Legal
Withya Privacy Policy
Last updated: September 13, 2026 · Version 1.0
1. Scope and responsible organization
STH Technologies, LLC, 9206 Sunshine Pl, Downey, CA 90240, United States, operates Withya and is responsible for the processing described in this policy. Contact [email protected] for support or privacy requests. The Indian privacy section below provides our grievance contact and its appointment status.
This policy covers the Withya app, website, account-deletion service, support and community. It does not cover another product solely because it shares an operator or provider organization. Our separate Consumer Health Data Privacy Policy explains health-related collection, use, sharing and rights. The Terms and Conditions govern use of the Service. Publishing this policy or accepting the Terms does not replace a specific permission required for sensitive information or another consent-based use.
2. Information, sources and purposes
| Information category | What it can include and where it comes from | Why it is used |
|---|---|---|
| Adult account and authentication | Name, email, account identifiers, credential and verification information supplied by you or handled by our sign-in service; account status | Register, verify, authenticate, recover and secure your account; communicate about the service |
| Child profile | Name, birth date, optional gender, saved city/state/country, optional gestational age, growth-reference sex, provider contacts and profile notes supplied by an authorized adult | Organize the selected child’s records; calculate age and relevant displays; tailor requested guidance |
| Family roles and invitations | Inviter, recipient email, selected profiles, role, acceptance and access changes | Establish, audit and revoke shared access |
| Care and preparations | Feeding, nursing, pumping, sleep, diapers, food introduction, temperature, medicines, symptoms, measurements, appointments, plans, checklists and outcomes entered by linked adults | Store, synchronize and display family-reported records, reminders and summaries |
| Journal and media | Captions, observations, milestone dates, selected photos/videos, attachment metadata and export requests | Preserve, present, process and export memories at your direction |
| Private assistant | Questions, responses, conversation history, cited sources, relevant authorized child context, context categories, usage counts and operational measurements | Produce the answer requested, maintain your private history, enforce limits and investigate failures |
| Community | Chosen display identity, broad area/stage selections, posts, replies, connections, messages, reports, blocks and moderation context | Publish to the disclosed audience, find opted-in adults, exchange messages and address abuse |
| Purchases | Store and customer identifiers, product, transaction lineage, payment status, renewal/expiry/refund and coverage records supplied by stores and verification providers | Verify purchases, restore access, reconcile billing, prevent reuse and provide support |
| Devices and requested permissions | App-installation identifiers, notification tokens and delivery state; location when permission is used; selected camera/library content | Deliver notifications, suggest home location and add chosen media |
| App activity and diagnostics | Screen/control interactions, form focus/edit state/validation, navigation, permission/media outcomes, API outcomes, session timing, account/child references and installation/session/event identifiers | Understand journeys, assess performance, improve features and investigate faults |
| Network and technical metadata | Upload-observed IP address, device model where available, platform/OS/app/build, locale, time zone, screen dimensions, font scale, network type and request status | Operate and secure the service, associate diagnostic events and understand technical failures |
| Support and legal records | Messages you send, troubleshooting details, verified rights requests and limited dispute/compliance records | Respond, verify authority, remedy problems, meet duties and defend legal claims |
Authentication providers handle passwords and verification challenges. Withya does not intentionally copy passwords or verification codes into journey analytics. Stores process payment credentials; ordinary Withya purchase verification does not require your full card number or bank password. Do not send those details to support.
Shared records may reveal information about adults as well as children, including nursing, pumping, health conditions, caregiver identity or family relationships. Get any required authority before supplying another person’s information. Withya does not currently provide a separate in-app step for another adult to give consent. Do not submit that adult’s health information unless legally required consent has been established; your assertion alone does not replace consent that Withya must obtain from the person concerned. We may restrict such entries or their use where authority is missing or the person validly objects.
3. Automatic collection and location
Journey instrumentation records activity that the app can observe. It does not include typed field values, private notes, care-entry text, conversation text, photos, videos, passwords, verification codes or screen recordings in its event payloads. However, screen names, actions, identifiers and timing can still reveal or support inferences about health-related activity. We do not treat those events as anonymous merely because text is excluded or identifiers are random or hashed.
The app can collect installation-bound events before sign-in and associate later activity with an authenticated account and selected child. The IP observed at upload reflects that network connection; it does not establish the device’s location at the time of each offline action. Events can be lost, delayed or duplicated. They are not conclusive evidence that a person understood advice or performed care.
