Privacy Policy
Last updated: September 25, 2026
Introduction
JaenWorld OÜ ("we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the Jaen Babymon app (on phones, tablets and companion watches) and the jaenworld.com web services.
Jaen Babymon is built local-first: your baby's audio and video are streamed directly between your own devices and are never stored on — and on your home network never even pass through — our servers.
We are based in Estonia and comply with the EU General Data Protection Regulation (GDPR) and Estonian data protection laws.
Who We Are — the Data Controller
For the personal data described in this policy, the controller under the GDPR — the company that decides why and how it is processed, and the company that provides Jaen Babymon — is:
Company: JaenWorld OÜ (an Estonian private limited company)
Estonian registry code: 17547671
Registered address: E. Vilde tee 89-54, Mustamäe linnaosa, 12911 Tallinn, Harju maakond, Estonia
Email: info@jaenworld.com
We are established in Estonia, in the European Union, so the GDPR applies to us directly. We have not appointed a Data Protection Officer — we are not required to — so privacy requests go to the address above and are handled by the company.
You can complain to a regulator. If you believe we have handled your personal data wrongly, you have the right to lodge a complaint with a supervisory authority (GDPR Article 77). The authority competent for us is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon): www.aki.ee/en, info@aki.ee, +372 627 4135. You may also complain to the supervisory authority of the EU or EEA country where you live or work. We would rather you came to us first, so we can put it right.
Camera & Microphone — What Never Leaves Your Devices
The app's core job is streaming video and audio from the device at the crib (Baby Unit) to your device (Parent Unit). Here is exactly what happens with that data:
- Direct, peer-to-peer: on your Wi-Fi or hotspot, the stream travels straight from the Baby device to the Parent device — it does not touch the internet or our servers at all.
- End-to-end encrypted: the stream is protected with WebRTC DTLS-SRTP encryption between your two devices. No one else — including us — can watch or listen.
- Never recorded by us: we never store or listen to your audio or video, and we could not if we wanted to — the stream is encrypted between your two devices and we hold no key to it. There is no cloud recording. The one exception is a picture rather than a recording: a screenshot you attach to a feedback report, where the live video is blurred out by default (see section 3 below).
- Analysis stays on-device: sound-level and motion analysis run entirely on the Baby device. Only derived events (e.g. "sustained loud sound") are sent to the Parent device — never raw audio or video.
Remote monitoring (paid tiers): when you monitor away from home, the encrypted stream is forwarded through our relay servers (signaling relay and TURN media relay). The relay is "blind": it forwards the already-encrypted data byte-for-byte and cannot decrypt it. Nothing is recorded or stored.
Information We Collect
1. Account Information
- Email address and name (provided when you create your account on jaenworld.com)
- If you sign in or create your account with Google: the Google account identifier and, for an account created with Google, the email address and name Google gives us — see “Signing in with Google” below.
- Password, if you set one (stored only as a salted hash — we never see the plain password; an account created with Google has none until you set one)
- Subscription tier and license status (used to enable your plan's features; the app checks these periodically and caches the result for a few days of offline use)
Signing in with Google (only if you choose it)
- Where the data comes from: Google, and only when you press “Continue with Google” (“Sign up with Google” on the sign-up page). You sign in on Google's own page; we never see your Google password.
- What Google sends us: the basic profile that comes with the two permissions we ask Google for, “profile” and “email” — including your Google account identifier, your name, a link to your profile photo, your email address and whether Google has verified it, and, for a Google Workspace account, the domain it belongs to. We refuse the sign-in if Google has not verified the address.
- What we keep: the Google account identifier and your email address; for an account created with Google, also the name, and that Google had verified the address — so the account starts out confirmed. We do not store the profile-photo link, or any token Google issues for the sign-in: the access token is used once, to ask Google for the profile above. The Workspace domain is only compared with your email address, never stored.
- Which accounts it can sign in to: Google can be linked to an existing account, or create a new one, only at an address whose mailbox Google itself runs — a Gmail address (gmail.com or googlemail.com), or a Google Workspace account at its own domain — because only there does Google's word that the address is verified say who holds the mailbox today. At any other address, sign in with your password or a passkey, or sign up with your email address and a password, instead. An existing account is linked only once its address has been confirmed with us. We recognise you by your Google account identifier first, and by your email address only when no account holds that identifier, and one Google account can be linked to one Jaen account only.
- Why, and the legal basis: to create the account you asked for, to sign you in, and to recognise you the next time you use Google — which is also how we refuse a Google sign-in to an account that belongs to someone else. An account created with Google uses that email address and name as its own. The legal basis is Article 6(1)(b) GDPR: it is needed to provide the account you requested. We do not use this data for advertising or profiling, and no decision with legal or similarly significant effects on you is made with it by automated means alone.
- It is optional: you can create your account and sign in with an email address and password instead — sign-up by email is open whenever sign-up with Google is. The Jaen app signs in with an email address and password only, so an account created with Google needs a password before it can use the app: set one with “Set a password” on your account page, or “Forgot Password?” on the sign-in page.
- How long we keep it: as long as your account exists. If your account's email address changes, we remove the link to Google at the same moment, and deleting your account erases the identifier with the rest of your account data (see “Data Retention & Account Deletion”). To have the link removed without either, contact us.
- Google's own role: for the sign-in on its pages Google is a separate, independent controller — Google Ireland Limited for users in the EEA and Switzerland — and Google's Privacy Policy applies to what Google does. You can also end the link from Google's side: on the linked apps page of your Google Account, choose “Stop using Sign in with Google”. Google then stops signing you in to us automatically; that does not delete what we already hold, which is covered above.
2. App Usage Data
- A random per-install app identifier — generated on the device, not a hardware ID, and replaced by a new one if you reinstall. It holds no name or email address, but it is an online identifier, so we treat it as personal data. It goes with the reports below whenever they are sent, which the end of this section describes. Some features you use while signed in send it whatever you choose about usage data, so that they can tell your devices apart: push alerts, showing which of your devices are online, watching from away, and Cloud Sync.
