Privacy policy

Last updated: July 2026

Who I am

I'm Scott Wittrock, an independent developer. I built Cleo (a family of apps for parents) as a solo project. Cleo currently includes Cleo Track (a baby tracking app for feedings, diapers, and sleep), Cleo Routine (a visual routine builder for toddlers), Cleo Plan (family meal and task planning for the web), and Cleo Connect (a connector that lets you bring your Cleo data to the AI tools you choose). If you have any questions about this policy, you can reach me at scott@cleofamily.app.

What I collect

Cleo Track, to make tracking work across devices, I collect the following:

  • Your email address: used to create your account and sign you in. The account belongs to you as the parent or guardian; see “Children's data” below.
  • Tracking data: feedings, diaper changes, sleep logs, and medicine records that you enter into the app. This data is stored securely via Supabase so it syncs across your devices and with your partner.
  • Child profiles: a child's name and birthday that you enter. The name is a personalization label stored under your account (for example, greetings in the app). I do not use a child's name for analytics, advertising, profiling, or any purpose other than showing it to you in the product. The birthday supports the tracking features you use.
  • Profile photos: if you upload a photo for yourself or your child, it's stored in a shared image location used across the Cleo apps, so the same photo shows up anywhere that person is pictured. It is never used for analytics, advertising, or any purpose beyond display in the product, and you can remove it anytime from Account or child settings.

Cleo Plan, to make planning work for your whole family, I collect the following:

  • Your email address: used to create your account and sign you in. As with Cleo Track, the account belongs to you as the parent or guardian.
  • Family member names: names that you enter so meals and tasks can be assigned to people. Like child profiles in Cleo Track, these are display-only labels stored under your account, never used for analytics, advertising, or profiling.
  • Meal plans, dishes, and tasks: the plans you create, shared with the family group you set up.
  • Nutrition log entries: the food descriptions you log and their estimated calories and protein. Your nutrition log is private to you: meal plans are shared with your family, but your log is not.
  • Dietary preferences: plain-text notes you add per family member (restrictions, preferences, foods to avoid). These are stored under your account and used only to inform AI-generated meal and task suggestions within the app. They are never used for advertising or profiling.
  • Family & personal context: optional freeform notes you write about yourself (“About you”) or your family (“About your family”) in Settings. Like dietary preferences, these are used only to inform AI-generated suggestions (meal and task ideas, and the optional daily recap email) and are never used for advertising or profiling.
  • Fridge & pantry overview: an optional, freeform note of what's in your family's fridge and pantry, family-shared like the fields above. You can write it yourself, or it's appended automatically when you check off a grocery item. It's used only to inform meal-planning suggestions.
  • Profile photos: if you upload a photo for yourself or a family member, it's stored in a shared image location used across the Cleo apps, so the same photo shows up anywhere that person is pictured. It is never used for analytics, advertising, or any purpose beyond display in the product, and you can remove it anytime from Settings.

Cleo Connect, depending on which optional features you turn on, I collect the following:

  • Your phone number: stored against your account when you verify it. Used only to send and receive SMS messages you initiate. Explicit consent is captured at the time you link the number. You can unlink it anytime in Connect settings, or opt out by texting STOP.
  • Connected calendars: if you link a Google Calendar account, I store the OAuth connection (encrypted) and which calendars you selected. Event details themselves are fetched live each day to inform your daily recap and are never stored or logged anywhere. You can unlink an account anytime in Connect settings.
  • Photos you attach in Cleo Voice: if you attach a photo (for example, a grocery receipt or a school flyer), it's sent to Anthropic so Cleo can read and act on it. The photo itself isn't stored after that reply; only a plain-text note of what happened (like “added milk to the grocery list”) stays in your conversation history.

Cleo Routine does not require an account. It does not collect personal data, email addresses, or tracking data. All routine data is stored locally on your device.

What I don't collect

  • No location data.
  • No advertising identifiers, and no data shared with advertising networks.
  • No browsing history or data from other apps.
  • I don't sell your data to anyone, ever.

How I use your data

In Cleo Track and Cleo Plan, the data you enter is used only to power the apps, syncing across your devices and with the family members and caregivers you choose to share with. I don't use your data for advertising, behavioral advertising aimed at children, analytics sold to third parties, or any purpose beyond making the apps work for you. A child's or family member's name is display-only personalization as described above. Cleo Routine stores all data locally on your device and does not transmit it anywhere.

AI features

When you log a food item in Cleo Plan, the text description of the food (for example, “one hard-boiled egg”) is sent to Anthropic (the company behind Claude) to estimate its calories and protein. Only the food description is sent: no names, no email addresses, no account information. Under Anthropic's commercial API terms, this data is not used to train their models. The estimate is saved back to your log entry, and nothing else is shared.

Cleo Connect is different, and entirely opt-in. It lets you bring your Cleo data into an AI tool of your choice (Claude, ChatGPT, or any tool that supports MCP). Your data is only shared with a tool when you connect it, and only in response to your own requests inside that tool. Once your data reaches an AI tool, that tool's own privacy policy governs how it's handled, and you can disconnect at any time.

There's one more AI feature, also entirely opt-in: the daily recap email. If you turn it on, once a day I send a short summary of your recent Cleo Plan and Cleo Track activity (recent meals, tasks, nutrition, and baby-tracking entries, along with your family members' first names and your child's age) to Anthropic so it can write the note in a warm, readable way. Under Anthropic's commercial API terms, this data is not used to train their models. The finished email is delivered to you through Customer.io. It's off by default, and you can turn it off anytime in your settings.

