Privacy Policy
Last updated: June 15, 2026 (rev 3)
Limitless Parenting (the "App") is an early-learning flashcard app for babies and toddlers, designed and operated by AMEOS LLC ("we," "us"). We take your family's privacy seriously, and this policy explains what we collect, why, and how to control your data.
The short version
We collect the minimum needed to give you a working app and to sync your family's progress across devices. We never sell your data, run ads, or share it with anyone outside our service providers. You can delete your account anytime.
What we collect
Required to create an account:
- Your email address (used to send sign-in codes)
Optional, only if you provide it:
- Your full name, caregiver role (Mom, Dad, Nanny, etc.), country of origin, photo, bio, and birthday
- Your phone number (if you choose to link one as an alternate sign-in method)
- Your mailing address (only if you opt in to receive Limitless merchandise — used only for shipping)
Created automatically as you use the App:
- Children's profiles you add (names, birthdates, languages, learning levels)
- Curriculum progress (which sets your children have completed, daily session counts, streaks)
- Custom photos you upload to personalize flashcards (e.g. photos of grandma, your dog, your home)
- Milestones you log (the milestone, its date, your note, and any photo you attach)
- Baby logs you record — feeding (nursing and bottle), diapers, sleep and naps, pumping, potty/elimination, introduced foods, growth measurements, medicine, and any notes — each with a timestamp. This can include health- and feeding-related information about your child.
- If you use caregiver features: caregiver hiring details you enter (such as an hourly rate) and shift clock-in/clock-out times and calculated hours (timesheets)
- If you contact a caregiver through the marketplace: your inquiry message and a snapshot of your name and email, shared with that caregiver so they can reply
- Session activity log (which caregiver completed which session, when) — used to show your co-parent your shared progress
Health and baby-tracking information
The baby logs and milestones you record can include health- and feeding-related
information about your child — for example sleep, feeding, diapers, growth, and
medicine. We treat this as sensitive. It is:
- stored on your device and, when you sign in, synced to our cloud backend and to the co-parents and caregivers you invite to your family group — so you can share tracking;
- used only to provide the tracking, reminders, and predictions (such as next-nap windows) you ask for;
- never sold, never used for advertising, and never shared with anyone beyond the co-parents/caregivers you invite and the service providers listed below that operate the App.
What we DON'T collect
- We do not use third-party analytics SDKs, advertising IDs, tracking pixels, or cross-app tracking
- We do not collect your precise location
- We never see your payment information — subscription billing is handled by Apple's App Store
- We do not access your phone's contacts, calendar, or other apps
Where your data lives
Your data is stored in two places:
- On your device — children's profiles, progress, and photos are cached locally so the App works offline and feels instant.
- In our backend (Supabase) — when you sign in, the same data is also stored in our secure cloud backend so it syncs across your devices and to invited co-parents. Data is encrypted in transit (TLS) and at rest. Our cloud provider, Supabase, hosts data in the United States.
Who we share data with
We don't sell or rent your data. We use the following service providers to run the App, and your data is shared only with them, only to the extent needed:
- Supabase (cloud backend) — stores your account, family data, and photos
- Resend (email delivery) — sends you sign-in codes via email
- Twilio (SMS, when phone sign-in is enabled) — sends sign-in codes via text
- Google Places API (address autocomplete) — only if you opt in for swag and start typing your address; suggestions are fetched from Google as you type
- Stripe (subscription billing on web) — processes payments and stores billing information when you subscribe via our website
- Apple App Store (subscription billing on iOS) — handles billing on Apple devices and shares only your subscription status (active / lapsed) with us
- RevenueCat (subscription management on iOS) — connects our app to Apple's billing system and tracks your subscription state. Receives an anonymous user ID generated by their SDK; does not receive your name, email, or any personal information from us.
- Spotify (audio podcast embeds in the in-app Academy) — embeds the Spotify episode player when you view a course module that has audio. Spotify may set their own cookies and receive standard browser information (IP, user agent) when the embed loads, per their privacy policy.