- A short status report when the app starts, when it comes back to the screen and every 15 minutes while it is open: the identifier, your device's name, its operating-system version and the app version, and how long the app has been open. It is sent whether or not you are signed in.
- Crash reports — if the app crashes, the error and the code path that led to it, with the identifier, your device's name and its operating-system version, uploaded the next time you open the app.
- Usage events and device diagnostics, only while you are signed in — which screens are opened and which features are used, how long a session lasts, events such as an alarm going off, a lost connection or a crib device's low battery, error messages the app recorded, and how the app is running (battery level and charging, memory in use, frame rate and smoothness, processor load and thermal state), with the app version, the platform and your device's name. They carry the identifier and are stored with your account, so they are pseudonymous, not anonymous.
- Your device's name, in these reports, is what the app can read of it: its maker and model on Android, and on Windows the name the computer was given when Windows was set up. On other devices, such as an iPhone or iPad, the app reads no name and sends only “Parent device”.
- Update checks — your platform, app version and build number, the update channel, and whether the app was installed from a store or downloaded directly, so we can offer the right update by the right route. No per-install identifier is attached. If you are signed in, the request also carries your account token, so an account-specific update channel can be answered.
- We use no third-party analytics, crash-reporting, or advertising SDKs. On Android, the QR-code scanner built into the app — Google's ML Kit — does report its own use to Google; see “Data Sharing and Third Parties” below.
In versions of the app after 0.9.2 (build 1230), the status reports, usage events, device diagnostics and crash reports are sent only if you say yes. The app's first-run walkthrough ends by asking whether you want to share usage data, with nothing chosen for you. If you started using the app before that question existed, it asks you once after you update, unless you had switched Share usage analytics off, which counts as your no. Until you say yes, none of it is sent. If you close the question without answering, nothing is sent and you are not asked again; you can still turn it on in Settings. The update check is the one exception: the app needs it to offer you the right update, and before you sign in it carries no identifier at all.
Your yes is your consent (GDPR Article 6(1)(a)), which is also what EU law requires before an app reads information like this on your device and sends it (Article 5(3) of the ePrivacy Directive). In those versions we do not rely on a legitimate interest for it. You can withdraw your consent at any time by switching off Share usage analytics in the app's Settings. That takes effect at once: nothing more is sent, not even what was already waiting on your phone. Withdrawing does not make what was sent before unlawful. The app keeps a record of your answer on your phone — yes or no, the version of the question you answered, and when — and what it sends after a yes carries that version's number. If the question changes in a way that matters, you are asked again, and nothing is sent until you answer.
Versions up to 0.9.2 (build 1230) — the app shows its version in Settings, under About — were published before that question existed and send this data without asking. In them, switching Share usage analytics off in Settings stops the status reports, usage events and device diagnostics at once, though the oldest versions have no such switch; crash reports are still sent, so we can fix what broke, and the switch says so. For those versions we rely on our legitimate interests instead — see “How We Use Your Information” below — and you can object to them (see “Your Right to Object”).
3. Feedback Reports (only when you send one)
- Your message, the app version and platform, the name your device uses on the network, and its OS version. A report is stored with your account, and a copy of the message — with your email address, so we can reply — goes to our feedback mailbox.
- A screenshot of the app screen, captured when the report sheet opens. Because a screenshot taken on the monitor screen would contain the live camera view of your child, the video areas are blurred out by default — you see the exact image that will be sent, and can draw on it, turn the blur off, or leave the screenshot out altogether. If the blur cannot be produced, no screenshot is attached at all.
- Technical diagnostics attached to the report
- If the screen shows your care log, the screenshot shows those entries too — the blur covers only the live video. Leave the screenshot out if you would rather not send them.
4. Remote-Sharing Metadata (paid tiers, only if you use remote access)
- Your device's public encryption key and crib-room membership (who may connect to which crib) — public routing material only, never private keys
- The names of your cribs and devices: a crib is named after the device it runs on until you rename it — to “Nursery”, for example — and a parent device is labelled with its own name automatically (see section 2)
- A record of each remote viewing — which account watched which crib, from which device, and when it started and ended — and a log of what happened during it, such as a device connecting (the log is deleted after 90 days)
- When the stream has to be relayed, our relay server sees the IP addresses of both devices and your account's id, which is part of the short-lived password the relay checks
- Invited caregiver contacts (email, name) that you explicitly add
5. Cloud Sync (optional — off unless you turn it on)
Cloud Sync is part of a paid plan and is off by default, for every account. It starts only when you turn it on yourself while signed in. In versions of the app after 0.9.2 (build 1230), every way of turning it on — the question the app asks before anything is backed up, the switch in Settings under Back up & sync, and creating or accepting a co-parent share (sharing cannot work without Cloud Sync) — first shows the same question. It says what is uploaded, that some of it is health information, who keeps it and where, and that we can read it. Nothing is chosen for you, and only your “I agree — back them up” starts it. Your answer is recorded, on your phone and on our servers, with when you gave it, the version of the question and where in the app you answered it, so that it can be shown later. If we change the question in a way that matters, you are asked again, and backing up pauses until you answer. The question has changed since earlier versions of the app, so if you answered it or turned Cloud Sync on in one of them, you are asked again after you update.
Versions up to 0.9.2 (build 1230) were published before that question existed, and keep your answer only on your phone. From 0.9.1 to 0.9.2 (build 1230), an earlier form of the question is asked before anything is backed up, but the switch in Settings, under Back up & sync, starts Cloud Sync at once without it, and creating or accepting a co-parent share turns Cloud Sync on even if you had chosen to keep your records on the phone — both sharing screens say so before you press the button. Some test versions older than 0.9.1 work differently again; if you still have one, please update it.
