Skip to main content

LEGAL & PRIVACY

Privacy Policy

Mamavi holds some of the most sensitive information a person ever records — a pregnancy, a birth, a newborn, a mental-health screening. This policy explains exactly what we hold, who can see it, and what we will never do with it.

Effective

Who we are and what this policy covers

Mamavi is operated by Mamavi Health, Inc. This policy covers the Mamavi mobile apps for iOS and Android, the Mamavi Care Provider Portal at app.mamavihealth.com, and the Mamavi API that both of them talk to.

It does not cover anything a third party does on their own site — for example, a retailer whose baby registry you link to from Mamavi. Once you follow that link, you are on their service and their privacy policy applies.

The information you give us

Almost everything in Mamavi is there because you typed it, tapped it or uploaded it. Concretely, that is:

  • Account details — your email address, a hashed password, your display name and your role (parent, co-parent, care provider or administrator). We store a one-way hash of your password, never the password itself.
  • Household details — who is in your household, your due date, your baby’s expected or actual birth date and sex, and the care mode you selected.
  • Pregnancy logs — contraction start and stop times, kick counts, weight and symptom entries, and hospital-readiness details such as your chosen birth location.
  • Postpartum logs — feeding sessions, pumping sessions, diaper changes, sleep, growth measurements and milestones.
  • Mental-health screening — your answers to the Edinburgh Postnatal Depression Scale (EPDS) and the resulting score.
  • Photos and media — milestone photos and birth-announcement images you choose to upload.
  • Messages and appointments — the content of messages you exchange with a connected care provider, and appointments on your shared calendar.
  • Provider information — for care providers, your practice name and verification status.
  • Payment information — if you subscribe to a paid plan, our payment processor handles your card details. Mamavi never receives or stores your full card number.

Information we collect automatically

We keep this list deliberately short. Mamavi runs no advertising SDKs, no third-party analytics trackers and no cross-site tracking pixels — which is what the "0 · Ad tracking" figure on our home page refers to.

What we do collect is the minimum needed to keep the service running and secure: server logs containing IP address, timestamp, requested endpoint and response status; the device platform and app version, so we can debug a crash; and authentication events such as sign-in, sign-out and password change.

Health information, and why we treat it differently

Contraction timings, EPDS scores, feeding logs and growth measurements are health information. Several US state laws — including Washington’s My Health My Data Act — treat consumer health data as a special category, and we handle it that way regardless of which state you live in.

Health information in Mamavi is used for exactly three things: showing it back to you, sharing it with people you have explicitly connected to your household, and producing documents you asked us to produce — today, a provider export; once FSA/HSA documentation support ships, an itemised receipt or a letter of medical necessity.

It is never used to build an advertising profile, never sold, never rented, and never shared with a data broker. If we are ever asked to disclose it in response to legal process, we will require valid legal process, will narrow the scope where we can, and will notify you unless we are legally prohibited from doing so.

Your EPDS results

The Edinburgh Postnatal Depression Scale is a screening questionnaire, not a diagnosis. Your individual answers and score are visible to you, and to a care provider only if you have connected that provider to your household and consented to sharing.

Josephine, our in-app assistant, has no access to your EPDS answers or score. That is enforced in the product, not by policy alone: the assistant has no tool that can read them.

If your score suggests you may benefit from support, Mamavi will surface resources. It will not contact anyone on your behalf without your say-so.

Photos, and the birth announcement engine

Milestone photos and announcement images are stored with our media provider and served over encrypted connections. Uploads are authorised per-request by our API — a signed upload cannot be reused by anyone else.

The birth-announcement feature is designed to offer facial-privacy blurring before you share a card. Once that ships, blurring will be applied to the image you export; the original will stay in your household unless you share it yourself. Once you post an announcement outside Mamavi, that copy is out of our hands.

Josephine, our AI assistant

Josephine answers questions about your pregnancy and postpartum data. To do that, the relevant parts of your household context and your conversation are sent to our AI provider so a reply can be generated.

