Feeding Start Feeding Start
Home Support
LanguageEN
RU EN
Download the app
Home Support Download the app

Privacy Policy

Feeding Start

Version 1.0 | 16 September 2026

1. Overview

This Policy explains what personal data is processed when you use the Feeding Start mobile application, why it is needed, who may receive it, and how to exercise your rights.

The data controller is Aleksey Trubnikov (Трубников Алексей), Armenia. Privacy contact: feedingstart@gmail.com. In this Policy, “we” and “us” refer to the controller, and “App” refers to Feeding Start.

The App is intended for adult parents and legal guardians. Child data must be provided by an adult who is authorised to act on the child's behalf.

Acknowledging this Policy does not provide blanket consent to every form of processing. Where applicable law requires separate consent, it must be obtained separately. Installing or using the App does not, by itself, replace that consent.

2. Data We Collect

The data processed depends on the features you use. You provide some information yourself; other information is received from Google or generated when the App operates.

2.1. Account Data

Email address, internal account identifier, information about the sign-in method you chose, interface language, account creation and activity timestamps, and initial setup status. When you sign in with Google, the App receives the information needed to authenticate you and create your profile. The App does not receive your Google account password.

The email address is used for sign-in and is processed by the authentication service; it is not stored separately in the App profile. The App does not ask for your name.

Records of legal document acknowledgements include the document version, language, acknowledgement type and date.

If you turn on identity confirmation when the App is opened, that setting stays on your device and is not sent to us.

2.2. Child Data

The child's name, date of birth, introduced foods, recorded allergies and food reactions. The date of birth is used to determine age and select appropriate content. Allergy entries are used for warnings and to take dietary restrictions into account.

Allergy and reaction information may constitute health data and requires special protection. Child data remains the child's personal data even when an adult enters it. Do not provide information about a child unless you have the necessary authority.

2.3. Feeding, Menu and Usage Data

Food introduction plans and history, daily entries and reactions, introduction statuses, menu dates and contents, and selected meals and recipes. This information supports progress tracking, personalisation and synchronisation between devices. Events relating to feature use may be recorded separately, such as signing in, viewing screens, using feeding features and opening the subscription screen. These events are not a complete copy of your profile or diary.

2.4. Subscriptions and Purchases

Subscription status and plan, subscription dates, trial information, purchase and transaction identifiers, purchase tokens, amounts, currencies, and payment and refund statuses. This information is received from Google Play or generated when a purchase is verified.

We do not receive or store payment card numbers, CVC/CVV codes or other full payment instrument details.

2.5. Technical Data, Analytics and Diagnostics

We use Google Analytics for Firebase to understand App usage and Firebase Crashlytics to diagnose failures. These services may process installation and app instance identifiers, device and operating system information, app version, language, events, viewed screens, error reports and technical context.

After sign-in, an internal user identifier is sent to Analytics and Crashlytics. Subscription status may also be included in diagnostic context. This information can be associated with an account and is not described by us as fully anonymous.

Names, email addresses, the child's exact date of birth and free-form user text are not intended to be included in product analytics events. Analytics events and error reports do not include allergy entries, food reactions or other information about a child's health.

Google services also process necessary network and service information, including IP addresses when handling requests. Advertising identifiers and advertising personalisation signals are disabled in the Android App configuration.

2.6. Support Requests

When you contact us, we receive your sender address, message and information you choose to include, such as your device model, App version or a screenshot. Do not send passwords, PINs, recovery codes, card details or unnecessary information about your child's health.

2.7. Referral Programme

If you use a referral programme available in the App, we process the invitation code, the association between the referring and referred accounts, information about qualifying actions, credits and reward status. This data is used to administer participation and prevent abuse.

3. Purposes and Legal Bases for Processing

We process data to create accounts and authenticate users, provide selected features, save history and menus, personalise content based on age and information entered, verify subscriptions and purchases, administer referral rewards, provide support, protect access and diagnose App operation.

Where the GDPR or UK GDPR applies, the legal basis depends on the processing:

  • Performance of our contract with you: providing your account, App features, subscription and selected referral programme to the extent necessary. This basis does not, by itself, authorise processing a child's special category data.
  • Legitimate interests: protecting the service, preventing fraud, resolving technical problems and protecting rights, unless these interests are overridden by the interests and fundamental rights of the user or child.
  • Legal obligations: maintaining required records and providing information where applicable law requires it.
  • Consent: processing for which consent is required by law. Child health data also requires an applicable condition for processing special category data; where consent is relied upon, it must be explicit and provided by a person with the necessary authority.

Where separate consent is required for analytics, identifiers or health data processing, acceptance of this Policy does not replace it. Consent may be withdrawn using the contact in Section 12. Withdrawal does not affect the lawfulness of processing carried out before it. Whether particular features can continue depends on whether they require the relevant data.

Account fields needed for sign-in and the child's date of birth needed for age-based content are required for the corresponding features. Withholding necessary information may make those features unavailable. App recommendations are not decisions that produce legal or similarly significant effects on you.