Once it is on, every baby on that phone is backed up, not only a shared one. Paying for a subscription does not switch it on by itself. It exists so your records reach your own other devices and any co-parent you invite. When it is on, these are uploaded to our servers:
- Your care log — sleeps, feeds, nappies, pumping sessions, medication, growth entries and the other events you record, with their times, anything you typed into a note, and medicine names and doses
- Your baby's profile — name, birth date, due date, gender if you set one, and the avatar photo if you choose one
- With each entry, who logged it — the caregiver name you typed, if you named one — and an id for the phone that wrote it, so two phones merge the same day instead of duplicating it
Camera and microphone streams are never uploaded — this is the recorded log and profile only. Turning Cloud Sync off only pauses it: nothing more is uploaded, and nothing already in your account is erased. If you share a baby, it also stops the shared log reaching the other parent, who keeps what they already have. To erase a baby's records, remove the baby in the app (tap their name at the top of the screen, then Edit, and choose “Remove”), then choose “Delete permanently” in the baby switcher: that erases them from that phone and from your account. A baby you only remove can still be restored, so its backup is kept until you delete it permanently. While Cloud Sync is on, deleting a single entry erases what it said from your account too. What is erased leaves only an empty marker on our servers — which entry or baby it was, and when it was deleted — so that the deletion reaches your other devices; the markers go when your account is deleted. To erase everything from our servers, delete the whole account at jaenworld.com/delete-account, or write to us and we will erase them without deleting your account. See “Data Retention & Account Deletion” below.
Some of the care log is health information: about your baby, medicines and doses, growth measurements and anything you write in the notes; and about you, your pumping sessions. We use it only to back up your records and keep them in step on your devices and with a co-parent you invite — never for advertising or profiling. The legal basis is explained under “How We Use Your Information” below.
A shared baby's log belongs to the parent who started sharing: it stays on our servers, including the entries the other parent logged, until that parent deletes the baby permanently or deletes their account. The other parent cannot delete it permanently. If sharing ends, whatever already reached the other parent's phone stays on that phone.
6. Records We Keep While You Use an Account
- Sign-in records — for each sign-in, however you sign in: the IP address, your browser's or app's user-agent string, the approximate place worked out from the IP address (see “Sign-In Location Check” below), when it was last used and, for some sign-ins, more details of your device where your browser shares them, such as its model and version details. They make up the list of devices signed in to your account. Each time you sign in, we delete the records of your sessions that have expired, and of those signed out more than 30 days before. Records of sessions that ended more than 12 months ago are deleted even if you do not sign in again. Our security checks also keep, for 7 days, a record of the latest sign-in from each kind of device you use, with your email address, your account's role and that sign-in's details: browser and operating system, IP address, place, time and how you signed in.
- Addresses you have signed in from — each IP address with its approximate city and country, when it was first and last used, and how often, so we can email you when you sign in from a new one. We stop adding to it if you switch Login Notifications off.
- The countries and devices your account has signed in from, to notice a sign-in from somewhere new.
- A security log of sign-ins and failed sign-in attempts, password, two-factor and passkey changes, deletion requests, and what administrators do to an account — with the email address, IP address and browser involved, and whether it succeeded. A failed attempt is logged with the email address that was typed, even if no account uses it.
- Risky sign-in attempts — when a sign-in attempt looks risky to our automatic checks, for example many attempts from one address within a few minutes, we record the IP address, the browser, what was requested and why it looked risky.
- Password resets — the IP address and browser a reset was requested from, and the IP address your password was last changed from.
- How often an address is sent reset and confirmation emails — when a password-reset email or a new confirmation email is asked for, we keep a keyed hash of the email address it is for — not the address itself — for about 15 minutes, and send no more than three of each kind to that address in that time, whoever asks.
- Confirmations by email — if your account has no password or authenticator app, some changes are confirmed through a link we email you (see “Security Measures” below). For each request we keep which change was asked for, the browser and IP address that asked, and when; the email and the page the link opens show them to you, so that a request that was not yours stands out. A request goes with your account, or once it has expired and you ask for another.
- Passkeys and two-factor sign-in, if you set them up — each passkey's public key, the name you gave it and when it was last used; your two-factor secret and your backup codes (the codes stored only as hashes).
- Push alerts — your device's push token, and a log of the alerts we pushed: the kind of alert, which crib sent it, when, and how many of your devices it reached.
- Which of your devices are online — while a crib is running a session, or a parent screen is open, the app tells our server every 20 seconds or so, with the device's name and role (crib or parent) and, for a crib, when it started monitoring. That is how your other devices show a crib as online, and how we can tell you when a monitoring crib goes silent.
- Anything optional you add to your profile on this website — for example a username, phone number, postal address, website, short bio or picture.
- Contacts — the people you add, any nickname or private note you give them, people you block, and the invitations you send and receive.
- Downloads from this website — for each installer you download: a pseudonym of your IP address, your browser, the time and, if you are signed in, your account. The pseudonym is worked out from the address with a secret key that only our server holds, so the same address always gives the same pseudonym, which lets us count how many different addresses download from us, but the address itself is not stored. Because we hold that key, we still treat the pseudonym as personal data. Download records made before 23 September 2026 held the address itself; we have deleted those addresses.
- Server logs — our web server logs each request (the IP address, the time, the address requested and your browser), and our application logs record some events with the email address or IP address involved.
7. Forms on This Website
- Beta sign-up — your email address and which form you used. We send one confirmation email.
- Contact form — your name, email address and message, and the company, phone number and subject if you give them. It is emailed to a Gmail mailbox we use for the contact form, so Google receives and stores it (see “Data Sharing and Third Parties”); it is not stored in our database.
- Newsletter and status updates — the email address you sign up with on our blog or on our status page; what we keep with it, how you confirm and how you leave are under “Newsletter and Status Updates” below. No address left on the status page before it used that list is kept.