Three commitments apply. Your conversations are not used to train anyone’s foundation model. Josephine cannot read your EPDS results. And Josephine does not give medical advice — it will tell you to contact your provider or emergency services when a question calls for that.

Conversations are stored against your account so the assistant has continuity between sessions. You can delete a conversation, and deleting your account deletes them all.

Who can see your data

Access in Mamavi is scoped, not global. The rules are enforced in our API on every request, not just hidden in the interface.

  • You — everything in your own household.
  • People you invite — a co-parent, a partner, a family member. What each one can see depends on the access level you gave them when you invited them, and you can change or revoke it at any time.
  • Care providers you connect — a doula, midwife or OB-GYN sees only the households that have connected to them, and only the categories of data that connection covers. Provider exports additionally require your consent.
  • Mamavi staff — only where strictly necessary to operate the service, respond to a support request you raised, or investigate abuse or a security incident. Access is limited to the smallest group that can do the job.
  • Nobody else. We do not have a data-sharing arrangement with any advertiser, broker, insurer or employer.

Companies that process data for us

Running Mamavi means a small number of vendors process data on our behalf, under contract, for the purpose we specify and nothing else:

  • Database hosting — a managed PostgreSQL provider stores your account, household and log data, encrypted at rest.
  • Media storage — our image provider stores milestone and announcement photos.
  • Transactional email — our email provider delivers password resets and account notices. Marketing sends and product data are kept separate.
  • AI inference — our AI gateway routes assistant requests to the model provider that generates Josephine’s replies.
  • Payments — our payment processor handles card details for paid plans. We receive a subscription status, not a card number.

What we never do

  • We do not sell your personal information, in the ordinary sense of that phrase or as defined by California law.
  • We do not share your health information for cross-context behavioural advertising.
  • We do not embed advertising SDKs or third-party trackers in the apps.
  • We do not use your identifiable health data to train machine-learning models.
  • We do not disclose your data to an employer, insurer or law-enforcement agency without valid legal process or your explicit instruction.

How long we keep your information

Account and household records are kept while your account is open. When you delete your account we delete your personal data within 30 days, except where we are legally required to keep something longer — for example, a payment record retained for tax purposes.

Backups roll off on their own schedule, so a deleted record can persist in an encrypted backup for a short additional period before it is overwritten. Password-reset tokens expire after 60 minutes. Server logs are retained for a limited operational window and then discarded.

Deleting an individual log entry, photo or conversation inside the app removes it from your household immediately.

Your choices and your rights

Wherever you live, you can do all of the following. Depending on your state or country you may also have formal statutory rights that we will honour on the same terms.

  • Access — see everything Mamavi holds about you, and request a copy.
  • Correct — fix anything that is wrong, directly in the app.
  • Delete — delete individual entries, or your whole account.
  • Withdraw consent — disconnect a care provider or revoke a family member’s access at any time. Revoking access is immediate.
  • Object and complain — write to us, and if you are not satisfied, raise it with your local data-protection authority.

How we protect your data

Data is encrypted in transit with TLS and at rest by our hosting providers. Passwords are hashed with bcrypt. API access requires a signed token, and every request is checked against the access scope of the household it touches.

Our API does not include request contents in its error responses. The web portal sets strict transport security, frame-denial and content-type-sniffing protections on every response.

No system is perfect. If we ever suffer a breach affecting your personal data, we will notify affected users and the relevant regulators as required by law.

Children

Mamavi is for adults. You must be 18 or older to create an account. We knowingly collect information about babies and children only as part of an adult account-holder’s household record — a birth date, growth measurements, feeding logs, photos — and that information belongs to, and is controlled by, the adult who entered it.

If you believe a child has created an account, write to us and we will remove it.

Changes to this policy

If we change this policy we will update the effective date at the top of this page. If a change materially affects how we handle your health information, we will tell you in the app or by email before it takes effect, rather than relying on you to notice.

Contact us

Privacy questions and rights requests: hello@mamavihealth.comMamavi Health, Inc.We aim to respond within 30 days.