NookBack to Nook

Privacy at Nook

Your family information stays your family information.

This policy explains what Nook handles, why it is needed, where it is kept, who may receive it and the choices available to you. Nook is designed for adult parents and carers and may contain personal and sensitive information about children in their care.

Last updated 14 September 2026

01

Who this policy applies to

This Privacy Policy applies to the Nook iPhone app, nook.baby and direct communications with Nook. In this policy, “Nook”, “we”, “us” and “our” mean Ombra Co Pty Ltd, based in Victoria, Australia (ABN 83 689 885 363; ACN 689 885 363). Privacy enquiries and legal notices can be sent through our Contact page or to hello@nook.baby.

Nook is made for adults managing or helping with a child's care. It is not intended for children to create or operate an account. A parent, guardian or authorised adult must decide what information about a child is added and who is invited to see it.

02

Information Nook handles

Depending on how you use Nook, the app may handle:

  • family and carer details, including a family name and sharing permissions;
  • a child's display name and optional birth date;
  • care records such as sleeps, feeds, nappies, play, mood, times, durations and notes;
  • photos, videos, story titles and captions you choose to save;
  • carer contact details and phone numbers supplied for invitations, profile number changes or the browser’s Messages fallback;
  • app preferences, theme choices, sync state and security settings;
  • subscription entitlement and transaction status supplied by Apple, but not your payment-card details;
  • messages, attachments and contact details you choose to send to support; and
  • limited website technical information, such as IP address, browser type, request time and security logs, processed automatically by our hosting provider.

Care records may be sensitive information and may include health information. Nook does not receive your Face ID, Touch ID, Apple ID password, device passcode or full payment-card details.

03

How information is collected

Most information is entered directly by you or another invited carer. Media is added only when you choose a photo, video or camera feature and grant the relevant device permission. Apple supplies the limited purchase, device and CloudKit information needed to provide subscriptions, sync and private family sharing. Website and security logs are created automatically when you visit nook.baby.

If you add information about a child or another person, you must have legal authority or permission to do so and must make sure any other adult concerned understands how the information will be used and shared. Where consent is required for sensitive information, you confirm that you are authorised to provide it. Nook may request a separate, express consent where appropriate.

04

Why Nook uses it

Nook collects and uses only information reasonably necessary to:

  • create, secure and maintain your private family space;
  • record care, calculate totals and show clearly labelled estimates or general guidance;
  • sync information across your Apple devices and authorised carers;
  • save and display private family moments;
  • provide Nook Ping, widgets, notifications and other features you choose;
  • provide support, exports, access management and deletion tools;
  • confirm subscription access through Apple;
  • diagnose faults, protect the service and prevent misuse; and
  • comply with applicable legal obligations.

Nook does not use family care data for third-party advertising, data-broker sales or cross-app tracking. Nook does not make automated decisions that determine a child's health care, safety, eligibility or legal rights.

05

Where information is kept

Family records are stored in the family owner's private Apple iCloud and CloudKit database. A protected offline copy may be kept on each authorised device so Nook can work reliably. Theme, notification preferences, drafts and some planning preferences remain on the device. Phone-addressed invitations also use the separate account-binding service described below.

When you select a photo or video, Nook creates a protected app copy and removes embedded metadata where supported. Apple may process iCloud, CloudKit, notification and App Store information in the countries where its services operate. The public website and separate notification service use OpenAI’s ChatGPT Sites hosting with a Cloudflare Workers runtime. These providers may process website requests, notification-service requests and security information in locations where their services operate. Service locations can change, and it may not always be practicable to identify every country in advance.

06

Who can receive information

Family information is available to the family owner and the trusted carers they invite through Apple's private CloudKit sharing permissions. Removing a participant revokes their future cloud access, although it cannot erase copies they lawfully exported or saved before removal.

Information may also be handled by Apple for iCloud, CloudKit, notifications and App Store purchases; by OpenAI’s ChatGPT Sites and its Cloudflare runtime to host and secure the website and separate notification service; and by professional advisers or authorities when reasonably necessary to obtain advice, comply with law, respond to valid legal process, investigate serious misuse or protect a person from a serious threat. Nook does not disclose family information to advertisers or data brokers.

07

Retention, export and deletion

Family records remain in the family owner's CloudKit database until the owner deletes them or Apple removes them under its service terms. Protected offline copies remain on authorised devices until removed through Nook, the family is left or deleted, or the app's local data is erased. Apple backups and operational recovery copies may take additional time to expire.

Support correspondence and limited security logs are kept only for as long as reasonably needed to resolve the request, maintain security, establish a record of our response or comply with law. Within Nook you can export family data and media, erase offline information from a device, leave a shared family or—if you are the family owner—permanently delete the family's CloudKit records. Permanent family deletion affects every participant.

08

Access, correction and control

You can review and correct most records in Nook and manage who has access to the family space. You may also ask for assistance accessing, correcting, exporting or deleting personal information by contacting us. We may need to verify your identity and authority over the relevant family before acting, and we will explain any lawful reason we cannot complete a request.

