Privacy Policy

Last updated: September 12, 2026

Introduction

This Privacy Policy describes how Novi Homines Software Oy ("we", "us", or "our") handles information when you use the Vaava mobile application.

By using Vaava, you agree to this Privacy Policy. We do not sell your data. Our business model is built on providing value through our app, not through data monetization.

Local Data

Vaava can be used without creating a user account. We do not require an email address or password for normal app use. Vaava runs locally on your devices, and your baby tracking data stays on-device by default instead of being uploaded to our servers in basic use.

What stays on your device in basic use:

Local Wi-Fi data sharing:

When you use local Wi-Fi data sharing, data is shared directly between your devices over your local network via peer-to-peer connections. No baby data passes through our servers. This is separate from Vaava Plus Family Data Sharing described below.

Privacy Promise: By default, your baby event history stays on your devices. If you enable Vaava Plus Family Data Sharing, syncable content is encrypted on your device before upload. The other limited exceptions described below are cloud AI features you explicitly enable, transient dictation or OCR processing, Vaava Plus purchase handling, and optional crash diagnostics.

Vaava Plus Family Data Sharing (optional, requires Vaava Plus)

Vaava Plus Family Data Sharing is optional. When enabled, it uploads syncable Vaava family data from your device to Vaava servers after the app encrypts it. Only authorized household devices holding the household encryption keys can decrypt the protected content.

Vaava Plus Family Data Sharing does not require an email address or password. The app creates a pseudonymous Vaava identity, household, and device records so the service can authorize household members and deliver encrypted data to the right devices. Your 24-word recovery phrase and device private keys never leave your devices. The encrypted recovery package can be used to restore your encrypted history on a new device.

Data transferred and stored encrypted:

Data transferred and stored as service metadata, not end-to-end encrypted:

This service metadata can show that a record or media object exists, its broad category, approximate edit activity, and size. It does not reveal the event type details, descriptions, notes, measurements, captions, photo contents, or actual baby event start and end times.

Vaava does not receive the plaintext payload, record keys, household keys, device private keys, or your 24-word recovery phrase for Vaava Plus Family Data Sharing. Encrypted records and media may remain available to the household for synchronization until they are deleted according to the app's sync controls. Deleted encrypted media is placed in a seven-day recovery grace period before its stored bytes are purged.

Household access

Authorized household devices may decrypt the shared data. Removing a household member and rotating household keys prevents that member from decrypting new changes after the rotation, but cannot erase copies or keys that were already delivered to a device.

Vaava Plus remote baby monitor (optional, requires Vaava Plus)

The baby monitor lets one device act as the baby unit and another household device act as the parent unit. In free local Wi-Fi mode, live audio and optional live video travel directly between the devices and do not pass through Vaava's backend or an external relay service. When the devices are on different networks, such as one on cellular data, Vaava Plus extends the monitor over the internet with encrypted live audio and optional live video.

A remote session is started from a household device, and only devices in the same household can join one. Live audio and optional live video are encrypted end-to-end between the two devices and transmitted through a third-party WebRTC relay service. The relay provider carries only encrypted media and cannot decrypt, listen to, watch, or record the audio or video content. Vaava does not hold keys that could decrypt it. Neither audio nor video is recorded or stored for later playback.

Connection relay

Remote baby-monitor sessions use a WebRTC relay (TURN) rather than establishing a direct connection between the devices. The relay sees the IP addresses of both devices, the timing and volume of traffic, and the duration of the session, but it only handles encrypted media it cannot decrypt.

Data transferred as service metadata, not end-to-end encrypted:

This metadata can show that a monitor session took place, when, and between which devices. It does not reveal any audio or video content.

Vaava AI chat and summaries (optional)

Vaava AI is optional. It powers the chat and the automatic daily, weekly, and monthly digest summaries. Before the first cloud AI request, the app explains this processing and asks for your permission. If you do not agree, no content is sent to a cloud AI provider and the summaries stay in their standard, non-AI form. You can also turn AI digest summaries off at any time in Settings, independently of whether the chat entry point is shown.