- “Was this article helpful?” — in the knowledge base: your answer and, if you answer “Not really”, what you write in the box that follows, with a pseudonym of your IP address worked out the same way as for downloads, so that each address counts once for each article. The vote is not linked to your account.
Information We Get From Others
Some personal data reaches us from someone other than the person it is about:
- Google Play, if you buy a subscription in the app: the subscription's status and product, its renewal and expiry dates, and any grace period, refund or cancellation — from Google's answers when we check it, and from the notices Google Play sends us.
- Google, if you sign in with Google: your Google account identifier and, for an account created with Google, your email address and name (see “Signing in with Google” above).
- A location database: the approximate city, country and map coordinates of an IP address come from DB-IP's IP to City Lite, a database we keep on our own server — your address is not sent to DB-IP (see “Sign-In Location Check” below).
- Other users: your email address, if someone invites you — together with their name, and their message if they wrote one; the entries the other parent logs in a baby you share; and the name of another caregiver, such as a grandparent, that a parent types into a care-log entry.
If someone invited you and you are not a user, what we keep depends on the kind of invitation:
- An invitation to join Jaen, from a friend or from our team, is emailed to you with a link to accept it. We keep it — your email address, who invited you, the message in it and whether it was accepted — so that you can accept it. It stays after it has expired, even after the person who sent it deletes their account.
- A contact invitation to an address with no Jaen account is never sent: we do not email you or tell you about it, and it does not reach you even if you join later. We keep it — your email address, who sent it and their message — so that the sender's list of invitations looks the same whether or not an address belongs to a Jaen user, which stops anyone using invitations to find out who uses Jaen. It is deleted when the sender deletes their account.
We have not yet set a time after which unanswered invitations are deleted; write to us and we will delete yours.
What we do NOT collect
- No audio or video recordings — ever. We never receive a recording of your camera or microphone, and we hold no key to the stream between your devices. The only picture of the app that can reach us is a screenshot you send with a feedback report, where the live video is blurred out by default — see section 3 above.
- No device location — the app never requests GPS or a location permission and never reads your device's own position. The only location we hold is the approximate city, country and coordinates worked out from the IP address you sign in from, described under “Sign-In Location Check” below. (Visits to this website separately resolve an approximate city from a shortened IP address; that is described under “Cookies and Tracking” below, and it is not tied to your account.)
- No address book access
- No advertising identifiers, no ads, no cross-app tracking
- Your care log (sleep, feeding, history) stays on your device unless you turn on Cloud Sync — see section 5 above and “Data That Stays On Your Device” below
Sign-In Location Check
Every time you sign in, however you sign in, we look up the IP address you connected from in a location database kept on our own server, which gives an approximate city, country and map coordinates. We use it to notice a sign-in from somewhere unfamiliar and warn you, and to show you where your signed-in devices are. A sign-in on record with neither its place nor its device details is looked up when the list of your signed-in devices shows it, and your account's security pages, and an administrator looking into a security problem, can look an address up again. Visits to this website are looked up the same way, from a shortened address (see “Cookies and Tracking” below).
No IP address leaves our server for this. The database is DB-IP's IP to City Lite, a file we keep on our own server, so neither DB-IP nor anyone else is sent your address. If it has no answer for an address, we record the location as unknown and carry on. The location data is DB-IP's, used under the Creative Commons Attribution 4.0 licence: IP Geolocation by DB-IP.
Emails about sign-ins. When you sign in from an IP address that your list of addresses (section 6) has not seen in the last 30 days, we email you the approximate place, the device, the IP address and the time — unless you have switched Login Notifications off. When a sign-in comes from a country and a device your account has not used before, we email you a security alert with the same details instead, whatever Login Notifications says. The sign-in that creates your account sends neither. If we have no earlier sign-in of yours on record and Login Notifications is on, a sign-in gets the first email rather than the alert. Both emails are sent through the mail service that sends all our email, Zone's (see “Data Sharing and Third Parties”), and through no other.
Data That Stays On Your Device
The app keeps your monitoring history, care log (sleep and feeding), and preferences in a local database on your device, encrypted at rest with AES-256 (SQLCipher). Pairing secrets and sign-in tokens live in your device's secure keychain/keystore. Pairing secrets never leave your devices, and the monitoring history the app keeps is not uploaded — what our servers do learn about monitoring while you use an account is listed in sections 2 and 6 above: usage events such as an alarm going off, when usage data is shared (section 2 says when); which of your devices are online and when a crib started monitoring, and which alerts were pushed. Your care log and baby profile are uploaded only if you turn on Cloud Sync, which is off by default and available on a paid plan — see section 5 above for exactly what that sends. You can export or erase all of it from the app's settings, and the local copy is removed when you uninstall the app.
How We Use Your Information — and Our Legal Basis
The GDPR lets us use personal data only when one of its legal bases applies. Here is each use, grouped by the basis it rests on.
To provide the service you asked for — Article 6(1)(b)
These are needed to perform our contract with you: without them, the account, your plan or the feature you asked for cannot work.
- Creating and running your account: signing you in and keeping you signed in, passkeys and two-factor sign-in, signing in with Google if you choose it, the list of devices signed in to your account, and the emails an account needs, such as confirming your address, resetting a password or confirming a deletion.
- Your plan: checking a subscription you bought in the app with the store that sold it, and turning your plan's features on.
- Watching from away from home: crib rooms and device keys, relaying the encrypted stream, and showing which of your devices are online.
- Push alerts on a plan that includes them, including “Jaen stopped monitoring” when a monitoring crib goes silent.
- Contacts and co-parent sharing: the contacts you add, invitations between users, and co-parent memberships.
Our legitimate interests — Article 6(1)(f)
We rely on these only where our interest, named for each, is not outweighed by your interests, rights and freedoms. You can object to any of them — see “Your Right to Object” below.
