ffostr ← Back to Fostr

Your family’s information

Privacy Policy

Effective August 8, 2026

This Privacy Policy explains what information Fostr collects, why it is used, who can access it, and the choices available to parents and caregivers. Fostr handles information about babies, parents, and family routines with care appropriate to its sensitivity.

Our data promise

Fostr does not sell or lease family logs, photos, transcripts, or account information. We do not use them for advertising or share them with data brokers.

1. Who Fostr is for

Fostr is designed for adult parents, legal guardians, and trusted adult caregivers. It is not directed to children, and children may not create accounts. The adult who creates a child profile must have authority to provide and share information about that child.

2. Information we collect

Account and family information

This includes email address, name, relationship to the child, authentication information, preferences, account role, invitation details, and the caregivers connected to a child profile.

Child and parent tracking information

This can include a child’s name, date of birth, sex or gender selection, feeds, pumping, diapers, sleep, weight, growth, notes, milestones, memories, checkup summaries, parent sleep, and wellbeing responses. It also includes timestamps and the account that created an entry.

Photos, videos, and generated media

This includes photos and videos added to memories, Daily Face, timelines, and Portrait Studio; cropped or compressed versions; generated portraits; thumbnails; and associated captions or dates. Photo files can contain metadata when uploaded. Avoid uploading media containing location or other information you do not want processed.

Portrait characteristics

When Portrait Studio is used, Fostr may process and store user-selected or AI-assisted descriptions such as visible eye colour, skin tone, and clearly visible unique marks to improve consistency. These descriptions are not used to identify a child across other services.

Voice Log information

The browser or operating system's speech-recognition service converts your speech to text. Fostr receives the resulting short transcript and does not receive or store the raw microphone audio. The transcript is sent to Google Vertex AI to identify a requested log type and prefill a form for your review. No log is saved until you submit the reviewed form.

AI feature information

When an AI-assisted feature is used, Fostr processes the prompt, relevant child profile details, selected recent logs, transcripts, or reference images needed for that request. Fostr also keeps limited request, rate-limit, status, and error records to secure the feature, prevent duplicate charges or work, and troubleshoot failures.

When you create a 7-Day Recap, Fostr sends Google Vertex AI a bounded view of the latest 7 days: an age range, routine statistics, selected feed, diaper, sleep, and pumping details, and capped text from notes attached to those logs or saved separately. The recap leaves out the child’s name, exact birth date, caregiver identities, document identifiers, weights, photos, and older history.

Technical and security information

Fostr and its infrastructure providers may process IP address, browser or device type, timestamps, authentication events, App Check or abuse-prevention signals, crash information, and server logs. This information is used to secure and operate the service, not for advertising.

3. Why we use information

Fostr uses personal information to:

  • create and secure accounts;
  • store, display, and synchronize family logs and media;
  • enable caregiver invitations and shared profile access;
  • calculate statistics and personalized routine estimates;
  • provide Voice Log, AI-assisted summaries, and Portrait Studio;
  • send account, verification, invitation, security, and service communications;
  • detect misuse, enforce limits, investigate errors, and protect Fostr and its users;
  • complete deletion requests and comply with legal obligations; and
  • understand aggregate service reliability without selling information or building advertising profiles.

4. Caregiver sharing

A child profile owner can invite other caregivers. An accepted caregiver can access information available through that shared child profile and may be able to add or change logs according to Fostr’s current permission model. Their name or account identifier may appear beside activity they create.

Profile owners should invite only trusted adults. Removing access stops future access through that caregiver account but does not erase copies that person previously downloaded, photographed, or recorded outside Fostr.

5. Service providers and disclosures

Fostr shares information only as needed to operate the service, follow user instructions, protect the service, or comply with law. Current providers include:

  • Google Cloud and Firebase for authentication, databases, Cloud Storage, hosting, server functions, security tooling, and backups;
  • Google Vertex AI for AI-assisted summaries, Voice Log transcript interpretation, image analysis, and portrait generation;
  • Browser or operating-system speech recognition when a user chooses Voice Log; and
  • Brevo for transactional account and caregiver invitation emails.

We may also disclose information when required by valid legal process, to respond to an emergency involving risk of serious harm, or as part of a business transaction subject to appropriate confidentiality and notice requirements.

If a payment provider or another material processor is added, this policy will be updated before that provider receives personal information.

6. International processing

Fostr’s providers may process and store information in Canada, the United States, and other locations where they operate. Information may therefore be subject to the laws and lawful access requirements of those jurisdictions. We use contractual, technical, and organizational measures appropriate to the service and the sensitivity of the information.

7. Retention and deletion

Active account information and family content are generally retained until the user deletes an entry, child profile, or account, or until the information is no longer needed to provide the service. Short-lived AI request artifacts and duplicate-prevention records are deleted through scheduled cleanup after their configured expiry.

Deleting a child profile removes its active Firestore records, associated media, invitations, and caregiver references. Deleting an account removes the authentication identity, account profile, owned child profiles and their associated content, invitations, AI request history, caregiver references, and access to profiles shared by others.

Deletion is designed to report an error rather than claim success if a request is incomplete. Limited information may remain temporarily in encrypted backups, security logs, fraud-prevention records, or records that must be retained for legal or operational reasons. These copies are isolated from normal use and removed or overwritten according to the applicable provider and retention cycle.

8. Security

Fostr uses measures intended to protect personal information, including encrypted network connections, provider encryption at rest, Firebase Authentication, App Check, role and profile checks, restrictive database and storage rules, rate limits, bounded server functions, and reauthentication for sensitive account deletion.

No online service can guarantee absolute security. Use a unique password, protect devices that stay signed in, invite only trusted caregivers, and contact us if you suspect unauthorized access.

9. Your choices and privacy rights

Depending on where you live, you may have rights to access, correct, export, or delete personal information; withdraw consent; object to or restrict certain processing; and complain to a privacy regulator.

Fostr provides controls to update profile information, remove caregiver access, delete individual entries, delete child profiles, and delete a full account. If you cannot sign in or need another form of assistance, contact us using the address below. We may need to verify identity and authority over a child profile before completing a request.

Account, security, and essential service messages cannot always be opted out of while an account remains active. Fostr does not send third-party advertising messages.

10. Cookies and local device storage

Fostr may use cookies, browser storage, and similar technologies that are necessary for authentication, security, preferences, and Progressive Web App operation. Fostr does not use third-party advertising cookies or sell browsing activity. If optional analytics or marketing technologies are introduced, this policy and any required consent controls will be updated first.

11. Changes to this policy

We may update this Privacy Policy as Fostr changes. We will update the effective date and provide reasonable notice of material changes through the service or by email when appropriate.

12. Contact

Fostr’s designated Privacy Officer is accountable for our privacy practices. For privacy questions, access or correction requests, complaints, or help deleting information when you cannot sign in, email the Privacy Officer at delete@fostr.com.