This Privacy Policy explains how 15064121 Canada Inc., a federally incorporated Canadian corporation with a registered office in Quebec, doing business as CoCo Parenting AI ("CoCo", "we", "us"), collects, uses, discloses, and protects personal information when you use the CoCo Parenting AI website, mobile apps, and related services (together, the "Service").
We act as a controller (under GDPR / UK GDPR) and an enterprise (under Quebec Act respecting the protection of personal information in the private sector, as amended by Law 25) for personal information you provide to us and that we collect through the Service. Where you use the Service in a professional capacity for another person, we may act as a processor / service provider for that party; in that case, the controller’s privacy notice governs and this policy supplements it.
Read this policy together with our Terms of Service, Cookie Policy, Subprocessors list, and Community Guidelines.
1. Quick summary (not a replacement for the full policy)
- We only allow adults aged 18 + to create accounts. The Service is not directed to children.
- Parents voluntarily provide limited information about their children so the Service can personalize guidance. We never sell this data.
- We use AI (OpenAI) under a zero-retention, no-training arrangement for our API traffic.
- We use Firebase/Google Cloud, Stripe, Apple/Google (in-app billing), Resend (email), Sentry (error diagnostics), and WeatherAPI. Full list in the Subprocessors page.
- We do not sell or "share" (as defined by CPRA) your personal information and we honor Global Privacy Control (GPC) signals.
- You can access, correct, export, and delete your data at any time from Profile Settings or by emailing support@cocoparentingai.com.
2. Who we are and how to contact us
Controller / business: 15064121 Canada Inc., doing business as CoCo Parenting AI, Quebec, Canada.
Privacy Officer (required by Quebec Law 25): the person holding the highest authority in the company, currently acting as our Person in Charge of the Protection of Personal Information. You can reach the Privacy Officer — and submit any general privacy request — at support@cocoparentingai.com with the subject line "Privacy request", or use the form inside the app (Profile Settings → Privacy).
UK / EU representative (for UK GDPR Article 27, where required): if we later appoint one, we will publish the representative’s contact details here. Until then, users in the UK and EEA can reach us directly at the address above.
3. What personal information we collect
3.1 Information you give us
- Account data: email, hashed password, display name, preferred language, time zone.
- Parenting profile: your parenting stage(s), optional location (city/region, never precise GPS).
- Children’s data you enter: child’s first name, date of birth, gender (optional), allergies, dietary notes, health conditions you choose to record, developmental logs (feeds, sleep, diapers, milestones). You decide what to enter.
- Content you create: reminders, notes, tracking logs, photos you upload to your private area, community posts/replies you choose to publish.
- Coco chat messages: the text of your messages to our AI assistant and the AI’s responses.
- Support and feedback: your support emails, survey answers, feedback widget submissions.
- Payment information: we do not store full card numbers. Stripe (on the web) and Apple/Google (on mobile) process payments and return to us a customer ID, subscription status, plan, currency, amount, and country.
3.2 Information we collect automatically
- Device / app data: device model, OS version, app build, crash reports, a randomly generated install ID.
- Log data: IP address (truncated where feasible), coarse approximate location derived from IP, request timestamps, HTTP status, request IDs for debugging.
- Push tokens: FCM / APNs device tokens you authorize us to store so we can deliver reminders you have turned on.
- Cookies / local storage / IndexedDB: session tokens (Firebase Auth), preferences, a small offline cache of your own data. Full list in the Cookie Policy.
- Error and performance telemetry: stack traces, request IDs, and minimal context sent to Sentry to fix bugs — scrubbed of obvious PII before transmission.
3.3 What we do NOT collect
- We do not collect biometric identifiers. If you enable the mobile app’s biometric lock, the biometric check happens entirely on your device (Face ID / Touch ID / device PIN) and we never see the biometric data.
- We do not collect precise (GPS) location.
- We do not scan your device’s photos, contacts, microphone, or other apps.
- We do not buy personal information from data brokers.
3.4 Sensitive / special-category information
Some information you choose to record — health conditions of a child, a child’s allergies, emotional well-being notes, postpartum mental-health inputs — may qualify as sensitive (GDPR Article 9 / CPRA §1798.140(ae) / Quebec Law 25 §12). We process this information only with your consent and only to deliver the features you use. We never use it for advertising.
