For the naido Android app and this site. Last updated: 6 September 2026
This URL stays unchanged because it is in the Play Store listing. The German version is the authoritative text; you can find it at naido.app/privacy/.
Daniel Pommranz, Untere Haldestraße 7, 72810 Gomaringen, Germany. “Velmun” is a brand name, not a company; the provider is Daniel Pommranz as an individual. Full details in the imprint at velmun.com. Contact: [email protected]. No data protection officer has been appointed; the conditions of § 38 BDSG (German Federal Data Protection Act) are not met.
Every entry — sleep, feeding, nappies, child profiles, imports and forecasts — is stored by naido locally on your phone. There is no user account, no registration, no e-mail address and no server holding this data. We have no access to it.
The forecast is computed on the device. It is a statistical estimate from the times you have recently recorded for your child — not profiling within the meaning of Art. 22 GDPR, no automated decision with legal effect, and it draws on no other users’ data. Nothing is transmitted to us or to third parties.
You can export everything as CSV or JSON at any time and delete the app together with its data; that removes the database from the device.
Android backup (Auto-Backup): if automatic device backup for apps is switched on in your Android settings, Android also copies naido’s database and the app’s own preferences — encrypted in transit and in your Google account, and on Android 9 and later additionally with your device passcode — into your Google Drive backup. That includes your sync code, your Premium entitlement token and an internally used donor identifier. This copy sits with Google, not with us; we do not see or receive it, and Google processes it as an independent controller (Google’s privacy policy). You can turn off backup for naido specifically in Android’s system settings under Backup, per app.
Only if you switch sync on.
On your home Wi-Fi the paired devices find each other directly on the network and exchange data encrypted. Nothing leaves your network and we process nothing.
Away from home sync runs through the mailbox: end-to-end encrypted packages of at most 2 MB, held temporarily on a Cloudflare service — exclusively in EU data centres. Only your paired devices hold the key; we cannot read the content.
What is processed:
— the encrypted envelope (at most 2 MB)
— the mailbox address: a SHA-256 hash computed from your sync code
— a SHA-256 hash of your write token (not the token itself), to check write permission
— version number, time of the last drop, expiry date, active status
We log no IP addresses. Cloudflare, as the operator of the infrastructure, sees the IP address of connecting devices, as with any request on the internet. We don’t know the exact scope and retention period of Cloudflare’s own connection logs; we will add that here once we have a reliable figure from Cloudflare.
Legal basis: Art. 6(1)(b) GDPR — performance of the sync-service contract you enter into by switching sync on. For operational security and abuse prevention of the relay, additionally Art. 6(1)(f) GDPR.
Deletion: a mailbox, contents included, deletes itself automatically if no new envelope has been dropped for 30 days. You can empty it yourself at any time in the sync settings.
Recipient: Cloudflare as processor under Art. 28 GDPR; data held exclusively in EU data centres.
The sync code carries the security. Exchanged by QR code between your devices, it is random and strong. If you choose it yourself, it is only as strong as what you typed. For the content of your envelopes we derive the key using PBKDF2-HMAC-SHA256 with 150,000 iterations from the code. The mailbox address and your write token, however, are formed as a plain SHA-256 hash of the code, without additional stretching — a short or guessable self-chosen code is easier to work backwards from at this level than the actual content, which stays protected by the 150,000 iterations. Use the randomly generated, QR-code sync code wherever possible. If you lose every device and the code, the mailbox stays shut; we cannot open it and cannot restore the data.
Partner sync costs EUR 39.99 per year or EUR 5.99 per month. In the current version, unlocking it does not yet run through Google Play’s purchase flow: you enter a code, the app exchanges it with our relay for a digitally signed entitlement token, which each of your devices verifies itself. The token contains only a mailbox identifier, an expiry date and the plan — no name, account or payment data. It sits locally on your device and travels along when you pair or sync devices. A purchase flow through Google Play (Play Billing) is planned for a later version; once it is introduced, we will update this section — payment data will then run exclusively through Google, without us seeing it (Google’s privacy policy).
Legal basis: Art. 6(1)(b) GDPR (performance of the contract for the add-on feature).
naido contains a feature for a voluntary data donation to improve the forecast. It is fully disabled in the current feature set: there is no switch for it in the app, no reminder and no transmission. Before we enable it, we will obtain our own explicit consent and describe here precisely which data is transmitted, in what form, how it is protected and how long we keep it.
naido.app is a static site with no cookies, no analytics, no third-party embeds and no forms. Fonts are served locally. There is nothing here we would need your consent for, and therefore no consent banner.
The host, Cloudflare (Cloudflare Pages), processes technically necessary connection data when you open a page: IP address, date and time, requested resource, status code, volume transferred, user agent, referrer if any. We don’t know the exact scope and retention period of these logs at the host; we will add that here once we have a reliable figure. We ourselves log nothing.
Legal basis: Art. 6(1)(f) GDPR (secure and error-free operation of the site); § 25(2) no. 2 TDDDG for technically necessary access to your device.
You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection to processing based on legitimate interests (Art. 21). You can withdraw a given consent at any time (Art. 7(3)). Contact [email protected].
Because your entries live only on your device, you exercise access and erasure yourself: export in the settings, deletion by removing the app. You can empty your mailbox in the sync settings.
For the mailbox we process no data that could identify you. If we cannot link a request to a specific processing operation, Art. 11(2) GDPR means we are not obliged to obtain additional information; you may, however, give us the mailbox address, which makes a link possible.
Complaints: Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg, Lautenschlagerstraße 20, 70173 Stuttgart, Germany, www.baden-wuerttemberg.datenschutz.de — or the supervisory authority where you live.
naido processes information about an infant or toddler: sleep and wake times, feedings, nappies, a first name or initial, and a date of birth or age. In law this is data about another, particularly vulnerable person; recital 38 GDPR stresses the special protection children’s data deserves. Accordingly:
— This data does not leave your device on its own. There is no server holding it and no analysis by us; the exception is the Android device backup described in section 2, if you have switched it on.
— If you use sync, it is end-to-end encrypted inside the envelope. We see only the metadata listed in section 3.
— For the data donation (section 5), you decide as the holder of parental responsibility, once it becomes available. It ships switched off.
— Handing your phone to someone else, or pairing another device, also hands over access to this data. The sync code is the access — share it only with people who should see the data.
— naido is aimed at parents and carers, not at children, contains no advertising and no tracking.
Sleep data can support inferences about a child’s health. We therefore treat it with particular care, even though it only ever reaches our systems encrypted.
Your entries live locally on your device. Sync between devices is end-to-end encrypted: for the content we use AES-256-GCM with a key we derive from your sync code as described in section 3. No one can promise absolute security; we apply measures appropriate to the state of the art (Art. 32 GDPR).
We update this policy when the processing described here changes; the version published here applies. Where a change concerns consent, we ask again. Last updated: 6 September 2026.