LittleStems

Privacy policy

Last updated 2026-09-22

LittleStems is an app for recording your child’s milestones and memories. That means it holds some of the most personal information you will ever type into a phone, and this page is a plain description of what happens to it.

The short version

Who we are

Keystone Dev Studio Ltd, trading as LittleStems is the data controller for the purposes of UK and EU data protection law. Registered in England and Wales, company number 17406929. Registered office: 61 Goodwin Close, London, England, SE16 3TL. You can reach us at hello@littlestems.app.

What the app stores on your device

Everything you record is written to your phone first and stays there: your children’s names, dates of birth or due dates, any considerations you choose to note, logged milestones and their dates, firsts, toddlerisms, notes, and any photos, videos, or sound clips you attach. Your on-device copy is the original. A backup, if you make one, is a copy of it.

If you never create an account, this information never leaves your phone.

What happens when you sign in

Creating an account lets your records sync across your devices and survive losing your phone. When you sign in, the following is stored in Google Firebase (Authentication, Cloud Firestore, and Cloud Storage) under an identifier belonging to your account:

Security rules restrict every one of those records to the account that created them. Local file paths from your phone are deliberately excluded from what is uploaded.

Before you create an account, the app uses an anonymous identifier so that data can be stored securely from the first launch. Adding an email later attaches it to that same identifier, so nothing has to be moved or copied.

Analytics

We use Mixpanel to understand how the app is used in aggregate - which screens people reach, whether onboarding completes, whether a purchase succeeded. It is configured against Mixpanel’s EU servers.

Analytics events are restricted to a fixed list of non-identifying properties, enforced in the app’s code rather than by policy. That list is: your account identifier, whether you have Premium, a rough band for how many children you follow, whether the build is development or production, an onboarding step number, a media type, a plan name, the part of the app an action came from, and a storage threshold.

No free text, email address, child name, date, note, photo, or file path is ever sent to analytics. There is no code path that could send one.

Purchases

Subscriptions and the lifetime purchase are processed by Apple or Google - we never see or store your payment details. We use RevenueCat to tell us whether your purchase is active, linked to your account identifier so your Premium access follows you between devices.

Asking a development question

Ask handles your question on your device first. Emergency phrases are recognised there — that never involves a server — and most questions are answered there too, by matching against a library of answers written from NHS, CDC, and WHO guidance. Every answer shows its source.

If Ask cannot answer a question, the question text is sent to us and kept, because an unanswered question tells us exactly which answer to write next. Before it leaves your device, your children’s names are replaced in the text, and it is stored with nothing else: no account identifier, no child record, no age — just the question, which country’s guidance the app was using, and when. Even so, please don’t type personal details into a question.

With your permission, Ask sends the question to our server so an AI service (Anthropic’s Claude) can word the answer for you, using your child’s name and age. The app asks you first, the first time you open Ask, and you can change your answer at any time in Settings under Ask LittleStems; with AI off, Ask still answers from the library, non-personalised, and nothing is sent. When it is on, three things are sent: the question exactly as you typed it, the identifiers of the library passages your device has already chosen, and a short note about your child - their first name, whether you have told us they are a girl or a boy, their age in months, and where the app has placed them against the guidance’s typical range. Never their record, never the considerations you have noted or the reasons behind them, and never the wider windows the tracker uses. Because the question is sent as written, please don’t type personal details into it. The server looks the passages up in its own copy of the library, so the AI only ever sees library text; the facts, the sources and the “when to get help” guidance come from the library, not from the AI, whose job is wording alone. Three commitments: your questions are never used for advertising, never sold, and never used to train third-party AI models. Emergency recognition stays on your device, and if the server cannot be reached your device answers on its own.

Notifications

Reminders are scheduled by your phone itself. We do not operate a push notification server and cannot send you anything you have not asked your device to schedule.

Children’s data

LittleStems is designed for parents and carers, not for children. The account holder is an adult; the records describe a child. We ask for the minimum needed for the app to work - a name so entries can be labelled, and a date so milestone timing makes sense. You are free to use a nickname or initials, and nothing is verified.

We do not build advertising profiles, we do not sell data, and we do not share your records with third parties beyond the service providers named on this page.

Legal basis and retention

Where UK or EU data protection law applies, we process your data to perform the service you asked for (providing and syncing the app), and on the basis of legitimate interests for limited, non-identifying analytics used to improve it. We keep your data for as long as your account exists. Delete your account and it is removed.

Your rights, and how to use them

Two of these are built into the app, so you do not have to ask us:

You also have the right to access, correct, or restrict processing of your data, and to complain to your data protection authority - in the UK, the Information Commissioner’s Office. Email hello@littlestems.app and we will respond within one month.

Ask, and the AI that words its answers

What is sent. Only when you have turned AI on: the question exactly as you typed it, the identifiers of the guidance passages your device has already chosen, and a short note about your child - their first name, whether you have told us they are a girl or a boy, their age in months, and where the app has placed them against the guidance’s typical range. Nothing else. Never your notes, photos, videos, milestone records, pacing preferences, email address or any identifier for you or your device.

How it is collected. The question is what you type into Ask. The child’s first name, sex and age come from the profile you filled in when you added them. The passage identifiers are chosen on your device before anything is sent.

Who it is sent to, and what they do with it. It goes to our own server, which passes it to Anthropic (the Claude API) for one purpose: wording the answer for you. Anthropic acts as our processor under contractual terms that require protection equivalent to our own, does not use the content to train its models, and retains it only briefly for abuse monitoring before deleting it. The facts, the sources and the “when to get help” guidance in every answer come from our own library, not from the AI.

You are asked first. The first time you open Ask, the app explains what is sent and to whom, and asks your permission. Nothing is sent unless you accept. If you decline, Ask still answers every question from the library on your device, non-personalised, and no request is made at all. You can change your mind at any time in Settings › Ask LittleStems.

Service providers

Changes to this policy

If we change how data is handled, we will update this page and its date. Material changes will be surfaced in the app rather than left here to be discovered.