There is also an optional overnight entry review for Cleo Track, available only on Cleo+ and off by default for each child. When it runs, it sends the previous day's tracking entries (feedings, sleep, diapers, and similar) along with the child's age to Anthropic to check for patterns that look like data errors or gaps. Under Anthropic's commercial API terms, this data is not used to train their models. The findings are saved as suggestions in your account. If there are any, the family owner receives a short summary email through Customer.io. Nothing in your logs is changed automatically.

Cleo Track's activity push notifications are also written with the help of Anthropic, so they read like a person wrote them instead of a flat “update” label. Any note you've added to an entry is included so the notification can reflect it. Under Anthropic's commercial API terms, this data is not used to train their models, and the finished notification is delivered through Customer.io.

If you submit feedback from Cleo Plan, I include a snapshot of your family's current meals, open tasks, grocery list, and dietary preferences along with what you wrote, so the reply you get back can be grounded in your actual situation instead of the feedback text alone. That snapshot and your feedback are sent to Customer.io, which uses an AI model to help draft a summary for me. It's only used to help me understand and respond to your feedback.

If you connect a Google Calendar account, and only for the daily recap email described above, I fetch that day's events live from the calendars you chose to help shape the note (for example, calling out a busy day or one thing worth prepping for). Events are never synced or stored: they're read at the moment the email is composed and then dropped. Only the OAuth connection and which calendars you selected are saved, and you can unlink an account anytime in Connect settings.

If you attach a photo to a message in Cleo Voice, it's sent to Anthropic so Cleo can read it and act on what it shows, a grocery receipt, a school flyer, a handwritten list. Under Anthropic's commercial API terms, this data is not used to train their models. The photo itself is not retained after that reply; only a plain-text note of what happened stays in your conversation history.

SMS / text messaging

When you opt in to receive text messages from Cleo, I collect your mobile phone number and your consent in order to send account-related messages, reminders, and updates. Message frequency varies and messages are user-initiated. Message and data rates may apply. You can opt out at any time by replying STOP.

Mobile information is never shared for marketing. No mobile information (including your phone number) will be shared with third parties or affiliates for marketing or promotional purposes. I share mobile information only with subcontractors and service providers (for example, my SMS provider, Twilio) strictly to deliver the messaging service. Text messaging originator opt-in data and consent are never shared with any third parties.

Product analytics

I use Mixpanel and Customer.io to understand how people use Cleo: things like which pages get visited and which buttons get clicked, so I can make the products better. They process this data on my behalf as service providers: it is never sold, never used for advertising, and never shared with anyone for their own marketing.

Data retention

Your data is kept for as long as your account is active. If you delete your account, I'll delete your data from the database. To request account deletion or a data export, email me at scott@cleofamily.app.

Your rights

You can request to view, export, or delete any data I hold about you at any time. Just send me an email and I'll take care of it.

Third-party services

Cleo uses a small number of third-party services to function:

  • Supabase: database, file storage, and authentication for Cleo Track and Cleo Plan. Your data, including any profile photos you upload, is stored on Supabase's infrastructure. See their privacy policy at supabase.com.
  • Stripe: handles all payments and subscriptions for Cleo Track. Stripe's privacy policy applies to those transactions. I never see your full payment details.
  • Anthropic: estimates calories and protein for food items you log in Cleo Plan; runs the optional overnight entry review for Cleo Track; if you opt in, writes your daily recap email; helps write Cleo Track's activity notifications; and reads any photo you attach in Cleo Voice, as described under “AI features” above.
  • Twilio: delivers SMS messages for the optional Text Cleo feature in Cleo Connect. Your phone number is shared with Twilio only if you choose to link one. Twilio's privacy policy applies to message delivery.
  • Google: if you connect a Google Calendar account in Cleo Connect, I use Google's Calendar API to read your event details live for the daily recap, as described under “AI features” above. Google's privacy policy applies to your Google account. You can unlink anytime from Connect settings.
  • Mixpanel and Customer.io: product analytics and support email, as described under “Product analytics” above. Customer.io also delivers the optional daily recap email and overnight entry review summary emails, and helps draft a summary when you submit feedback in Cleo Plan, as described under “AI features” above.

Cleo Routine does not use Supabase, Stripe, or any third-party services. It is a fully offline app with no external data transmission.

Cleo doesn't use advertising networks, and analytics are limited to the product-analytics services above. I don't share personal or child-related information with third parties for their own marketing or behavioral advertising; the services above process data only to operate Cleo.

Children's data

Cleo Track and Cleo Plan are built for parents and guardians. The user of record is the adult who creates and controls the account. I do not collect personal information directly from children (for example, I don't ask a child to sign up or fill out their own profile).

Information about your child appears in the apps only because you added it: a child's profile in Cleo Track, or a family member's name in Cleo Plan. I don't use that information for behavioral advertising or to profile children for marketing, and I don't sell personal information.

Cleo Routine does not use accounts and does not collect child-identifying information on my servers. Apps are rated for broad family use (4+), but compliance for children's privacy follows this model: parent-owned account, parent-entered personalization, no independent child sign-up.

Changes to this policy

If I make meaningful changes to this policy, I'll let you know via the app or by email. The date at the top of this page reflects when it was last updated.

Contact

Questions? Just email me: scott@cleofamily.app.