Privacy
Updated October 8, 2026
Next Up helps you keep track of your baby’s first year. Creating a Next Up account stores your username, a salted password hash and a hashed recovery code. Passwords and recovery codes are not stored as readable text. A secure, HttpOnly cookie identifies your login session; the server stores only its hashed token. When you submit a baby profile, the app stores a private family page on its server, including your baby’s details, task check-offs, visit questions, selected office identifier, daily records, appointments, Parent Diary entries and milestones, caregiver notes and confirmed after-hours instructions. Your username identifies you in the caregiver list. All approved family caregivers can view and edit these records.
Account recovery and removal
You can save an optional recovery code from Account settings after signup or a password update/reset. Keep it private: it can reset your password. This app does not send password-reset emails. Password changes invalidate other login sessions and replace the recovery code. You can log out or permanently remove your account in Family → Account settings. Removing an account also removes any family page it owns. Existing family records from the previous sign-in system can move into your new account only through an explicit transfer while that previous access is available in the same browser.
Private family sharing
The public app link exposes the app and fictional sample, not private family records. The family owner can create a one-use invitation that expires after 24 hours, cancel it or remove a caregiver’s future access. Anyone with an active invitation who logs in can join, so share it directly with a trusted caregiver. Up to 8 accounts can join a family. Removing access does not recall information someone already downloaded or copied. The app checks family membership on private requests. It refreshes records while open, roughly every 20 seconds, and retains unsaved changes in session memory if a save fails.
Device-only profiles and deletion
Older remembered profiles remain in their original browser until you explicitly choose to move them into a private workspace. Anonymous sample data and Ask drafts stay in session memory. To export or delete a private family page, open Family. Deletion is available to the owner and removes the active records for every caregiver. Caregivers can leave a family; owners can remove caregiver access. To remove an older device-only profile, use Your baby’s details → Remove saved information. Clearing browser data can erase device-only profiles and unsaved drafts. Hosting-provider operational logs and backups are handled separately under the provider’s policies. Don’t enter insurance member numbers, Social Security numbers or document images into task notes.
Diary and Community
Parent Diary entries are saved with your private family records. They are visible and editable by you and invited caregivers, included in family exports, and removed when the workspace is deleted. They are never automatically shared in Community.
Community posts, photos and replies are visible to all signed-in Next Up accounts. Anyone can create an account. Your username identifies your posts and replies; baby profile details are not attached. Photos are resized and converted to JPEG before sharing, and location-bearing photo metadata is stripped on the server. Image files are kept in private object storage and served only after checking login and post visibility. Signed-in members may still copy or screenshot what you share. Share only pictures and details you have permission to share.
You can edit or delete your posts and remove your replies. Deleting a post removes its active photo and replies. Deleting your account removes your posts, replies, and reports. Reports include the reason, post and reporting account; a report hides that post for the reporter and is saved. There is no live moderation team or guaranteed review. Community is not an emergency service. Do not post private medical, insurance or identity documents. Posting and commenting use short-lived rate counters. Hosting-provider operational logs and backups are handled separately.
Pediatrician searches
The doctor or registered office name you search for, and any optional town/state in that search, are sent through this site to the U.S. Centers for Medicare & Medicaid Services (CMS) public NPI Registry to find matching providers. Choosing an office retrieves its public practice-location record. Your baby’s name, birthday, sex, preferences and question list are not included. The directory requires no Google API key, payment details or billing account. Only the selected NPI and address identifier are saved with your family page or existing device-only profile. A short-lived server cache holds public search results and provider records to reduce repeated requests; it does not hold your baby’s profile.
CMS operates the directory under its Privacy Policy. Opening directions or “Find practice website” takes you to Google’s ordinary Maps or Search website, under Google’s Privacy Policy. A web-search link is not a verified practice website. Patient portals and office websites have their own policies.
Ask Next Up
Questions entered into Ask Next Up stay in session memory and are not stored with a remembered plan or sent to an AI service. The feature matches common topics in your text to prewritten summaries of pediatric references. All matching happens in this browser; the question is not sent to a server. It does not provide a medical assessment. Choosing “Copy for ChatGPT” places your question, your baby’s chronological age (when using a personal plan), and educational instructions on your clipboard. It does not include the profile name, exact birthday, sex, office details or saved question list. Opening ChatGPT alone does not transmit this text. If you paste it there, ChatGPT handles the conversation under your account settings and its policies. Avoid identifying or sensitive details. Reloading this page clears the draft.
Feedback
Feedback is sent only when you select Send feedback. The site stores your message, category, the app section you sent it from, submission time, and an optional email you choose to provide. It does not attach your account, baby profile, family records or Ask question. The site owner can read messages and optional email addresses through a private owner inbox; other parents cannot read them. An email lets the owner contact you but does not guarantee a reply. Feedback is retained separately from family records and is not removed by deleting your account. Please leave out identifying baby details, medical information and passwords. Feedback is not an emergency or medical support service. To limit spam, a keyed hash of your network address is stored in a counter with a one-hour limit window; expired counters are removed on later submissions; the raw address is not saved in feedback records.
Site operation
The hosting provider handles normal requests, including network metadata. The office lookup uses short-lived request counts to limit repeated searches. Next Up records first-party anonymous visit counts: page or section names, the day, broad device category and broad referral source (such as Google or Direct / unknown). Visits are page opens, not unique people. No analytics cookies or persistent visitor identifiers are used. Random event identifiers are hashed for one day to avoid counting a retried request twice. Daily aggregate counts are retained for up to 400 days. Baby details, usernames, passwords, diary text, office searches and Ask questions are never sent to the statistics endpoint. The owner can see aggregate statistics and counts of currently registered accounts; this report does not include account names or family records. Use the visit-count setting in Sources & privacy, or below, to opt out on this browser. Do Not Track and Global Privacy Control also disable these counts. The browser keeps only your opt-out preference. These reports are private to anyone holding the owner’s private stats access link. The analytics request does not use your account cookie. The server uses short-lived request limits based on network addresses, without storing those addresses in analytics records. Do not enter patient details into the office search.