4. Why we process personal information (purposes and legal bases)
We process personal information for the purposes below. For users in the EU/EEA and UK, we indicate the GDPR / UK GDPR legal basis. For Quebec, we rely on the equivalents under Law 25.
- Account and sign-in — to create your account, authenticate you, and keep the Service secure. Legal basis: performance of contract; legitimate interests (security).
- Service personalization — to tailor content (meal plans, schedules, tips) to your stage, child’s age, and preferences. Legal basis: performance of contract.
- AI assistant (Coco chat, AI-generated guides) — to generate personalized responses based on the context you provide. See section 5 for AI-specific disclosures. Legal basis: performance of contract. For sensitive data shared in chat, explicit consent given by using the feature.
- Reminders and notifications — to send push, email, or local reminders you turn on. Legal basis: consent (notifications); performance of contract (essential service emails).
- Community features — to display posts you choose to publish and moderate content for safety. Legal basis: performance of contract; legitimate interests (safety and abuse prevention).
- Billing and fraud prevention — to process payments, manage subscriptions, prevent chargebacks and abuse. Legal basis: performance of contract; legal obligation (tax records); legitimate interests (fraud prevention).
- Analytics and product improvement — aggregated, de-identified analytics of feature usage. Legal basis: legitimate interests; consent where cookie-based and required by local law.
- Security, error monitoring, and integrity — logs, Sentry error reports, abuse detection, rate limiting. Legal basis: legitimate interests; legal obligation (where applicable).
- Legal compliance — to comply with laws, respond to lawful requests, and defend legal claims. Legal basis: legal obligation; legitimate interests.
- Marketing (opt-in only) — newsletter or product-update emails, only if you opt in. Legal basis: consent. You can withdraw consent at any time.
You can withdraw consent and change your preferences at any time in Profile Settings without affecting the lawfulness of processing carried out before the withdrawal.
5. AI features — transparency and automated decision-making
Our AI features (Coco chat, personalized schedules, meal plans, developmental tips, progress reports) are powered by models hosted by OpenAI under our API agreement.
- What we send to OpenAI: your prompt plus a minimal personalization context (child’s first name or initial, age, any allergies, dietary preferences and health conditions you have entered, city/region, language). We do not send your email address, password, payment information, precise location, or device identifiers.
- No training, zero-retention: Our API usage is covered by OpenAI’s zero-retention endpoints where available; OpenAI does not use your API content to train its models. See OpenAI Enterprise Privacy.
- No solely-automated decisions with legal or similarly significant effects. AI outputs are informational parenting suggestions — they are not medical, legal, financial, or psychological advice. A human (you) decides what to do with them.
- Crisis safeguards: when the assistant detects crisis language (self-harm, child-abuse, medical emergency), it surfaces region-appropriate crisis resources and does not give clinical advice.
- Your control: you can review your chat history, delete individual messages, or delete the entire conversation at any time. You can opt out of AI features by not using them; core tracking features work without AI.
6. How we share personal information
We share personal information only in the circumstances listed below. We do not sell personal information, we do not share it for cross-context behavioral advertising (as those terms are defined under CCPA/CPRA), and we have not done so in the past 12 months.
6.1 Service providers (subprocessors)
We share personal information with vendors that help us run the Service. Each vendor is bound by a written data-processing agreement, processes data only on our instructions, and must maintain appropriate security. See the full list on our Subprocessors page. Key categories:
- Google LLC / Firebase — authentication, Firestore database, Cloud Storage, hosting, push (FCM). United States with EU SCCs where applicable.
- Vercel Inc. — web hosting and content delivery.
- Stripe, Inc. — payment processing for web subscriptions. PCI-DSS Level 1.
- Apple Inc. / Google LLC — in-app purchases on iOS / Android; we receive only anonymized transaction receipts.
- OpenAI, L.L.C. — AI model inference. Zero-retention API, no training on our data.
- Resend, Inc. — transactional and reminder emails.
- Functional Software, Inc. d/b/a Sentry — error monitoring.
- WeatherAPI.com — weather data keyed on a coarse city/region only.
