Milestones
Digital Studio

Child Illness Companion

Privacy Policy and Consumer Health Data Notice

Effective 20 August 2026 · Version CIC-PRIVACY-v1.1-2026-08-20

Plain-language summary. Milestones Digital Studio Limited does not receive, collect from the device, or store on its servers the personal or health information entered into Child Illness Companion. The app has no account, developer-operated backend, analytics, advertising, tracking, crash-reporting service, remote push-notification service or automatic cloud upload.

The app stores and processes information locally on the caregiver’s device. Information leaves the app only when the caregiver deliberately uses the device share sheet to save or send a personal-record export, consultation-summary PDF or one selected media attachment, or deliberately writes an email. The caregiver chooses the destination, whose privacy terms then apply.

Controller and contact

Milestones Digital Studio Limited
A company registered in New Zealand
30A Woodcock Rd, RD3, Waikato 3283, New Zealand
Privacy and support: admin@milestonesdigitalstudio.co.nz
App version: 1.0.0

Scope

The app is for adults acting as a child’s parent or authorised caregiver. It is not designed for children to use independently. The controller does not operate an app backend and cannot access the encrypted local health record or protected media. On-device processing is described because consumer-health-data laws may define collection or processing more broadly than app stores do.

Consumer health data processed

A caregiver may provide a child’s name or nickname and age band; the country or region selected to display the correct emergency number; illness concerns and symptom observations; temperature and measurement notes; medicine name, amount already given and time; feeding, hydration, urine, breathing, behaviour and sleep observations; episode dates and notes; and optional photos, short videos or audio notes. The app also creates timestamps, consent records, random identifiers and technical attachment details needed for local operation.

The app does not request a child’s surname, exact date of birth, precise location, contacts, advertising identifier, account credentials or medical-record connection. Avoid unnecessary identifiers and capturing unrelated people, documents, addresses, screens or background conversations.

Sources and purposes

Information comes from the parent or authorised caregiver, the camera or microphone only after an explicit capture action and permission, and technical records generated locally by the app. It is processed only to create and display the encrypted illness record, produce a caregiver-requested temporary JSON export or consultation-summary PDF, and encrypt and associate optional media with the relevant child and episode.

The app does not use health information to diagnose, assess urgency, recommend or prescribe treatment, calculate medicine doses, advertise, profile a family, train or operate AI, recognise images, analyse audio or infer a condition from media.

Storage, security and retention

Text records and protected media are encrypted locally. Keys are held separately in platform secure storage. Android application backup is disabled. The iOS protected-media vault is excluded from backup and uses native file protection. Other encrypted app data may be included in an iOS device backup controlled by the caregiver and Apple, but keys are device-bound and restoration to another device is not promised.

Records remain until the caregiver deletes an entry, episode, child or all app data, or removes the app or erases device storage. Related protected media is deleted with its record. Milestones Digital Studio Limited cannot recover local records. Data may be permanently lost if the device, app or encryption key becomes unavailable.

The app has no separate Face ID, Touch ID or PIN lock. It relies on the device passcode and operating-system protections. Anyone using an unlocked device may be able to open it.

Temporary plaintext captures are removed after protection succeeds or fails. Temporary JSON, PDF and decrypted sharing copies are removed from app-controlled cache after the share action finishes or is cancelled. The app cannot remove copies saved by destinations selected by the caregiver.

Exports and sharing

The portable JSON export contains the complete structured local record but is not encrypted by the app after leaving app-controlled storage and cannot currently be restored into the app. The PDF is a readable summary of one episode. Both omit protected media files, local file paths and internal vault identifiers. Media is shared separately, one attachment at a time.

The app does not automatically share health data with the controller, affiliates, advertisers, analytics providers, data brokers, cloud-storage providers or AI providers. It does not sell health data, use it for targeted advertising or profile a family. User-directed recipients are the operating-system share service and whichever destination the caregiver selects.

Third-party software and services

The reviewed production candidate contains no advertising, analytics, tracking, crash-reporting, AI, cloud-database, remote-notification or payment SDK. Expo and React Native libraries provide on-device interface, encryption, secure storage, camera, microphone, file, PDF and sharing functions. They are not configured to send the health record to Milestones Digital Studio Limited.

The device operating system, app store, email or telecommunications provider, and destinations selected through sharing operate under their own terms.

Consent and withdrawal

Before creating a record, the app presents a separate health-data notice and requires affirmative parent-or-caregiver confirmation. Optional media has separate consent before first capture. A caregiver may decline media and keep using text recording. General or media consent can be withdrawn by deleting all local app data; new consent is required before recording again.

Caregiver controls and rights

The caregiver can view local records and attachment details, replace an incorrect entry, export a portable JSON copy, create an episode PDF, delete an entry, episode, child or all local data and media, and withdraw consent by deleting all data.

Applicable law may also provide rights to confirm processing, access, correct, delete, obtain a portable copy, withdraw consent, learn about recipients and appeal a refusal. Email admin@milestonesdigitalstudio.co.nz with the subject Privacy Request or Privacy Appeal. Do not include child health information. No account is required.

Because the controller cannot retrieve the local record, support normally helps the caregiver use on-device controls. Controller-held correspondence or incident data will be authenticated and handled under the applicable regional procedure.

Regional rights and regulators

United Kingdom

Health information is special-category personal data. Where UK law applies, the controller will document an Article 6 lawful basis and Article 9 condition. Rights requests will normally be handled within one calendar month. Complaints may be made to the Information Commissioner’s Office. Any required UK representative details will be added before UK launch.

Australia

Where the Australian Privacy Act and Australian Privacy Principles apply, access, correction and complaints may be requested through the contact above. The internal response target is 30 calendar days, subject to applicable law. Complaints may be made to the Office of the Australian Information Commissioner; state health-record laws may add rights and complaint routes.

New Zealand

The controller is subject to the Privacy Act 2020 and will designate a privacy officer before release. Access and correction requests will be decided as soon as reasonably practicable and within 20 working days unless lawfully extended. Complaints may be made to the Office of the Privacy Commissioner.

United States

Where an applicable consumer-health-data law uses a 45-day period, the controller will respond within that period and use only a legally permitted extension. A denial will identify the relevant state regulator route.

Security incidents

No safeguard removes all risk. The controller will investigate, preserve evidence, contain events and make legally required notifications. Timing depends on jurisdiction and may include the UK ICO’s 72-hour regulator period, Australia’s eligible-data-breach rules, New Zealand’s serious-harm notification duty, and the FTC Health Breach Notification Rule’s requirement to notify affected people without unreasonable delay and no later than 60 calendar days after discovery.

Policy changes

The controller will not process a new category of consumer health data or use or share data for a materially different purpose without updating disclosures and obtaining any required affirmative consent. Material changes will be communicated through the app, website or both before changed processing begins.

App-store disclosure position

For the reviewed candidate, health information is processed only on-device and is not automatically transmitted off-device. Subject to verification of the signed production binary, the intended Apple and Google declaration is Data Not Collected. This terminology does not determine whether federal or state privacy law applies.

Contact

Privacy questions, requests or appeals:
admin@milestonesdigitalstudio.co.nz
Milestones Digital Studio Limited
30A Woodcock Rd, RD3, Waikato 3283, New Zealand