Beta
FeaturesPricingOur storyGift MiloCreate your family

Privacy

We are parents. You are about to put a record of your baby, and his face, into someone else’s app, and we have been on your side of that decision. This is what we do with it, in plain sentences.

Last updated August 16, 2026

Who we are

Milo is a baby-tracking app made by two parents. We are the data controller for everything described here, and you can reach a human, one of us, at hello@milo.baby.

What we collect

What you log about your baby: feeds, nursing, pumping, diapers, weights, heights, supplements, notes, and photos you choose to add.

What your baby’s profile needs to be useful: name, birth date, sex and gestational age, because the growth curves cannot be drawn without them. If you fill in the emergency card, that includes the contacts, conditions, medications and insurance details you put there.

Who you are: your email address, a display name if you set one, and which household you belong to.

Ordinary technical records needed to run a service securely: sign-in records and server logs.

What we use it for

Showing you your own log, and showing it to the people you invited at the level you invited them.

Sending the emails the app has to send: your sign-in code, an invitation you asked us to send, and notifications you turned on. If you buy Milo as a gift and ask us to email the card to the person it is for, we send that one message to the address you type and do not keep it.

Keeping the service working and secure.

That is the list. We do not profile you, we do not build an advertising audience, and we do not use your log to make decisions about you.

What we never do

We never sell your data. Not to advertisers, not to data brokers, not to anyone, and not as part of any future change of ownership without telling you first.

We never share it with advertisers, and there are no third-party advertising or tracking scripts inside the app.

We never use what you log, or your photos, to train machine-learning models, ours or anybody else’s.

We never read your household’s log to build features or write marketing. Everything you see on this website is either our own family or an invented demonstration household.

How it is protected

Everything travels over encrypted connections (TLS), and everything is encrypted at rest: both the database and the photo storage, by the platforms that hold them.

Households are isolated from one another in the database itself, by row-level security, rather than by application code remembering to filter. Someone in another family cannot read yours even if we make a mistake in a query.

Photos are served through signed links that expire after hours. They are not public URLs, so a link that escapes stops working.

If you install Milo to your home screen, it keeps the last ordinary screens you viewed on the device so it opens instantly, even offline — but never the sensitive ones: the health, emergency, report and account screens always load fresh over the network, so they are not left sitting on the device. Signing out clears the saved screens, and opening the app as a different person clears them too. A device that is offline cannot be reached to clear them remotely, though, so on a shared or lost device, sign out on the device itself.

There is no admin screen that browses families’ logs. We can reach the database to operate the service; we do not read your log, and we will not without a reason we would tell you about.

Who else touches it

Only the suppliers it takes to run the thing: hosting, a managed Postgres database, object storage for photos, and an email provider for sign-in codes and notifications. They process data on our instructions and for no purpose of their own.

These marketing pages load Google Analytics so we can see whether anyone finds Milo, and so does the demo and the sign-in screen on milo.baby. The demo household is invented, from the family down to the baby, and watching where people put it down is how we learn what to fix. No real household is ever given the measurement ID. “Don’t count my visits” turns it off on this device: at the foot of every marketing page, and on the black bar inside the demo.

On those pages we also record which version of a page you were shown. We keep two wordings of our sales pages running at all times and compare which one people find clearer, so a visitor is put in one group or the other by a random number kept in a cookie. That number describes nobody — it is not derived from you, it is not joined to your account, and it is never sent to Google; only which of the two pages it produced. What we count is what everybody counts: the page was seen, a button was pressed, a sign-in code was asked for, somebody got in, the family form was reached, a family was created. Turning off “Don’t count my visits” stops all of it, and the page you get is unaffected either way.

Where it lives, and for how long

On servers in the United States. If you are in the EU or UK, that means your data is stored in the US. That is lawful and ordinary, and you should know it rather than discover it.

We keep what you log for as long as your household exists. Deleting your account deletes it: your address, your name, your picture, every device you are signed in on. What you logged stays in the family’s record with your name deleted from it — it is their record of their baby, and a mother leaving should not empty the log a father is still keeping.

Deleting the household deletes everything: the baby’s name, every entry, every note, address, phone number and health detail, and every photo. Photos are removed from our storage permanently and cannot be recovered by us or by you, so take what you want to keep first. It happens 30 days after you ask, and you can stop it at any point in those 30 days.

What is left afterwards is numbers with nobody attached to them — no name, no address, nothing that points back at a person. We keep that to test and improve Milo. It is not your data any more, because there is no longer any way to tell it was ever yours.

Your rights

Export everything you have logged as CSV, from Settings → Data, at any time, without asking us and without a waiting period.

Delete your account yourself, from Settings → Your account, without asking us and without a waiting period. A parent can delete the whole family from the same screen — every entry and every photo, permanently, 30 days after asking.

Ask for a copy, a correction, or anything the screen does not cover by writing to hello@milo.baby, and a person will do it. Depending on where you live you may also have the right to object to processing or to complain to a data protection authority; nothing here is meant to take that away.

About your child

Most of what is in Milo is information about a child, provided by their parent. We treat it as the most sensitive thing we hold, because it is. It is never sold, never used for advertising, never used for training, and never shown to anyone the parent did not invite.

Milo is for the adults looking after a baby. It is not designed for, or directed at, children using it themselves.

Changes

If this policy changes in a way that matters, we will say so by email rather than quietly editing the page. The date at the top is the last time it changed.

Asking anything

Questions, corrections, deletions and complaints all go to the same place, and a person answers: hello@milo.baby. If you want to know why any of this is the way it is, our story explains most of it.

From our family to yours.
FeaturesOur storyGift MiloPrivacyTermshello@milo.baby
EnglishItalianoEspañol