- Account security — the sign-in location check, the addresses, countries and devices you have signed in from, new-sign-in emails and security alerts, confirming a sensitive change with your password, an authenticator code or an emailed link, pausing sign-in after repeated wrong passwords, rate limits, and the security log, with its records of risky sign-in attempts. Our interest: keeping accounts, which unlock a live view of a child's room, safe from takeover and abuse, and being able to investigate an incident and show what was done to an account.
- Usage data from versions up to 0.9.2 (build 1230) — the status reports, usage events, device diagnostics and crash reports those versions send without asking (section 2). Our interest: learning which features are used and how the app runs on real devices, and finding and fixing faults that stop the app, and with it the monitor, from working. Where those versions have the Share usage analytics switch, it turns off all of it but the crash reports; newer versions ask for your consent instead.
- Update checks. Our interest: getting fixes to the apps people have installed.
- Feedback reports, and replying to them. Our interest: fixing the problem you reported and answering you.
- Messages you send us, through the contact form or by email. Our interest: answering the people who write to us.
- Invitations to people who are not users yet. Our interest: for an invitation to join Jaen, emailing it so that the person invited can accept it; for a contact invitation to an address with no account, which is never sent, keeping it so that nobody can use invitations to find out who uses Jaen.
- What you record about other people — the name of another caregiver that you type into a care-log entry, the nickname or private note you give a contact, and the people you block. Our interest: letting you keep your records and your contacts the way you need them, and keeping away the people you have blocked.
- Optional details you add to your profile on this website, such as a username, phone number, address, website, bio or picture. Our interest: keeping and showing your profile as you chose to fill it in — your contacts also see your name, username and picture.
- Getting your device ready for push alerts — while push alerts are on and notifications are allowed, the app registers with Google's push service (and on iPhone and iPad with Apple's) each time it starts, signed in or not, and a signed-in account's push token is kept on our servers even on a plan that does not include alerts. Our interest: that an alert can reach you as soon as your plan includes alerts, without setting anything up again. You can switch push alerts off in the app.
- The map of where your sign-ins came from, on your account pages. Its map pictures come from OpenStreetMap through our own server, so your browser loads nothing from OpenStreetMap. Our interest: letting you see at a glance whether a sign-in was yours.
- The QR-code scanner on Android, Google's ML Kit, and what it reports to Google. Our interest: pairing your devices by scanning a code, with a scanner that runs on the phone itself.
- Counting website visits and measuring how fast pages load. Our interest: knowing which pages are read and which are slow, without cookies.
- Download records. Our interest: stopping abuse of downloads and counting the downloads of each release.
- “Was this article helpful?” votes in the knowledge base. Our interest: learning which help articles answer people's questions, with each address counted once.
- Google's STUN servers as a fallback. Our interest: keeping remote viewing working when our own server cannot be reached.
- Server logs and backups. Our interest: keeping the service running and secure, and being able to restore it after a failure.
Your consent — Article 6(1)(a)
- Usage data from the app — status reports, usage events, device diagnostics and crash reports (section 2) — in versions after 0.9.2 (build 1230), only if you say yes. This is also what EU law requires before an app reads this information on your device and sends it (Article 5(3) of the ePrivacy Directive). For those versions we do not rely on a legitimate interest for it; for older ones, see our legitimate interests above.
- Cloud Sync, and sharing a care log with a co-parent (section 5). Nothing is uploaded until you agree. Some of the care log is health information — medicines and doses, growth measurements, notes and pumping sessions — and we use it only for backing up and syncing your records.
- Send the newsletter and status updates to the addresses that asked for them and confirmed — see Newsletter and status updates
- Beta sign-up, if you join the beta list: we keep your email address to send you beta access.
You can withdraw your consent at any time: switch off Share usage analytics in the app's Settings; turn Cloud Sync off in the app, under Settings, Back up & sync; use the unsubscribe link in any newsletter or status-update email, or your mail app's Unsubscribe button, and your address is deleted from the list at once; or write to us about the beta list, and we remove your address. Withdrawing does not make what we did before it unlawful. Turning Cloud Sync off only pauses it: nothing more is uploaded, and what is already on our servers stays there until you delete the baby permanently, delete your account or ask us to erase it — section 5 says how.
A legal obligation — Article 6(1)(c)
- Carrying out a request you make under your GDPR rights, such as erasing your account.
- Giving information to authorities when the law requires us to.
- Keeping the store's record of a subscription you bought in the app after your account is deleted: accounting law requires us to keep it for 7 years after the subscription ends.
We do not sell your data, we show no ads, and we do not use your data for advertising of any kind.
Newsletter and Status Updates
We run two email lists: the newsletter you can join on our blog (new blog posts and Jaen Babymon product news), and status updates you can join on our status page (outages and planned maintenance). Both are separate from your Jaen account — you do not need an account to join, and having one does not put you on either list.
Why, and on what basis: we email you only because you asked us to — your consent, GDPR Article 6(1)(a). We never promise how often we write.
Double opt-in: when you sign up, we send one email with a link to confirm. Nothing else is sent to your address until you open that link and press the button on the page it opens. The link works for 72 hours. If you never confirm, your sign-up is deleted 7 days after you last asked.
What we keep: your email address and, as the record of your consent, when you asked and when you confirmed, the wording you agreed to, the page you signed up on and a pseudonym of your IP address — a keyed hash of it, which is still personal data. We keep no browser details. While you are subscribed we also log which issues were sent to you.
No tracking: our emails carry no tracking pixels and no tracked links. We do not record whether you open an email or click a link in it.
Leaving: every email has a one-click unsubscribe link, and your mail app's own Unsubscribe button works too. Unsubscribing deletes your address from the list at once. You can withdraw your consent at any time; it does not affect what was sent before.
