The scale of the SDK problem. A 2018 study by ICSI and UC Berkeley researchers examined 5,855 popular free Android apps marketed to children. It estimated that roughly 57% to 60% were potentially violating COPPA, that 73% transmitted sensitive data over the internet, and that 19% collected personal information through SDKs whose own terms prohibited use in child-directed apps.21

Where the data ends up. The FTC has ordered data brokers, including X-Mode/Outlogic in 2024, to stop selling precise location data gathered without consent, and in the same year took action against Gravy Analytics for selling location data tied to healthcare facilities and other sensitive places.22

Read that list once and the shape is clear. The data leaves the app through the pieces bolted on for advertising: SDKs, ad networks, analytics, brokers. The consent parents thought they gave was a clause in a wall of text. And the enforcement, when it came, arrived years later, after the data had already moved.

None of this means “don’t track your baby”. The record is the right idea; the problem is the plumbing around it, not the log.

What “GDPR compliant” actually means

The phrase appears in a lot of app store listings. It is not a badge, and there is no certification body that awards it. It is a legal framework with named obligations: you must tell people what you collect and why, collect no more than you need, honour requests to access, correct, export, and delete, and report breaches within 72 hours of becoming aware.23

For a parent, the practical translation is shorter. You have enforceable rights, a regulator to complain to, and a company that is legally required to respond. That is the whole difference.

It is also not a guarantee. Breaches happen at EU-hosted companies too. The difference is not that nothing can go wrong. It is that when something does, there is a defined chain of consequence: the company owes you a notification, a regulator can investigate, and the fine is not pocket change. That chain is the product. Everything else is marketing.

Choosing a tracker: six questions in ten minutes

You can assess any baby tracker with a plain-language privacy policy in about ten minutes. Skip the promises, take the policy to the questions.

1. Where is the data stored, and whose law governs it? Look for the legal entity, the country, and the hosting region. “EU-hosted”, “servers in the EEA”, “data controller in Finland” all mean something specific. “Cloud”, “secure servers”, “trusted partners” do not. If the policy does not name a country, that is the answer.

2. Does the app have ads or third-party SDKs? This is the load-bearing question, because it is how data leaves the app. The policy should name the SDKs or say there are none. Free apps are usually funded by advertising, and advertising is funded by data; read the list before you accept the trade.

3. Does the app sell or share your data? “We do not sell your data” is a sentence you can actually verify against the rest of the policy. Then check what “share” covers, because sharing with advertisers is the door the “no sale” line often leaves open.

4. Is the data encrypted in transit and at rest? Both. In transit means HTTPS; at rest means the stored database is encrypted. Both should be stated plainly.

5. Can you export and delete, yourself, without a support ticket? Export means the data is yours, in a usable format, whenever you want it. Deletion means delete, not “contact us and we might”. If you have to email someone to leave, you are not really free to leave.

6. What happened last time, and who can the company answer to? A breach history is not automatically disqualifying; how they handled it is. And a company with a regulator that can fine it is a different proposition from one that answers to no one.

Where Storklet fits

Storklet is a private, shared baby tracker, and this section is the concrete version of that claim, the way the checklist above would audit us.

Storklet is a Finnish company, and your data is stored on servers in the EU. The GDPR applies to us from day one, and the privacy policy is written to the standard the checklist asks for: it names the controller, the hosting region, and the regulator you can complain to — the Finnish Data Protection Ombudsman.

There are no ads and no third-party ad SDKs. The privacy policy states that we do not sell your data, and that the child content you enter is not used for analytics, advertising, or anything beyond the service itself. The product analytics we do run is cookieless, with no persistent identifiers. Photos, health notes, and logs are encrypted in transit and at rest.

Illustration of a large soft shield sheltering a sleeping baby in a cradle while grey data points drift away outside it, a calm stork standing watch

Access is per person. A partner can have admin rights, a pediatrician read-only access to growth and health records, a grandparent a view of feeds and naps, a nanny limited write access that logs the day without opening medical records. Export is a CSV of your logs, anytime, free. Deletion is self-serve and immediate from live systems, with backups purged within 30 days.

The honest limits: we use a small set of service providers, named in the privacy policy, for payments, email, and authentication, and they are bound to the same standard. And Storklet is paid, not free: €6 a month or €60 a year, after a 14-day trial. That is the trade this whole subject comes down to. An app funded by its users does not need your data to be its product. An app that is free usually is.

The private baby tracking app page spells out the details, as do the privacy policy and security page.

Quick answers

Is it safe to use a baby tracker at all? Yes. The record is worth keeping, and the alternative, memory, is worse. The question is not whether to track, but who else can touch the data. That is a choice you make once, at download, and it is hard to undo later.

Does “free” mean they sell my data? Not necessarily, and “sell” is rarely the word. The typical arrangement is ad-funded: an ad network pays the developer, and the ad network’s SDK collects identifiers and behavioural signals from the app. The policy’s list of third-party SDKs tells you which one you are in.

What does EU hosting actually change? The law that governs the company: GDPR applies as the baseline, individuals have enforceable rights, and a data protection authority can investigate and fine. For data on a child, which is health data about a minor, that is the strongest framework either region offers.

I don’t live in the EU. Does any of this apply to me? If the app serves EU users, the GDPR reaches it no matter where you are, because it is the company, not you, that the law binds. If the app is US-only, you are back to the patchwork: COPPA for under-13s, state laws that vary, and the FTC acting case by case.

Can I delete my baby’s data? You should be able to, yourself, in the app, without a support ticket. If deletion requires an email and a wait, the data is not really yours.

