NextSide — Privacy Policy
Last updated: 14 August 2026
This Privacy Policy explains how Cemal Karabulaklı
("we", "us", "our"), the developer of the NextSide mobile
application (the "App", package com.nextside.nextside), collects,
uses, stores, and shares your information.
NextSide is an offline-first breastfeeding side-tracker. We built it to be private by default: the core features (logging, history, reminders, and night mode) work entirely on your device and require no account and no internet connection. We do not show ads and we never sell your data.
Questions? Contact us at cemalkarabulakli@gmail.com.
1. Summary (the short version)
| What | Details |
|---|---|
| Feeding logs — just the side (L/R) and time (no names, notes, weights, or amounts) | Stored locally on your device by default. Only leaves your device if you turn on the optional Premium cloud backup. |
| Account (email or Google sign-in) | Collected only if you choose to sign in to use cloud backup. |
| Cloud backup | Optional, Premium-gated. Mirrors your feeding history to Google Cloud Firestore so you can restore it. |
| Analytics & crash reports | Anonymous usage analytics (Firebase Analytics and Mixpanel) is on by default and you can turn it off anytime in Settings. Firebase Crashlytics helps us fix crashes. |
| Push notifications | Used for feed reminders. |
| Content updates | Firebase Remote Config lets us correct the Premium guide's text without an app update. Sends an app installation identifier; receives text. |
| Subscriptions | Managed via Adapty; payments handled by Apple/Google. |
| Ads | None. We do not use advertising or ad networks. |
| Selling data | Never. |
| Delete your data | You can delete your account and all associated data at any time — see sections 9 and 10. |
2. Who is responsible for your data
The data controller is Cemal Karabulaklı, Türkiye. For any privacy request, email cemalkarabulakli@gmail.com.
3. What we collect, and why
We only collect what a feature needs.
3.1 Feeding history — only the side and time, local by default
When you log a feed, the App stores just the side (left or right) and the date and time, on your device, in a local database. It does not record names, notes, weights, amounts, or any other detail about you or your baby. By default this never leaves your device and is not transmitted to us or anyone else — it is used only to show your history and compute the suggested next side. It becomes associated with your account only if you enable cloud backup (Section 3.3).
3.2 Account information — only if you sign in
Signing in is optional and exists only to protect (back up) history you already have. If you sign in we process, via Firebase Authentication, your email address (email sign-in) or your Google account identifier and email (Google sign-in).
3.3 Cloud backup data — only if Premium + enabled
If you have an active Premium subscription and turn on cloud backup, your
feeding history is copied to Google Cloud Firestore under your
account (users/{your-id}/feeds/…) so you can restore it. This is a
single-device backup, not multi-caregiver or real-time sync. Restoring replaces
the local history on that device.
3.4 Usage / analytics data — anonymous, with an opt-out
We use Firebase Analytics and Mixpanel to understand onboarding, feed logging, landing-page store clicks, and Premium conversion. These events are anonymous and are collected by default. You can turn analytics off at any time in the App's Settings (or through Privacy choices on the website) and the App stops sending events immediately. We send anonymous interaction events, platform, app version, language, and an analytics-assigned device identifier. We do not send your email, feeding time, breast side, or onboarding quiz answers to analytics, and we do not use this data for advertising and do not share it with data brokers. Mixpanel uses European data residency.
3.5 Diagnostics / crash data
We use Firebase Crashlytics to detect and fix crashes, receiving crash stack traces, device state, OS version, and device model. We do not include your feeding history in crash reports.
3.6 Push-notification token
We use Firebase Cloud Messaging to deliver notifications (e.g. feed reminders), using a device push token. Local reminders scheduled on the device do not transmit data.
3.7 Subscription / purchase data
We use Adapty to manage paywalls and subscription state, processing a subscription/transaction identifier and a device/user identifier. Payment is processed by Apple App Store or Google Play — we never receive or store your payment details.
3.8 App configuration and content updates
We use Firebase Remote Config to update the text of the Premium breastfeeding guide without publishing a new version of the App, so corrections and improved wording reach you promptly. To fetch the current content, your device sends Google an app installation identifier together with basic app and device information (app version, operating system, language, and country). We do not send your feeding history, account details, or any analytics event through this service — the App receives text.