- Image CDNs (Pixabay, Unsplash, iStock, others) — provide curriculum flashcard images; standard image loads, no personal data sent
Phone numbers and SMS messaging
If you choose to link a phone number to your account, the following applies:
- What we send: we send SMS messages via Twilio for the following purposes only:
- One-time sign-in codes when you request to sign in by phone
- Account notifications when meaningful events occur on your account, such as a new caregiver joining your family group or a sensitive account change (e.g., a new device signing in)
- One-time family invitations to a phone number you have entered in the app to invite a caregiver or family member to join your family group. Invited recipients receive exactly one (1) SMS invitation; no follow-up SMS is sent unless the recipient joins your family and adds their own phone number under the self-link flow
- Customer-care responses when you initiate a conversation by texting our support number
We do not send marketing texts, promotional offers, or unsolicited messages.
- Message frequency: message frequency varies and is driven by your activity — typically one SMS per sign-in attempt or family-account event you initiate. Invited recipients receive one SMS invitation only.
- Costs: message and data rates may apply, depending on your mobile carrier and plan. Limitless does not charge you for the messages themselves; any charges come from your carrier.
- Opt-out: reply STOP to any SMS to opt out of further messages. You can also remove your phone number from your account at any time in Settings → Phone number → "Remove from this account." Invited recipients who do not wish to join can simply ignore the invitation or reply STOP. Reply HELP to any SMS for support information.
- Non-sharing of mobile information: we do not share, sell, or rent your mobile phone number or SMS opt-in status with third parties or affiliates for marketing or promotional purposes. Mobile information is shared only with Twilio (our SMS delivery provider) and only for the purpose of delivering the messages described above.
Family sharing
Limitless is built around families. When you invite a co-parent (or other caregiver) to your family using an invite code:
- They will be able to see your children's profiles, progress, custom photos, and the activity log of who did which session
- They will NOT see your private profile fields: your mailing address, swag opt-in status, or phone number
- You can see who is in your family at any time in Parent Profile → Your family
- You can leave a family at any time by contacting us
Caregiver discovery and inquiries
Limitless includes an optional marketplace that helps parents and professional caregivers (nannies, babysitters, au pairs, doulas, and similar) find one another. What is shared depends on how you use this feature:
- If you list yourself as a caregiver: the profile details you choose to provide — your name, caregiver role, general location (city, region, country), photo, and bio — become discoverable by parents searching for care. We use the city/region/country you enter to show you in location-based searches. This is general, self-entered location only; we do not collect or use your device's precise GPS location.
- If you contact a caregiver: when you send an inquiry, that caregiver receives the information you include — typically your name, email address, and the family details you choose to share (such as your children's ages and what you're looking for) — so they can respond to you directly.
- Inquiry records: we store inquiries and their status (sent, viewed, interested, passed) so both sides can see where a conversation stands, and we may send email notifications about new inquiries and responses via our email provider (Resend).
- Important: Limitless only helps parents and caregivers discover each other. We do not employ, screen, or background-check anyone, and any arrangement you make is solely between you and the other person. See our Terms of Use for details.
How we store your photos
Plain-English version: Photos you upload (of grandma, your dog, your child's favorite toy, etc.) are stored in our cloud so your co-parents and caregivers can see them when they use the App. The storage URLs are technically reachable on the public internet, but the path to each photo contains random, unguessable identifiers — like a Google Drive "anyone with the link" share. Without the link, the photo is effectively private.
More precisely:
- Where photos live: uploaded photos are stored in a Supabase Storage bucket called
family-photos. The bucket is configured as "public" in the technical sense that the storage endpoint does not require authentication to serve a photo.
- Why it's still private: the URL to each photo embeds your family's randomly generated UUID, your child's randomly generated ID, and a millisecond timestamp. These identifiers are not enumerable, indexable, or linked from any public page. The only place these URLs exist is in your family's private database rows (which ARE protected by authentication — only family members can read them).
- This is the same model used by: Google Drive's "anyone with the link can view," Dropbox share links, Zoom invite links, and most major image CDNs.
- What this means in practice: someone who manages to obtain a photo's full URL — for example, if you accidentally screenshot it with the URL bar visible, or if you paste the URL into a public chat — could view the photo. We do not log photo URLs in any analytics or third-party tools.
- What we don't do: we do not index your photos for search, do not share them with advertisers, do not use them for AI training, and do not include them in any backup or archive accessible outside our team.
- How to delete photos: tap any photo in your Photo Library to delete it. Deletion removes both the storage file and the database row immediately.
