Privacy Policy

Last updated: August 2026. This privacy policy covers the GrowwW app and the website www.growww-app.com. It replaces the February 2024 version, which still named service providers we no longer use.

1. Controller

The controller under the General Data Protection Regulation (GDPR) is:

Becomyng GmbH
Feierabendstr. 31
85764 Oberschleißheim
Germany
Email: service@growww-app.com

Full provider details: imprint. Please direct privacy enquiries to the address above.

2. What GrowwW is — and what that means for your data

GrowwW guides parents through starting solids. You provide data about yourself and your child. We process it for the app, security, analytics, support and communication purposes described in this policy. We do not sell it or share it for third-party advertising.

3. Encryption and on-device storage

Traffic between the app, the website and our servers is encrypted throughout (TLS). On the website you can see this from the “https://” in your browser's address bar.

The app stores identifiers and details classified as sensitive in the operating system's protected keystore where possible (iOS Keychain or Android Keystore). For existing installations, or if secure storage is technically unavailable, the app may fall back to local app storage. Protect your device with a passcode or biometrics and current system software.

4. What data we process

4.1 Account

An account requires your email address and a password. We never store the password in plain text, only as a cryptographic hash. You may optionally give a first name.

Legal basis: performance of the contract, Art. 6(1)(b) GDPR.

4.2 Details about your child

So the app can show the right steps, it records:

  • the child's name or nickname,
  • date of birth or age,
  • optionally an avatar image,
  • where you currently are with starting solids (your answers during setup),
  • which foods, allergens and articles your child has been introduced to,
  • whatever you write in the diary — that text is entirely yours.

Legal basis: your consent, Art. 6(1)(a) GDPR. Where what you enter counts as health data — a known allergy, say, or a reaction to a food — the processing rests on your explicit consent under Art. 9(2)(a) GDPR. We collect two separate consents for that, because the two situations are not alike:

  • What you tell us during onboarding (a known allergy, an increased allergy risk): we ask once, during onboarding. Giving that consent is optional — you may decline it and keep using the app; without it we do not ask about a known allergy or an increased risk, and so cannot warn you accordingly. You may withdraw it at any time in the app under Settings → Privacy.
  • Reactions you log: if your child reacted to a food, you can record that in the app. Before the first entry is stored we ask you once, explicitly, for your consent; after that we do not ask again. We deliberately do not put the recording itself behind a setting, because it serves a protective purpose: while a reaction is on record, we keep that food out of your suggestions. If you go through the emergency path, we store the reaction without asking first — the legal basis is then Art. 9(2)(c) GDPR (protection of vital interests). Withdrawal: you delete the reaction history in the app under Settings → Privacy. Because an entry only has effect while it is stored, withdrawal here means deletion — afterwards a food your child reacted to can be suggested again.

Withdrawal takes effect for the future in both cases: we then process no further health information. The withdrawal does not affect the lawfulness of processing based on consent before its withdrawal. It does not affect onboarding information already stored — you delete that individually in the app, or together with your account.

4.3 Technical data while using the app

Operation produces: operating system and device type, app version, language and region, time zone, installation and registration time, and the IP address of the connection. We use these to render the app correctly on your device, to narrow down faults, and to detect abuse.

Legal basis: our legitimate interest in a working, secure service, Art. 6(1)(f) GDPR.

4.4 Subscription

Paid content is bought as an in-app purchase through the Apple App Store or Google Play. We neither collect nor see payment data — it stays with the store. We receive your subscription status (active, start, end, and where applicable the reason it ended) in order to unlock content.

Legal basis: performance of the contract, Art. 6(1)(b) GDPR.

4.5 Website

When you visit the website, our hosting and security services process standard server-log data (address requested, time, volume transferred, referring page, browser and operating-system identifiers, and IP address). Analytics cookies are set only with your consent — details in the cookie policy.

4.6 Advertising measurement and app tracking

We advertise GrowwW on Meta platforms (Facebook and Instagram). So we can tell whether those adverts work, the app can pass usage events and your device's advertising identifier to Meta. This happens only if you have agreed to analytics and, on iOS, allowed tracking in Apple's App Tracking Transparency dialog. We store your answer to that dialog so that we do not ask again. If you decline either one, no advertising data is sent. On Android, your analytics consent alone governs it.

Legal basis: your consent, Art. 6(1)(a) GDPR. You can change your analytics consent at any time in the app's privacy settings, and the tracking permission in your iOS system settings.

Meta as joint controller. For the collection of this data and its transmission to Meta, we and Meta Platforms Ireland Limited (Merrion Road, Dublin 4, D04 X2K5, Ireland) are joint controllers under Art. 26 GDPR. We have entered into Meta's Controller Addendum with them, which sets out which of us is responsible for which GDPR obligation. Meta's processing of the data after that transmission is Meta's own responsibility and is not part of the joint processing.

We are responsible for informing you about the joint processing — which is what this section does. Meta is responsible for enabling your rights of access, rectification, erasure, restriction, portability and the related rights under Art. 15–20 GDPR for the data Meta stores after the transmission. You can exercise those rights directly against Meta. If you address them to us instead, we will forward your request to Meta within seven days; we are not permitted to answer on Meta's behalf.

