Privacy policy
This explains what we collect, why, and what you can do about it. We have written the short version first, because a policy nobody reads protects nobody.
Last updated: 12 August 2026The short version
You are pregnant, or you have a small child, and you are telling us things you would not tell most people. Here is how we treat that.
- We ask for your explicit consent before we touch anything health related, and you can take it back.
- Your health data never reaches a third-party analytics tool. Not once, not anonymised, not by accident. The app is built so that it cannot happen.
- We do not sell your data. We do not work with data brokers. We do not carry third-party trackers. We never collect a consent on someone else's behalf.
- Scan images, photographs and anything you write stay in the United Kingdom.
- If you use the weather in your world, your position is rounded to about ten kilometres on your phone before anything leaves it, and the rounded point goes to the weather service, never to us.
- You can ask for everything we hold in a couple of taps, and you can leave in a couple of taps.
The rest of this page is the formal detail. If anything below contradicts the short version, tell us, because we have made a mistake.
Our promise about advertising and partners
Pregnancy is one of the most heavily marketed moments in a person's life, and the usual pregnancy club exists to collect your details and pass them on. We were built as the opposite of that, and these are commitments, not aspirations.
- We never sell your personal data. There is no price at which we would.
- We never share your data with data brokers, list brokers or lead generators.
- We carry no third-party advertising or tracking software. There is no advertising network in the app or on this website.
- We never collect a consent on behalf of a third party. If a brand wants to talk to you, you choose that brand, one at a time, and you can change your mind.
- Sponsored articles are matched on your device. When you see a piece of sponsored reading, the advertiser receives a daily count and nothing else. They never receive anything that could be traced back to you.
1. Who we are
The Parent Room is a pregnancy and early-parenthood companion, available as a mobile app and at theparentroom.co.uk. It is operated by WTTW Retail Ltd ("we", "us", "our"), a company in the Window to the Womb group. For the data described in this policy, WTTW Retail Ltd is the data controller.
| Detail | Information |
|---|---|
| Data controller | WTTW Retail Ltd |
| Registered address | Victoria Works, Woodhead Road, Holmfirth, England, HD9 2PR |
| Company number | 13438144 |
| ICO registration | ZA167524 |
| Data protection contact | [email protected] |
| Data Protection Officer | [NEEDS DAN: confirm whether a DPO has been appointed under Art. 37 and, if so, publish their name and contact details. Given the scale of special category processing here, this is likely to be required.] |
Your scan images, appointment records and clinical reports are held by Window to the Womb (Franchise) Ltd, a separate company in the same group and the controller for the Window to the Womb and firstScan clinic network. Section 10 explains how the two companies work together.
2. What we collect
When you create an account
- Your name and email address
- Your password, which is never stored in plain text
- Your date of birth, which is optional. If you give it, we use it to look for a matching Window to the Womb booking so your scans are already waiting for you. If we find no match, nothing happens and you keep your account.
- Your due date, or your baby's date of birth, or that you are trying to conceive, depending on where you are joining from
- A record of the three consents you gave, with the date, the time and the IP address you gave them from, so that we can prove the consent was real
Anyone in the UK can join. You do not need to be a Window to the Womb customer. A booking match is a quiet upgrade, never a gate.
As you use the app
- Your pregnancy stage or your child's age, worked out from the date you gave us
- Anything you choose to record: check-ins, notes, letters, kick sessions, memories, documents, names, appointments
- Your scan images, clips and appointment details, if you have connected your clinic records
- Photographs you add, including photographs of your baby and children
- Your avatar and your baby's avatar
- Hearts, levels and which parts of the app you have opened
- Who is in your family circle, and what each of them is allowed to see
Technical data
- Your device type and operating system version
- A device identifier and a push token, if you turn notifications on
- Your IP address, in our server logs and against your consent records
- An approximate location, only if you turn the real weather on, and only in the way described in section 5
3. Health data and your explicit consent
Most of what makes The Parent Room useful is special category data under Article 9 of the UK GDPR, because it concerns your health. That includes your due date and pregnancy stage, your scan images and clinical reports, your symptoms and check-ins, your cycle if you use that part of the app, and your baby's health milestones.
We process all of it on the basis of your explicit consent under Article 9(2)(a), with Article 6(1)(a) as the lawful basis for the processing itself.
You give that consent when you create your account. It is a separate tick from agreeing to the terms and from confirming that you have read this policy, and none of the three is pre-ticked. We record the date, the time and the IP address for each one.
