Effective August 24, 2026
This Privacy Policy explains how Knitty (“we,” “us”) collects, uses, and protects your information when you use the Knitty app. Knitty is a personal pregnancy-tracking tool, and we built it with the assumption that the information you put into it is some of the most sensitive information you have.
Who is responsible for your data
Knitty is operated by Fourello Inc., a corporation registered in the Republic of the Philippines, with its principal office in Quezon City, Philippines. Under the Data Privacy Act of 2012 (Republic Act No. 10173), Fourello Inc. is the Personal Information Controller for the information described in this policy.
For any question about your data, or to exercise any of the rights described below, contact us at support@knitty.baby.
Information we collect
- Account information: your email address and authentication details.
- Pregnancy details you choose to enter: due date, baby’s name, partner’s name, and similar profile information.
- Health-adjacent records you create: journal entries, checkups, medications, and expenses.
- Documents and photos you upload: checkup notes, prescriptions, lab results, ultrasounds, bump photos, and your profile photo.
- Your conversations with Knitty ai, including any documents you share in those conversations.
- AI usage metadata: which feature you used (general chat, per-checkup chat, weekly insight, medication scan), the AI model, an approximate token count for the request, and a timestamp — not stored to build a profile of you, but to catch bugs and prevent runaway usage costs.
- Push notification subscription details, if you enable notifications — this is the technical address your browser gives us to deliver a notification (an endpoint URL and encryption keys), not anything about the notification’s content.
- Basic technical information (like time zone) needed to show you accurate dates and reminders.
Sharing your pregnancy with a partner
Knitty lets you invite one other person — a partner — to share your pregnancy.
- They can read everything you’ve entered for that pregnancy — journal entries, checkups, medications, expenses, uploaded documents and photos, and your Knitty ai chat history.
- They can also write and delete most of the same records — this isn’t a read-only view. Either linked member can add, edit, or remove checkups, medications, journal entries, and documents.
- This access is mutual and symmetric — there is currently no way to share some things with a partner but not others, and no read-only or limited-access sharing mode.
- You choose who to invite, and either of you can remove the link at any time from Sharing settings, which immediately ends the other person’s access to that pregnancy’s data going forward. Removing the link does not retroactively undo anything either of you already did while linked.
- Your Knitty ai conversations are shared with your linked partner — both the general Knitty ai chat and any per-checkup conversations, including their full history. The app shows who asked each question, so it isn’t a silent surprise, but a question you’d rather keep private from your partner shouldn’t be asked through Knitty ai.
How Knitty ai uses your information
Knitty ai (the weekly check-in and chat features) is powered by Anthropic’s Claude API.
- What’s sent: the specific records relevant to your question or the weekly summary — for example, recent journal entries, upcoming or recent checkups, active medications, and any document or photo you explicitly attach to a chat message. We don’t send your entire history on every request.
- Who it’s sent to: Anthropic, as the AI provider generating the response. This is a live, per-request API call — nothing is sent to Anthropic unless you actively use a Knitty ai feature.
- Not used to train Anthropic’s models. By default, data submitted through Anthropic’s commercial API (what Knitty uses) is not used to train its models, except in narrow cases such as explicit feedback submission or opt-in — neither of which Knitty implements.
- Retention on Anthropic’s side: per Anthropic’s published policy for standard API usage, inputs and outputs are automatically deleted from Anthropic’s backend within 30 days of the request, with narrow exceptions for legal compliance and abuse prevention.
Other third-party service providers
We do not sell, rent, or trade your personal or health-adjacent information to third parties for marketing or any other purpose. We share information only with the service providers below, only as needed to run the app:
- Supabase — our database, authentication, and file storage provider. Your data is stored in a private database and private storage buckets, gated by row-level security policies scoped to your account and any account you’ve linked as a partner.
- Anthropic — powers Knitty ai. See above for what’s sent and how it’s used.
