Peekaboo helps you check food and bath time products for your little ones. This page explains what data the app touches, what it never touches, and the choices you have. We wrote it to be read, not skimmed past.
Effective date: August 26, 2026
Everything about your child stays on your phone. Your child's profile (name, birth month and year, allergies, skin conditions) is stored only on your device, in an encrypted store, and is never sent to our servers. Our cloud database has no place to put child data, by design.
When you check a product, the photo or barcode goes to our server just long enough to analyze the product itself. The request carries no information about your child. Personalization ("flagged for your child's milk allergy") happens on your phone, after the answer comes back.
If you sign in, your shelf scan photos are saved privately to your account so your history can follow you to a new phone. Only you can see them.
Peekaboo is operated by Alen Faljic s.p., Ulica Iva Standekerja 7, 2000 Maribor, Slovenia, the data controller for the processing described here. You can reach us at hello@d.mba.
Child profiles never leave your device. That includes:
On the phone, this data sits in a local store encrypted with 256 bit AES. The encryption key lives in the iOS keychain in a device only class, so phone backups contain only unreadable ciphertext and the key never moves to another device. To remove this data, delete the child profiles in the app or delete the app itself.
To be precise about what this is and is not: this is not "end to end encryption" of data in transit, because the data is simply never transmitted. It stays where you put it.
The app works with an anonymous account at first. If you add your email, we use it to sign you in with a one time code and to let you get your check history back on a new phone. We do not send marketing email to this address unless you separately ask for it.
So your history follows you across devices, we sync a small record of each check: the product's barcode or a generated id, name, brand, category, score, verdict, a product image link, and a timestamp. We also sync household preferences: dietary choices (for example vegetarian), country, language, a recall alerts toggle, and whether onboarding is done. Shelf scans sync too, including the shelf photo, so past scans can be restored on a new phone (see "Shelf photos" below). Photos from single product checks are not uploaded with your history. Each record is protected by row level security, meaning only your account can read or write your rows.
When you check a product, the app sends the photo, the barcode, or the product name you typed, plus your country and language, to our server for analysis. During analysis, photos are processed transiently: they are used to produce the answer, and the analysis step keeps nothing. Photos from single product checks are not saved on our servers. Shelf photos are saved to your account when you are signed in, as described next. See "AI processing" and "Caching" below for the details.
When you are signed in and scan a whole shelf, the shelf photo is saved to your account together with the scan's results, so you can reopen past shelf scans and restore them when you switch phones. These photos are personal to your account: row level security means only you can read them. We never share them with anyone, never use them to train AI models, and never use them for anything except showing you your own scan history. Deleting a shelf scan in the app, or deleting your account, permanently removes the photo.
If you subscribe to Peekaboo Pro, Apple processes the payment. We receive only your subscription status (active or not, which product, when it expires) so we can unlock unlimited checks. We never see your card number or billing details. Subscription management uses RevenueCat (see the provider list below).
To keep bots and abusers from draining the service, the app uses Apple's App Attest. Your device proves to our server that requests come from the genuine Peekaboo app. We store a device key identifier and a counter for this purpose, plus per device usage counts (how many checks, how fast) to enforce fair use limits. These signals identify a device installation, not your name.
Like nearly every online service, our infrastructure processes IP addresses and basic request metadata in transit and keeps short lived technical logs for security and debugging. We do not use these for advertising or profiling.
Peekaboo's answers are generated by Claude, an AI model operated by Anthropic in the United States. When you check a product, the photo or barcode and the product information are sent to Anthropic to identify the product and research its ingredients, including running a web search against public sources. The request contains nothing about your child.
Anthropic processes these requests to provide the service and, under its commercial API terms, does not use them to train its models. Because Anthropic is in the United States, this transfer of the scan image out of the EU is protected by the European Commission's Standard Contractual Clauses under our data processing agreement with Anthropic.
To make checks fast and affordable, the result of a clean barcode check (barcode only, no photo, no typed text) is cached for up to seven days, keyed by the barcode, country, and language. These cached product cards are generic: they contain no user identity and no child data, just the product analysis any parent would get. Photos never enter this shared cache. Photo checks are answered live. The only place a photo is kept is your own account's shelf history, described under "Shelf photos" above.
Separately, if a check finishes while your phone has dropped the connection (for example the app was backgrounded mid check), the result is parked for about ten minutes under your account so the app can pick it up when it retries, without charging you a second check.
| Provider | Role | Region |
|---|---|---|
| Cloudflare | Hosts our API (Workers), the result cache, and usage counters. Processes IP addresses in transit. | Global edge network |
| Supabase | Account database: your email, sign in sessions, and synced history, saved items, preferences, and shelf photos. | EU (Frankfurt, Germany) |
| Anthropic | AI analysis of product photos and product data (see "AI processing"). | United States (SCCs) |
| Resend | Sends the one time sign in codes to your email. | United States (SCCs) |
| Apple | App distribution, App Attest device integrity, and all subscription billing. | Per Apple's terms |
| RevenueCat | Subscription status management (being added; active once subscriptions launch). | United States (SCCs) |
| Netlify | Hosts this website (peekabooapp.net). Standard web server logs. | United States (SCCs) |
Data about your child is entered by you and stays on your device. It is never transmitted to us, so we do not process it as a controller or a processor. You stay in control of it entirely.
Under the GDPR you can ask us for access to your data, correction, deletion, restriction, portability, and you can object to processing based on legitimate interests. Write to hello@d.mba and we will respond within the legal deadline. You also have the right to complain to a supervisory authority, either where you live or where we are established.
Deleting your account: the app has a built in "Delete account" action. It permanently removes your server side data (account, history, saved items, shelf photos, preferences) and cannot be undone. Data on your phone, including child profiles, is under your control: it is removed when you delete the app. If you have an active subscription, cancel it in your App Store settings; deleting the account does not cancel Apple billing.
Peekaboo is an app for parents and caregivers. It is not directed at children, and you must be an adult to use it. We do not knowingly collect personal data from children. The information you enter about your child never leaves your device, as described above.
All connections use TLS encryption. Child profiles are encrypted at rest on your device. Server side data is protected by per user row level security, and our API accepts requests only from authenticated sessions on devices that pass Apple's App Attest integrity check.
If we make material changes to this policy, we will notify you, in the app or by email, before they take effect, and update the effective date above. Continued use after the effective date means the updated policy applies.
Questions about privacy: hello@d.mba
See also our Terms of Use and Support page.