If you allow foreground location, the device obtains coordinates and uses its location/geocoding service to suggest city, state and country. The profile saves the selected place. This feature does not continuously track background location. You may deny permission and enter location manually. The device/platform provider processes information under its own rules; a broad location saved by Withya does not mean the device never processed precise coordinates.
We do not use advertising IDs, device fingerprinting, facial recognition or contact-list uploads for the described features. Our public website does not use advertising pixels or website analytics tags. Hosting and network providers still receive connection information when you request a page. We will provide appropriate notice and obtain required prior consent before introducing additional tracking.
4. Cookies, local storage and your device choices
Cookies are browser-stored values. Session storage, protected mobile storage, local databases, installation identifiers and server logs are different technologies that can also involve personal information. The mobile app can collect activity without browser cookies.
| Technology | Purpose and handling |
|---|---|
| Website connection logs | Hosting and network services receive ordinary request and connection information for delivery, operation and security. |
| Account-deletion browser session storage | Holds sign-in state and temporary recovery or receipt information needed for the requested flow; handled through session lifecycle and explicit cleanup. |
| Hosted sign-in state | The authentication provider may use necessary session and security storage; clearing it may require signing in again. |
| Protected app storage and local database | Holds authentication/recovery information, settings, pending care/journal changes and retry state. Clearing storage can lose unsynchronized changes. |
| Installation and notification identifiers | Associate an installation and notification delivery with the correct account. Some Firebase installation identifiers can exist before notification permission is enabled. |
| Usage-event queue | Holds a bounded queue of app events for best-effort upload. Server retention is described below. |
| Rating-prompt counters | Records activity counts and request dates to limit prompts. We do not receive the rating selected in the native store dialog. |
| Temporary media and export files | Prepares requested uploads and downloads and supports display. Cleanup can be delayed by processing failures. Your independently saved originals are separate. |
You can manage browser storage, app permissions, location and notifications through your device settings. Denying location does not hide the IP address used to connect to a service. Disabling notifications does not disable usage analytics. Uninstalling does not cancel a subscription or itself request deletion of server records.
Contact our privacy email to exercise a right to withdraw consent or object to a use. There is currently no general in-app analytics switch. The current app does not present a separate consent step for these usage events. This policy does not supply missing consent: where law requires prior permission, collection without that permission is not authorized by accepting the Terms or reading this notice. Consent-based processing must stop after valid withdrawal. A browser “Do Not Track” setting is not a general in-app analytics control. Because we do not sell personal information or share it for cross-context behavioral advertising, an opt-out preference signal does not change those practices. If we introduce processing subject to such a signal, we will honor it as required.
5. Requested features and other uses
We process information to perform the features you choose, keep data associated with the correct family, synchronize records, prepare exports, deliver requested notifications and verify paid access. We also use appropriately limited information for security, fraud prevention, troubleshooting, service improvement, rights requests and legal obligations.
Where a law requires consent for sensitive data, optional analytics, disclosure or another purpose, contractual acceptance alone is insufficient. Processing based on consent must stop after valid withdrawal except for a separately permitted purpose. If essential information is unavailable, the affected feature may not work; that does not remove unrelated account-management or legal rights.
We do not sell personal information or share it for cross-context behavioral advertising, and we do not run targeted advertising using family or health information. Private records are not used for employment, insurance, credit or other decisions producing legal or similarly significant effects. We do not authorize use of private family data to train general-purpose answer models. These are limits on Withya’s processing and contracting, not a guarantee about every independent website you choose to visit.
6. Who can receive information
Linked adults. Each adult linked to a child may view, change, delete and export that profile’s shared records and invite more adults within the limit. The Primary alone manages core profile settings, member removal, profile deletion and billing. Another linked adult cannot access your private assistant conversations merely through that role. Exported or separately saved copies cannot be recalled by removing access.
Community users. Questions and replies are available to eligible community members and moderators. Chosen discovery details are shown through discovery when enabled. Connected participants receive messages addressed to them. Moderators may receive reports and captured context, including reported messages. Community privacy is not guaranteed anonymity or confidentiality against recipients taking copies. Private family content is not automatically published.