This is separate from analytics and is not covered by the analytics consent choice, because it is needed for the App to show correct content rather than to measure your behaviour. In practice it is only contacted when a Premium subscriber opens the guide; if it is unavailable, the App simply displays the guide text that shipped inside it.
We do not collect your contacts, precise location, microphone, camera, photos, SMS, or the list of other apps on your device.
4. Legal bases for processing (GDPR / UK GDPR)
The App is offered to users in the European Union, so the EU GDPR (and UK GDPR) applies. We rely on contract (to provide the App, accounts, backup, subscriptions), consent (for optional cloud backup), and legitimate interests (security, abuse prevention, improvement — including anonymous usage analytics, which you can switch off at any time in Settings). The feeding logs themselves are minimal (side and time only) and are not tied to your identity unless you enable cloud backup. Depending on how your national data-protection authority classifies infant-feeding information, additional protections may apply; where they do, we rely on your explicit consent (e.g. when you enable cloud backup).
5. How we share information
We do not sell your data and do not share it for third-party marketing. We use the following service providers (processors):
| Provider | Purpose | Data involved |
|---|---|---|
| Google Firebase (Auth, Firestore, Analytics, Crashlytics, Cloud Messaging, Remote Config) | Sign-in, cloud backup, analytics, crash reporting, notifications, in-app content updates | Email/account ID, backed-up feeding history, usage/diagnostics, push token, app installation identifier |
| Adapty | Subscription management / paywalls | Subscription + device/user identifiers |
| Mixpanel | Consent-based product and subscription analytics | Anonymous interaction events and analytics identifier; subscription state forwarded by Adapty |
| Apple App Store / Google Play | Payment processing, app distribution | Purchase transaction (handled by the store) |
We may disclose information if required by law, to enforce our terms, or to protect rights, safety, and security.
6. International data transfers
Mixpanel analytics is configured for European data residency. Other providers may process data on servers outside your country, including the United States. Where required, transfers rely on appropriate safeguards (e.g. Standard Contractual Clauses).
7. Data retention
- Local feeding history: kept on your device until you delete it or uninstall the App.
- Cloud backup: kept until you delete it, disable backup, or delete your account.
- Account data: kept while your account exists; removed on deletion (subject to limited retention for security, fraud prevention, or legal compliance).
- Analytics/diagnostics: retained according to the configured Firebase, Mixpanel, and Crashlytics retention settings.
8. Security
Data in transit to our providers is encrypted using TLS/HTTPS. Cloud backup is protected by access rules tied to your authenticated identity. No method of transmission or storage is 100% secure, but we take reasonable measures to protect your information.
9. Your choices and rights
Depending on your location (e.g. EEA/UK under GDPR, California under CCPA/CPRA), you may have the right to access, correct, delete, export, or object to/restrict processing of your data, and to withdraw consent. Exercise these in-app or by emailing cemalkarabulakli@gmail.com. You may also complain to your local data-protection authority.
In-app controls: use the App fully without an account; turn cloud backup on/off anytime; enable or withdraw anonymous analytics in Settings (or via Privacy choices on the website); manage or cancel your subscription in the App Store / Google Play.
10. Account and data deletion
(Required by Google Play for apps with accounts.) You can delete your account and all associated data at any time:
- In-app: open Settings → Account → Delete account. This permanently deletes your account and cloud-backed feeding history from Firebase.
- By email: write to cemalkarabulakli@gmail.com from your account email; we will delete your account data within 30 days.
Feeding history stored locally on your device is deleted when you delete it in-app or uninstall the App. We may retain limited information where necessary for security, fraud prevention, or legal compliance.
11. Children's privacy
NextSide is intended for use by parents and adult caregivers, not by children. Although it records information relating to an infant's feeding, that information is entered and controlled by the adult user. The App is not directed to children and we do not knowingly collect personal data directly from children. If you believe a child has provided us personal data, contact us and we will delete it.
12. Changes to this policy
We may update this Privacy Policy from time to time. We will change the "Last updated" date above and, for material changes, provide a more prominent notice in the App.
13. Contact
Cemal Karabulaklı
Email: cemalkarabulakli@gmail.com
Address: Türkiye