How long: your address is kept while you are subscribed and deleted the moment you unsubscribe. The record of your consent — asked, confirmed, unsubscribed — is kept while you are subscribed and for 3 years after you unsubscribe (or after your last request, if you never confirmed) as proof, with a keyed hash of your address in place of the address, and then deleted. The log of which issues were sent to you is deleted after 180 days.
Who sends it: the emails are sent through Zone Media OÜ, the Estonian company that hosts our email.
What You Have to Give Us
No law requires you to give us any personal data, and monitoring over your own Wi-Fi works without an account.
An account needs your email address and a way to sign in to it, such as a password: we cannot run an account without them. Without an account you cannot watch from away from home, have a subscription, use Cloud Sync or share a baby with a co-parent.
Everything else is up to you: a name (without one, we use the part of your email address before the @), the optional profile details on this website, passkeys and two-factor sign-in, sharing usage data from the app — apart from what versions up to 0.9.2 (build 1230) send either way, as section 2 says — feedback reports, and Cloud Sync.
Automated Decisions
We make no decision about you based solely on automated processing that has legal or similarly significant effects on you (GDPR Article 22). A few automatic security checks do run:
- After five wrong passwords for an account within 15 minutes — on the sign-in page, on this website or in the app, or when the app asks for your password as you subscribe — it stops accepting a password for that account for 15 minutes.
- If too many requests come from one address or account in a short time — a form sent again and again, for example — further requests are refused for a while, usually for a minute to an hour.
- The encryption key a device uses for watching from away can be changed only once a day. If a device was lost or stolen, write to us.
- Every sign-in, however you sign in, is compared with the countries and devices your account has used before. A sign-in from somewhere new is recorded and can lead to an email to you, but it is never blocked for that reason.
If one of these checks gets in your way, write to us.
How Long We Keep Each Kind of Record
Deleted automatically after a set time:
- Usage events and device diagnostics from the app: 90 days.
- Crash reports: 180 days.
- The app's status reports: 12 months after that device was last active.
- Records of visits to this website, and page-speed measurements: 90 days.
- The newsletter and status-update lists: as set out under “Newsletter and Status Updates” above.
- The log of what happened during a remote viewing: 90 days.
- The countries and devices your account has signed in from: a year after each was last used to sign in.
- The latest sign-in from each kind of device you use, kept for the security checks: 7 days.
- A pause after wrong passwords: 15 minutes. Rate-limit counters: about an hour at most; the ones kept under a keyed hash of an email address, about 15 minutes.
- The security log — sign-ins and failed sign-in attempts, account changes and what administrators do to an account: 12 months after each entry was written. Two kinds are kept longer: the entries that outlive an account deletion, and the record that a deletion was carried out, both under “Data Retention & Account Deletion” below; and the record of a request to delete an account, which is not deleted while the request is still pending.
- The addresses your account has signed in from, which decide when a sign-in from a new one is emailed to you: 12 months after each was last used.
- The records of your sign-in sessions: 12 months after each session ended.
- Password-reset links: 12 months after each expired or was used.
- Records of risky sign-in attempts, kept to detect attacks: 12 months after each attempt.
Kept while your account exists:
Your account and profile, passkeys, your push token and alert log, which of your devices are online, remote-viewing records, contacts, downloads tied to your account, feedback reports, Cloud Sync data, and the record of your answers to the Cloud Sync question. Each time you sign in, the records of your sessions that have expired, and of those signed out more than 30 days before, are deleted; a request to confirm a change by email goes once it has expired and you ask for another; and a push token goes when you turn push alerts off or sign out on that device. What happens when you delete your account — and what outlives it — is under “Data Retention & Account Deletion” below.
No set period yet:
Beta sign-ups; invitations to people who are not users; download records not tied to an account; “Was this article helpful?” votes; and messages sent through the contact form and copies of feedback reports sent to our feedback mailbox, which stay in those mailboxes. We have not yet set a time after which these are deleted; until we do, we delete yours when you ask. Our server logs and backups have no set period yet either.
Data Storage and Security
Storage Location
Account data is stored on our servers within the European Union. All traffic between the app and our servers uses TLS encryption; media between your devices uses end-to-end DTLS-SRTP.
Security Measures
- End-to-end encryption for all baby audio/video
- Per-pairing keys — no shared or hardcoded secrets between households
- Passwords stored as salted hashes; optional multi-factor authentication (TOTP)
- Sign-in tokens kept in the platform keychain/keystore, unlockable with Face ID / fingerprint
- Local history encrypted at rest (AES-256)
- Changes that could weaken your account or hand it over — changing your password or email address, two-factor sign-in, adding or removing a passkey, signing devices out, turning off Login Notifications and deleting your account — ask for your password or authenticator code first. An account with neither, such as one created with Google, confirms signing devices out, removing a passkey and turning off Login Notifications through a link we email instead, which works only with the six-digit code shown on the screen that asked, only for that sign-in and that one change, and for 15 minutes; its deletion is confirmed through a link of its own, and for the other changes it sets a password first.
