Privacy Policy

Version 2026-06-06 · Last updated 6 June 2026

Draft — pending legal review

This document is AI-drafted and has not yet been reviewed by a lawyer. We are sharing it openly ahead of launch so you can see exactly how we intend to treat your data. It is not legal advice, and the final wording may change once our legal review is complete.

Cocoon is built for one job: to make the journey into parenthood a little calmer. We take the trust that involves seriously. This policy explains, in plain language, what personal data we collect, why, where it lives, who we share it with, and the rights you have under Singapore's Personal Data Protection Act (PDPA).

1. The personal data we collect, and why

We only collect what we need to help you. For each item below, the legal basis is your consent — you give it at sign-up and you can withdraw it at any time (see section 6).

  • Your email address — to create your account, send you a magic sign-in link, and deliver the timeline reminders you ask for.
  • Your citizenship status (Singapore Citizen, PR, or other) — to calculate the government schemes (Baby Bonus, CDA, subsidies) you may be entitled to.
  • Your baby's estimated delivery date (EDD) and date of birth (DOB) — the anchor for your personalised checklist, vaccination schedule, and disbursement timeline.
  • Your child's records — name, birth order, sex, and the milestones, growth measurements and photos you choose to add to the Memory Vault.
  • Mood and mental-health check-ins — if you choose to log how you are feeling, we store these to support you. These are private to you and are never shared with your partner.
  • Tracker data — the feeds, sleep, diaper changes, kick counts, contraction timings, growth records and maternal-weight entries you log.
  • Third-party contact details you provide for the maternity-leave letter — if you use the leave feature, you may enter your HR manager's name and email, and your company and employee name. This is another person's personal data that you supply; we store it only to help draft your leave-notification letter, on the same consent basis and with the same retention and deletion guarantees as your own data.

2. How we use your data

We use the data above solely to run the features you use: to compute your scheme entitlements, build and update your checklist, send the reminders you opt into, and keep your records in sync between you and your partner (where you share a household). We do not sell your data, and we do not run programmatic advertising.

3. Where your data is stored and processed

Your data is stored and processed by two infrastructure providers on our behalf: Supabase (our database, authentication and file storage) and Vercel (our application hosting).

Overseas transfer notice. Because these providers operate global infrastructure, your personal data may be stored on, or processed by, servers located outside Singapore. Where data is transferred overseas, we take steps to ensure it receives a standard of protection comparable to the PDPA, including through our providers' contractual and security commitments.

4. Third parties we share limited data with

  • PostHog — privacy-first product analytics, so we can understand how the app is used and improve it. We do not use third-party advertising cookies.
  • Amazon and Shopee — when you tap a product link in the Village wishlist, you may be taken to Amazon or Shopee through an affiliate link. If you buy something, we may earn a small commission at no extra cost to you. Your purchase is made on their site under their privacy policies.

5. How long we keep your data (retention)

We keep your data for as long as your account is active. When you delete your account, we purge your personal data from our live database immediately, and from our routine encrypted backups within 90 days as those backups age out. Anonymous, aggregated usage statistics that cannot identify you may be retained.

(Specific retention periods are being finalised with our legal review and may be updated.)

6. Your rights under the PDPA

You have the right to:

  • Access the personal data we hold about you.
  • Correct any data that is inaccurate or out of date.
  • Withdraw your consent to our collection and use of your data.
  • Delete your account and all your personal data.

Withdrawing consent and deleting your account are the same action in Cocoon: there is no partial opt-out, because nearly every feature relies on the data you have given us. You can do this yourself, instantly, using the one-tap account deletion in your account settings. When you delete your account, we erase your records across every part of Cocoon — your household, children, checklists, trackers, vault photos, mood check-ins and consent records — as described in section 5. For records in a shared household that you authored (for example a journal entry or wishlist item), these are retained for the remaining household member, as the data belongs to the shared household and is not yours alone to erase.

7. Contact us / Data Protection Officer

For any privacy question, or to exercise any of the rights above, please contact our Data Protection Officer (DPO) at privacy@ourcocoon.app. We aim to respond within a reasonable time.