Taking your consent back
You can withdraw your health data consent at any time, from Privacy and permissions inside the app. Because that consent is the lawful basis for the whole service, withdrawing it closes your account. When you tap it:
- Your consent is marked withdrawn immediately, with a timestamp
- Your journey is closed, so nothing further is recorded and your family circle stops seeing it
- Every sign-in token is revoked, so you are signed out on every device at once
- An erasure request is queued for our team, which we action within one month
Withdrawing consent does not make anything we did beforehand unlawful.
Weekly pregnancy updates
Weekly emails matched to your stage are switched on when you join. They are not sent on the basis of your health data consent. We send them under our legitimate interest, supported by the soft opt-in exemption in Regulation 22(3) of PECR, and we have published our full reasoning in our Legitimate Interest Assessment rather than keeping it in a drawer.
You can switch them off at any time from your profile or from the unsubscribe link in any email. It takes effect immediately, it is free, and it changes nothing else about your account. You will still get the essential emails: verification, password resets and security alerts.
4. Why we use your data, and our lawful basis
| What we do | Lawful basis (Art. 6) | Health data condition (Art. 9) |
|---|---|---|
| Creating and running your account | Contract, Art. 6(1)(b) | Not applicable |
| Working out your stage and giving you the right week | Consent, Art. 6(1)(a) | Explicit consent, Art. 9(2)(a) |
| Showing your scan images, clips and appointments | Consent, Art. 6(1)(a) | Explicit consent, Art. 9(2)(a) |
| Matching your account to your clinic booking records | Consent, Art. 6(1)(a) | Explicit consent, Art. 9(2)(a) |
| Letting your family circle see what you have chosen to share | Consent, Art. 6(1)(a) | Explicit consent, Art. 9(2)(a) |
| Storing the memories, notes and photographs you add | Consent, Art. 6(1)(a) | Explicit consent, Art. 9(2)(a) |
| Transactional email: verification, password reset, security | Contract, Art. 6(1)(b) | Not applicable |
| Weekly pregnancy update emails | Legitimate interest, Art. 6(1)(f), with PECR Reg. 22(3) | Not applicable |
| Push notifications you have not switched off | Consent, Art. 6(1)(a), given at the operating system prompt | Explicit consent, Art. 9(2)(a), where the content refers to your stage |
| Hearts, levels and the rewards programme | Contract, Art. 6(1)(b) | Not applicable |
| Sharing data with a specific partner brand you have chosen | Consent, Art. 6(1)(a) | Explicit consent, Art. 9(2)(a), where anything health related is shared |
| App engagement analytics, with no health context | Legitimate interest, Art. 6(1)(f) | Not applicable, by design |
| Local weather in your world | Consent, Art. 6(1)(a), given at the permission prompt | Not applicable |
| Security monitoring and fraud prevention | Legitimate interest, Art. 6(1)(f) | Not applicable |
Where we rely on legitimate interest we have carried out a balancing test and concluded that our interest does not override your rights. You can read that reasoning in the Legitimate Interest Assessment, and you can object at any time under section 13.
Do you have to give us this?
- Name, email and password: needed to create an account. This is a requirement of the contract, not of any law.
- Health data consent: needed for the service to exist. If you do not give it, we cannot create your account.
- Date of birth: entirely optional.
- Location, camera, photo library and notifications: all optional, all refusable, and the app works without every one of them.
No law requires you to give us any of this.
5. Location and the weather
The app can draw the real weather where you are into your world. This is off until you turn it on, and it is the only reason the app ever asks for location.
Here is exactly what happens, and you can check it against the code:
- Your phone works out roughly where you are, at the lowest accuracy the operating system offers.
- Before anything leaves the device, the coordinates are rounded to one decimal place, which is roughly ten kilometres. That is town level, not street level.
- Only the rounded point is sent, over HTTPS, to Open-Meteo (api.open-meteo.com), which answers with the current weather code. No account identifier, no name, no device identifier and no cookie go with it.
- Your location is never sent to us. It does not reach our servers and it is not stored against your account.
- If you also turn on the option to be offered a holiday album when you are away, the rough home point that comparison uses stays on your phone.
- The app never asks for background location, and never tracks you when it is closed.
[NEEDS DAN: legal characterisation of Open-Meteo. It is called directly from the device with rounded coordinates and no identifiers, so arguably no personal data is disclosed to it at all. Confirm the position you want stated, and whether any written arrangement is in place. Open-Meteo is operated from the EU (Switzerland and Germany) and is keyless, so there is no contract today.]