Data Retention & Account Deletion
We retain your account data for as long as your account is active. You can delete your account directly in the app (Settings ▸ Account ▸ Delete account) or on the web, or email us from the address on the account and we schedule it for you the same way. When you delete it yourself, you confirm it with your password or authenticator code; an account with neither, such as one created with Google, confirms it through a link we email to its address. Deletion is scheduled with a 7-day grace period — the account is signed out on every device at once, and a cancellation link is emailed to you in case you change your mind. Alarm notifications and remote viewing through Jaen stop for the account from that moment; monitoring on the same Wi-Fi network is not affected. You can still sign in, but only to cancel the deletion: nothing else works until you do. Your account will be deleted after the 7-day grace period, once an administrator has reviewed it (within a month of your request). You can cancel the deletion with the link in our email until the deletion is done, or by emailing us. For a request you email us, the month runs from when your email reached us, and if it would end before the 7 days are up, we may complete the deletion sooner. When it is deleted, your account data is permanently erased, with these exceptions: the store's record of a subscription you bought in the app, which accounting law requires us to keep (GDPR Article 6(1)(c)), and which is kept without your account attached to it until 7 years after the subscription ends, or 7 years after the refund if it was refunded; a record that the deletion was carried out, which holds a one-way hash of the account's email address rather than the address itself, and the time the deletion was requested (for a request you emailed us, the time we scheduled it), and is deleted after 7 years; security-log entries that name the account — an administrator's action on it, or a sign-in attempt with its address that never reached the account — which are kept with the same one-way hash in place of the address, and deleted 7 years after the first account deletion they outlive, as are, if it was an administrator's account, the entries it wrote about other accounts, without the account attached to them; and a copy of each feedback report you sent us — its message, the app version, your device or browser, and your email address — which stays in our feedback mailbox at Zone, in Estonia, until you ask us to delete it. Our account deletion page lists what is deleted and what is kept.
Your Rights Under GDPR
As an EU-based company, we ensure you have the following rights:
- Right to Access: Request a copy of your personal data
- Right to Rectification: Correct inaccurate or incomplete data
- Right to Erasure: Request deletion of your personal data
- Right to Restriction: Limit how we use your data
- Right to Data Portability: Receive your data in a machine-readable format
- Right to Object: to our use of your data based on legitimate interests — see “Your Right to Object” below
- Right to Withdraw Consent: where we rely on your consent — usage data from the versions of the app that ask for it, Cloud Sync, the newsletter and status updates, and the beta list — at any time, without affecting what we did before; see “How We Use Your Information” above
- Right to Lodge a Complaint (Article 77): Take a complaint to a supervisory authority — for us the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), or the authority of the country where you live — see “Who We Are” above for its contact details
To exercise any of these rights, contact us at info@jaenworld.com
Requests are free. We may ask you to confirm that a request comes from you — for example by writing from your account's email address. Some of it you can do yourself: export your care log in the app's Settings, correct your details on your account page, and delete your whole account. Deleting a baby permanently in the app erases its records from that phone and from your account — section 5 says what is left.
Your Right to Object
You can object at any time to our use of your personal data that rests on our legitimate interests (GDPR Article 21) — everything listed under “Our legitimate interests — Article 6(1)(f)” above.
- Usage data from versions up to 0.9.2 (build 1230): switch off Share usage analytics in the app's Settings, where the version has it. It takes effect at once. For their crash reports, write to us — or update the app, which sends none of this without your yes.
- New-sign-in emails: switch off Login Notifications on your account's Security page on this website. Because these emails are how you would hear that someone else got into your account, switching them off asks you to confirm it first (see “Security Measures” above). The security alert about a sign-in from a new country on a new device still comes, whatever that switch says.
- Anything else — for example the sign-in location check, the security log, counting website visits or download records: write to info@jaenworld.com. We will stop, unless we have compelling legitimate grounds that override your interests, rights and freedoms, or need the data to establish, exercise or defend legal claims.
The newsletter is the only marketing email we send, and only to an address that confirmed it. Use the unsubscribe link in any issue, or your mail app's Unsubscribe button, and it stops at once.
Data Sharing and Third Parties
We do not sell your personal data, and we do not share it with analytics or advertising companies. Your information is shared only with:
- Infrastructure Providers: Zone Media OÜ (Zone.ee), in Tallinn, Estonia, which hosts our servers and our jaenworld.com mailboxes, and delivers the emails we send. Its terms of service make it our processor under the GDPR.
- Push Notification Delivery: push alerts are on by default. While they are on, the app starts Google's Firebase Cloud Messaging each time it opens and, once notifications are allowed, gets a registration token for your device — on iPhone and iPad through Apple's push service — so Google, and on those devices Apple, see your device's IP address even before any alert is sent, whether or not you are signed in. In versions of the app after 0.9.2 (build 1230), the app does not ask for permission to show notifications when it first opens on Android, iPhone or iPad: it asks when you start monitoring on the parent's device, or turn on an alert or a reminder that needs it, and says why first — and on Android the system also asks while you set a device up as the baby's or the parent's. Earlier versions ask as soon as the app opens. When you are signed in, the app gives the token to our server. To deliver an alert, Google (Firebase Cloud Messaging) and, on iPhone and iPad, Apple (Apple Push Notification service) receive your device's push registration token, which kind of alert it was, an event identifier, a timestamp, an identifier for the crib device, and the short notification text — which we compose on our own servers from the alert type, so it never contains anything you typed. They do not receive audio, video, your baby's name, your room labels, or any sound or movement measurement. Google says it acts as a processor for the Firebase services it provides; where each company is, and what covers sending data to it, is under “International Data Transfers”. You can turn push alerts off in the app at any time, which asks our servers to delete your token; signing out deletes it too.
- Connection Set-Up Away From Home: when you watch from outside your home, your devices need to work out how to reach each other. For that the app uses our own STUN and relay servers; if those cannot be reached it falls back to public STUN servers operated by Google (stun.l.google.com). A STUN server answers exactly one question — what does this device's connection look like from the internet — so it receives your device's IP address and nothing else: no account, no name, nothing you have written down, and no audio or video. They are not used at all when both devices are on the same Wi-Fi, where the phones reach each other directly: on your own network both the Baby Unit and the Parent Unit offer local addresses only and contact nobody, which is why monitoring at home works on a router with no internet at all. If a direct route cannot be found from outside, the encrypted stream is relayed through our own TURN server, which cannot decrypt it and does not store it.
- Google (ML Kit), on Android only: the scanner the app uses to read a pairing QR code is Google's ML Kit, built into the app. Google states that ML Kit sends Google information about the device (such as its maker, model and operating-system version), the app's name and version, an identifier for this installation, and performance, event and error information, for diagnostics and usage analytics, encrypted in transit, and that it does not pass this on to third parties. The camera picture and the code you scan are not on Google's list.
