Last updated: 2026-06-15
Privacy Policy
Forever Yours is a private place for parents to follow their child's development, keep reminders, and store keepsakes. We built it to hold some of the most personal data a family has, so we keep the rules simple: we collect only what the product needs, we never sell it, we never show you ads, and we never use your content to train anything. This policy explains exactly what we process and the choices you have.
1. Who we are
Forever Yours is operated by Big Dreams Group LTD, a company registered in Bulgaria (UIC/EIK 206986388), with its registered seat at 42 Boulevard General Skobelev, Sofia, Bulgaria. We are the data controller for the personal data described here. You can reach us about any privacy matter at [email protected].
2. Who this applies to
This policy covers the Forever Yours website and the Forever Yours iOS and Android apps (together, the "Service"). The Service is for parents and is restricted to people 18 or older. We do not offer accounts to children and children do not interact with the Service directly - a parent enters everything about a child.
3. What data we process
For each parent account:
- Email address, display name, and (optionally) your role and timezone.
- A password, stored only as an argon2id hash - we never hold the plain text.
- Session records: a hashed session token, plus the IP address, browser/device user agent, and last-used time, kept so you can see and revoke active sessions.
- Family membership and invitation records linking co-parents to one family.
- Push notification tokens for any mobile app you install and grant permission to.
For each child profile:
- First name only - no surname is required.
- Date of birth, used to show age-appropriate developmental content.
- Any optional notes, avatar, or tracker entries you choose to add.
For photos you upload (drawings, keepsakes, bump photos):
- The image itself, re-encoded to WebP at a few sizes for display.
- EXIF metadata - including any GPS location - is stripped on upload and never stored.
- Any caption you add and the child or week you link it to.
For reminders, the pregnancy companion, and other features:
- Reminder and appointment text, the time it should fire, and any recurrence rule.
- Pregnancy details you enter (due date, nickname) and anything you record in the optional toolkit (see section 4).
- Baby name proposals and ratings, kept private between the parents in a family.
We also keep a minimal security log of state-changing actions (which account and family, the route, the result, the IP, and timing). These logs deliberately store identifiers and metadata only - the free text you type (notes, symptoms, reminder bodies) and anything credential-shaped is excluded or masked before anything is written.
4. Health-related information
Some optional pregnancy and baby features let you record information that may relate to health - for example a symptom journal, a contraction timer, kick counts, bump photos, doctor's appointments, or a newborn feed/sleep tracker. You are never required to use these. When you do, we process that information only on the basis of your explicit consent, store it within the EU, and show it back only to you and the co-parents you have chosen to share it with. Entries you mark private are visible only to you, right down to the stored image bytes. We never use this information for any purpose beyond showing it to you, and you can delete any entry at any time.
5. Why we process it, and our lawful bases
- To run the Service you signed up for - accounts, family, content, reminders, gallery, billing. Lawful basis: performance of our contract with you.
- To personalise content to a child's age and to store the child and health-related details you add. Lawful basis: your consent (and your explicit consent for any health-related information), which you can withdraw at any time by deleting the relevant data, the child profile, or your account.
- To keep the Service secure - the security log, abuse prevention, and rate limiting. Lawful basis: our legitimate interest in protecting families' data and the integrity of the Service.
- To send you transactional messages you have asked for - verification and password emails, family invitations, and the reminders and notifications you have switched on. Lawful basis: contract for essential messages and consent for the optional ones, which you control in Settings.
We do not run advertising, we do not sell or rent your data, and we do not carry out any automated decision-making that produces legal or similarly significant effects. Choosing which content to show based on a child's age is the only profiling we do, and it has no such effect.
6. Cookies and similar technologies
We use only the cookies the Service genuinely needs: a cookie that keeps you signed in, and (in the mobile apps) a marker that tells the web view it is running inside the app. Your cookie choice itself is stored locally in your browser, not on our servers. We do not run third-party advertising or cross-site tracking cookies. The mobile apps contain no analytics or tracking SDKs of any kind. If we ever introduce usage analytics, it will be a privacy-friendly, cookieless tool that loads only after you opt in.
7. Who we share data with
Your family's data is hosted on our own infrastructure in the EU. We rely on a small number of service providers that act only on our instructions and only to deliver the Service. We disclose them by category rather than steering you through a long vendor list:
- An email delivery provider, for transactional email.
- A payment processor, used only if you subscribe to a paid plan; it handles your card details directly, and we never receive your full card number. On iOS, subscriptions are purchased and processed through the App Store under Apple's terms.
- A push notification relay and your device's operating-system push service, used only to deliver the notifications you enable.
- A network provider that routes and secures public traffic to the Service.
We share only the minimum each provider needs for its task. We do not give your data to anyone for their own purposes. A current list of the specific providers we use is available on request to [email protected]. We may also disclose data where the law requires it, or to protect the rights and safety of families using the Service.
8. International transfers
Your account and content are stored in the EU. The only routine processing outside the EU/EEA is the delivery of transactional email and push notifications, and payment handling if you subscribe. Where a provider processes data outside the EU/EEA, that transfer is covered by appropriate safeguards - in practice, the European Commission's Standard Contractual Clauses.
9. How long we keep it
- Active accounts: kept until you delete the account.
- Deleted accounts: your account and all linked data (parents, children, reminders, photos, stored files, push tokens) are removed from primary storage within 30 days.
- Database backups: a rolling 30-day window, then deleted.
- In-app notification history: pruned after 90 days.
- Security logs: identifiers and metadata only, kept no longer than needed for security and abuse investigation (up to 12 months), then deleted.
10. How we protect your data
Passwords are hashed with argon2id and session tokens are stored only as hashes - we cannot recover either. Your photos are private: they are served only by our authenticated, family-scoped API, the underlying storage is not reachable from the public internet, and photos you mark private are withheld even from co-parents at the byte level. All external traffic uses HTTPS, and the application is not exposed directly to the internet - it sits behind a private network tunnel. No system is perfectly secure, but we treat children's data as load-bearing, not an afterthought.
11. Your rights
Under the GDPR and Bulgarian law you have the right to:
- Access and portability. Sign in and use Export my data in Settings to download a machine-readable archive of your family's data plus every photo.
- Erasure. Use Delete account in Settings; deletion follows the timeline in section 9.
- Rectification. Edit any field directly from Settings.
- Withdraw consent. Where we rely on your consent, you can withdraw it at any time - by turning off a feature or notification, deleting the data, or deleting your account - without affecting processing already carried out.
- Object and restrict. Email [email protected] with the specific processing you object to.
- Complain to a supervisory authority. In Bulgaria this is the Commission for Personal Data Protection (2 Prof. Tsvetan Lazarov Blvd, Sofia 1592). You may also complain to the authority in your own country of residence.
12. Children's data
The Service is for parents and accounts are restricted to people 18 or older. A child profile contains only what you, the parent, choose to enter, and you control it on the child's behalf. Children cannot create accounts or sign in. If you believe a child has created an account, contact us and we will remove it.
13. Mobile app permissions
The apps request only what their features need: the camera and your photo library, so you can add photos of drawings and keepsakes, and notifications, so we can deliver reminders you set. The apps do not request your location, microphone, or contacts, and they carry no advertising identifier. You can change any of these permissions in your device settings at any time.
14. Data breaches
If a personal-data breach occurs that is likely to result in a risk to your rights, we will notify the supervisory authority within 72 hours where required, and we will tell you directly without undue delay if the risk is high.
15. Changes to this policy
When we change this policy, we update the "last updated" date above, and we email all account holders if the change is material.
16. Contact
Questions, requests, or complaints - [email protected].
