24/7 Mom
HomeDemoAboutContactWhat It DoesJoin Waitlist →
Legal

Privacy Policy

24/7 Mom is a personal AI assistant for parents and caregivers, operated by Batoom LLC. This policy explains what data we collect, why, how we use it, and what choices you have.

Effective: June 4, 2026·Last updated: July 19, 2026
On this page
  • Who we are
  • What this policy covers
  • Data we collect
  • How we use each category
  • How the AI works
  • Google Limited Use
  • Sub-processors
  • How we make money
  • Data retention
  • Your rights
  • Consents at onboarding
  • Children’s data
  • Health data
  • Security
  • Where data is stored
  • California privacy rights
  • Changes to this policy
  • Contact

Who we are

24/7 Mom is a personal AI assistant for parents and caregivers, operated by Batoom LLC (“we”, “us”, “24/7 Mom”). This policy explains what data we collect when you use the 24/7 Mom mobile app and web demo, why we collect it, how we use and share it, how long we keep it, and what choices you have.

support@247mom.ai
Batoom LLC
8 The Green, Suite B
Dover, DE 19901

What this policy covers

This policy covers your use of the 24/7 Mom mobile app and the 24/7 Mom web app. It does not cover third-party services you choose to connect — Google, your school’s Canvas/LMS, Instacart, Crossmint, your device’s built-in calendar, Apple iCloud Calendar, and health/fitness sources (Apple Health, Oura, WHOOP). Those services have their own privacy policies, which we link to under “Sub-processors” below.

Data we collect

We collect data from four sources: (1) what you tell us when you sign up and onboard, (2) what flows in from third-party services you choose to connect, (3) what’s generated as you use the app, and (4) what our systems infer from the above. Each category is listed below with what it contains and where it comes from.

1. Account data (source: Clerk authentication)

When you create a 24/7 Mom account we receive from Clerk: your email address, your name (from Google profile if you sign in with Google, or as you type it), your Clerk user ID, and authentication state (sign-in events, session tokens). We do not receive your Google password.

2. Onboarding & household data (source: you, in the app)

During onboarding and in Settings you can provide:

  • About you — your name, mailing/shipping address, life stage and household situation, and health focus areas you select (which may include reproductive-health context such as pregnancy, nursing, or menopause).
  • About your partner, if you add one — name, food preferences, and allergies.
  • About your children, if you add them — name, age and date of birth, gender, height and weight, shoe and clothing sizes, allergies, dietary restrictions and food rules, grade level, academic focus and notes, sports and interests, and brand preferences.

You provide household-member data on behalf of those people; see “Children’s data” below.

3. Photos you upload for avatars

You can optionally upload a photo of yourself or a family member so the agent can generate a cartoon avatar with a similar likeness.

We never store that photo. It is held in server memory for the duration of that single request, forwarded once to the image-generation provider, and discarded when the request ends. It is never written to our database, never written to file storage, never logged, and never included in a data export — because no copy of it exists to export.

The generated cartoon avatar is stored, so the app can display it without regenerating it. It is kept in access-controlled private storage and served through short-lived signed links; it is not publicly accessible. It is deleted when you replace it, remove the family member, or delete your account.

4. Connected Google data (source: your Google account, with your consent)

If you connect Google in Settings, we request the following OAuth scopes. Each is requested only to power a specific user-facing feature:

ScopeWhat we read/writeFeature this powers
gmail.modifyRead messages and bodies; create drafts; send replies you’ve approved; add/remove labels; archive — all on your own mailbox. We do not permanently delete mail.Background email pipeline that extracts events, school notices, and reminders for the Today tab/Morning Brief; agent read, draft, approved-send, label, and archive in chat
calendar.eventsRead, create, update, and delete events on your primary calendarToday tab, Morning Brief, agent-created calendar events, school-extracted events
userinfo.emailYour connected Google account’s email address (and account identifier)Show which Google account is connected in Settings

We request a single Gmail scope, gmail.modify, which covers all of the above. We do not request full-mailbox access (https://mail.google.com/) or any scope that permanently deletes mail. We do not request access to Google Drive, Contacts, YouTube, Photos, Search history, or any other Google product, and we do not request the userinfo.profile scope (we never read your Google profile name, picture, or other profile fields).

