In short: Sheina stores your baby's data in your account in the cloud (Google Firebase, region me-west1), so both parents see the same record and nothing is lost if you change phones. We do not sell your data to anyone, and the app has no analytics and no ads.
1. Who we are
Sheina AI is operated by PALATNIKS LTD ("we"), the data controller.
Privacy contact: hello@sheina.ai
2. Your account
An account is required to use the app. There is no anonymous mode. You sign in one of three ways:
- Apple, including "Hide My Email". The relay address Apple issues is stored as-is and works as an ordinary address.
- Google
- An emailed sign-in link (magic link), with no password. The link itself is a credential: whoever holds it can sign in.
We store your email address, first name, parent gender (Hebrew needs it to address you correctly), interface language, a user id (Firebase UID), the provider subject identifiers for the service you signed in with, and when the account was created.
We do not collect a phone number, a postal address or a parent's date of birth.
3. Your baby's details
Information you enter that describes your child:
- Name, date of birth, sex
- Gestational age at birth, for corrected-age calculations
- Birth weight and current weight
- A profile photograph, if you choose to add one
- Country — set when the baby's profile is created, from your device's region setting, and changeable at any time in Settings. It is stored as a field on the baby and is never re-sampled: changing your phone's region or travelling abroad does not change it. This is not location tracking — the app reads no GPS and requests no location permission. The country decides two things: which medical emergency number is shown, and whether the vaccine module appears at all — Sheina's vaccine schedule is the Israeli one, so outside Israel the Health vaccines card, the night-view shortcut, the profile vaccines row, the vaccine timeline in Reports and the vaccine entries in the journal are not shown. Vaccine records already logged are kept and are not deleted.
- Feeding method and any notes you write about it
- Day/night boundaries and engine preferences
4. The journal
- Sleep — settling start, onset, night wakes and returns to sleep, waking, day/night classification, extensions, tiredness signs you reported and any free text you added, mood on waking, settling method, the sound played, and a lateness reason if you gave one.
- Feeding — type, nursing duration per side, volumes, descriptions of solids, notes.
- Pumping — side, duration, volume. This is information about the parent's body.
- Diapers — type, duration, notes.
- Developmental events — teething, growth spurts, milestones.
- Free-text notes that you write.
5. Health information
Called out separately because it is sensitive:
- Body temperature readings
- Medications — name and dose
- Vaccinations, including any side effects observed and notes
- Growth measurements — weight, height and head circumference
This is stored only if you choose to record it. Under the GDPR it is a "special category" of data, and the lawful basis for processing it is your explicit consent, which you give by choosing to record it.
Sheina is not a medical device and does not diagnose. See the medical section of the Terms of Use.
6. Where your data is stored
In Google Firebase (Firestore, Authentication, Cloud Functions), in region me-west1 — Israel.
Your data is not kept on the device alone. Deleting the app removes the local copy only; the cloud copy remains until you delete your account. See section 13.
7. Family sharing
You can invite a second parent into your family. A parent who joins:
- can read, create, edit and delete every record for your baby — including records you created;
- sees who performed each action, by first name;
- sees a live indicator when the other parent has a sleep session open.
An invite link is a credential. Whoever holds it can join the family and see the whole record. Send it only to someone you mean to give full access.
You can send the invitation yourself (over WhatsApp, say) or ask us to email it. If you choose the second option:
- The address you enter is used solely to send that one invitation. We do not use it for mailing lists, for marketing, or for anything else.
- The email contains your first name, the link, the fallback code and the expiry. It does not contain your baby's name.
- We keep the address only while the invitation is pending, so you can see on your family screen where it was sent. It is deleted the moment the invitation is redeemed, revoked or expires, and it is never written to the audit trail.
- The address is visible only to you — the parent who created the invitation.
- We do not check whether the address already has a Sheina account, and we never report that either way.
8. Public share links
You can create a link that shares the journal — with a grandparent, a nanny or a sleep consultant, for example.
- The link requires no sign-in, so it exposes only the minimum needed for everyday shared care: your baby's first name, their age (not their date of birth), sleep records (times, durations, settling and night wakings), feeds (type, amount, duration and side) and diapers. Records are shown with the first names only of the parents who logged them.
- What the link does not expose: temperature, medication name and dose, vaccinations and their side effects, growth measurements, pumping records, development entries, and any free text you have typed — notes on a sleep, a feed, a diaper or a side effect. The filtering happens on the server against an explicit list of fields: a field not on the list is not sent, and a new field added to the app in future stays private unless it is deliberately added to that list.
- You can revoke it at any time from the app.
- It is revoked automatically if its creator stops being a parent of that baby, or deletes their account.
- It does not expire on its own — it works until it is revoked.