The information required by Art. 13(1)(a) and (b) GDPR about Meta, further detail on how Meta processes the data, the legal basis Meta relies on, and the ways to exercise your rights against Meta are set out in Meta's privacy policy.

5. Service providers we use

We use the service providers below. Depending on the service, they act as processors or under their own data-protection responsibility. We put Art. 28 GDPR agreements in place where required. For third-country transfers we use the applicable adequacy decision (including the EU-US Data Privacy Framework) or appropriate safeguards such as the EU standard contractual clauses.

AreaProviderWhat for
Database and sign-inSupabase Pte. Ltd, Singapore (with Supabase, Inc., USA as an affiliated company)Account, authentication, and the content described in 4.1–4.2
HostingVercel, Inc., USARunning the website and the app's server endpoints
Abuse preventionUpstash, Inc. (EU region)Briefly limiting requests per account to prevent misuse of our interfaces
Media deliveryCloudflare, Inc., USADelivering publicly available images and media
Subscription managementRevenueCat, Inc., USASubscription status from the app stores
Messaging and pushCleverTap, Inc. (EU region)Product emails and push messages, where you have agreed to them
Email deliveryTwilio SendGrid, USATechnical delivery of our email
In-app usage analyticsAmplitude, Inc., USAAggregate analysis of which parts of the app are used
Website analyticsGoogle Ireland Limited / Google LLCGoogle Analytics 4, only after consent
Advertising measurementMeta Platforms Ireland LimitedMeasuring our adverts for GrowwW on Facebook and Instagram — see 4.6, only with your consent
Error monitoringFunctional Software, Inc. (Sentry), EU regionDetecting technical faults
SupportZoho CorporationHandling your support requests
Weekly recapGoogle Ireland Limited / Google LLC (Google Cloud)Generating the weekly recap — see section 6

For Sentry, we use technical filters intended to remove credentials, tokens and comparable values from event data before transmission. Error reports may still contain technical identifiers and usage context.

No longer in use and therefore removed from this policy: Backendless as hosting provider, Klaviyo as email sender, and Google Tag Manager, Google Ads Remarketing, Google Analytics for Firebase and embedded YouTube content.

6. The weekly recap

Once a week, GrowwW may generate a short recap text in the diary using a language model on Google Cloud infrastructure. Depending on use, the input may include language, journey stage, dietary details, the number and content of relevant diary events, newly introduced foods and allergens, and an excerpt from the previous recap. A name, email address or free-form contact details are not needed for text generation and should not be included in the prompt.

The text is a summary, not an assessment. There is no automated decision with legal effect within the meaning of Art. 22 GDPR; no medical assessment is produced and no recommendation is derived that is meant to replace a clinical judgement. For every recap we store the inputs it was based on, so that we can review its quality later.

Legal basis: performance of the contract, Art. 6(1)(b) GDPR; where details under 4.2 are involved, your consent under Art. 6(1)(a) and Art. 9(2)(a) GDPR.

7. Email and push messages

We send you messages about the product, for instance about the week ahead. Whether and how you receive them can be changed in the app's settings at any time, and every email carries an unsubscribe link. Push messages require permission from your operating system.

We record whether an email was opened and whether a link was clicked, so we can tell which messages are read at all. You may object at any time at service@growww-app.com.

Legal basis: consent under Art. 6(1)(a) GDPR; for messages about our own similar products to existing users, also § 7(3) UWG together with Art. 6(1)(f) GDPR.

8. Retention and deletion

We keep your account data while the account exists. You can request deletion in the app. A self-service request is technically scheduled for 24 hours and then executed. The sign-in account is deleted and the operational record is anonymised or stripped of directly identifying details. Data held by integrated providers is deleted, anonymised or disassociated according to their applicable deletion and retention processes.

Excepted is data we must retain for legal reasons — in particular records subject to tax or commercial retention periods (typically six to ten years, § 147 AO, § 257 HGB). We block such data from further use.

We retain technical logs and error reports only for as long as needed for security, fault analysis and legal evidence. Specific periods depend on the data type and provider configuration.

9. Age of users

GrowwW is for parents and guardians aged 18 or over. An adult enters the details about the child; the child does not use the app. If we learn that a minor created an account, we will review and suspend or delete it.

10. Your rights

You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), and objection to processing based on a legitimate interest (Art. 21). Consent once given can be withdrawn at any time with effect for the future (Art. 7(3)); for the consent covering health details about your child, section 4.2 sets out how.

Write to service@growww-app.com. We reply within the statutory period of one month.

You may also lodge a complaint with a supervisory authority (Art. 77 GDPR). The authority responsible for us is the Bayerisches Landesamt für Datenschutzaufsicht, Promenade 18, 91522 Ansbach, Germany. You may equally approach the authority where you live.

11. Changes to this policy

When the app, the website or the legal position changes, we update this policy. The version in force is always at growww-app.com/en/privacy; the date at the top shows how current it is.