- Google Play and Apple: only if you buy a subscription in the app. To check whether a Google Play subscription is still valid we hand Google back the purchase token it issued in the first place, and Google Play tells us when a subscription changes. Google receives no name, email address or other account details from us — only a random code the app attaches to a purchase, so that its messages about it reach the right Jaen account — and nothing about your baby. The app sells no subscription on Apple's platforms, so we check no App Store purchase with Apple.
- Google, if you sign in with Google: you sign in on Google's own page. Our server then exchanges the one-time code Google gives it for an access token, and uses that token once to ask Google for the profile described under “Signing in with Google” above.
- Google (Gmail), for the contact form: messages sent through the contact form on this website are delivered to a Gmail mailbox we use, so Google receives and stores what you wrote in the form — your name, email address and message, and the company, phone number and subject if you gave them. Email you send to our jaenworld.com addresses stays in our mailboxes at Zone.
- People You Choose: a co-parent you share a baby with sees that baby's shared care log and profile (section 5), and when you invite a friend to try Jaen, the email we send them shows the name on your account.
- Legal Requirements: When required by law or to protect our rights
- Business Transfers: In case of merger, acquisition, or sale of assets (you will be notified)
Two things that might look like sharing are not. The approximate place of an IP address comes from a location database on our own server, so no address is sent anywhere for it (see “Sign-In Location Check” above). And the map pictures on your account pages come from OpenStreetMap, fetched and kept by our own server: your browser asks only this website for them, and OpenStreetMap receives nothing that identifies you — not your IP address, not a cookie. The pins on the map come from this website too.
Cookies and Tracking
The jaenworld.com website uses cookies for sign-in only — there is no advertising cookie and no preference cookie. For detailed information, see our Cookie Policy. The Jaen Babymon app itself uses no cookies, no advertising identifiers and no third-party tracking; the usage data it does send is described in section 2 above.
Website audience measurement. We count visits to this website so we can see which pages are read. To do that we record the page path, the referring page, how long the page was open, your browser and operating system, and a shortened form of your IP address (the last part is removed), from which we resolve an approximate country and city.
We do not store anything on your device to do this — no analytics cookie, no identifier in local storage, nothing to consent to. Visits are grouped using a value we calculate on our own server from the shortened IP and browser, mixed with a secret that changes every day, so that identifier cannot be carried from one day to the next. There are no third-party analytics, and this data is never combined with your account.
To be exact about what that does and does not give you: the identifier expires nightly, but the record it sits in still holds the shortened IP, the browser and the operating system for as long as we keep it. Somebody with access to our database could therefore still group those records by hand. We delete the whole record after 90 days, we do not do that grouping, and we would rather say so plainly than claim an anonymity the data does not have.
Page-speed measurements. Each page also reports how quickly it loaded and responded in your browser: the timing figures, the page's path (without anything after a “?”) and your browser's user-agent string. We use them to find slow pages, and delete them after 90 days. The approximate city for a visit is looked up from the shortened IP address in the location database on our own server, so the address is not sent anywhere — see “Sign-In Location Check” above.
Children's Privacy
Jaen Babymon is made for parents and caregivers — accounts may only be created and operated by adults. It is also used to look after a baby, so it does hold information about a child: the profile and care log a parent keeps. When you enter your child's details, you do so as their parent or guardian.
Although the app monitors an infant, the baby's audio and video never reach our servers on the local path and are never stored by us (see "Camera & Microphone" above). Unless you turn on Cloud Sync, we hold no profile of your child, and the care-log entries you keep about your baby stay encrypted on your own device. Cloud Sync is off by default for every account and starts only when you turn it on yourself; while it is on, your baby's profile and care log are stored on our servers and are readable by us — unlike the video stream, they are not end-to-end encrypted. See section 5 above for exactly what that sends. We use them only to back up and sync your records, never for advertising or profiling, and you — or your child, once old enough — can ask us to erase them.
International Data Transfers
Our servers are in the European Union, and that is where your account and Cloud Sync data are stored. Some of the recipients named under “Data Sharing and Third Parties” are based in the United States, so what they receive can be processed outside the EU and EEA:
- Google — push delivery (Firebase Cloud Messaging), checking Google Play purchases, signing in with Google if you choose it, its public STUN servers, on Android the QR-code scanner (ML Kit), and Gmail, which receives the messages sent through the contact form.
- Apple — push delivery on iPhone and iPad (Apple Push Notification service).
Google LLC is certified under the EU-U.S. Data Privacy Framework, and the European Commission has decided that the Framework protects personal data adequately (Implementing Decision (EU) 2023/1795), so that decision covers what we and the app send to Google in the United States. Apple states that the personal data of people in the EEA is controlled by Apple Distribution International Limited in Ireland, and that Apple's transfers of it out of the EEA are governed by the European Commission's Standard Contractual Clauses.
Write to us if you want to know more about any of these transfers.
Changes to This Policy
We update this policy when what we do changes, and the date at the top of this page shows when it last changed. Before a significant change takes effect, we will tell you with a notice on this page and in the app.
If a change needs your consent — for example a new use of your Cloud Sync data — we will ask for it again rather than treat continued use as agreement.
Contact Us
If you have questions about this Privacy Policy or wish to exercise your rights, contact us:
Email: info@jaenworld.com
Company: JaenWorld OÜ (an Estonian private limited company)
Estonian registry code: 17547671
Registered address: E. Vilde tee 89-54, Mustamäe linnaosa, 12911 Tallinn, Harju maakond, Estonia
Data Protection Officer: none appointed — we are not required to have one; privacy requests go to the email above
Supervisory authority: Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), with whom you may lodge a complaint — www.aki.ee/en
Response time: We aim to respond to all privacy requests within one month, as GDPR requires (Article 12(3)).