Data sent when you use cloud AI:

This data is encrypted in transit and sent through Vaava's backend to a third-party AI provider, currently OpenAI or Google Gemini, to generate the response or the summary. Vaava does not use chat or summary content to train AI models.

Storage and retention:

Your chat history, generated summaries, and local attachment copies remain on your device until you delete them in the app or remove the app's data. Vaava does not retain your raw chat messages, baby context, tool results, or attachments as server-side conversation history after processing. For credit metering, abuse prevention, and reliable retries, Vaava may retain pseudonymous user and household identifiers, a request fingerprint, technical usage and status records, timestamps, and the final assistant response. You may request deletion of cloud AI records associated with your Vaava identity by contacting us.

OpenAI may retain API inputs and outputs for up to 30 days for abuse monitoring, unless a longer period is required by law. Vaava sends OpenAI Responses API requests with application-state storage disabled; OpenAI's abuse-monitoring retention still applies. Google Gemini may retain prompts, contextual information, and outputs for 55 days for abuse monitoring. Google states that paid Gemini API prompts and responses are not used to improve its products. Images and files may also be scanned for child-safety purposes.

Apple Foundation Models and Private Cloud Compute

The Vaava backend and third-party AI processing described above applies when you choose Vaava Cloud AI. On eligible devices running iOS 27 or later, you can instead choose Apple Foundation Models for Vaava AI. When Private Cloud Compute handles a request, your message, relevant conversation context, attached photos, and baby profile or records needed to answer go directly from your device to Apple, without passing through Vaava's servers.

Apple uses request content only to fulfill the request. Private Cloud Compute does not retain it or make it available to Apple staff. If Private Cloud Compute is unavailable, Vaava uses Apple's on-device model instead; information processed on device does not leave your device. Private Cloud Compute requires internet access and has a per-user daily request limit. You can change your AI provider in Vaava's settings.

Voice dictation and OCR

When you use voice dictation, a short audio snippet is sent to the Vaava service server, which forwards it to an AI service provider, currently Google or OpenAI, for transcription and structuring. The audio is not stored after processing.

When you scan growth measurements, the photo is sent to the Vaava service server, which forwards it to an AI service provider (including Google Gemini) for OCR. The image is not stored after processing.

These payloads are used only to return structured results to your device. Vaava does not use them to train any model or to create encrypted Vaava Plus Family Data Sharing records on the server. Upstream provider terms (AI service provider APIs) apply to transit handling.

Backend infrastructure is hosted in the EU.

Vaava Plus purchase handling

Vaava Plus is purchased through the Apple App Store or Google Play. Vaava uses RevenueCat on the device for entitlement checks and to support restoring a purchase on the same platform.

For that purpose, RevenueCat may receive purchase-related information from the store platform together with an app-specific identifier provided by Vaava so the app can determine whether Vaava Plus is unlocked on that device or restored on another device on the same platform.

In the current setup, Vaava does not send your email address, password, or baby event content to RevenueCat.

Optional Crash Reporting

Vaava includes an optional crash reporting feature powered by Firebase Crashlytics to help us diagnose technical failures and improve reliability.

What may be collected when enabled:

What Vaava does not attach:

Crash diagnostics are used only for app stability and debugging, not for advertising or marketing.

Third-Party Services

Vaava uses the following third-party services:

These services have their own privacy policies. We only share the minimum necessary data with each service to provide the stated functionality.

Data Security

We implement industry-standard security measures:

Your Rights

You can:

Account and Family Sync data deletion

You can request deletion of your Vaava Plus Family Sync data without reinstalling the app. Email hello@novihomines.com with the subject Delete my Vaava data.

Include your Vaava user ID if you have it. It helps us locate the correct records, but it is not a password. Do not send your 24-word recovery phrase, private keys, or family content by email.

Local data on your device and copies already downloaded to other family devices are not deleted from those devices by these actions. We may retain a limited amount of security or audit metadata where necessary to protect the service or comply with legal obligations. Any such retention is limited to the stated purpose and period.

Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any significant changes through the app. Continued use of Vaava after changes constitutes acceptance of the updated policy.

Contact Us

If you have questions about this Privacy Policy or our data practices, please contact us:

Email: hello@novihomines.com
Company: Novi Homines Software Oy

← Back to home