3.1. Child Nutrition and Health Information

The essentials are set out below: what you enter, who enters it, why it is needed, where it is stored and how to stop it being processed.

What information: the child's date of birth; foods marked as allergenic; the complementary feeding diary - the introduction plan, daily entries, reactions and the outcome of an introduction; and generated menus.

Who enters it: an adult - a parent or legal guardian of the child, or another adult with the necessary authority. A child is not a user of the App and does not create an account.

Why: selecting and checking menus by age and introduced foods, warnings about foods related to marked allergens, and keeping and displaying the history of complementary feeding.

Where it is stored: on servers operated by Google, which provides our cloud infrastructure. Data centre locations are determined by the service provider and may change together with the services we use; international transfers are described in Section 5. The complementary feeding diary is kept for as long as the account exists: the introduction history is needed throughout your use of the App, and it has no separate clean-up period.

How to stop the processing: delete your account as described in Section 8. When the recovery period ends, the child profile is deleted together with the complementary feeding diary, allergy entries and menus. For any questions about your rights, including withdrawing consent where processing relies on it, contact us using the address in Section 12 (see also Section 7).

4. Subscriptions and Payments

Google Play processes purchases and payments under its own terms. We receive the purchase and subscription information listed in Section 2.4 to verify payment, determine access and account for refunds.

You can manage renewal and cancellation in Google Play. Deleting the App or your Feeding Start account does not, by itself, cancel a subscription or request a refund. Cancel the subscription in Google Play to stop future charges. Cancelling a subscription is not a prerequisite for submitting an account deletion request.

Manage subscriptions: https://play.google.com/store/account/subscriptions

5. Data Sharing and International Processing

The following services are used to provide the App:

  • Google Sign-In and Firebase Authentication: sign-in and authentication management.
  • Cloud Firestore, Cloud Functions and Cloud Storage: data storage, server processing, and delivery of App files and content.
  • Google Analytics for Firebase: usage events and analytics.
  • Firebase Crashlytics: error reporting and diagnostics.
  • Firebase App Check and Google Play Integrity: app authenticity checks and protection against abusive requests.
  • Firebase Remote Config: delivery of App configuration; the service may use installation identifiers.
  • Google Play: purchases, subscriptions, payment verification and refunds.
  • Email services: receipt and handling of messages sent to support.

The controller and authorised service providers may access data to the extent needed for their roles. Information may also be disclosed where required by law or a lawful request from a competent authority, or to protect rights and security within the limits permitted by law. We do not sell personal data or provide child health data to advertisers for personalised advertising.

Processing is not limited to your country of residence or Armenia. Firebase Authentication processes data in the United States; other Google services may use infrastructure in different countries. Hosting some server functions in Europe does not mean all data is processed exclusively there.

International transfers are subject to applicable data protection requirements. Where specific safeguards are required, the applicable mechanism depends on the recipient, country and transfer terms: it may involve an adequacy decision or standard contractual clauses and necessary supplementary measures. You may request information about the recipients and safeguards applicable to your data using the contact in Section 12.

Provider information: https://firebase.google.com/support/privacy and https://policies.google.com/privacy

6. Data Storage and Retention

Retention depends on the data category, purpose, account status and applicable obligations. The account recovery period is not a single deletion deadline for all data held by us and our service providers.

  • Complementary feeding diary, allergy entries and menus: kept for as long as the account exists and deleted together with the child profile when the account deletion recovery period ends (Section 8). They have no separate clean-up period.
  • Account and child profile: used while the account exists. After a deletion request, the standard recovery period is 30 days. The specific deadline is provided when the request is made. Subsequent processing is explained in Section 8.
  • Payment and subscription records: retained to the extent needed to verify transactions, handle refunds and disputes, and meet mandatory record-keeping periods. Retention is determined by the relevant legal obligation or the conclusion of a specific dispute, review or limitation period for a claim. This does not justify indefinite retention of the child's entire history.
  • Document acknowledgements, deletion requests and referral records: retention is determined by the need to evidence an action or reward, address a complaint and meet applicable obligations. Keeping these records does not mean they are fully anonymous.
  • Analytics: individual events and identifiers are processed within the retention period configured in Google Analytics for the relevant data type. The start and renewal of that period depend on service settings. Aggregate reports may have different retention periods. Deleting a Feeding Start account does not mean all analytics events are deleted immediately.
  • Crashlytics: according to Firebase's published terms, crash reports and associated identifiers are retained for 90 days before removal from live and backup systems begins.
  • Support requests: processed to respond to and resolve your enquiry; any subsequent retention depends on associated complaints, obligations or the need to evidence its resolution. The App does not specify an automatic deletion period for the support mailbox.

Removal from providers' backup and technical systems may finish later than removal from the user interface. For example, Firebase states that Authentication data is removed from live and backup systems within 180 days after deletion of the relevant user is initiated, subject to the data categories described by the provider.

Where particular records must be retained to comply with law or protect a specific claim, only the necessary information is retained. On request, we explain the applicable categories, purpose and grounds for continued retention. Further provider retention information: https://firebase.google.com/support/privacy

7. Your Rights

Depending on applicable law, you may request access and a copy of your data, correction, deletion, restriction of processing, object to processing, receive data in a portable format or withdraw consent where processing relies on it.