- It is rate-limited, and marked so search engines do not index it.
You decide who receives the link, and you are responsible for that choice.
9. Email
Resend is used to deliver service-related email messages.
Messages currently sent through this system include:
- Sign-in links — sent to your account email address.
- Family invitations — only when you ask us to send an invitation by email to the address you provide. See section 7.
The app also includes an optional “email tips and updates” preference. This preference is stored on your account and can be turned off at any time. If we enable optional tips, useful information or product updates through this mechanism in the future, they will be sent according to your stored preference, and you will be able to stop them through the app setting or an appropriate unsubscribe mechanism.
Turning off optional tips and updates does not prevent necessary service messages, such as sign-in links, verification messages or family invitations you ask us to send.
For email delivery, the provider receives the recipient email address and message content and may retain technical delivery logs according to its own policies.
Verification and email-address-change messages sent directly by Firebase Authentication are handled by Google.
We do not sell email addresses and do not use them for advertising tracking.
10. Payments
- RevenueCat manages subscription state. It receives your user id (Firebase UID) and purchase events from the store. It does not receive your name, your email or any baby data.
- Apple App Store and Google Play take the payment. We never see your payment details and have no access to them.
- We store only your subscription status, plan tier and trial end date.
11. Notifications
If you allow notifications we store a device token per install. Delivery is through Apple APNs and Google FCM, including iOS Live Activities on the lock screen.
Note that notification text contains your baby's name and the other parent's first name — "Dana put Noam down", for example. That content passes through Apple's and Google's notification infrastructure.
Notifications scheduled locally on the device (engine alerts, medication reminders) never reach a server.
12. Diagnostics and bug reports
- Firebase Crashlytics is active in released builds. If the app crashes, we may receive technical information such as the stack trace, platform, device model, operating-system version and app version. We do not attach your name, email address or journal content to these reports. Crashlytics may attach a technical installation identifier for crash grouping.
- Cloud Functions logs are stored in Google Cloud infrastructure and are used for operation, security and troubleshooting.
- If you choose to submit a sleep-calculation problem report from the app, the report will include the description you entered together with technical diagnostic data needed to reproduce the recommendation and investigate how it was calculated. This may include the relevant inputs used by the recommendation engine, the resulting recommendation, app version, device and platform information, language and timezone.
- A sleep-calculation diagnostic report does not include the baby's name or profile photo, parent names, email addresses, access keys, or information unrelated to reproducing the calculation. Technical identifiers may be replaced or hashed for diagnostic purposes.
- These diagnostic reports are retained for up to 90 days and are then scheduled for automatic deletion. They are not used for advertising, advertising tracking or sale of personal information.
The app contains no advertising, and we do not sell personal information.
13. Retention and deletion
Your data is kept while your account exists.
Deleting your account from Settings → Delete account:
- permanently deletes your sign-in account;
- removes your name, email, gender and other identifying details from your record;
- deletes your baby and their entire journal — unless another parent is in the family, in which case the shared record stays with them and you are removed from the family;
- revokes any open invitations and every share link you created;
- deletes notification markers and, immediately, every report you sent — both bug reports and sleep-calculation diagnostic reports.
The 90 days in section 12 is a retention ceiling, not a wait: the diagnostic reports of a deleted account are removed with the deletion itself and do not sit out the period.
Your own record is kept with the identifying fields removed, so that historical actions in a record left with your co-parent read as "a parent" rather than as an empty identifier.
What is deliberately retained: an audit trail of invitations you issued (who joined the family and when), and append-only correction and recommendation records that no client can delete.
Deleting your account does not cancel an active subscription. Cancel it in your App Store or Google Play subscription settings, or billing continues.
You can also write to hello@sheina.ai from the account's email address. We will act within 30 days.
14. Your rights
You may request access to your data, its correction or deletion, a copy of it, and you may object to or restrict processing. Write to hello@sheina.ai. If you believe we have not handled a request properly, you may complain to the supervisory authority in your country.
15. Security
Data is encrypted in transit and at rest by Google Cloud's infrastructure. Access is enforced server-side by security rules.
These are measures, not a promise of outcome: no online system can be guaranteed absolutely secure.
16. International processing
Your data is stored in Israel. RevenueCat, Resend and the app stores process data outside Israel as well, including in the United States.
17. Children
Sheina is for parents and carers, to record information about their own children. It is not designed for children to operate, is not marketed to children, and we do not knowingly collect information directly from children.
By entering information about a child you confirm that you are their parent or legal guardian, or that you have that person's permission.
18. Changes to this policy
We update this policy from time to time. A material change will be brought to your attention in the app or by email. The date of the last update appears at the top of this page.
19. Contact
Privacy questions: hello@sheina.ai