6. Analytics, and the line we will not cross
We use Firebase Analytics, part of Google Analytics for Firebase, to understand how the app is used. It is worth being precise about what that does and does not mean, because this is exactly where other pregnancy apps have failed their users.
The app has two separate analytics lanes, and they cannot be crossed:
| Lane | What it carries | Where it goes |
|---|---|---|
| App engagement | A fixed, closed list of events: the app opening, which of the five main screens you moved to, a game being opened or played, something being shared, a wave being sent, an invite being started, a notification being opened. Counts, true or false values and screen names only. | Firebase Analytics, and our own servers |
| Journey | Anything shaped like health: a week unlocking, a letter being opened, a check-in, a scan being viewed, a kick session, a memory being added, an arrival being recorded. | Our own servers only. Never Firebase, never any other third party. |
This is not a policy we intend to follow. It is how the app is built. The journey lane has no code path that reaches Firebase, and the event names are a fixed list that the app will not compile without, so a new health event cannot quietly find its way into the wrong lane.
What that means in practice: Google never learns that you are pregnant, how far along you are, what you logged, or anything about your baby.
Firebase Analytics does receive a device identifier and an app instance identifier so that events from one installation can be counted together. The app declares no tracking to Apple, carries no advertising identifier, and lists no tracking domains.
[NEEDS DAN: confirm the Google Cloud data processing terms are accepted for this Firebase project, whether Google Analytics for Firebase data is set to a specific region, and the transfer mechanism relied on for the United States. Also confirm the retention setting on the Firebase property.]
This website
theparentroom.co.uk uses a session cookie only where you sign in. It carries no advertising or analytics tags. Fonts are loaded from Google Fonts and a 3D library from a public code CDN, so those services see your IP address as they would on any site that uses them.
7. Photographs, including photographs of children
You can add photographs to your memories, file documents such as certificates and school reports, and give your baby a profile photo. These are often photographs of a child who cannot consent for themselves, so we treat them carefully.
- Photographs are stored on our own servers in the United Kingdom, in a folder scoped to your journey. They are not sent to any third-party image service.
- Every uploaded image is re-encoded before it is saved. That removes the embedded camera metadata, including the GPS coordinates that phones write into photographs by default. We do not strip this afterwards, we make it impossible to store, because the file we keep is a new one.
- A photograph is private to you unless you choose to share it with your family circle.
- We never use your photographs for marketing, for training any model, or for anything other than showing them back to you and the people you have chosen.
- Camera and photo library access are asked for only when you use a feature that needs them, and refusing does not break the app.
If you post a photograph of someone else's child, please make sure that their parent is happy for you to do so.
8. Push notifications
If you allow notifications, your device gives us a push token, which we store against your account so we can reach that device. You can turn notifications off in the app or in your phone's settings at any time, and you can turn individual categories off separately.
Notifications are deliberately rationed. The rules are enforced by the server, not by good intentions:
- At most three notifications per member per day, four in the week of a scan.
- Of those, at most one per day may be the app talking about itself. The rest are reserved for something a real person actually did.
- Quiet hours are respected, and anything that would land inside them waits.
- Repeated activity about the same thing collapses into a single notification.
- Paused, closed and memorialised accounts are never notified at all.
Delivery uses the Expo push service, which passes the message to Apple's and Google's own notification networks. Notification text can refer to your stage, for example that a new week has opened, so the content itself can be health related.
[NEEDS DAN: name the push delivery processor formally (Expo is operated by 650 Industries, Inc., United States), confirm a data processing agreement is in place, and confirm the transfer safeguard relied on. Also confirm how long push tokens are retained after a device stops responding.]
9. Your family circle
You can invite a partner or family member into your journey. When you do:
- They create their own account with their own password. They never sign in as you.
- You decide what each person can see, one area at a time, and you can change it or remove them whenever you like.
- Some things are yours alone and are never shared with the circle, including anything you record about trying to conceive and your clinical records.
- If you pause or close your journey, the circle stops seeing it straight away.
Inviting someone means sharing health information about yourself with them. Please only invite people you would tell in person.
11. Where your data is held
Your account, your journey, your writing, your photographs and your scan media are stored in the United Kingdom. Your health data and your scan images do not leave the UK.
Two things do cross the border. Email delivery goes through Mailchimp Transactional in the United States, carrying only your name, your email address and the content of the email, and never any health or scan data. Firebase Analytics and push delivery involve services operated from the United States, carrying only the app-level events and the push data described above.