Operational providers. We use Amazon Web Services for application hosting, authentication, database, private storage, service email and managed private-answer processing. Requested questions, source material, limited conversation history and relevant authorized child records can be sent to the managed answer service. Google/Firebase supports Android push delivery and configured purchase notifications; RevenueCat supports subscription verification; Google Play handles Android checkout and receipts. Apple handles relevant device/store functions when the corresponding iOS service is available. The operating-system location/geocoding provider can process a permitted location request. Google’s email service handles correspondence sent to our support mailbox, including privacy requests and any information a sender includes. Do not send unnecessary health details in an email request. Providers receive information appropriate to their function; payment/notification providers do not need the full private journal to perform those functions.
A provider operating strictly under our instructions acts as a processor/service provider where the law so provides. Stores, an email service used by you, and external websites may also process information independently under their own policies. We do not designate a recipient a processor merely because it is called a vendor; required contractual restrictions must actually apply.
Authorized personnel. Access for operations, support, security and moderation is limited to the role and purpose that requires it. “Private” means restricted access, not that no authorized operator or contracted provider can ever process the information. We do not claim end-to-end encryption of every record.
Law and business changes. We may disclose minimum necessary information in response to valid legal process, to meet reporting duties, to investigate abuse, or to protect rights and safety where law permits or requires. A merger, restructuring or asset transfer may involve restricted information review and transfer, subject to the existing purposes, legal safeguards and any required new notice or consent. This is not permission to sell health data or use it for an incompatible purpose.
Recipients you choose. You decide where to send an export or external message. Withya cannot control a copy held outside its service, but recipients remain responsible under applicable law.
7. Storage locations and international transfers
The application backend and private storage currently use infrastructure in the United States, including Oregon. Service providers may also process information in other locations involved in their documented operations and support. Indian users’ information is therefore processed outside India. We do not promise Indian-only residency or that every provider copy stays in one US region.
Cross-border processing must comply with applicable restrictions and safeguards; accepting this policy does not waive them. Where consent or a specified transfer safeguard is required, it must be in place before the transfer. Contact us for information about the recipients and safeguards relevant to your data.
8. Retention and deletion
We retain personal information for the purposes described in this policy, taking account of whether your account or feature remains active, the sensitivity and necessity of the information, your deletion or withdrawal request, unresolved support or safety matters, and applicable legal recordkeeping and limitation periods. We do not promise lifetime storage or automatically delete a profile merely because a child reaches age five.
| Category | Retention period or criteria |
|---|---|
| Account, child profiles, care records, plans and journal | While needed to provide the requested account/profile features, subject to a valid deletion request and applicable necessity limits. |
| Private questions and responses | For your conversation history, requested feature operation and necessary failure investigation, subject to deletion and applicable purpose limits. |
| Community posts, messages and reports | For the selected audience and feature, and as necessary to handle reports, appeals or a particular lawful preservation duty. |
| Family photos and videos | Follow the associated profile and deletion process. A subscription lapse or reduced storage allowance does not alone trigger automatic deletion. |
| Generated exports and temporary files | Generated download links normally remain available for up to 24 hours. Link expiry is different from deletion of underlying records or asynchronous cleanup of temporary copies. |
| Raw app-usage events | Server storage currently has no automatic age-based expiry. Associated raw records are included in applicable account/child erasure. Continued retention remains subject to necessity, lawful purpose, withdrawal and applicable erasure duties. |
| Connection and server logs | Kept for necessary service operation, security and fault investigation, subject to applicable legal log-preservation duties and erasure rights. IP addresses attached to raw usage events follow the raw-event handling described above. |
| Revisions and removed-entry archives | Kept separately from ordinary views for necessary recovery, integrity, dispute handling or a specific legal duty; removing an entry from a screen does not immediately erase every revision. |
| Billing, transaction lineage and deletion-prevention records | Minimum information needed for payment reconciliation, disputes, legal recordkeeping, prevention of purchase misuse and prevention of reintroduction of erased data. |
| Backups and processor copies | Follow recovery and provider lifecycles, subject to applicable erasure deadlines. Restricted backup copies are not retained as an alternative active family database. |
| Support and verification records | As needed to complete the request, document its handling, resolve a related dispute and meet a specific legal duty. |
Retention periods differ by category; there is no single expiry applying to every record or provider copy. A preservation obligation is limited to the information and duration it requires. It does not authorize retaining all family information indefinitely. Where we retain information after a deletion request under a legal exception, we will explain the applicable reason unless legally prohibited.