5. Other connected calendars

You can also connect Apple iCloud Calendar (using an Apple ID and an app-specific password, which we store encrypted) or grant access to your device’s built-in calendar. From either we read event titles, times, and locations to populate your Today tab and daily brief.

6. Connected Canvas/LMS data (source: school portal, with your consent and per-kid)

If you connect Canvas or another supported LMS provider for a specific child, we receive: course list, assignment titles, due dates, grades, missing-assignment counts, and teacher names for that child. We retain a history of these grade snapshots over time so the app can show trends. This is minor data — see “Children’s data” below.

7. In-app generated data

As you use 24/7 Mom, we generate and store:

  • Chat messages — what you send the agent and what it replies
  • Agent memory (“gbrain”) — facts the agent learns about your household, stored as a personal knowledge graph in your dedicated server-side workspace
  • Extracted events, reminders, and proactive notes — derived from your email and chat
  • Email reply drafts — proposed replies awaiting your approval
  • Email classifications and skip patterns — short-lived operational signals that decide what to surface vs. ignore
  • Sender memory and sender trust — long-running learned context per sender
  • Pantry inventory and shopping history — items you’ve marked in your pantry, your shopping lists, and remembered product preferences from prior orders
  • Audit logs — every action the agent takes on your behalf in Gmail (gmail_audit) or Google Calendar (calendar_audit), and a record of actions the agent takes generally
  • Agent reasoning records — for a limited period we retain the prompts we sent to the AI model and the responses it returned, so we can debug incorrect behavior and investigate abuse. Because a prompt carries whatever context that turn required, these records can include email bodies, household and children’s details, health context, and memory facts. They are retained for 30 days and then deleted.
  • Usage events — model and token counts for cost accounting
  • Content reports — if you report an agent message you find objectionable, we store the reported message text and any reason you provide so our team can review it and act on it
  • Support messages — if you contact us through the in-app support form, your message and the contact details you provide are sent to our support mailbox by email. We do not store them in the app database.

8. Inferred data

Some features work by drawing inferences rather than reading a value you supplied. Specifically, we derive and store wellbeing signals — for example an indication that you may be overloaded or running low, computed from calendar density and connected sleep data — which we use to adjust what the app surfaces and when. We also track which health screenings may be due based on the profile information you provide. These are inferences, not diagnoses, and they are covered by the health-data protections below.

9. Device data

When you enable push notifications: your Expo push token (or, on the web app, your browser’s push subscription) and the timezone reported by your device, used to deliver the 7am Morning Brief in your local time.

10. Financial data

When you make a purchase through 24/7 Mom we receive and store: the order details, the merchant (Crossmint, Instacart, etc.), the status, and the merchant’s order identifier. Where agent-assisted checkout is available to you and you enrol a payment card, we store only a vaulted reference to that card held by our payment processor, plus its brand and last four digits. We do not receive or store your full credit-card number, bank-account details, or wallet private keys.

If you ask us to send something to an address other than your own, we store the delivery address and any instructions you provide for that order.

11. Connected health & fitness data (source: Apple Health, Oura, or WHOOP — with your explicit consent)

If you connect a health or fitness source in Settings, we read the metrics you authorize — steps and activity, sleep and sleep stages, heart rate and heart-rate variability, resting heart rate, blood-oxygen and skin-temperature readings where the device reports them, and workouts. On iOS this uses Apple HealthKit and is read on-device only after you grant permission for each category in Apple’s system Health prompt; Oura and WHOOP data is read from their APIs using a token you authorize.

This can include a child’s data. With your consent as the parent, a child’s own wearable can be connected, and the same categories are collected for that child.

We use this data solely to show in-app health trends and to personalize your daily brief. We never use health or fitness data for advertising, and we never share it with third parties for marketing.

12. Children’s screen-time data (not yet available)

We are building a feature that would show you summary screen-time and app-usage information for a child you have added. It requires an Apple entitlement we have not yet been granted, and no screen-time data is collected today. If and when it ships, it will be off by default, will require your explicit consent, and will be treated as minor data — see “Children’s data” below. We will update this policy before it becomes available.