[NEEDS DAN: state the transfer mechanism relied on for each United States processor, for example the UK Addendum to the EU Standard Contractual Clauses, or the UK Extension to the EU-US Data Privacy Framework, and confirm a transfer risk assessment has been completed for each.]
12. How long we keep it
| What | How long |
|---|---|
| Account details: name, email, date of birth | While you are a member, then twelve months after your account closes or your last sign-in, whichever is later |
| Pregnancy and health data | While you are a member, then six months after closure so you can come back |
| Photographs, memories, letters and documents | [NEEDS DAN: set a retention period. These are the most personal items we hold and they currently have no stated limit.] |
| Scan images and clips | Shown in the app while you are a member. The originals stay with Window to the Womb (Franchise) Ltd under its own retention policy. |
| Consent records | For as long as the processing continues, then six years after your account closes, so that we can show a consent was properly given |
| Email logs | Twenty-four months from the date of each email |
| Engagement and event data | Aggregated and anonymised after twenty-four months. Individual records go when your account does. |
| Technical logs, including IP addresses | Ninety days |
| Push tokens | [NEEDS DAN: set a retention period, and confirm dead tokens are pruned.] |
When something reaches the end of its period it is deleted or irreversibly anonymised. You can ask for it to go sooner.
[NEEDS DAN: confirm each period above is actually enforced by a scheduled job rather than only written down. A retention promise nobody runs is worse than no promise.]
13. Your rights, and how to use them
Under the UK GDPR you have the right to get a copy of your data, to have it corrected, to have it erased, to restrict what we do with it, to receive it in a portable format, to object to processing based on legitimate interest, and to withdraw any consent you have given.
Two of these are built in
- Get a copy of everything. Privacy and permissions, then ask for your data. It is one tap. We send it within one month.
- Leave. Privacy and permissions, then leave. Your health data consent is withdrawn on the spot, your journey closes, you are signed out everywhere, and an erasure request goes to our team, which we action within one month.
You do not need to write us a letter or explain yourself for either.
Everything else
Email [email protected]. We reply within one month. If a request is genuinely complicated we can take up to two months more, but we will tell you inside the first month if that happens. We may need to check who you are first. We do not charge, unless a request is plainly excessive.
Complaining
If we get this wrong, please tell us first, because we would like the chance to fix it. You also have the right to complain to the Information Commissioner's Office at any time.
- Website: ico.org.uk
- Telephone: 0303 123 1113
- Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
14. Security
- Everything travels over HTTPS. The app pins no traffic to plain HTTP.
- Passwords are never stored in readable form.
- Sign-in tokens can be revoked, and are revoked everywhere when you leave.
- Face ID can be turned on to keep your records private on a shared phone.
- Access to personal data inside our organisation is limited to the people who need it.
- Uploaded images are re-encoded, which removes their embedded location data.
- Our export tooling is unreachable from the web.
No system is perfectly secure. If a breach happens that is likely to put your rights at risk we will tell the ICO within seventy-two hours, and we will tell you without undue delay where the risk to you is high.
15. Children and young people
The Parent Room is for pregnant people, parents and the families they invite. We know some users will be young.
[NEEDS DAN: set and state the minimum age. The old web terms said sixteen. The app does not currently enforce an age at registration, because date of birth is optional, and the only date check in the code implies thirteen. Decide the number, and decide whether the app should ask.]
We also hold data about children who are far too young to consent for themselves: your baby's name, birth details, milestones and photographs. That data belongs to the account of the parent who recorded it, is never used for advertising or profiling, and is deleted with that account.
[NEEDS DAN: confirm whether a Children's Code (Age Appropriate Design Code) assessment has been completed. The ICO expects one for any service likely to be accessed by under-eighteens.]
16. Automated decisions
We use your due date, or your child's date of birth, to work out which week you are in and therefore which content you see. That is automated, but it has no legal effect on you and nothing significant turns on it. It decides which article appears, not anything about your life.
We make no automated decisions with legal or similarly significant effects, and we do not profile you for advertising.
17. Changes to this policy
When we change this policy we will update the date at the top. If the change is material we will tell you by email or in the app, and where a change affects processing based on your consent we will ask again rather than assume.
18. Contact us
- Email: [email protected]
- Post: Data Protection, WTTW Retail Ltd, Victoria Works, Woodhead Road, Holmfirth, England, HD9 2PR
See also our terms of use and our Legitimate Interest Assessment.