You can withdraw a device permission or leave a shared family at any time. Withdrawing a permission may stop the related feature from working. A request by one carer cannot override the family owner's or another person's legal rights.

09

Security and data breaches

Nook uses Apple's private CloudKit permissions, iOS file protection, optional Face ID, Touch ID or device-passcode protection, and privacy shielding when the app leaves the foreground. Access is limited to what is reasonably needed to operate and support the service. No online or device service can promise absolute security.

Protect your Apple ID, device passcode and family invitations, and remove access promptly if a trusted carer should no longer see the family space. We will assess suspected data breaches and notify affected people and the Office of the Australian Information Commissioner where required by the Notifiable Data Breaches scheme.

10

Children's privacy

Nook does not knowingly collect account information directly from children. Adults should add only information reasonably necessary for care and should consider the child's privacy, dignity and best interests before adding or sharing a record, photo or video. Do not use Nook to monitor a child secretly or for an unlawful purpose.

If you believe a child's information has been added without proper authority, contact us with the subject “Child privacy”. We will review the request, verify authority where necessary and take appropriate steps.

11

Website, links and communications

nook.baby does not display third-party advertising. The website host may use strictly necessary security and delivery technologies and process request data to prevent abuse and keep the site available. External links are governed by the destination's own privacy practices.

If you contact Nook, we use your message and contact details to respond, keep an appropriate support or legal record and improve the service. Please do not email passwords, device passcodes, full payment details, private family photos or sensitive care information unless necessary for us to help.

12

Questions, complaints and changes

For a privacy question or complaint, email hello@nook.baby with the subject “Privacy”. We will acknowledge the request and aim to provide a substantive response within 30 days. If you are not satisfied with our response, you may be able to complain to the Office of the Australian Information Commissioner.

We will update this policy when Nook's practices or legal obligations change. The current version will appear here with its last-updated date. If a change materially affects how existing family information is used or shared, we will provide appropriate notice before it takes effect and seek consent where required.

13

Optional family alerts

If you choose to connect family alerts, Nook’s notification service checks your iCloud family access and routes alerts to the intended carer’s device. It stores an encrypted Apple push token, device and account identifiers, family and carer identifiers, registration times and delivery receipts. It also keeps rate-limit records using hashed IP addresses and account identifiers to protect the service from abuse. Hashing and encryption protect these records, but they remain linked for routing and access checks. They are used to provide and protect alerts, not for advertising or tracking.

Current installed versions use Apple App Attest and a one-time Apple identity token to authenticate requests. The app sends a limited, signed projection of freshly read family, carer, share and Ping records for access checks. The service stores the attestation public key, Apple validation receipt, replay-prevention counter, environment and last-used time, linked to the Apple account. Earlier supported versions check the same limited records through CloudKit web authentication. Neither flow keeps the submitted record projection, family photos, card letters, voice recordings or care history in the notification database. Apple authentication credentials are handled in memory for service requests; the earlier web-authentication session is kept in the device-only Keychain. Nook’s service code does not save that session in its database or logs. Notification text does not include the private Ping message or family names.

For a phone-addressed invitation or a profile number change, the app sends the number to Apple to look up the associated sharing participant and to Nook’s service to bind that participant to the intended profile. The service retains a keyed hash of the number, linked to the family and carer, rather than the readable number. This is an Apple-account lookup, not an SMS verification service. The browser’s explicit Messages fallback uses the contact number saved on that device.

14

Notification records and deletion

Notification records are separate from your family’s CloudKit records. A device registration stops being used after 90 days without a refresh. Delivery receipts become eligible for cleanup after seven days, and rate-limit records after two minutes. App Attest challenges expire after two minutes; attestation keys and validation receipts become eligible for cleanup after 180 days without use. Pending invitations expire for acceptance after 14 days. Database cleanup runs during later service requests, so expiry is not a promise of deletion at that time.

In the updated app, confirming “Delete family for everyone” first removes the CloudKit family, then requests removal of that family’s notification registrations, account/profile links, hashed-number reservations and invitations. Confirming “Leave family” removes only that account’s service records for the family. Other families remain unchanged. The app saves progress before contacting Apple and keeps confirmed notification cleanup in protected, device-only storage for retry after a restart or connection failure. Pending cleanup can be checked and retried in Privacy & data.

To support recovery after CloudKit access ends, the service keeps a deletion-only receipt identifier linked to the family, account and profile, its scope and preparation time. The matching protected device credential cannot read data or send Pings. The service removes the receipt when used; a renewed invitation or changed account/profile binding retires an older participant receipt. Erasing this device’s offline data discards unused cached credentials without sending a family-deletion request, while already confirmed cleanup remains queued.

Later authenticated owner checks can also clean up a departed carer’s service records. This requires repeated complete membership checks at least five minutes apart, protects current carers and renewed invitations, and keeps temporary account-linked protection times. Five minutes is not a deletion deadline. Rejoining after cleanup requires a new invitation. An owner can cancel an unaccepted invitation; expired reservations are not automatically deleted. Deleting the app alone does not delete the CloudKit family or all service records. Delivery/security records retain their separate cleanup periods, and provider logs and backups are separate. Contact support if a removal cannot finish.