Restricted departure statistics can include broad country/state, child gender and age band, join/departure month, tenure band, an optional structured reason and grouped activity counts. They exclude original account/child/device identifiers and source-record lookup, names, contacts, exact birth dates, precise location, private text and media. We commit to maintain and use retained deidentified statistics only in deidentified form, take reasonable measures against association with an individual, not attempt reidentification, and require any recipients by contract to observe applicable deidentification restrictions. Information that fails the applicable legal deidentification standard remains personal information subject to the relevant rights and retention limits.
9. How account and child deletion works
Ordinary account deletion
After the service accepts an account deletion request, ordinary access pauses and a seven-day recovery period begins. Deliberately signing in again with fresh credentials during that window cancels the account request. Automatic token refresh, background activity or another caregiver’s sign-in does not cancel it.
At the deadline, the service begins irreversible cleanup. The deadline is not a guarantee that all storage, backups and provider systems finish erasure at that instant. A failure can leave a stage pending for retry. Once irreversible processing has begun, restoration is no longer available through the grace process.
The Primary’s account deletion includes all child profiles it owns. Children owned by another Primary and their structural care history remain. The departing adult’s memberships and identifying account information are removed, and affected free text and associated media are removed or scrubbed. Shared measurements and event structure may remain in the other family’s records. You may separately request deletion of information concerning your own health; retention of a shared record does not override an applicable right. Owned private conversations, identifying private content, associated media/exports and associated raw journey records are included in the applicable erasure scope.
If you need to contact support about a pending request, email without signing back in if you do not intend to cancel it. An independent privacy request must not be silently canceled merely because you authenticate to exercise a right; the ordinary account-recovery behavior is distinct from that request.
Individual child deletion and ordinary entry removal
Only a child’s Primary can schedule that profile for deletion. The profile is hidden and ordinary shared access pauses during its seven-day window. Restore it explicitly through the available pending-deletion controls within that window; ordinary sign-in does not restore the child automatically. The Primary’s account deletion takes precedence over its owned profiles.
Other linked adults retain applicable statutory rights to request their own personal information through the rights contact, including during the recovery period. Request promptly while data remains available. This does not shorten legal request periods, grant access to someone else’s private information, or require retention inconsistent with a valid erasure duty.
Deleting a care entry removes it from ordinary family views. Internal revisions, removed-record archives, report evidence and recovery records have separate handling. On-screen removal is not a representation of immediate physical erasure from every store. If you need a legal deletion of identifying data beyond ordinary entry removal, submit a privacy request.
Access cancellation and subscriptions
Removing an adult stops future authorized access and associated notifications for the profile. It cannot recall external exports, screenshots or information already learned. A Secondary leaving or deleting their account does not cancel the Primary’s subscription or delete a child owned by that Primary.
Withya account/profile deletion, uninstalling and subscription cancellation are separate actions. Cancel each unwanted subscription through Apple or Google Play. We provide support for locating the relevant management route; we do not claim to cancel a store charge merely by deleting its family data.
Recipients, backups and applicable deadlines
We notify processors and other recipients of an erasure request where legally required and take required steps to prevent deleted information from reappearing after restoration of an older backup. A processor failure does not suspend legal deadlines indefinitely. We cannot directly erase a copy independently saved by another adult from that adult’s device; this does not remove our own notification duties or the recipient’s responsibilities.
Statutory deadlines run under the applicable law, independently of the seven-day account recovery period. The Consumer Health Data Privacy Policy describes relevant health-data deadlines. You can submit an independent privacy deletion request without using the account-recovery process. We do not condition a valid request on a purchase, release of liability or waiver of complaint rights.
10. Security and incidents
We use access controls, protected authentication storage, encrypted transport and private storage protections appropriate to the Service. Pending care and journal changes can use encrypted local storage. Temporary media and exports may exist on devices. These safeguards cannot eliminate every risk, and they do not constitute a claim of certification or universal end-to-end encryption.
If a security incident triggers legal notice duties, we will provide required notices to affected people and authorities within applicable deadlines. We do not require you to waive breach notices, compensation or statutory remedies. Report suspected issues to our contact without including credentials or unnecessary child information.
11. Your choices and rights
Depending on applicable law, you may request confirmation/access, a copy, correction, deletion, withdrawal of consent, restrictions on sensitive-data use, information about recipients, and an appeal of a refusal. Some jurisdictions provide additional opt-out or authorized-agent rights. We accept requests through our contact email and available account controls. You do not need a paid plan to exercise a legal right.
