Effective July 15, 2026

Privacy Policy
DonnaAI

A clear explanation of how DonnaAI handles your data and your baby's routine information.

1. Who this policy covers

This Policy describes how DonnaAI processes the personal data of adult parents and caregivers who use the DonnaAI app and donnaai.app website.

Under Brazil's Law No. 13,709/2018 (LGPD), DonnaAI acts as controller for the data processed to provide the service. Service providers may act as processors or independent controllers for the activities described below.

2. Data we process

Account and identity data may include your account identifier, name, email, session credentials or tokens, and information received through Sign in with Apple according to the permissions you choose.

Caregiver-provided data may include baby profiles, caregiver relationships, dates and routine records such as sleep, feeding, diapers, and growth, plus messages, responses, and conversation memories used by Donna.

Technical, subscription, attribution, and support data may include app version and build, operating system, language, predefined operational events, crashes, latency, purchase status, Support ID, and the content you choose to send when contacting support.

3. Why we process data

We process data to create and protect accounts, synchronize records, answer requests, personalize the experience, generate responses and insights, manage subscriptions, provide support, prevent abuse, and maintain a safe and stable service.

Legal bases may include performing a contract or requested steps, legal obligations, exercising legal rights, legitimate interests assessed for necessity and impact, and consent where required.

Advertising tracking and marketing communications require specific consent. Data about a baby is handled with enhanced safeguards, for the requested functionality, under the authorization and responsibility of the adult caregiver.

4. Storage and synchronization

DonnaAI is local-first: operational records are stored on the device through SwiftData and may synchronize with your private iCloud database through Apple CloudKit.

Account data, profiles, relationships, conversations, memories, and context required for online features may also be stored by Donna Brain using backend infrastructure and a Supabase/Postgres database.

Local storage and iCloud synchronization are not guaranteed backups. Device loss, changes to the iCloud account, or failures beyond our control may affect data availability.

5. Artificial intelligence

Messages and only the context needed to answer a request may be sent by Donna Brain to the OpenAI API. Requests are configured not to retain response state with the provider (store: false).

Under OpenAI's current API policy, API inputs and outputs are not used to train models by default. The provider may retain abuse-monitoring logs for up to 30 days unless a different contractual setting or legal requirement applies.

AI-generated responses can be incorrect and do not replace medical, nutritional, psychological, or emergency care.

6. Analytics and diagnostics

We use PostHog Cloud EU for product analytics. We send predefined operational events and categories, linked to an account identifier when needed. Conversation content and baby routine data are not sent to PostHog, and session recording and automatic screen capture are disabled in the app.

We use Sentry for stability and diagnostics. The app configuration disables default PII, screenshots, view hierarchy, network tracking, and automatic breadcrumbs; an account identifier, app version/build, and technical error codes may be sent.

You may object to product analytics by contacting us. Data strictly required for security, fraud prevention, and service operation may continue to be processed under the applicable legal basis.

7. Advertising and tracking

We use the Meta SDK and Apple's attribution mechanisms to measure campaigns. Events sent to Meta are limited to funnel milestones and do not include messages or baby routine data.

The device advertising identifier and related collection are enabled only after App Tracking Transparency authorization. If you decline, the app continues to work and measurement may use Apple mechanisms that do not rely on ATT authorization.

You can change tracking permission at any time in iOS Settings.

8. Subscriptions, email, and support

Apple processes App Store payments through StoreKit. DonnaAI does not receive your card number. RevenueCat processes account identifiers and purchase, product, and renewal data to manage access.

We may use Resend for transactional emails and, only with consent, marketing communications. Service or account emails required to provide the service are not treated as advertising.

Support channels are shown according to the user's region. No conversation or baby data is attached automatically; you choose what to include in a support request.

9. Providers and international transfers

We may share only the data needed with Apple, Supabase, OpenAI, PostHog, Sentry, RevenueCat, Meta, and Resend for the services described in this Policy.

These providers may process data outside Brazil. We use contractual, technical, and organizational measures consistent with the LGPD and assess the providers used by the service.

We do not sell personal data. We may disclose data when required by law or a valid order, to protect rights, prevent fraud, or defend the service and its users.

10. Retention and deletion

We retain data for as long as needed to provide the service, protect accounts, meet legal obligations, resolve disputes, and exercise rights. Technical logs, backups, and providers may have different retention cycles.

You can delete your account in Profile → Tools → Delete Account or request help at suporte@donnaai.app. Deletion closes the account and begins removal of data controlled by DonnaAI, subject to legal, fraud-prevention, and technical retention requirements.

Data stored in iCloud is also subject to your Apple account and Apple's controls. Uninstalling the app alone does not delete your DonnaAI account.

11. Your privacy rights

Under the LGPD, you may request confirmation, access, correction, anonymization, blocking or deletion where applicable, portability under applicable regulation, information about sharing, review of applicable automated decisions, and withdrawal of consent.

We may ask for information to verify your identity and protect the account. Mandatory privacy and consumer rights that apply where you live remain unaffected.

12. Children and teenagers

DonnaAI is intended for adult caregivers. Children do not create accounts and should not use the service directly. Baby data is entered and managed by a responsible adult or someone they authorize.

When adding a child, you confirm that you have authority to provide and manage that data. We may restrict access or delete data if direct child use or missing authorization is identified, subject to legal duties and the child's best interests.

13. Security and limitations

We use access controls, authentication, TLS/HTTPS connections, environment separation, and telemetry minimization. CloudKit protects private-database data with Apple account authentication and encryption.

No system is completely secure. Protect your device and Apple account, use current iOS versions, and contact us promptly if you suspect unauthorized access.

14. Changes and contact

We may update this Policy for legal, technical, or product changes. Material changes will be communicated through an appropriate channel, and the effective date will remain visible on this page.

For privacy questions, rights requests, or security incidents, email suporte@donnaai.app or visit donnaai.app.

Need help?

Contact us about your account, privacy, or the DonnaAI service.

suporte@donnaai.app
DonnaAI

Your AI partner for a lighter, calmer,
more predictable parenting journey.

Download on the App Store
© 2026 DonnaAIMade with for parents