Privacy Policy
Last updated: 11 August 2026
1. Scope
This Privacy Policy describes how Lullaby collects, uses, discloses, and protects information when you use the Lullaby mobile app, our support pages, and related services. Lullaby helps you and a room-mate discover baby names you both like.
Lullaby is operated by Solardev, a sole proprietorship (eenmanszaak) established in the Netherlands. Solardev ("we", "us") is the controller responsible for the personal data described in this policy.
Lullaby is offered internationally and may appear under a localised name depending on your region — for example, Droomnaam for users in the Netherlands. More localised names may be added over time. This Privacy Policy applies to the same app whichever of these names you use it under.
2. Information we collect
- Account and identity information: when you sign in with Apple or Google we receive and store your name, email address, a profile image if your provider supplies one, authentication identifiers, and the internal account ID we use to manage your account. We never ask for or store a password — sign-in is handled entirely by Apple or Google.
- Session and device information: to keep you signed in and to protect your account, we store session tokens and related metadata, including your IP address and device/browser user-agent.
- Name activity: the names you react to (like or dislike), the names you favourite, the name sets you select, and the feed filters you save.
- Rooms: the rooms you create or join, your membership in them, and the invite codes used to connect you with a room-mate.
- Subscription information: if you purchase Lullaby Premium, we store your subscription and entitlement status and related purchase events. Payment is processed by Apple — we do not receive or store your full payment card details. See "Subscriptions and payments" below.
- Support information: details you provide when you contact us for support, privacy requests, or legal inquiries.
- Usage and diagnostic data: the app sends pseudonymous product-analytics and crash-diagnostic events, which are never linked to your account. See "Analytics and diagnostics" below for exactly what these contain.
3. How we use information
- Provide sign-in and account management.
- Build your name feed and remember your reactions, favourites, selected name sets, and filters.
- Connect you with a room-mate and surface the names you both like (your matches).
- Provide and manage Lullaby Premium and your subscription entitlement.
- Maintain service security, detect abuse, and prevent fraud.
- Measure, in aggregate, how the app is used and where it fails, so we can fix bugs and improve it.
- Provide support and respond to your requests.
- Comply with legal obligations and enforce our terms.
4. Analytics and diagnostics
We use PostHog to measure how the app is used and to find out when it breaks. PostHog processes this data on our behalf as a data processor, on its EU Cloud infrastructure in the European Union.
This data is pseudonymous and is never linked to your account. The app generates a random identifier that is stored on your device and sent with each event, so that we can tell one device apart from another and count how often something happens. The app is deliberately configured so that this identifier can never be connected to your account: the analytics SDK's user-identification features are switched off in our code, and no account ID, name, or email address is ever sent with an event.
What is sent:
- Events describing what happened in the app — for example that a name was liked or disliked, a name was favourited, a room was created, joined or left, an invite was shared, the premium paywall was shown or a purchase completed, an onboarding step was finished, the app language was changed, or the rate-the-app prompt was shown or dismissed.
- Non-identifying context on those events — such as counts (how many names you have liked, how many name sets you selected), whether a feed filter is set rather than what you typed into it, which name genders you chose to see, whether you signed in with Apple or Google, and which screen an action started from.
- Screen views and app lifecycle events — which screens are opened, and when the app is installed, updated, opened, or sent to the background.
- Technical context — app version and build, operating system and version, device type and model, language/locale, and analytics SDK version.
- Crash and error diagnostics — when the app hits an unexpected error, the error message and technical stack trace, so we can fix it.
What is not sent:
- your name, email address, profile image, account ID, or session tokens;
- the specific names you react to or favourite, and the invite codes you use;
- your location — we have turned off location lookup from IP addresses, and IP addresses are discarded rather than stored with analytics events;
- screen or session recordings — session replay is switched off;
- any advertising identifier. We do not use analytics for advertising, we do not track you across other apps or websites, and we do not share this data with advertisers or data brokers.
Because these events are pseudonymous, we cannot connect them back to you. That also means we cannot single them out to erase when you delete your account — they contain nothing that identifies you. Analytics events are kept only as long as they are useful for product analysis.
There is currently no in-app switch to turn analytics off; we are adding one. In the meantime, if you want to object to this use of your data, contact us at lullaby@solardev.io.
5. Subscriptions and payments
Lullaby offers an optional auto-renewing subscription, Lullaby Premium. Purchases are made through the App Store and processed by Apple under your Apple ID — we never see your full payment details. We use RevenueCat as our subscription management provider: to track your entitlement we share a user identifier with RevenueCat and receive your purchase and subscription status in return. RevenueCat acts as a data processor and processes this information solely on our behalf. Apple's and RevenueCat's own privacy notices govern how they handle payment and purchase data.
6. Legal bases (where applicable)
Depending on your location, processing is based on one or more of the following: performance of our contract with you, our legitimate interests, your consent, and compliance with legal obligations. We rely on our legitimate interest in understanding and improving our own app for the pseudonymous analytics and crash diagnostics described above; that measurement is first-party only and is not used for advertising or profiling.
7. Data sharing and tracking
We do not sell or rent your personal data, and we do not track you across third-party apps or websites for advertising. We share information only with the service providers needed to run Lullaby — such as hosting, authentication (Apple, Google), subscription management (RevenueCat, Apple), and analytics and crash diagnostics (PostHog) — and only as far as that requires. We may also disclose information where required by law, to protect rights, safety, and security, or in connection with a corporate transaction subject to lawful safeguards.
8. International data transfers
Information may be processed in jurisdictions outside your place of residence. Where required, we apply appropriate safeguards for cross-border transfers. Analytics and crash-diagnostic data is processed on PostHog's EU Cloud infrastructure inside the European Union.
9. Data retention and account deletion
We keep your data for as long as necessary to provide the service and as required for legal, security, and dispute-resolution purposes.
You can delete your account at any time from within the app. Deleting your account permanently removes your profile, linked sign-in records, reactions, favourites, selected name sets, feed filters, and the rooms you own, except where limited retention is required by law. If you signed in with Apple, deleting your account also revokes Lullaby's Sign in with Apple grant. Pseudonymous analytics events are not covered by this deletion, because they are not linked to your account and cannot be traced back to you — see "Analytics and diagnostics".
10. Your choices and rights
Depending on your jurisdiction, you may have rights to access, correct, delete, restrict, or object to the processing of your personal information, to data portability, and to withdraw consent where processing is consent-based. You can exercise many of these directly in the app — including account deletion — or by contacting us at lullaby@solardev.io.
11. Children's privacy
Lullaby is intended for adults planning or choosing baby names and is not directed to children under the age required by local law to provide valid consent. If we become aware that we have collected personal information from a child without appropriate consent, we will take steps to delete it.
12. Security
We use administrative, technical, and organizational safeguards to protect your information. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
13. Third-party services
Lullaby integrates with third-party providers, including Apple and Google (sign-in), Apple (payments), RevenueCat (subscription management), and PostHog (analytics and crash diagnostics). Their handling of your data is governed by their own terms and privacy notices.
14. Changes to this policy
We may update this Privacy Policy. Updated versions are effective when posted, and material changes may be additionally communicated through the app or service.
15. Contact
Privacy inquiries and requests: lullaby@solardev.io
General support: lullaby@solardev.io
Also review our Terms of Service.