- Sentry — error tracking, so we can find and fix bugs. Sentry receives error messages, stack traces, and non-sensitive request metadata. It does not receive cookies, authentication headers, or request bodies — our error-reporting code strips those before anything is sent.
- Resend — sends transactional email on our behalf: sign-up and password-reset verification codes, checkup reminders, and partner-invitation emails. We do not use it for marketing email.
- Vercel — hosts the app itself, and by nature of that role, processes standard web request data (IP address, request logs) as part of serving the app.
- PayMongo — processes payments for paid plans. When you pay, PayMongo receives the transaction amount, a reference to your Knitty account, and whatever details you provide to your own bank or e-wallet during payment. We never see or store your bank, card, or e-wallet credentials — those go directly to PayMongo and your payment provider. We receive back only the payment’s status, amount, and reference identifiers, which we store to maintain your subscription record.
How we protect your data
Your records are stored in a private database protected by row-level security — every table-level access is checked against your identity and your pregnancy’s membership, not just at the application layer. Uploaded photos and documents live in private storage buckets and are only ever served through short-lived, signed links — never public URLs. Passwords are hashed and never stored in plain text.
Backups
We maintain periodic encrypted backups of the database and uploaded files, for disaster-recovery purposes (e.g. accidental data loss, infrastructure failure). These backups are encrypted at rest, held by the Knitty team, and are not accessible to any third party we haven’t already named above.
Deleted data may persist in these backups for some time after you delete it. A backup taken before you deleted a record or your account is a snapshot from that point in time — it still contains what you deleted, until that specific backup file is itself deleted or overwritten. We do not currently have a fixed backup retention schedule; older backups are deleted manually and irregularly, not on a set timeline.
Data retention and deletion
- Deleting an individual record (a journal entry, checkup, medication, document, or photo) removes it immediately and permanently from the live app — this is a hard delete, not a soft delete with a recovery window. As noted under Backups above, a copy may still exist in an encrypted backup taken before the deletion, until that backup is itself deleted.
- Deleting your account (available any time from Account settings, no need to contact us) permanently removes your profile, checkups, journal entries, photos, medications, and expenses from the live app. This also cannot be undone — and is likewise subject to the same backup caveat above.
- We do not currently offer a way to export or download your data. If this changes, this policy will be updated to reflect it.
Your rights under the Data Privacy Act
The Data Privacy Act of 2012 (Republic Act No. 10173) gives you specific rights over your personal information. Because much of what Knitty holds is sensitive personal information about your health and your pregnancy, we take these seriously. You have the right to:
- Be informed— to know that we’re collecting your personal information, and why. This policy is our attempt to tell you plainly.
- Access— to ask for a copy of the personal information we hold about you, and to know how it’s been used and who it’s been shared with.
- Correct — to have inaccurate or incomplete information corrected. Most of this you can do yourself, directly in the app.
- Object— to object to the processing of your personal information, including withdrawing consent you’ve previously given.
- Erasure or blocking — to ask us to remove or block your personal information from our systems. Account deletion is available at any time from Account settings, without contacting us.
- Data portability— to obtain a copy of your data in an electronic format that you can move elsewhere. We don’t yet offer a self-service export — see “Data retention and deletion” above — so for now this means contacting us directly.
- Damages — to be indemnified for damages sustained due to inaccurate, incomplete, outdated, false, unlawfully obtained, or unauthorised use of your personal information.
To exercise any of these, email support@knitty.baby. We’ll respond within 15 days.
If you believe we’ve mishandled your information and we haven’t resolved it, you may lodge a complaint with the National Privacy Commission (privacy.gov.ph).
Children's privacy
Knitty is designed for people managing a pregnancy — their own, or one they’re supporting as a partner. We don’t knowingly collect information from children who are not themselves pregnant or using the app for that purpose.
Changes to this policy
If we make material changes to this policy, we’ll update the effective date above and, where appropriate, let you know in the app.