How we use each category

We use your data only to provide and improve user-facing features that are prominent in the 24/7 Mom app. We do not sell your data. We do not use it for advertising. We do not transfer it to third parties for any purpose other than operating the service or as required by law.

CategoryUsed for
Account dataAuthentication, account management, communication about the service
Onboarding/householdPersonalizing the agent’s responses; surfacing kid-relevant content
Uploaded photosGenerating a cartoon avatar in that one request, then discarded
Google (Gmail/Calendar)Email triage, event extraction, reply drafting, calendar reads/writes — all visible features
Other calendars (iCloud, device)Populating your Today tab and daily brief
Canvas/LMSShowing upcoming assignments, grades, and grade trends to the parent
Chat & memoryContinuing prior conversations; recalling facts you’ve shared
Audit logs & agent reasoning recordsShowing you what the agent did; debugging incorrect behavior; security investigations
Inferred wellbeing signalsAdjusting what the app surfaces and when
Usage eventsInternal cost accounting (no external sharing)
Push tokenDelivering Morning Brief and other notifications you’ve opted into
FinancialOrder tracking, transaction history, refund/dispute handling
Health & fitness (Apple Health / Oura / WHOOP)In-app health trends dashboard and personalizing your daily brief — never advertising, never shared for marketing
Content reports & support messagesReviewing and acting on what you report or ask us

How the AI works, and what it receives

24/7 Mom is built on large language models operated by third parties. To answer a question or take an action, we assemble a prompt and send it to a model provider.

What that prompt can contain. Depending on what you asked, it may include: your recent chat messages; facts from your agent memory; your household profile, including your children’s names, ages, and allergies; your calendar for the relevant period; the full text of an email we are triaging or drafting a reply to; and summaries derived from your connected health data.

Which providers receive it. Conversational and reasoning requests go to Anthropic. Text we index for memory search is sent to OpenAI to compute embeddings. Avatar image generation goes to Google (Gemini) or fal.ai — this is the only case in which a photo you upload leaves our servers, and no copy is retained by us.

Model providers process this data under their commercial API terms in order to return a response. Anthropic and OpenAI do not train on data submitted through their APIs. For avatar image generation we rely on the applicable terms of the provider used; where a provider’s terms would permit training on submitted content, we do not send that provider a reference photo.

Google API Services User Data Policy — “Limited Use”

Our handling of data obtained from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements reproduced verbatim below:

Limited Use: Your use of data obtained via the product’s specified scopes must comply with the below requirements. These requirements apply to the raw data obtained from the scopes and data aggregated, anonymized, or derived from them.

  • Limit your use of data to providing or improving user-facing features that are prominent in the requesting application’s user interface;
  • Transfers of data are not allowed, except:
    • To provide or improve your appropriate access or user-facing features that are visible and prominent in the requesting application’s user interface and only with the user’s consent;
    • For security purposes (for example, investigating abuse);
    • To comply with applicable laws; or,
    • As part of a merger, acquisition, or sale of assets of the developer after obtaining explicit prior consent from the user.
  • Don’t allow humans to read the data, unless:
    • You first obtained the user’s affirmative agreement to view specific messages, files, or other data, with the limited exception of use cases approved by Google under additional terms applicable to the Nest Device Access program;
    • It is necessary for security purposes (for example, investigating a bug or abuse);
    • It is necessary to comply with applicable law; or
    • The data (including derivations) is aggregated and used for internal operations in accordance with applicable privacy and other jurisdictional legal requirements.

All other transfers, uses, or sales of user data are prohibited, including:

  • Transferring or selling user data to third parties like advertising platforms, data brokers, or any information resellers.
  • Transferring, selling, or using user data for serving ads, including retargeting, personalized or interest-based advertising.
  • Transferring, selling, or using user data to determine credit-worthiness or for lending purposes.

You must ensure that your employees, agents, contractors, and successors comply with this Google API Services User Data Policy.

Sub-processors

We rely on the sub-processors below to operate the service. Each receives only the categories of data necessary for its function. We update this list when we add or remove a provider.

