Effective June 29, 2026

How BaeMax handles your data.

Most personal records are created and kept on your phone. When you choose to share with a partner, BaeMax sends an encrypted copy through our relay. This page explains what stays local, what service providers process, and what controls are available today.

Data flow

Your phone can read it. The relay can't.

When you and your partner pair, both phones use a shared secret. Partner-sync payloads and private chat messages are encrypted before they leave the sending phone, passed through our relay as ciphertext, and decrypted by the paired phone. Push-notification text follows the separate process described below and is not end-to-end encrypted.

Your phone Local record
encrypt
Locked update Scrambled — unreadable
relay
Private relay Cannot decrypt
unlock
Partner phone Unlocked on their phone

Message contents are encrypted before they reach the relay.

No central profile is created for BaeMax to browse.

We don't run ads, trackers, or analytics SDKs.

On-device records

Your phone holds your data.

Your primary app record is saved on your device. BaeMax does not maintain a readable central profile of your check-ins, cycle logs, tasks, or chats. Encrypted copies of data you share can be held by the relay for delivery to your partner.

On Android, BaeMax protects its main app-state records and private-chat history with authenticated encryption derived from a root key kept in device secure storage. Private-chat database records are migrated and verified before older plaintext columns and database free pages are purged. Generated thumbnails and lightbox previews are kept in memory instead of being persisted as readable JPEG previews. When you explicitly open an encrypted attachment, BaeMax may create a temporary decrypted file for the receiving Android app and clears its private temporary-open area on startup and background transitions.

  • Mood & check-insBody and mood check-ins you choose to log. Selected fields are sent as encrypted payloads only when partner sharing is enabled.
  • Cycle & period dataStart dates, period length, symptoms, flow, and daily logs. Stored on your phone unless you choose to share.
  • Sleep & hydrationRecorded on your phone and included in encrypted partner updates only when the related sharing control is enabled.
  • Tasks & care messagesShared to-dos and partner notes sync only through encrypted channels.
  • SettingsMost preferences stay on device. Notification mute, detail, and quiet-hour preferences are also sent to the relay so it can apply them before sending a push.

Server visibility

What our server can and cannot see.

Our server handles the delivery of messages, similar to how a postal service knows a letter was sent, when it was mailed, how big the envelope is, and where it's going — but cannot open the letter and read it.

Can see: that a message was sent, when it was sent, the size of the message, and which paired couple it belongs to.

Cannot see: the contents inside encrypted partner-sync and private-chat payloads. Operational identifiers, IP/network metadata, push tokens, and notification text are handled separately and are visible where needed to operate those services.

Delivery queues expire encrypted messages after 7 days and encrypted attachment objects after 14 days. Message retention is enforced in the relay's durable database, including on-disk cleanup; backups may retain encrypted records until their own documented rotation completes.

Notifications

Choose what appears in alerts.

When you enable notifications, BaeMax sends alert data through the Expo push service and Google Firebase Cloud Messaging on Android. This notification path is separate from end-to-end encrypted partner sync. Those providers process the push token, delivery metadata, and the notification text needed to deliver the alert.

New installs hide notification details by default and use wording such as "Open BaeMax for your update." Existing beta users should check Settings > Notifications > Hide notification details.

If you turn detail hiding off, partner names, event types, or message hints may be included in push text and may appear on your lock screen. Your phone's notification privacy settings also apply.

Notifications that come from the phone itself (like reminders you set) stay entirely on your device and don't involve our server.

Cycle & period

Your cycle data is yours alone.

Your cycle data is recorded on your phone. If you enable partner sharing, selected cycle details are included in encrypted partner-sync payloads; the relay cannot read those details. BaeMax provides estimates and summaries, not a diagnosis, contraceptive method, emergency service, or substitute for professional medical care.

If you are paired with a partner, you decide whether cycle data is shared with them. This is a setting you control. Off means off — BaeMax removes cycle details from partner updates.

When sharing is turned on, cycle data is encrypted the same way as all other synced content. Our server still cannot read it.

Pairing & security

Treat your pairing code like a password.

When you pair with someone, BaeMax gives you a pairing code, QR code, or shareable link. This contains the shared secret your phones need to set up the private connection.

Don't post your pairing code publicly or send it somewhere you wouldn't trust. If someone else gets that code while your pairing screen is active, they could attempt to pair with your account.