6.2 Community content you publish
If you choose to publish a post or reply in the public community, the post content, your display name, and your avatar are visible to other signed-in users. Do not post information you want to keep private. See the Community Guidelines.
6.3 Legal disclosures and safety
We may disclose personal information if we reasonably believe it is necessary to: (a) comply with law, regulation, or valid legal process; (b) protect the rights, property, or safety of CoCo, our users, or the public — for example, reporting suspected child abuse to authorities; or (c) enforce our Terms of Service. We publish a transparency report summary on request.
6.4 Business transfers
If CoCo is involved in a merger, acquisition, financing, reorganization, or sale of assets, your personal information may be transferred as part of that transaction. We will notify you (and provide choices where required by law) before any such transfer.
7. International data transfers
We are based in Canada and use vendors primarily located in the United States. When we transfer personal information outside of your country of residence:
- EU/EEA and UK: transfers to countries without an adequacy decision are made under the European Commission’s Standard Contractual Clauses (2021) and, where applicable, the UK International Data Transfer Addendum. A transfer-impact assessment is on file with our Privacy Officer.
- Canada: we rely on PIPEDA Principle 4.1.3 and Quebec Law 25 §17 by performing and documenting a privacy-impact assessment before enabling any new cross-border transfer of personal information.
- UK: we process UK personal data under UK GDPR; we use the UK Addendum to the EU SCCs where needed.
- Australia: we take reasonable steps to ensure overseas recipients handle your personal information consistently with the Australian Privacy Principles.
- New Zealand: transfers are made only where the receiving jurisdiction provides comparable safeguards, consistent with Privacy Act 2020 Part 9A.
You can request a copy of the safeguards we use by emailing support@cocoparentingai.com with the subject line "Transfer safeguards".
8. How long we keep personal information (retention schedule)
| Category | Retention | Reason |
|---|---|---|
| Account profile + children’s data | While account is active | Perform the contract |
| Chat history with Coco | Until you delete it or close your account | Service delivery |
| Tracking logs, reminders, posts | While account is active; deleted on account closure | Service delivery |
| Closed account → soft-deleted | Up to 30 days, then hard-deleted or anonymized | Accidental-deletion recovery window |
| Billing records | 7 years after last transaction | Canadian/US/EU tax & accounting law |
| Fraud / abuse signals (IP hashes, device ids) | Up to 12 months | Security and fraud prevention |
| Server access logs | 90 days | Security, debugging |
| Sentry error events | 90 days | Product quality |
| Email deliverability events (Resend) | 12 months | Compliance & troubleshooting |
| Community posts you published | Until you or an admin deletes them; anonymized on account deletion | Preserve conversation integrity |
When you delete your account (Profile Settings → Delete Account or by emailing us), we anonymize or delete the categories above on the schedule shown. Backups are overwritten on the normal backup rotation and are not used to restore deleted accounts.
9. Security
We use industry-standard technical and organizational safeguards, including:
- TLS 1.2+ encryption in transit; AES-256 encryption at rest on our databases and storage.
- Hashed, salted passwords (handled by Firebase Auth) — we never see your password.
- Role-based access controls; least-privilege access for staff; MFA required for admin accounts.
- Firestore security rules and server-side authorization on every API route.
- Structured logging with automatic PII scrubbing before shipping to Sentry.
- Regular dependency and vulnerability scanning; 24-hour maximum patch window for critical CVEs on production surface.
- Annual policy review; incident-response runbook.
No method of transmission or storage is 100% secure. If we become aware of a confidentiality incident that poses a risk of serious injury, we will notify you and the competent authorities — including the Commission d’accès à l’information du Québec and, where applicable, the UK ICO, EU supervisory authorities, OAIC (Australia), and the NZ Privacy Commissioner — without undue delay and, where required, within 72 hours of becoming aware.
10. Your rights
Subject to the law that applies to you, you have the following rights. We do not charge a fee for most requests and will respond within 30 days (extendable once by 30 days for complex cases, with notice to you).
10.1 Everyone
- Access — get a copy of the information we hold about you. Use Profile Settings → Export my data for a machine-readable copy.
- Correction — fix inaccurate or incomplete information (directly in the app or via email).
- Deletion — delete your account and all associated personal information.
