Legal
Privacy Policy
Last updated: March 27, 2026
We built UpPapa for parents, and we take your family's privacy seriously. This policy explains what data we collect, why we collect it, and what control you have — written in plain language, not legalese.
1. Who We Are
UpPapa™ is operated by UP PAPA, LLC, a company registered in the United States. We design parenting products and run the UpPapa Club — a free digital companion for parents to track memories, milestones, and family moments.
Privacy contact: privacy@uppapa.com
2. What Data We Collect
Account data
- Email address (required for sign-in)
- Name, role (Dad, Mom, etc.), gender, birthday, location, bio (optional — you choose what to share)
- Profile photo (optional)
Child profiles
- First name, date of birth, gender, nickname
- All child data is entered by the parent — children never interact with UpPapa directly
Content you create
- Journal entries and daily logs
- Photos you upload
- Growth measurements (height, weight, shoe size)
- Travel logs and bucket lists
- Movie ratings and watchlists
- Quotes, letters, and personal notes
Activity data
- Game scores and quiz results
- Points and Papa Level progress
- Leaderboard entries
Technical data (collected automatically)
- IP address, browser type, device type
- Pages visited and time on site
- Collected via our analytics provider — anonymized, no personal identifiers
Purchase verification
- If you claim a Verified Buyer badge, we check your email against our e-commerce platform orders
- We do not store your payment information — that stays with the e-commerce platform
3. How We Use Your Data
- To provide and personalize your UpPapa Club experience
- To display your journal entries, growth charts, and memories
- To send memory notifications ("On This Day" reminders)
- To verify e-commerce purchases for Verified Buyer status
- To improve our products and services
- To send transactional emails (magic links, account updates)
- To respond to your support requests
Our promise:
- We NEVER sell your data to anyone
- We NEVER share your data with third parties for advertising
- We NEVER use your family photos or content for marketing without your explicit consent
4. Legal Basis for Processing (GDPR — EU Users)
If you are located in the European Economic Area (EEA) or the UK, we process your data under the following legal bases:
- Consent — When you create an account, you consent to us storing and processing your data to provide the service
- Contract — Processing necessary to deliver the UpPapa Club features you signed up for
- Legitimate interest — Service improvements, security monitoring, and memory notifications (you can opt out anytime)
5. Your Rights Under GDPR (EU/UK Users)
If you are in the EU or UK, you have the following rights:
- Right to access — Request a copy of all data we hold about you
- Right to rectification — Edit or correct your profile and content at any time
- Right to erasure ("right to be forgotten") — Delete your account and all associated data
- Right to data portability — Export your data in a machine-readable format (JSON)
- Right to restrict processing — Ask us to limit how we use your data
- Right to object — Opt out of emails or specific processing activities
- Right to withdraw consent — You can withdraw consent at any time by deleting your account
To exercise any of these rights, email us at privacy@uppapa.com. We will respond within 30 days.
6. Your Rights Under CCPA/CPRA (California Residents)
If you are a California resident, you have the following rights under the California Consumer Privacy Act and California Privacy Rights Act:
- Right to know — What personal information we collect, use, and share
- Right to delete — Request deletion of your personal information
- Right to correct — Request correction of inaccurate personal information
- Right to opt out of sale — We do not sell personal information, but you can still submit this request
- Right to non-discrimination — We will not treat you differently for exercising your rights
To exercise your CCPA rights, email privacy@uppapa.com with the subject line "CCPA Request."
7. Children's Privacy (COPPA Compliance)
We take children's privacy very seriously. Here is how UpPapa handles child-related data:
- UpPapa does NOT collect data directly from children
- All child profile data is entered by the parent or guardian
- Children under 13 cannot create accounts
- Child profiles contain only: first name, date of birth, gender, and nickname — the minimum needed to display milestones
- Parents can edit or delete child profile data at any time
If you believe a child under 13 has provided us personal information without parental consent, please contact us immediately at privacy@uppapa.com and we will delete it promptly.
8. Data Storage & Security
- All data is stored on a secure cloud database (PostgreSQL hosted on AWS)
- Data is encrypted in transit using TLS 1.3
- Data is encrypted at rest using AES-256
- Row-level security (RLS) ensures each user can only access their own data
- Photos are stored in secure cloud storage with authenticated access — no public URLs
- Authentication uses secure, token-based sessions (no passwords stored)
While no system is 100% secure, we follow industry best practices to protect your family's data.
9. Third-Party Services
We use a limited number of third-party services to run UpPapa. Here is a description of each category and what data they may access:
Cloud database and authentication provider
Authentication, database, file storage — All account and content data
Web hosting and analytics provider
Website hosting and analytics — Anonymized usage data only — no personal identifiers
Email delivery service
Transactional emails (magic links, notifications) — Your email address
E-commerce platform (for purchase verification only)
Purchase verification for Verified Buyer badge — Email lookup only — we do not store payment data
Marketing analytics
Marketing performance for our shop — Anonymized page views on shop pages
Stock photo service
Stock photos in the app — No user data shared
Movie database service
Movie search for Family Movie Night feature — No user data shared — search queries only
Location search service
Location search for travel logs — No user data stored by this service
We do not share your personal data with any third-party for advertising or marketing purposes.
10. Cookies & Tracking
Essential cookies (required)
- Authentication session cookie — keeps you signed in
- Cookie consent preference — remembers your choice
Analytics
- Web analytics — anonymized, no personal data collected, no cookies set
Marketing
- Meta Pixel — used for shop marketing performance only. You can opt out via your browser or ad preferences
What we do NOT use:
- No advertising cookies from Google, Amazon, or ad networks
- No third-party tracking pixels (other than Meta Pixel for shop)
- No fingerprinting or cross-site tracking
11. Data Retention
- Account data — kept for as long as your account is active
- Content (journals, photos, etc.) — kept until you delete it or delete your account
- After account deletion — all personal data is permanently removed within 30 days
- Anonymized analytics data — may be retained indefinitely (cannot be linked back to you)
12. International Data Transfers
UpPapa is a US-based company, and your data is stored on servers located in the United States (via AWS infrastructure).
If you are located in the EU, UK, or another country with data protection laws, please be aware that your data will be transferred to the US. We rely on Standard Contractual Clauses (SCCs) approved by the European Commission to ensure your data receives an adequate level of protection during transfer.
13. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make significant changes, we will notify you by email and update the "Last updated" date at the top of this page.
We encourage you to review this policy periodically. Continued use of UpPapa after changes constitutes acceptance of the updated policy.
14. Contact Us
If you have any questions about this Privacy Policy, want to exercise your rights, or just want to understand how your data is handled — we are happy to help.
Contact Us