SafeSleep Privacy Policy

Effective date: May 25, 2026

Overview

SafeSleep is built to keep things simple, and to keep you in control of your data. By default, the app works entirely on your device and collects nothing. Signing in to a cradleOS account is optional; it is the only feature that transmits data off your device, and it exists so a childcare center can sync records across multiple devices and view them in the cradleOS web app. This policy explains both modes.

Using SafeSleep Without an Account (Default)

If you do not sign in, SafeSleep behaves as it always has: all data you create — student names, dates of birth, sleep check logs, LIC 9227 records, and group configurations — is stored locally on your device using iOS on-device storage. Nothing is sent to us or to any third party, and the app makes no network requests for your data. You can use SafeSleep this way indefinitely, for free.

Using SafeSleep With a cradleOS Account (Optional)

If you choose to create or sign in to a cradleOS account, SafeSleep synchronizes your records with cradleOS so they are available across your devices and in the cradleOS web dashboard. Your device remains the working copy; synchronization happens in the background. When you are signed in, the following data is transmitted to and stored on cradleOS servers:

  • Account information — your email address and the organization (facility) name you provide at signup. Authentication is handled by our identity provider (Supabase); we never see or store your password in plain text.
  • Children's information — student names, dates of birth, and the sleep-check records associated with them (sleep position, breathing, distress observations, timestamps, and notes).
  • LIC 9227 records — sleep-position waiver events, including parent or guardian names and the parent/guardian signature image captured in the app.

This data is stored on cradleOS's backend infrastructure (a Rails API backed by Supabase Postgres and Supabase Storage) and is scoped to your facility. It is used solely to provide the sync and reporting features of cradleOS; it is not sold, rented, or used for advertising.

Data We Never Collect

Whether or not you sign in, SafeSleep does not collect usage analytics or telemetry, location data, advertising identifiers, or crash reports tied to your identity. The app contains no third-party ad networks or analytics SDKs.

Children's Privacy

SafeSleep is a tool for childcare providers to document safe sleep checks for children in their care; it is not directed to or used by children. Information about children is entered by the provider. In the default on-device mode, that information never leaves the provider's device. If the provider signs in to cradleOS, that information is transmitted to and stored on cradleOS servers as described above, for the purpose of record-keeping and multi-device access by the provider's facility. We handle this information consistent with the Children's Online Privacy Protection Act (COPPA): we do not knowingly collect personal information directly from children, and children's records are accessible only to the authorized facility that entered them.

Parent and Guardian Signatures

LIC 9227 records may include a signature from a child's parent or guardian. In on-device mode these signatures stay on the device. If you are signed in to cradleOS, signature images are uploaded to private cradleOS storage and are accessible only to your authorized facility. They are retained for as long as the associated record exists and are deleted when the record is deleted.

Data Retention and Deletion

On-device data: you can delete individual records in the app, or remove all local data by deleting the app from your device. Synced data: deleting a record in SafeSleep while signed in removes it from cradleOS. To delete your entire account and all associated server-side data, contact us at the address below; we will delete it within 30 days.

Sub-processors

When you use a cradleOS account, we rely on Supabase (authentication, database, and file storage) as a data processor. Supabase processes this data on our behalf under its own security and privacy commitments.

Changes to This Policy

If we update this privacy policy, we will post the revised version here with a new effective date. If a future version of SafeSleep changes what data is collected or transmitted, this policy will be updated before that change is released.

Contact

If you have questions about this privacy policy, or to request deletion of your account data, contact us at [email protected].