Littles NOTEBOOK

Littles Notebook

Privacy Policy

Last updated: 5 September 2026

This pilot policy explains how Littles Notebook handles information in the Littles Notebook app and on littlesnotebook.com (including www.littlesnotebook.com). Questions can be sent to hello@littlesnotebook.com.

Who uses Littles Notebook

Littles Notebook is a communication and recordkeeping tool for licensed home daycare providers and the parents linked to children in their care. Children do not create accounts or use the app. Provider staff create and maintain child records. Parents receive an invite, confirm their email, and set up their own account.

Information we collect

We collect provider and parent account details, including names, email addresses, role, and login information. Providers may enter child care records such as attendance, meals, naps, diapers or potty attempts, activities, notes, photos, injury details, medication authorizations and doses, emergency contacts, and authorized pickup information. We also process device tokens for push notifications and keep audit logs of sensitive changes and logins.

On the public marketing website (and related marketing-styled pages such as signup and billing), we use Google Analytics to understand site traffic. Google may collect technical information such as approximate location derived from IP address, browser and device type, pages viewed, and referral source. This analytics data is separate from in-app care records and is not used to show ads to children.

How we use it

We use this information to run the service, show a child's parent-visible timeline to linked parents, send push notifications and end-of-day emails, help providers maintain care records, protect accounts, and provide support. End-of-day summaries are template-based from logged events only. They do not use AI to invent details.

We use Google Analytics to measure how visitors use the marketing site so we can improve content and signup flows. We do not sell analytics data or use it for third-party advertising networks.

Visibility and photos

Provider staff for the relevant daycare can access the records needed to provide care. Linked parents can access parent-visible records for their own children. Staff-only notes do not appear on the parent timeline. Photos are kept in private object storage and accessed with short-lived signed URLs. They are not kept in public buckets.

Notifications and choices

Linked parents may receive push notifications for care events and an end-of-day email digest. In the app, parents can turn push notifications off overall, turn individual event types off, and turn off the email digest. We do not use SMS in the product.

You can limit analytics cookies through your browser settings or Google's tools (for example Google Analytics opt-out browser add-ons where available). Blocking analytics may not affect use of the app itself.

What we do not do

We do not sell personal information, run child-directed advertising, use public photo buckets, or operate public social feeds. We do not place third-party advertising trackers in the mobile apps. The marketing website uses Google Analytics for traffic measurement only, not for selling ads on our pages.

Consent and children

The home daycare provider uses Littles Notebook to communicate with parents. Parent access is created through an invite and parent-child link. We aim to minimize data and treat child information as sensitive. This is a COPPA-aware pilot posture, not a statement that the service has received a COPPA certification.

Retention, export, and deletion

For the pilot, we currently keep records indefinitely unless you ask us to remove them. Staff can export a child's event history as a CSV file. Staff can also soft-delete a child from the active roster; this does not erase the child's history, which is retained for export and audit.

To request account deletion, use Delete your account. To request deletion of some or all data without closing your account, use Delete your data. You can also email hello@littlesnotebook.com. There is not a fully self-service deletion portal in the app at this time.

Service providers and security

We use trusted subprocessors for hosting, email, push notifications, payments, and website analytics. Current product documentation identifies AWS or Lightsail hosting, Amazon SES for email, Firebase Cloud Messaging for push, Stripe for SaaS billing, and Google Analytics for marketing-site measurement. Google's use of information is also governed by Google's privacy policy. We use TLS for API traffic, encrypted managed storage, available staff multi-factor authentication, access controls, and append-only audit logs for sensitive changes. No system can promise absolute security.

Missouri records

The app can help a Missouri provider keep attendance and daily care records. It is not a substitute for state-required paper forms, signatures, facility packets, or records the app does not yet support, including immunization tracking.

Changes and template notice

We may update this policy as the pilot changes and will update the date above. This is a plain-language pilot template, not legal advice or a law-firm opinion.