Privacy Policy
Effective date: 2026-08-23
Cradle Lady is built on a simple principle: your data stays yours. This policy explains what the service collects, and what we do — and don't do — with it.
1. What we collect
Cradle Lady collects only what is necessary to operate the service:
- Account credentials. Your email address and a salted, hashed password.
- Journal content you enter. The entries, moods, quick responses, photos, and videos you record. This content is encrypted at rest (see Section 5 below).
- Standard server logs. Our application records the request method and path, the response status, how long the request took, a random request identifier, and a timestamp. These logs do not include your IP address or browser user-agent, and they are never used to build a profile of you. They are written to the server's standard output and rotated by the hosting environment; we do not archive them or send them to any third-party logging service.
We do not use advertising networks, analytics services, behavioral trackers, or social media pixels. We do not sell or rent personal information.
One third-party request is made on your behalf: the site loads its typefaces from Google Fonts, so Google receives your IP address and browser user-agent when those files are served. We send Google nothing else and receive nothing back.
2. How we use your information
We use your information solely to operate, maintain, and improve Cradle Lady. We do not sell it, share it for marketing, or add you to any mailing list.
3. Your content
Everything you put in your journal — entries, moods, quick responses, and the photos and videos you upload — is yours. It is encrypted under your password (see Section 5), so we cannot review, moderate, or read it, and we never use it for any purpose other than storing it for you.
4. Data retention
We retain your account and journal data for as long as your account is active. You may request deletion of your account and all associated data at any time by contacting us (see Section 10), and deleting an entry removes it and its media immediately.
5. Encryption at rest
Your journal content (entries, moods, quick responses, photos, and videos) is encrypted at rest under a key derived from your password. Text is encrypted in our database, and media files are encrypted on our server before they are stored in object storage — the storage only ever holds ciphertext. We cannot read any of it in the database, in backups, or in storage — and neither can anyone else, including us.
To be precise about how this works: your key is derived from your password when you log in and is held only in server memory for that session. While you are signed in and viewing your journal, the relevant content is decrypted in memory so it can be shown to you; we do not log it or keep a decrypted copy. When your session ends, the key is dropped. We never store your password or your key in a form we can use to read your data on our own.
If you lose both your password and your recovery key, your journal is unrecoverable. We have no mechanism to decrypt it on your behalf. Keep your recovery key in a safe place.
6. Data sharing and disclosure
We do not sell or share your personal information. We may disclose information if required by law, regulation, legal process, or enforceable governmental request, or where necessary to protect our rights or safety.
The service runs on third-party hosting infrastructure. Those providers necessarily process request metadata (including your IP address) to deliver the service, and act as our service providers.
Media storage (Cloudflare R2). Uploaded photos and videos are stored in Cloudflare R2, an object-storage service. Because each file is encrypted on our server before it is uploaded, R2 holds only encrypted data and cannot read your media.
Content delivery / DDoS protection. If the site is served behind a content-delivery network or reverse proxy, that provider receives your IP address and request metadata and — because such a provider can terminate the encrypted (HTTPS) connection at its edge — could in principle observe request and response contents in transit. This is the normal arrangement for any site behind a CDN, and we state it plainly rather than let "we can't read your data" imply more than it should: the guarantee that only you can read your journal is about data at rest in our database and storage.
7. Security
We take reasonable technical measures to protect your information. No method of transmission over the Internet or electronic storage is completely secure, and we cannot guarantee absolute security.
8. Do Not Track and cross-site tracking
Some browsers can send a "Do Not Track" (DNT) signal. There is no industry-standard agreement on how such signals should be interpreted, and Cradle Lady does not respond to them differently — because there is nothing for them to change. We do not track you across third-party websites or over time, and we do not build behavioral profiles.
9. Children's privacy
Cradle Lady is intended for adults. It is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, please contact us and we will delete it.
10. Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will revise the effective date above. Your continued use of the service after changes take effect constitutes acceptance of the updated policy.
11. Contact us
Cradle Lady is operated by Shibby Ventures LLC. Questions about this Privacy Policy can be sent to [email protected].