GYST Baby

Privacy Policy

Effective date: August 23, 2026 · Version 1.4

This Privacy Policy explains how GYST Baby LLC, the owner and operator of the GYST Baby application ("GYST," "we," "us," "our"), handles information. By using GYST you agree to this policy.

The short version

The information you enter stays in your hands: on your device and, if you're signed in to iCloud, synced through your own private iCloud account so your plan appears on your other devices. We do not operate accounts, we do not sell your information, and we do not use it for advertising. We cannot read your private iCloud data.

Two optional features work differently, because they have to. GYST Family shares what you assign with people you invite, through Apple's own sharing. The baby shower wish list publishes items you pick to a web page we run, so guests can see them without an app. Both are off until you turn them on, both are described in full below, and both stop the moment you turn them off.

What is stored on your device

When you set up and use GYST, the following is stored locally on your device:

This information stays on your device and within your device's own backup/sync (for example, an encrypted device backup you control). We do not receive any of it, apart from the two optional features you turn on yourself: a baby shower wish list you choose to publish, and — if you use GYST Family — the short invite code record described below.

iCloud sync

If you are signed in to iCloud, GYST stores your information in your private iCloud database using Apple's CloudKit service, so the same plan appears on your iPhone, iPad, and Mac. That data lives in your Apple Account, is protected by Apple's iCloud security (encrypted in transit and on Apple's servers), and is accessible only to you — not to us. We have no way to read your private database, and nothing we run ever touches it. If you sign out of iCloud or disable iCloud Drive for GYST in your device settings, your information simply stays on the device. Apple's handling of iCloud data is governed by Apple's own privacy policy.

GYST Family (optional)

If you start or join a GYST Family, Apple's own sharing creates a shared area of iCloud that the members can read. Your plan does not move into it. What goes there is narrower: anything you assign — the task or event title, its details, its date, and who it is for — plus your name, the email in your profile if you added one, your role, and a short record of who finished what. Members join with the Apple Account already on their device, there is no GYST account, and we never see a password. Your calendar, visits, questions, GYST Log, milestones, and birth plan are not shared — they stay in your private database. One deliberate exception: if you turn on "Let my GYST Family know I checked in" in a wellness check-in, the family activity feed records that you checked in and whether it was a good day or a rough one — "Checked in — feeling good today" or "Checked in — not feeling great today". Which symptom you picked, which part of your body you tapped, and anything you wrote down never leave your private database. Turning the toggle off stops even that.

So that someone can join by typing a short code instead of opening a link, the app stores one record in the public area of our iCloud container: the six-character code, your name, and the join link. The code is a key — while it is live, anyone who has it can join your family. Rotating the code, turning invites off, or ending the family in Settings deletes that record.

Baby shower wish list (the one thing you publish)

GYST includes an optional baby shower wish list. If you publish one, the items you include leave your device and go onto a web page that anyone with the link can open. It is the only feature that works this way, so here is exactly what happens.

Where it goes. Publishing copies the list into the public area of GYST's own iCloud (CloudKit) container — ours, not yours. That is what lets guests open a page without an app or an account. While a list is published its contents are not private: anyone with the link can open them, and because the records sit in our container we could technically read them too — nothing in GYST does.

What is published. The host name and message you enter, and for each item you include: its name, the short description GYST shows for it, its category, the quantity, and how important it is — which is what shows guests a “Most wanted” tag. If you set a password, only its scrambled form (a SHA-256 hash) is published — never the password itself.

What is not published. Prices, stores, links, your own notes on an item, and who you had noted as buying it all stay on your device. So does everything else in GYST: your plan, calendar, visits, questions, GYST Log, milestones, birth plan, baby info card, meds, and baby names.

Which items go up. Shopping items carry a gift toggle that starts switched on, so a published list is everything you still need unless you switch individual items off. Nothing is published until you publish it, and you can review and change the list first.

The page and the relay. The page lives at gystbaby.com/wishlist and is reached only by a random twelve-character code. It is not listed anywhere and not linked to, and the page asks search engines not to index it, so nobody finds it by browsing. To serve it we run one small piece of server-side code — the only server GYST operates. It fetches your published list from iCloud when a guest asks for it and passes it straight back. It keeps nothing of its own: no database, no accounts, no analytics, and no copy of your content. If you set a password, a guest's browser remembers it for that visit and forgets it when the tab closes.

What guests do. A guest who buys something types a first name and taps "I got this." That name is saved with the item, shown to every other guest so nobody doubles up, and pulled back into your app the next time it syncs. Guests are not asked for anything else and never create an account.

Taking it down. Unpublishing in the app deletes the list and every item record, and the link stops working immediately. Settings → "Erase all data" takes a published list down first, and stops without erasing anything if it cannot. Deleting the app does not take a published list down — that only happens from inside the app, so unpublish before you delete.

Notifications

If you enable reminders, GYST schedules local notifications on your device through the operating system. You can change or revoke notification permission at any time in your device settings.

What we do not do (current version)

Children's privacy

GYST is intended for adults (18+) organizing their own pregnancy or parenting journey. It is not directed to children, and we do not knowingly collect personal information from children. Information you choose to record about your child is stored on your device under your control. The one exception is a baby shower wish list: the host name and message you type there appear on a public page, so leave your child's name out of them unless you mean to share it. If you believe a child has used GYST to provide information to us, contact us and we will address it.

Share-sheet exports

GYST includes share buttons that hand a summary to your device's standard share sheet. Most are plain text — a shopping list, your to-do list, a weekly update, milestone progress. Two are PDF documents you ask for by name and that contain health information: the visit summary you share with a provider, which carries the vitals, symptom check-ins and answered questions from the period you pick, and your birth plan. There is also a shareable image of the week's baby-size card. Nothing is exported automatically, and nothing you send this way passes through our servers — the content goes only where you send it (for example, Messages or email), under the terms of the app you send it with. Think before you share information about your child, and get permission before sharing information about other people.

Future features (products, sponsors)

As GYST grows, we may add features such as optional analytics, product links, affiliate programs, or sponsored content. Before any feature that changes how information is collected, used, or shared takes effect, we will update this policy, update the version and effective date, and ask you to review it. When affiliate or sponsored features are added, we will disclose material connections clearly and, where required, comply with U.S. Federal Trade Commission guidance. We will describe at that time exactly what (if anything) is collected, why, and your choices.

Third-party links

If GYST links to third-party products, retailers, registries, or websites, those parties have their own privacy practices that we do not control. Review their policies before providing information to them.

Your choices and rights

Security

No method of storage is perfectly secure, but keeping your information on your own device — rather than on our servers — reduces exposure. Protect your device with a passcode and keep your operating system up to date. You are responsible for the security of your device and backups.

A published baby shower wish list is meant to be opened by guests, so treat its link like the invitation itself — anyone you send it to can pass it on. You can put a password on it, and you can take it down at any time.

Data retention

Your information remains on your device until you delete it (by erasing data in Settings or removing the app). We keep no copy of it.

A published baby shower wish list is the exception: it stays online, in the public area of our iCloud container, until you take it down in the app or use "Erase all data." Deleting the app does not take it down, so unpublish first. A GYST Family invite code record stays until you rotate the code, turn invites off, or end the family.

International users

GYST is operated from the United States and reflects U.S. guidance and law. If you use GYST from elsewhere, you are responsible for compliance with your local laws, and local data-protection rights may apply.

Changes to this policy

We may update this policy. Material changes will be reflected in a new version and effective date, and you will be asked to review the current version. Settings always shows the current policy, along with the version and date you accepted.

Contact

Questions about privacy: info@GYSTBaby.com.