We verify identity and authority proportionately and ask only for information necessary to prevent disclosure to an impostor. We will explain a permitted refusal, applicable extension and appeal route. We do not discriminate for exercising rights, although a feature may depend on information you choose not to provide. These statements describe rights where applicable and are not a claim that every US state privacy statute applies to every business at every size.
For California residents where the CCPA applies: the table above supplies category, source and purpose information; recipient and retention sections supply the corresponding disclosures. You may exercise applicable rights to know/access, correct, delete, opt out of sale/sharing and limit specified uses of sensitive information. We do not sell or share for cross-context behavioral advertising. Because no sale or cross-context advertising sharing occurs, an opt-out preference signal does not change those practices; we will honor such signals if we introduce processing to which they apply. The cookies and device section above explains the available settings and their limits. We do not offer financial incentives for personal information.
Health-specific and other state laws can apply even when a general privacy law’s revenue or volume threshold is not met. The Consumer Health Data Privacy Policy describes the relevant collection, sharing and request process. Contact us if you cannot exercise a right through the current interface.
How to submit a request
Send requests to our privacy email or use the account and profile controls in the app. Account deletion is done within the app. Identify the account and whether you want access, a copy, correction, deletion, consent withdrawal, recipient information or an appeal. Do not include your password or complete health history. A shared-journal export is not necessarily a complete statutory copy of account, conversation and technical information; tell us if you seek that broader record.
We respond within the period required by the applicable law and notify you of a permitted extension with the reason. Where applicable, an authorized agent or legal representative may act with proportionate verification. If we refuse all or part of a request, we explain the reason and available appeal route. To appeal, reply with the subject “Privacy appeal.” You may also contact your state attorney general, consumer or data-protection authority, or pursue an available legal remedy. A request concerning a child or another adult requires authority for that person’s information; holding a Primary role does not extinguish another person’s independent statutory rights.
12. Indian privacy and grievances
For Indian users, this policy identifies the information collected, its purposes, intended recipient categories and the organization collecting and retaining it. Sensitive information can include health records, medical history and authentication information handled by the sign-in service. Applicable law may require legally valid consent before collection. The current app does not provide a separate general sensitive-data consent step beyond the information-entry flow. Merely submitting information does not automatically satisfy every applicable consent requirement, and this policy does not replace a required consent. You may choose not to supply information and may withdraw consent through our contact. You may request review and correction of your information. Withdrawal can prevent a feature that needs the information, while unrelated rights remain available.
Indian grievance contact: [email protected], STH Technologies, LLC, 9206 Sunshine Pl, Downey, CA 90240, United States. A designated India grievance officer has not yet been appointed. We will publish the officer’s name and contact details here upon appointment. You may send complaints to the contact above in the meantime.
Send privacy grievances to this contact with the relevant account identifier, issue and requested remedy. We address grievances covered by the 2011 sensitive-data rules expeditiously and within one month, or within a shorter period where another applicable rule requires it. Our Terms describe the additional Indian consumer and content-complaint routes.
Indian information is processed in the United States and may be handled in other provider operating locations as described above. Transfers must satisfy applicable protection, purpose, permission and other legal conditions. Acceptance of this policy does not authorize a prohibited transfer or waive local rights.
Indian data-protection legislation has phased commencement. We apply obligations when they become operative, including required notices, consent and withdrawal, access/correction/erasure, grievance and nomination rights, language access and children’s-data protections where applicable. Adult-only accounts do not exempt information about a child from children’s-data law. Where verified parental consent is required, an ordinary account registration or caregiver assertion alone does not replace it. We do not rely on consent to override an applicable prohibition on tracking or behavioral monitoring of children or advertising directed at children.
13. Children and policy changes
Withya is intended for adults. It necessarily handles information about children supplied by authorized adults. If we learn that a child is operating an account without an appropriate lawful arrangement, we will restrict that use and address the data as required. Reporting an adult-only age does not establish legal authority over a child’s information.
We will post a dated version when this policy changes and give additional notice or seek fresh consent when required. A privacy-policy update does not retroactively authorize an undisclosed use. Send questions or rights requests to [email protected], or by mail to STH Technologies, LLC, 9206 Sunshine Pl, Downey, CA 90240, United States.