Core infrastructure

Sub-processorWhat it receivesPrivacy policy
Clerk (authentication)Email, name, sign-in eventsView
Supabase (database & file storage, us-east-1 — North Virginia)All non-secret app data (users, kids, messages, events, generated avatars, etc.)View
Hostinger (application server hosting, Boston, United States)Runs our API and all per-user OpenClaw containers. Receives encrypted data-at-rest within the server filesystem.View
OpenClaw (per-user agent runtime)Your in-app chat content, agent memory; runs in your dedicated container on our Hostinger VPS.Self-hosted on our own infrastructure (covered by Hostinger above; no separate third party)
Sentry (error monitoring)Server-side error reports with PII scrubbed (email/token bodies, message contents)View
Expo (push notifications, app distribution)Your Expo push token; push payload contents at send timeView
Browser push services (Apple, Google, Mozilla — web app only)Encrypted push payloads addressed to your browserGoverned by your browser vendor
Netlify and Vercel (web app hosting and routing)Requests to the web app, including IP address and request pathView·View
esm.sh (script CDN, card-enrollment page only)A request from your browser for the payment SDK when you open the card-enrollment pageView
Google Workspace / Gmail SMTP (our support mailbox)Support messages you send us, and the contact details you provideView

AI model providers

Sub-processorWhat it receivesPrivacy policy
Anthropic (Claude — conversation and reasoning)The prompt described under “How the AI works” above, plus your latest messageView
OpenAI (text embeddings for memory search)The text of memory facts and notes to be indexedView
Google (Gemini — avatar image generation)The avatar prompt and, if you supplied one, the reference photo for that single requestView
fal.ai (avatar image generation, fallback provider)The same avatar prompt and reference photo, where Gemini is unavailableView

Connected services you choose

Sub-processorWhat it receivesPrivacy policy
Google (Gmail, Calendar, OAuth)API requests authorized by your OAuth grant; outbound emails you’ve approvedView
Apple (iCloud Calendar, HealthKit)Calendar requests authenticated with the app-specific password you provide. HealthKit data is read on-device and is not sent to Apple by us.View
Canvas / LMS provider (educational data source)Read-only API calls using the personal access token you providedVaries by provider — refer to your school’s or LMS provider’s privacy policy
Oura (health & fitness data source)Sleep, heart-rate/HRV, and activity metrics via the Oura API, using the token you authorizeView
WHOOP (health & fitness data source)Recovery, sleep, and activity metrics via the WHOOP API, using the token you authorizeView

Commerce and fulfillment

Sub-processorWhat it receivesPrivacy policy
Crossmint (payment processing)Wallet identifier, vaulted card reference, and transaction parameters for purchases you approveView
Instacart (grocery fulfillment)We hand off a shopping list URL; you transact with Instacart directlyView
Google Places (address autocomplete)The address text you type while we suggest completionsView
Impact (affiliate attribution)Attribution parameters appended to retailer links we surface — see “How we make money” belowView

Lookup and search providers

These receive a query, not your account identity. We never send your name, email, or account ID with these requests. Note that a query can carry household context where that context is what makes the result useful — a product search may include your family’s allergies as terms to exclude, and a health lookup may pass along the wording of your question.

Sub-processorWhat it receivesPrivacy policy
SearchAPI.io (product and travel search)Product search terms; for travel, the origin, destination, dates, and party size you asked aboutView
Brave Search (health and general web lookup)The search terms derived from your questionView
Spoonacular (recipes and nutrition)Recipe search terms, and the diet and intolerance filters that apply — which reflect your household’s dietary restrictions and allergiesView
OpenWeatherMap (weather)Your postal code, resolved to approximate coordinates. We do not collect or send precise device location.View
openFDA and NCBI PubMed (drug and medical reference)The health or medication terms from your questionPublic U.S. government services
Open Food Facts and UPCitemdb (product lookup)Product names or barcodesView

How we make money

24/7 Mom does not currently charge a subscription fee, and we do not sell your data or run advertising.

