/ privacy
Baby Name A-Z privacy policy
Last updated
Effective date: 18 August 2026
Data controller: Dominic Sinclair-Moore, publishing as an individual
Contact: developer@dsinclairmoore.com
This policy describes what Baby Name A-Z does with your information. It was written against the app's actual behaviour, and the sections below name the specific data each feature stores.
The short version
- Your shortlist, rankings, surname and settings stay on your device. We never receive them.
- Nothing is sent to our servers until you choose to connect with a partner.
- Usage analytics and performance data are off unless you turn them on, and never include names.
- Crash reports are on by default, so we can fix what breaks. They contain no names, and you can switch them off in Settings.
- You can delete everything we hold from inside the app, at any time, without asking us.
- We do not sell or share your data with advertisers, and there are no ads in the app.
What stays only on your device
Held in the app's local storage and never transmitted to us:
- the names you like, pass and rank, and the order you put them in
- names you add yourself
- your surname, if you enter one for full-name previews
- your country, culture and gender filters, and your haptics and notification preferences
Depending on your device settings, your operating system's own backup (iCloud or Android Backup) may include this local data. That backup is controlled by you and your OS provider, not by us.
You can erase all of it with Settings → Reset all local data.
What we receive, and only when you use partner sharing
Connecting with a partner creates an anonymous account — an account with no email, name or password, identified only by a random identifier. Using that account, we store:
- Which names you liked, as catalogue identifiers rather than text, so that we can work out which names you and your partner both liked. Your partner is never shown your likes; only mutual matches are revealed to either of you.
- Names you add yourself and send to a partner. These are stored as text, because your partner needs to see them.
- Your invitation, as a single-use token that expires 24 hours after it is created.
- Your mutual matches and the outcomes of the head-to-head comparisons you make to rank them.
- Rate-limiting counters, to stop the service being abused.
Match notifications
If you turn on match notifications, we store a push token for the device, a random installation identifier, and whether the device is iOS or Android. Notifications are delivered through Expo's push service, which passes them to Apple or Google to reach your device. A notification tells you that a match exists; it does not include the name.
Turning notifications off removes the registration.
Analytics and performance data
Both are off until you agree to them, on a screen shown when you first open the app, and can be changed at any time in Settings. When on:
- Google Firebase Analytics receives pseudonymous records of which screens and features are used. These are counts and fixed categories — never text you typed.
- Google Firebase Performance Monitoring receives timing data: how long the app takes to start, how quickly screens draw, and how long requests to our own services take, together with your app version, device model and operating system version.
Neither ever includes names, your surname, searches, invitations or account identifiers.
Crash reports
Crash reports are on by default, because we cannot fix crashes we never hear about. You can turn them off at any time in Settings.
When the app crashes or hits an unexpected error, Google Firebase Crashlytics receives:
- the type of error, and the sequence of code locations that led to it
- your app version, device model and operating system version, and whether the device was low on memory or storage
- a random installation identifier, which lets us tell one device's crashes apart without identifying you
The app deliberately discards the error's own message before sending it, because an error message can quote something you typed — a name, a surname or an invitation code. Only the type of error and the code locations are kept. Crash reports never include names, your surname, searches, invitations or account identifiers.
We rely on legitimate interests for crash reporting: keeping the app working for everyone who uses it. The switch in Settings stops collection on your device if you would rather not send them.
Culture requests
If you ask us to add a country or culture, we receive the text you type and your current country filters, so we can judge demand. We do not receive your surname or your saved names.
Who else processes your data
- Google Firebase (Authentication, Firestore, Cloud Functions, Analytics, Crashlytics, Performance Monitoring) — hosting and storage for everything described above.
- Expo — push notification delivery, if you enable notifications.
- Apple / Google — delivery of push notifications to your device.
Whenever your device contacts these services, Google necessarily receives its IP address and can derive an approximate, country-level location from it. We do not use IP addresses ourselves.
We do not use advertising networks or data brokers.
How long we keep it
- Invitations expire 24 hours after creation.
- Notification jobs are removed on a short retention schedule once delivered.
- Crash reports and performance data are held by Google Firebase on a rolling basis and expire automatically. We do not copy them anywhere else.
- Everything else is kept until you delete it, or until you disconnect from your partner.
Deleting your data
Two routes, both inside the app:
- Disconnecting from your partner deletes the shared couple space for both of you — matches, suggestions, private likes and invitations.
- Settings → Delete my cloud data deletes everything we hold for you, including the anonymous account itself, and signs the device out. Your local shortlist stays on the device.
Neither requires you to contact us. If you would rather ask us to do it, use the contact address at the top of this policy.
Your rights
If you are in the UK or EU, you have rights of access, rectification, erasure, restriction, objection and portability over your personal data. Because accounts are anonymous, we may be unable to identify your records from an email alone — the in-app deletion above is usually the fastest and most reliable route. The lawful bases we rely on are consent (analytics, performance data, notifications) and legitimate interests / performance of the service (partner sharing, abuse prevention, crash diagnostics).
You may also complain to your data protection authority. In the UK, that is the Information Commissioner's Office.
Children
The app is for adults choosing names. It is not directed at children, and we do not knowingly collect data from them. The names in your shortlist are your own entries, not information about an identifiable child.
Changes
If this policy changes materially we will update the effective date above and, where the change affects how your data is used, tell you in the app.