If you share a pairing link through another app, that app handles the link according to its own privacy practices. BaeMax has no control over how other apps treat links you send through them.

Permissions

Only what BaeMax actually needs.

Android asks for permission when a feature needs protected device access. You can deny optional permissions, although the related feature will not work. BaeMax does not request contacts access.

  • CameraUsed to scan pairing QR codes and capture an image when you choose a camera-based feature.
  • Photos and videosUsed through the system picker when you choose media to send.
  • MicrophoneUsed only while you record a voice message. Voice-message content is encrypted before relay upload.
  • LocationUsed when you choose to attach a location or start live location sharing. Background location is used only while live sharing is active, with an Android foreground-service notification.
  • ClipboardUsed only when you copy a pairing code or your user ID. Your phone's clipboard is managed by your operating system.
  • NotificationsUsed for partner updates and reminders. You choose whether to enable them.
  • BiometricsUsed for app lock. We never receive your fingerprint or face data.

Controls

You can lock, export, clear, or disconnect.

App lock Lock BaeMax behind your fingerprint, face scan, or device passcode. Your phone handles verification on its own — we never receive, store, or process your biometric information.
Export your data Export the main app-state record and settings. The current beta export is not a complete archive: private-chat database rows and attachment files are not included. Exports are readable files, so choose where you save or send them carefully.
Clear all data Removes local app data. For a paired device, BaeMax first records the minimum derived revocation credential in secure storage and keeps retrying relay and notification cleanup if the network is unavailable.
Disconnect Creates a durable relay revocation before removing partner data from this phone. If the relay is unavailable, BaeMax keeps the revocation credential in secure device storage and retries automatically; new pairing is blocked until cleanup finishes. Clearing local data can proceed offline while the minimum derived revocation credential is retained for retry.

Outside services

What we use. What we don't.

BaeMax does not include advertising networks or a general-purpose analytics SDK. It uses service providers for push delivery, Android app distribution, optional maps, and beta email. BaeMax does not request contacts access and does not currently include Sentry or another remote crash-reporting SDK.

  • Expo and Google Firebase Cloud MessagingProcess push tokens, delivery metadata, and notification text to deliver Android alerts.
  • Google PlayDistributes the Android app and processes installation, update, security, and device information under Google's terms.
  • Google MapsProvides map display for location features and can receive network/device information and the map area requested by the app.
  • Your phone's OSHandles local and secure storage, camera, microphone, location, notifications, media picking, and biometric authentication.
  • Our relay serverPasses encrypted messages between paired phones without reading them.
  • ResendProcesses beta-waitlist email addresses, message content, and delivery details so we can send signup confirmations and notify the BaeMax owner about new signups.
  • BrevoMay process the same beta-waitlist email and delivery details as a backup transactional-email provider if the primary email provider is unavailable.
  • Apps you share toThrough your phone's share menu — those apps follow their own privacy rules.
  • Image hostingIf you set a profile picture using a web link, your phone connects to the host directly. Our server does not see, store, or pass along your profile photo.

Beta signups

What we store from the waitlist.

If you explicitly agree and sign up for the beta on our website, we store your email address, signup and consent times, privacy-notice version, an internal random ID, one-way confirmation and cancellation-token hashes, confirmation status, email-delivery status, and server-side request metadata such as IP address, an IP hash, masked IP, trusted proxy chain, browser family, and bounded user-agent text. This request metadata is used for abuse prevention and operational review, is not returned by the public signup form, and raw IP/browser details are not exposed in public website scripts. Resend processes the address and delivery details to send the confirmation; Brevo may process the same details as a fallback provider. You can confirm your signup from that email, remove your address with the cancellation link in that email, or email [email protected] from the address you joined with. After removal, we keep only daily signup and cancellation totals with no email address or other identifier.

The short version

Your data is yours.

Your primary record lives on your phone. Partner-sync content is encrypted before it reaches our relay, but notification delivery, maps, beta signup, and operational metadata involve the providers described above. The current beta's retention and incomplete-export limitations are stated on this page.

Encrypted partner-sync and chat payloads are not readable by the relay. Notification text and the operational records listed above follow separate handling.

We don't run ads or sell personal data. We limit collection to the app, delivery, security, and support purposes described here.

Questions about privacy?

Send privacy questions, correction requests, or concerns to the BaeMax team.

[email protected]