When we surface a link to a retailer — for example an Instacart shopping list — that link may carry an affiliate code, and we may earn a commission if you complete a purchase through it. This does not change your price. It also does not change what we recommend: the agent selects products and retailers based on your request and your saved preferences, not on which link pays us.

Data retention

We keep different categories of data for the periods below.

CategoryRetention
Account dataUntil you delete your account
Chat messagesUntil you delete your account
Agent memory (“gbrain”)Until you delete your account, or until you clear it in Settings
Uploaded reference photosNot retained at all — discarded at the end of the request
Generated avatarsUntil you replace them, remove the family member, or delete your account
Email classifications and skip patterns90 days
Sender memory and sender trustUntil you delete your account
Email draftsMarked expired after 7 days and no longer offered to you; the draft text is deleted at 90 days
Gmail audit log (gmail_audit)90 days
Calendar audit log (calendar_audit)90 days
Agent action log180 days
Agent reasoning records (prompts and model responses)30 days
Events, ordersEvents until you delete your account, or 2 years past the event date — whichever comes first. Orders for 2 years.
Instacart links and delivery records2 years
Pantry inventory and shopping historyUntil you delete your account
Morning briefs and proactive notes90 days
Proactive outreach records180 days
Health information you enter manually (children’s allergies, household dietary preferences)Until you delete your account or remove the record
Connected health & fitness metrics (Apple Health / Oura / WHOOP)1 year, and deleted sooner if you disconnect the source or delete your account
LMS grade snapshots2 years
Content reportsUntil you delete your account
Support messagesDelivered to our support mailbox as email and retained there; not stored in the app database
Google, LMS, Oura, WHOOP access tokensUntil you disconnect or delete your account. We also revoke tokens that have gone unused — Google after 180 days of inactivity, Oura and LMS after 30 days — and unused push tokens after 180 days.
Usage events (model/cost telemetry)180 days
Server error records90 days
Account audit events (records of consent, export, and deletion)7 years — see below

When you delete your account, we remove your account and the data associated with it, as described under “Your rights”. One narrow exception: we retain a minimal record that a deletion occurred — its date and an internal account reference — for 7 years, so we can demonstrate to a regulator that we honored your request. That record contains no chat, email, health, household, or children’s data.

Retention exception for data export requests: If you have requested a data export within the past 30 days, automated retention deletion is paused for most categories on your account until that window closes, so the data in your export matches what we held when you asked. Account deletion is not affected by this exception and always runs immediately.

Your rights

You have the right to:

  • Access and export your data — via Settings → Export my data, you can download a machine-readable JSON bundle of every row associated with your account (profile, kids, chat history, events, orders, health metrics, audit logs, etc.). Token and credential fields are stripped from the bundle for safety. This satisfies both your right of access and your right to data portability.
  • Delete your account and the data associated with it — via Settings → Delete account. The cascade revokes external OAuth tokens where the provider supports revocation, removes your agent container and all of its memory, deletes your generated avatars from storage, deletes your records from our database, and deletes your Clerk identity. If any step fails we record the failure and complete it manually; you can ask us to confirm at support@247mom.ai.
  • Correct inaccurate data — edit your profile in Settings, edit kid records in Settings, or contact support@247mom.ai.
  • Withdraw consent for a connected service at any time — Settings → Disconnect. Disconnecting revokes the OAuth grant where the provider supports a revoke endpoint and removes the local credential.

Consents we record at onboarding

When you sign up we record explicit, versioned grants for each of the following. The version is captured alongside the grant so that if the underlying document changes we will re-prompt you for a fresh acknowledgement of the updated version:

  • Acceptance of these Terms of Service
  • Acknowledgement of this Privacy Policy
  • Your representation that you are 18 years of age or older
  • Consent to AI processing of your data, including data from services you connect
  • Parental authority and authorization to provide children’s information — required only if you add one or more children to your household
  • Household-member authorization to provide partner information — required only if you choose to add a partner

These records persist while your account is active and are included in any data export you request.

Children’s data

The 24/7 Mom app is designed for and directed to adult parents and caregivers, not children. We do not knowingly collect personal information directly from children under 13, and children do not have their own accounts.