A parent or legal guardian may make requests concerning a child's data where they have the necessary authority. To protect data, we may request proportionate evidence of identity, account ownership or authority. Do not send identity documents unless specifically requested.

Send requests to the address in Section 12, stating your account email and the nature of your request. Requests are handled within the period required by applicable law. Under the GDPR and UK GDPR, the usual response period is one month; an extension permitted by law requires notice explaining the reasons.

You may complain to the competent data protection authority. In the EEA this includes the authority where you habitually reside, work or consider an infringement to have occurred; in the United Kingdom, the Information Commissioner's Office: https://ico.org.uk/make-a-complaint/

If you live in the United States, your rights regarding consumer health data are described in the Consumer Health Data Privacy Policy: https://feedingstart.com/en/consumer-health-data/

Rights may be subject to legal limitations, for example where specific financial records must be retained. If a request cannot be fulfilled in full, we explain the reason and the available way to challenge the decision.

8. Data and Account Deletion

You can request deletion in the App through “Profile / Security”, on the website or by email:

https://feedingstart.com/en/support/#delete-account

feedingstart@gmail.com

The website requires confirmation of ownership of the Google account linked to the profile. If you cannot sign in that way, contact us by email. Reinstalling the App is not required to send an email request.

After the request is accepted, normal account use is restricted. During the standard 30-day recovery period, you can sign in and explicitly cancel the request. Signing in alone does not cancel deletion. After that period, recovery through this process is unavailable, and a server process completes the handling of the request.

The automated process deletes the authentication service account - and with it the email address associated with it - and deletes the child profile together with the child's name, date of birth, introduced food and allergy lists, complementary feeding diary and menus. It also clears the sign-in method details and last sign-in time from the profile, and certain identifiers and tokens from subscription and payment records.

The following records are not deleted automatically: technical account records, document acknowledgements, referral, payment and administrative records. They may remain associated with technical identifiers. Removing a name or disabling access does not, by itself, make those records irreversibly anonymous.

If you require the remaining personal data to be deleted, state this in a request to feedingstart@gmail.com. The request is considered in accordance with the rights in Section 7 and applicable exceptions. Completion of the automated account deletion process does not replace consideration of a request to erase other personal data.

Deleting the account does not cancel a subscription and is not a refund request. Subscriptions are managed by the app store: to stop further charges, cancel in Google Play (Section 4). You may delete the account without cancelling, but charges will continue.

Retention after a request is permitted only where an applicable ground exists. Financial record-keeping or fraud prevention does not automatically authorise retaining all information about a child's health.

9. Security

We use sign-in through an established authentication provider, server-side access controls and secure connections. Your account data is available only to a session signed in to that account: server-side access rules close it to other users. Our cloud infrastructure provider applies encryption in transit and at rest on its side.

The App can ask you to confirm your identity when it is opened. The confirmation is performed by the device operating system and accepts whatever locks the device itself: biometrics, a pattern, a code or a password. Biometric samples are processed by operating system facilities and are not sent to us as face images or fingerprints. This setting protects access from your device; access to the account itself is governed by your Google account.

We do not claim that data is accessible to the user alone: access on our side is possible for operating the service, providing support and resolving faults, and is granted only to the extent necessary.

No system can guarantee absolute security. Protect your device and your Google account. Report a suspected breach or unauthorised access using the contact in Section 12.

10. Children and Health Information

The App is intended for adults, not for independent use by children. We do not invite children to create their own accounts. If a child has provided information without an authorised adult's involvement, contact us so that deletion can be considered.

This app does not provide medical care and does not diagnose. Recommendations and warnings are for reference only. Make decisions about your child's nutrition together with a pediatrician. If you see signs of a severe reaction, seek medical help immediately.

The App provides informational content about complementary feeding and nutrition. It is not a medical device and is not intended to diagnose, treat, cure or prevent any medical condition. Consult a qualified healthcare professional about symptoms, allergies, diagnosis and treatment.

An entry in the App does not establish a medical diagnosis, and the absence of a warning does not guarantee that a food is safe for a particular child. These limitations do not remove obligations to protect personal data and health information.

11. Changes to This Policy

We may update this Policy when features, data processing or legal requirements change. Each version is identified by its number and date at the start of the document and applies after publication.

The current version is provided in the App and on the website. We notify users of material changes through an available channel, such as the App. If a change requires separate consent, a notice or continued use of the App does not replace obtaining it.

12. Contact

Controller: Aleksey Trubnikov (Трубников Алексей), Armenia.

Email for privacy, rights and deletion requests: feedingstart@gmail.com

Support and online deletion request form: https://feedingstart.com/en/support/#delete-account

For requests concerning a child's data, state that you are acting as a parent or legal guardian and describe your request without unnecessary sensitive information.

Privacy Policy Terms of Use Consumer Health Data Support
Copyright © 2026 Feeding Start feedingstart@gmail.com Information on this website is not a public offer.