Baby tracker privacy in Australia: where the data goes, and what to ask

Where is my baby tracker data stored, and who can see it?

It depends on the app, and most do not say plainly. BubSync keeps account and activity data in AWS Sydney, sells nothing, runs no ads, and shows data only to people you invited, by role, or to whoever holds a 24-hour handover link you sent. Any app worth trusting answers the same four questions in its policy.

Where it sits

Primary data in Sydney. Some delivery and routing metadata crosses borders, and the policy says which.

Who sees it

The people you invite, in the role you gave them, and anyone you send a 24-hour handover link to. Never an advertiser.

Best for

Parents choosing an app, parents already using one who never read its policy, and anyone asked by a partner "is this safe?"

What does a baby tracker actually collect?

More than the feeds. A tracker holds an account (usually an email address), a profile for each baby including a date of birth, every activity logged against that baby, any photos attached to memories, the push-notification token of every device, and technical diagnostics when something goes wrong. Taken together that is a detailed record of a named child’s first year, tied to an adult’s identity.

BubSync collects those categories and says so in its privacy policy, section by section. Two details are worth knowing because they are unusual. Every photo is re-encoded on your phone before it is stored or shared, which strips camera details and GPS location from the file. And the app does not collect precise location at all: no entry carries a place, and nothing asks for one.

Where is the data physically stored?

BubSync’s primary account, family and activity data is hosted and processed in AWS ap-southeast-2, which is Sydney. That is where the database lives, where photos for Premium families are held encrypted, and where the AI features run by default.

It would be dishonest to stop there, so the policy does not. Delivering the website and app involves global content-delivery and routing services, so connection metadata such as an IP address, a timestamp and a browser identifier can be processed outside Australia. And when you ask the AI hub for a schedule or a summary, the structured summary of recent feeds, sleep and nappies it sends as context runs primarily from Australia but may be routed through another region when a model is unavailable locally. The stored record, the database that holds your baby’s day, stays in Sydney; the exception is that summary, for the moment it takes to answer you.

What does the Privacy Act 1988 ask of an app like this?

The Act sets out thirteen Australian Privacy Principles. The ones a parent should care about are easy to name: an entity must be open about what it does with personal information, collect only what it reasonably needs, tell you at the point of collection, use the information only for the purpose it was collected, take reasonable steps to secure it, give you access to it and correct it on request, and be accountable for anything it sends overseas. Since 2018, the Notifiable Data Breaches scheme has also required a breach likely to cause serious harm to be reported to the affected people and to the Office of the Australian Information Commissioner.

BubSync’s privacy policy commits to those principles and to the breach-notification scheme in its own words, and it is written to be read rather than clicked past. What the Act does not do is tell you where a company’s servers are, whether it sells data, or how long deletion takes. Those are the questions a policy has to answer for itself, which is why the four below are worth asking of every app.

Who can see what, once you start sharing?

Sharing is where most privacy questions about a baby tracker actually live, because the risk is rarely a stranger and usually a relative. BubSync answers it with roles. An invite asks who the person is: a parent, family, a carer, or a mix you define, and which babies they should see. A carer sees and logs activities for those babies only. Family can be given the memories and nothing else. Any single entry can carry its own answer to who can see it, and a memory can be set to Only me.

Removing someone is as plain as inviting them: a carer who loses access is told what they can no longer see, and everyone logs from their own account, so removing one person never means changing a password everyone else shares. The one deliberate exception is the 24-hour handover link. It opens for anyone who has it, for 24 hours, so it should be sent only to someone you would show that page to in person.

What never happens to your data?

It is not sold, and it is not used for targeted advertising; the policy says both in plain words. It is not used to train AI models: the AI hub sends structured summaries of recent activity as context to produce an answer for you, and under BubSync’s current arrangements those prompts and outputs are not used to train the underlying models. BubSync also takes no money from formula, pharmaceutical or employer-benefits companies, which matters in a category where the free app is sometimes paid for by someone who would like to sell you something.

Deletion is spelled out too. Deleting your account requires a one-time code sent to your email on top of the confirmation, so a stray tap cannot erase a family. Active data is removed within 30 days of the request being processed, and encrypted disaster-recovery backups expire within 35 days.

What should you ask any baby tracker before you trust it?

Four questions, all answerable from a privacy policy in about ten minutes. If a policy cannot answer one of them, that is the answer.

  • Where is the data physically stored, and what crosses borders?
  • Who is it shared with, and is it sold or used for advertising?
  • How does deletion work, how long does it take, and what about backups?
  • Once I share with someone, what exactly can they see, and how do I take it back?

The four questions, answered for BubSync

The four questions, answered for BubSync
QuestionBubSync’s answerWhere it is written
Where is the data stored?Primary data in AWS ap-southeast-2 (Sydney). Delivery metadata may be processed elsewherePrivacy policy, section 4
Is it sold or used for ads?No, on both counts. No advertising, no advertising audiencesPrivacy policy, sections 3 and 8
How does deletion work?An emailed one-time code, then removal within 30 days; backups expire within 35Privacy policy, section 9, and the FAQ
Who can see it once shared?Invited people, by role, scoped to chosen babies, plus anyone holding a 24-hour handover link you sent; any entry can overridePrivacy policy, section 7, and the features page

Summarised from the BubSync privacy policy dated 30 August 2026. The policy is the binding document; this table is a reading guide to it.

Frequently asked questions

Is BubSync data stored in Australia?
The stored data, yes. Primary account, family and activity data is held in AWS ap-southeast-2, which is Sydney. Two things can be processed elsewhere: connection metadata such as an IP address, through the global content-delivery services that serve the website and app, and the structured activity summary sent to the AI hub when you ask it for something, which runs primarily from Australia but may be routed through another region when a model is unavailable locally.
Does BubSync sell data or show ads?
No. BubSync does not sell personal data, does not use it for targeted advertising, runs no ads in the app or on this site, and takes no money from formula, pharmaceutical or employer-benefits companies.
Is BubSync GDPR compliant?
BubSync is built around GDPR and Australian Privacy Act principles, including access and deletion rights. The privacy policy carries the current details on storage, retention and your rights.
Are my baby’s photos private?
Every photo is re-encoded on your device, which strips location and camera details. On the free plan photos stay on the device and are never uploaded. On Premium they sync encrypted to the family, and each memory carries its own audience: the family by default, or Parents only, Only me, or the people you name.
Is a handover link private?
It is unguessable and unlisted, but anyone who has it can open it for 24 hours without an account. Send it only to the person who is looking after your baby that day, the same way you would hand them a written note.
What happens when I delete my account?
Deletion needs a one-time code emailed to your verified address on top of the confirmation. Active account data is removed within 30 days of the request being processed, and encrypted disaster-recovery backups expire within 35 days. Store subscriptions are cancelled separately in the App Store or Google Play.

Written by the BubSync editorial team. Not yet reviewed by an independent clinician. The editorial policy says who writes these pages and how their figures are sourced. Read how we write and check these pages.

General information only, not legal advice. The Privacy Act 1988 and the Australian Privacy Principles are summarised here in plain language; the Office of the Australian Information Commissioner publishes the full text. For how BubSync handles data, the privacy policy is the document that binds us, not this guide.

Baby tracker privacy: where your data is stored

Save this for later

Pin this page to a board and it will be waiting when you need it — at 3 am, or at the next appointment.

Save to Pinterest