What is the single most important thing to check? Where the data lives and who can reach it, then whether the app has ad SDKs. Everything else, encryption, export, deletion, is checkable in the same ten minutes, but those two questions do most of the work.

The pattern in every case above is the same: a tracker filled with love, a plumbing system built for something else, and a promise read too late. You cannot fix the plumbing of an app you already downloaded. You can choose the one you download next, and the choice takes ten minutes. Your baby’s whole medical record is worth ten minutes.

Sources and Further Reading

We base our explainers on high-quality academic research and public health standards.


  1. Precise location data is treated as its own sensitive category by US regulators and state law: the FTC has ordered data brokers to stop selling it, and the CPRA in California added it to the categories consumers can limit. See the enforcement notes in footnote 22.
  2. Under Article 9 of Regulation (EU) 2016/679, the GDPR, data concerning health is a special category of personal data, and processing it is prohibited except on specific grounds such as explicit consent. Full text on EUR-Lex.
  3. GDPR Recital 38 states that children merit specific protection because they may be less aware of the risks of processing their personal data. The European Commission’s overview of children’s safeguards explains Article 8, under which parental consent is required for online services up to an age each member state sets between 13 and 16.
  4. The FTC’s COPPA rule covers operators of online services directed to children under 13. It treats persistent identifiers, including advertising IDs used to recognise users over time, as personal information, and requires verifiable parental consent before collection.
  5. Article 3 of the GDPR gives it territorial scope: it applies to any company processing the personal data of people in the EU, regardless of where the company or its servers are located.
  6. Commission Implementing Decision (EU) 2023/1795 of 10 July 2023, which found the US adequate under the EU-US Data Privacy Framework, allowing certified companies to receive EU data without additional transfer mechanisms.
  7. The CJEU struck down the Safe Harbor decision in 2015 and the Privacy Shield in 2020 (Schrems II, Case C-311/18), ruling that US surveillance powers gave EU data insufficient protection. The court’s press release summarises the 2020 judgment.
  8. The EU General Court dismissed the challenge to the adequacy decision in September 2025 (Case T-553/23, Latombe v Commission), holding that the safeguards behind the framework addressed the deficiencies found in its predecessors. An appeal is pending before the Court of Justice. Coverage of the judgment.
  9. Directive 2002/58/EC, the ePrivacy Directive, requires consent for storing or accessing information on a user’s device, which is why cookie banners exist. It applies alongside the GDPR in EU member states.
  10. The ICO’s Children’s code (Age Appropriate Design Code) requires online services likely to be used by children in the UK to design with the child’s best interests at the centre, covering default settings, data minimisation, and geolocation, among other standards.
  11. The IAPP’s overview tracks the US state privacy laws. California’s CCPA (2018) and CPRA amendments created a dedicated enforcement agency; Virginia, Colorado, and Connecticut laws took effect in 2023, and further states have passed or amended laws since.
  12. The FTC is the agency that enforces COPPA, bringing its own complaints and settlements, and COPPA is the most protective US privacy law specific to children. The enforcement actions in the next section are its record.
  13. The Record, March 2024: after California’s data broker registry went live, 24 of roughly 480 registered brokers disclosed that they sell data belonging to minors; 79 sell precise geolocation data and 25 sell reproductive health information. COPPA does not bar the sale of children’s data.
  14. The FTC’s 2014 report, Data Brokers: A Call for Transparency and Accountability, found brokers’ files contained thousands of data segments, including health-related inferences, built largely without consumers’ knowledge.
  15. Article 83 of the GDPR caps administrative fines at €20 million or 4% of global annual turnover, whichever is higher, which is why the fines in EU privacy enforcement run far above anything COPPA has produced.
  16. FTC press release, June 2021: the FTC finalized its order against Flo Health, which shared users’ health data with Facebook and Google despite promising it would remain private. The order required affirmative consent for future sharing, notice to users, and direction to third parties to delete the data.
  17. FTC press release, June 2020: HyperBeard allowed third-party ad networks to collect persistent identifiers from children in its apps to serve behavioural advertising without parental consent. The $4 million penalty was largely suspended for inability to pay; the company paid $150,000.
  18. FTC press release, March 2022: the FTC settled with WW International and its Kurbo subsidiary over collecting children’s weight, food intake, and other personal information without verifiable parental consent. The order required deleting the data and any algorithms trained on it, and limited retention to one year.
  19. FTC press release, January 2018: VTech settled the FTC’s first connected-toy case, paying $650,000 over COPPA violations and a 2015 breach. The complaint said it collected children’s names, birth dates, and photos without parental consent and misrepresented that the data was encrypted.
  20. ICO enforcement notice, April 2023: TikTok was fined £12.7 million for processing the personal data of an estimated 1.4 million UK children under 13 without parental consent and failing to remove underage users it was aware of, between May 2018 and July 2020.
  21. Reyes et al., Won’t Somebody Think of the Children? Examining COPPA Compliance at Scale, Proceedings on Privacy Enhancing Technologies, 2018. The study analysed 5,855 popular free Android apps marketed to families and children.
  22. FTC order against X-Mode Social/Outlogic (January 2024) and FTC order against Gravy Analytics/Venntel (December 2024) prohibited the sale of precise location data, including location data tied to healthcare facilities, places of worship, and other sensitive places, collected without consent.
  23. The GDPR’s obligations are in Articles 5 to 22 of the regulation: lawfulness, purpose limitation, data minimisation, the data subject rights to access, correct, export, and erase, and, under Article 33, notification of a breach to the supervisory authority within 72 hours of becoming aware of it.

Read Next

ennllt-ltpt-br