Privacy
Lacta is a small, invite-only tool made for the people who use it — not a data business. This page says plainly what we keep and what we never do.
What we store
If you create an account, the server stores your email address, display name, a one-way password hash, hashed session tokens, and the invite-code redemption record. It also stores the milk data you sync: bag identifiers, amounts and units, recorded dates, notes, used status, named storage places, explicit handling events, versions, conflict receipts, and disabled notification/guidance records.
The iOS app separately keeps 19 baby-care models only on your device, including baby profile data and records for pumping, nursing, bottles, diapers, sleep, growth, milestones, schedules, equipment, solids, medication, tummy time, temperature, notes, doctor visits, weaning, and a local caregiver memory aid. Those records are not part of Lacta account sync or server backups.
What we never do
No ads, advertising profiles, sale of data, or third-party analytics SDKs. Lacta does not make one account’s milk records available to another account. Application queries are account-scoped and the lifecycle tables also enforce row-level database policies.
Where it lives
Account and milk-sync data are hosted by Hetzner in Helsinki, Finland. Cloudflare provides the public edge and encrypted tunnel. Caddy writes limited access logs (request time, address, path, status, and user-agent metadata) in rolling files on the server. Operational monitoring uses ntfy for service/backup alerts; those alerts are not intended to contain milk records. To slow password and deletion attacks, Lacta keeps short-lived counters derived from IP addresses and account identifiers using a keyed one-way code; raw values are not stored, and expired counters are removed after a 24-hour cleanup margin. HTTPS protects data in transit.
Postgres dumps run nightly on the server and are also copied offsite. The current backup policy keeps copies indefinitely in three locations; there is no point-in-time recovery guarantee. A nightly recovery point means changes since the latest successful backup could be lost in a severe failure.
Deleting your account
You can delete your account from Account in either the iOS app or the website; both ask for your password. Deletion removes the account and its milk records from the live database and signs out its sessions. The invite-code row retains redemption counters, timestamp, and the former user identifier for audit. Existing keep-forever backups are not selectively rewritten, so deleted data can remain in those access-controlled copies indefinitely. You can also email [email protected] and we’ll do it for you.
Device data and choices
Deleting an online account does not delete the 19 device-local baby-care models. Use iOS device/app controls for local data, and export records before removing the app if you want to keep a copy. Lacta uses local notifications only; notification choices are stored on the device. The app does not currently enable iCloud caregiver sharing.
Children
Lacta is for parents and caregivers, not children. We don’t knowingly collect anything from anyone under 13.
Questions? Visit Lacta Support or email [email protected]. If this policy ever changes, the change will be visible on this page before it takes effect.