Information about a child is provided or authorized by the account-holding parent or caregiver, who represents that they have legal authority to do so. Depending on which features you use, that information can include:

  • Name, age, date of birth, and gender
  • Height, weight, shoe and clothing sizes
  • Allergies, dietary restrictions, and food rules
  • School data via Canvas/LMS — courses, assignments, due dates, grades, grade history, missing-assignment counts, and teacher names
  • Health and fitness metrics, if you connect a wearable for that child
  • Screen-time and app-usage summaries — planned, not yet available; see section 12 above
  • A generated cartoon avatar, and — for the single request that creates it — a photo you upload

Before any of this is collected we ask for your explicit parental-authority consent, and we ask for a separate consent before a child’s data is shared with any third party.

Parents can review, correct, or delete a child’s information at any time by editing or removing that child in Settings, via the in-app account deletion flow, or by contacting support@247mom.ai. If we learn that we have collected personal information from a child under 13 without verifiable parental consent, we will delete it.

Health data

24/7 Mom collects health-related information from three sources, all only with your involvement: (1) information you enter yourself — your own health focus areas and life stage, and your children’s allergies and your household’s dietary preferences — which we use to filter agent suggestions so they respect your family’s safety constraints; (2) health and fitness metrics from a source you explicitly connect, for you or for a child, as described above; and (3) inferences we draw from that data, as described under “Inferred data”.

24/7 Mom is not a medical device. Nothing the agent says about your or your family’s health constitutes a medical diagnosis or medical advice. We are not a HIPAA-covered entity; the health, fitness, dietary, and allergy data you choose to share with us is consumer health information, not Protected Health Information under HIPAA in this context. All of it is encrypted in transit (TLS) and at rest, is never used for advertising and never shared with third parties for marketing, and is removed when you disconnect the source, delete the corresponding record (e.g., a child profile), or delete your account.

Note that health context can be included in a prompt sent to an AI model provider, as described under “How the AI works”.

Security

  • In transit: All traffic between the app, our API, Supabase, and third-party services is encrypted with TLS.
  • At rest: All data in our Supabase database is encrypted at rest. Credentials stored in our connections vault — including iCloud Calendar app-specific passwords — receive a second layer of application-level encryption on top of that, using a key held only in our server environment.
  • Database access control: Row-Level Security (RLS) on every Supabase table denies all direct client reads. Application access goes through our authenticated API only.
  • File storage: Generated avatars are held in a private bucket and served only through short-lived signed links.
  • Admin access: Operator access to the admin dashboard is gated by Clerk authentication and a per-user allowlist. Destructive operations require a shared secret plus a typed confirmation phrase.
  • Agent isolation: Each user’s agent runs in a dedicated containerized workspace; one user cannot read another user’s memory or chat.
  • Breach notification: If a data breach occurs that affects your personal information, we will notify you and the relevant regulators as required by applicable law.

Where your data is stored and processed

Your data is stored and processed in the United States. Our database is hosted on Supabase in the us-east-1 region (North Virginia). Our application servers are hosted on Hostinger in Boston, United States. Some sub-processors listed above may process data outside the United States; where they do, they operate under their own published safeguards. If we add our own infrastructure in other regions, we will update this policy and notify users in advance.

California privacy rights

California residents have additional rights including the right to know what personal information we collect, the right to delete, the right to correct, the right to opt out of sale or sharing (we do not sell or share personal information for cross-context behavioral advertising), and the right to non-discrimination. Exercise these rights via support@247mom.ai or the in-app account deletion flow.

Changes to this policy

We may update this policy from time to time. When we do, we will update the “Last updated” date at the top and, for material changes, notify you via the app and/or by email at the address on file. The current version of this policy is always available at www.247mom.ai/privacy. Prior versions are available on request at support@247mom.ai.

Contact

For privacy questions, data requests, or to report a concern:

support@247mom.ai
Batoom LLC
8 The Green, Suite B
Dover, DE 19901

This Privacy Policy is effective June 4, 2026 and was last updated July 19, 2026.

Made with care. Built with purpose. © 2026 Batoom LLC · Privacy · Terms · About · Contact

24/7 Mom is a product of Batoom LLC.