- Opt-out of marketing — unsubscribe from every marketing email with one click.
10.2 EU/EEA and UK residents (GDPR / UK GDPR)
- Right to access, rectification, erasure, restriction, and portability.
- Right to object to processing based on legitimate interests.
- Right to withdraw consent at any time.
- Right not to be subject to solely automated decisions with legal or similarly significant effects (we do not make such decisions).
- Right to lodge a complaint with your local supervisory authority, including the UK ICO, EU supervisory authorities.
10.3 Canada (PIPEDA) and Quebec (Law 25)
- Right to access, correction, and withdrawal of consent.
- Right to be informed of disclosures, including cross-border transfers.
- Quebec-specific: right to data portability (since September 22, 2024), right to de-indexation (erasure), and the right to be informed of automated processing used to render a decision about you — including the principal factors and parameters used.
- Complaint to the Commission d’accès à l’information du Québec or the Office of the Privacy Commissioner of Canada.
10.4 California (CCPA/CPRA) and other US states
- Right to know — categories and specific pieces of personal information collected, sources, purposes, and categories of recipients (all disclosed above).
- Right to delete personal information, subject to legal exceptions.
- Right to correct inaccurate information.
- Right to limit use of sensitive personal information — we already limit our use to what is necessary to deliver the Service.
- Right to opt out of sale or sharing — we do not sell or "share" personal information. We also honor browser-level Global Privacy Control (GPC) signals.
- Right to non-discrimination — we will not deny service, raise prices, or provide lower quality because you exercised a privacy right.
- Right to appeal — if we decline a request, you can appeal by replying to our decision email within 60 days; a different reviewer will respond within 45 days.
- California "Shine the Light" — we do not share personal information with third parties for their direct marketing.
- Authorized-agent requests are accepted if you provide written authorization and we can verify your identity.
10.5 Australia
You have rights to access and correct your personal information under the Privacy Act 1988 and the Australian Privacy Principles. You may complain to the Office of the Australian Information Commissioner (OAIC).
10.6 New Zealand
You have rights of access and correction under the Privacy Act 2020. You may complain to the Office of the Privacy Commissioner (NZ).
10.7 How to make a request
- Use Profile Settings → Privacy in the app (fastest).
- Or email support@cocoparentingai.com from the email on your account with the subject line "Privacy request", describing your request.
- We verify identity via the email on file; for deletion, we additionally require you to confirm a unique code sent to that email.
11. Children (COPPA and equivalent)
The Service is intended for adults aged 18 and over. We do not knowingly collect personal information directly from children. All account holders confirm at sign-up that they are at least 18.
Parents voluntarily record information about their own children to personalize the Service. This information is provided by the parent and is governed by the parent’s account. Parents can review, correct, export, and delete this information at any time. We do not use children’s data for advertising, profiling beyond personalization of the Service you asked for, or cross-product marketing.
If we learn that a child under 18 has somehow created an account, we will close that account and delete the associated data. Contact us at support@cocoparentingai.com to report a suspected under-age account.
12. Cookies, similar technologies, and Do-Not-Track
See the full Cookie Policy. In short: essential cookies / tokens are always on; analytics and non-essential cookies require your consent in jurisdictions that require it (EEA / UK / Quebec Law 25 residents are shown a banner on first visit). We respect Global Privacy Control (GPC) signals and treat them as a valid opt-out of any analytics cookies that are not strictly necessary.
13. Third-party links and integrations
The Service may link to third-party websites or embed third-party content (for example, links to pediatric-health resources). We are not responsible for the privacy practices of those third parties. Read their privacy policies before providing them with personal information.
14. Changes to this policy
We review this policy at least annually. We will post any changes here and update the "Last updated" date. If changes are material, we will notify you by email or in-app notice at least 30 days before they take effect so you can review them (and, for EEA/UK/Quebec users, withdraw consent where applicable).
15. Contact
15064121 Canada Inc. (doing business as CoCo Parenting AI)
Quebec, Canada
Email: support@cocoparentingai.com — please use a clear subject line (e.g. "Privacy request", "Data export","Account deletion") so we can route your message to the right team.
Related policies: Terms of Service · Cookies · Subprocessors · Refund policy · Community guidelines · Mobile EULA