If you would prefer not to upload personal photos, the App works fully without them — uploaded photos are an optional personalization feature for flashcards like "Mother," "Father," "Grandma," etc.
Children's privacy
Limitless Parenting is designed for parents to use on behalf of their babies and toddlers. Children do not have their own accounts and do not interact with the App independently — the parent is the user.
Information about children (names, birthdates, photos, learning progress) is provided to us by the parent or guardian, who chooses what to share. We do not knowingly collect any information directly from children. If you believe a child has provided us information without parental consent, please email us at hello@limitlessbabies.com and we will promptly delete it.
Your rights and choices
You can:
- See your data — Everything we store about your family is visible to you in the App while signed in.
- Edit your data — Update your profile, children, or family at any time from within the App.
- Sign out — Tap Sign Out at the bottom of Settings. Your account stays intact; you can sign back in anytime.
- Export your data — Email hello@limitlessbabies.com from your account email and we'll send a copy of your profile, family information, and activity within 30 days.
- Delete your account — From within the App: Settings → Delete my account. This permanently removes your account, profile, and all data you've created within 30 days. If you've uninstalled the App or can't sign in, follow the instructions at app.limitlessbabies.com/delete-account or email hello@limitlessbabies.com from your account email.
If you are in the EU/UK (GDPR)
The General Data Protection Regulation gives you specific rights including the right to access, correct, delete, restrict processing of, port, and object to processing of your personal data. The legal basis for our processing is your consent (given when you create an account) and our legitimate interest in providing the App you signed up for. You can withdraw consent or exercise any of these rights by emailing hello@limitlessbabies.com. You may also lodge a complaint with your local data protection authority.
If you are in California (CCPA / CPRA)
California residents have the right to know what personal information we collect, to delete it, to correct it, to opt out of sale (we do not sell personal information), and to non-discrimination for exercising these rights. You can exercise these rights by emailing hello@limitlessbabies.com.
Subscriptions and payments
When subscriptions are enabled, billing is processed by one of two payment providers depending on how you signed up:
- On the iOS app: billing is handled entirely through Apple's App Store using In-App Purchase. Apple shares limited subscription status (active / lapsed / canceled) with us so we can grant or revoke premium features. We never see your credit card number, billing address, or full payment information. Apple's privacy policy applies to your purchase: https://www.apple.com/legal/privacy/en-ww/.
- On the web app: billing is handled by Stripe. We work with Stripe to securely process your payment information. Stripe stores your payment method and billing details on their PCI-compliant infrastructure; we never see or store full payment information ourselves. We do receive transaction metadata (subscription status, plan, renewal date) so we can grant or revoke premium features. Stripe's privacy policy: https://stripe.com/privacy.
Voice and audio
The App uses your device's built-in text-to-speech engine (Apple's AVSpeechSynthesizer or the browser's Web Speech API) to read flashcards aloud. The text being spoken is processed entirely on your device by the operating system's voice engine. We do not record, transmit, or analyze any audio. The App does not request microphone access.
Data retention
While your account is active, we retain your data as long as you keep using the App. If you delete your account, we permanently remove your personal data within 30 days. Anonymous, aggregated information (e.g. total number of sessions completed by all users combined) may be retained indefinitely for product improvement.
Backup copies maintained by our cloud providers may persist for up to 90 days after deletion before being purged, as part of standard disaster-recovery practice.
Security
We protect your data with industry-standard measures:
- All connections to our servers use TLS encryption (HTTPS)
- Data is encrypted at rest in our database and storage providers
- Database row-level security ensures that family data is only readable by members of that family — even within our own database, one family cannot see another's data
- We use industry-standard authentication tokens (JWT) and do not store passwords
No security is perfect. If we ever experience a data breach affecting your information, we will notify you promptly as required by law.
Children under 13 (COPPA)
The App is designed for parents, not children. We do not knowingly collect personal information directly from children under 13. Parents make all decisions about what information to provide about their children. If you are a parent and believe we have inadvertently collected information directly from a child without parental consent, please contact us at hello@limitlessbabies.com and we will delete it promptly.
Changes to this policy
If we change this policy, we will update the "Last updated" date at the top and notify you within the App. Material changes (for example, adding a new category of data we collect) will be announced more prominently — usually via in-app notification or email.