Privacy Policy

Winkle Privacy Policy

Last updated: August 23, 2026

TL;DR

We collect only what’s needed to run Winkle and improve it. We never sell your data. Winkle is designed for adult caregivers. Any child-related information is entered by a parent or caregiver, not collected directly from a child.

1. Who We Are

Winkle is operated by Winkle Sleep, LLC, based in New York, USA.

Under the GDPR, Winkle Sleep, LLC is the data controller for your personal data.

Questions? Contact us.

2. Information We Collect

Data about you, the account holder: Winkle is intended for use by adults, including parents, guardians, and other caregivers. We collect your email address for account creation, login, account security, and communication related to the app.

Data about your child: Winkle allows adult caregivers to enter information about a child, such as the child’s first name, date of birth, sex, sleep events, and meal events. This information is used to provide age-based guidance, reminders, and tracking features. We do not collect information directly from children or knowingly allow children to create accounts.

  • Account details: Your email address for login and account management via Firebase Authentication.
  • Child details: First name, date of birth, and sex, entered by the parent or caregiver, to provide age-based insights.
  • Event data: Sleep and meal events you track in the app.
  • Analytics data: Usage analytics via Firebase Analytics / Google Analytics for Firebase to help us improve performance. We analyze this in an anonymized or aggregated way where possible.
  • Crash and diagnostic data: Crash reports and technical diagnostics via Firebase Crashlytics to help us identify and fix app issues.
  • Subscription data: Subscription status and purchase-related information processed through RevenueCat so we can provide access to paid features.
  • Caretaker invite and marketing emails (Resend): If you invite another caregiver to share access to a child, we send that invitation email through Resend. If you opt in to marketing emails, Resend also manages your marketing contact status and sends messages that may be informed by your child’s age (for example, milestone or birthday-related messages) – Resend never receives your child’s name or date of birth, only anonymized age-based event names.
  • Account and child mirror data (Supabase): A subset of your account email and your child’s name, date of birth, and sex is mirrored into Supabase, our data platform, to support subscription reporting and marketing-list management. Supabase also stores a copy of each subscription transaction (purchase, renewal, cancellation) reported by RevenueCat, linked to a pseudonymous account identifier, for customer support, fraud prevention, and revenue reporting. See Data Retention and Deletion below for how long this is kept.

3. How We Use Your Information

  • Provide insights about your child’s sleep and meals.
  • Track sleep and meal activity that you choose to enter.
  • Keep your account secure and the app functional.
  • Manage subscriptions and access to paid features.
  • Diagnose crashes, fix bugs, and improve app reliability.
  • Improve Winkle by analyzing anonymized or aggregated trends where possible.
  • Send caretaker-invite emails and, if you opt in, age-informed marketing emails.

Legal bases (GDPR): performance of a contract (running the app and providing subscription features); your consent where required, such as for analytics or marketing emails; and our legitimate interest in improving performance, reliability, and security.

4. Sharing of Information

We do not sell or trade your personal data.

We use trusted third-party processors to operate the app:

  • Firebase Authentication for account creation, login, and authentication.
  • Cloud Firestore for Firebase for app data storage, including account-related data, child profiles, sleep events, and meal events. Firestore data is stored in the “nam5” United States multi-region.
  • Firebase Crashlytics for crash reporting and technical diagnostics.
  • Firebase Analytics / Google Analytics for Firebase for usage analytics in anonymized or aggregated form where possible.
  • RevenueCat for subscription management, purchase status, and access to paid features.
  • Supabase for mirrored account and child data used in subscription reporting and marketing-list management, and for the subscription transaction records described above.
  • Resend for caretaker-invite emails and, if you opt in, marketing emails.

These providers may process data in the United States or other countries where they operate, and apply contractual safeguards for international data transfers under their respective data processing terms. RevenueCat may also process data in accordance with its own data processing terms and applicable transfer safeguards.

5. Data Security

We use industry-standard security measures. Firebase Authentication and Firestore apply encryption and security controls to help protect your data from unauthorized access, alteration, disclosure, or destruction.

6. Data Retention and Deletion

We keep your account and app data for as long as your account remains active, or as needed to provide Winkle’s features. We may retain anonymized or aggregated data to help improve the app.

You can delete your account in the app by going to Main MenuSettingsAccount.

Deleting your account permanently deletes your Firebase Authentication record, your account record, and every child profile you own, together with that child’s sleep and meal data. This happens automatically as a single action – there is no separate option to keep this data.

If another caregiver shared a child with you, deleting your account does not delete that child’s profile or data, because it is owned by the other caregiver’s account. Your own access to it is simply removed.

A small amount of data can persist after your account is deleted:

  • If you were a caregiver on a child owned by someone else, entries you logged there may still show an internal identifier (not your name or email) attributing that entry to you, since that data belongs to the other account.
  • Subscription transaction records (purchases, renewals, cancellations) are kept indefinitely as financial records, identified only by a pseudonymous account identifier that no longer links to any of your other data once your account is deleted.
  • RevenueCat, our subscription processor, retains its own copy of your subscription and purchase history independently of Winkle, in accordance with RevenueCat’s own data retention practices. Winkle does not delete your RevenueCat customer record when you delete your Winkle account.

You may also request deletion of your data. See delete your data for more information.

7. Your Rights

Under GDPR, you can:

  • Access the data we hold about you.
  • Request correction or deletion of your data.
  • Restrict or object to certain processing.
  • Request a copy of your data (data portability).
  • Withdraw consent at any time where processing is based on consent, such as analytics or marketing emails where applicable.
  • Lodge a complaint with your local data protection authority.

To exercise these rights, delete your account in the app by going to Main MenuSettingsAccount, or contact us. If you wish to withdraw consent for analytics or marketing emails, contact us and we’ll assist.

8. Children’s Data

Winkle is intended for use by adult parents, guardians, and caregivers. Children may not create accounts or use Winkle directly.

We collect a child’s first name, date of birth, sex, and sleep or meal activity only when that information is entered by an adult caregiver. We do not knowingly collect personal information directly from children.

By using Winkle, you agree to this Privacy Policy. You can withdraw consent where applicable, request deletion, and/or delete your account at any time from Main MenuSettingsAccount. Deleting your account permanently deletes the child profiles and data you own, as described above. For help, please contact us.

10. Changes to This Policy

We may update this policy from time to time. We’ll post changes here and update the “Last updated” date above. If changes are significant, we’ll notify you in the app where appropriate.

Contact Us

If you have any questions about our privacy policy, please contact us.