J W Horneman Pty Ltd (ABN 23 607 125 217), trading as Small Hours(referred to in this policy as we, us, or our), is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, disclose, and protect personal information when you use the Small Hours website, mobile app, and related services (the Service).
We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
1. About Us and Our Role
Small Hours is a private journaling platform for families with babies in neonatal intensive care. We are an Australian company. We are not a healthcare provider, and we are not part of any hospital or clinical care team. Information you record about a baby's medical care is information you enter for your own family's records.
2. Information We Collect
2.1 Information you give us
- Account details: name, email address, password (stored in hashed form), and any profile information you choose to add.
- Baby and family details: baby's name (or nickname), birth date, due date, corrected age, and details of family members you invite to share the journal.
- Journal content: journal entries, care notes, photos, milestones, appointments, and any other content you upload.
- Onboarding responses: any optional questions we ask during onboarding to personalise your experience.
- Support correspondence: anything you send us when you contact hello@smallhours.app.
2.2 Information collected automatically
- Device and usage data: device type, operating system, app version, IP address, crash logs, approximate location (derived from IP), and basic usage analytics (which features were used, when).
- Cookies and similar technologies on the website (see clause 8).
2.3 Sensitive information
Some content you choose to record, for example notes about a baby's diagnosis, medications, weight, or treatment, is sensitive information (specifically, health information) under the Privacy Act. By recording this content in the Service, you consent to us collecting and handling it for the purposes described in this Privacy Policy. You can delete this content at any time.
We do not sell, rent, or use sensitive information for advertising, ever.
2.4 Children's information
Small Hours accounts are held by adults (16+). Information about a baby or child in the Service is recorded by an adult account holder, who is responsible for ensuring they have authority to do so. We do not knowingly create accounts for children.
3. How We Use Your Information
We use personal information to:
- create and operate your account and the Service;
- store and display your journal content to you and the family members you invite;
- generate scrapbook layouts and, if you order one, produce and ship a printed book;
- send service emails (account, security, important changes);
- provide customer support;
- detect, prevent, and respond to fraud, abuse, or security incidents;
- maintain backups and ensure service reliability;
- understand how the Service is used so we can improve it (using aggregated and de-identified analytics where possible);
- comply with our legal obligations.
We will only send you marketing emails if you opt in, and you can unsubscribe at any time using the link in the email or by contacting us.
4. When We Share Personal Information
We share personal information only as described below, and only to the extent reasonably necessary.
4.1 Service providers
We use trusted third parties to operate the Service. These providers are bound by confidentiality and data-protection obligations and may only use personal information to provide services to us. They include:
| Provider | Purpose | Location of data |
|---|---|---|
| Supabase | Database, authentication, file storage | United States / EU |
| Resend | Transactional email delivery | United States |
| ImprovMX | Email forwarding for our domain | United States / EU |
| Vercel | Website hosting | Global edge network |
4.2 Family members you invite
When you invite a family member to share a journal, the content you have shared with them, your name, and your email address may be visible to them.
4.3 Legal and safety
We may disclose personal information if we reasonably believe it is necessary to:
- comply with a law, court order, or lawful request from a government or regulator;
- enforce our Terms or protect our rights, property, or safety; or
- protect the safety of any person.
4.4 Business transfers
If we are involved in a merger, acquisition, or sale of assets, personal information may be transferred as part of that transaction. We will notify you and require the recipient to honour this Privacy Policy or give you a chance to opt out.
4.5 No sale of personal information
We do not sell your personal information. We do not use your journal content, photos, or any sensitive information to train artificial intelligence models, and we do not provide it to third parties for that purpose.
5. Overseas Disclosure
Several of our service providers are located in the United States and the European Union (see the table in clause 4.1). When personal information is disclosed overseas we take reasonable steps to ensure the recipient handles it consistently with the Australian Privacy Principles, including through contractual protections.
6. Security
We take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access, modification, or disclosure. These steps include relying on reputable third-party infrastructure providers for hosting, database, authentication, and payment services, and applying access controls within our own systems.
No method of transmission or storage is completely secure, and we cannot guarantee the absolute security of any information you provide. You use the Service at your own risk and are responsible for keeping your password confidential. Please notify us promptly at hello@smallhours.app if you suspect unauthorised access to your account.
Nothing in this clause is a warranty or guarantee of any specific security outcome, beyond any guarantees that cannot lawfully be excluded.
7. Data Retention and Deletion
- Active accounts: we keep your information for as long as your account is open.
- Closed accounts: when you close your account, we delete or de-identify your personal information within 30 days, except where we are required or permitted by law to retain certain records.
- Backups: information may persist in encrypted backups for up to 90 days after deletion before being overwritten.
- Inactive accounts: we may delete accounts that have been inactive for an extended period after giving you reasonable notice.
You can export your data at any time from within the Service.
8. Cookies and Analytics
Our website uses a small number of cookies and similar technologies to keep you signed in, remember preferences, and measure how the website is used. You can control cookies through your browser settings. Disabling some cookies may affect how the Service works.
We use privacy-respecting analytics to understand aggregate usage. We do not use advertising cookies or third-party advertising trackers.
9. Your Rights
Under the Privacy Act and the Australian Privacy Principles you have the right to:
- Access the personal information we hold about you;
- Correct information that is inaccurate, incomplete, or out of date;
- Delete your account and the personal information associated with it (subject to clause 7);
- Withdraw consent to our handling of sensitive information (note: this may mean we can no longer provide the Service to you); and
- Make a complaint about how we have handled your personal information.
If you are in the European Economic Area or the United Kingdom, you may have additional rights under the GDPR / UK GDPR, including the rights to data portability and to object to certain processing.
To exercise any of these rights, email hello@smallhours.app. We will respond within a reasonable time (and within 30 days for most requests). We may need to verify your identity before acting on a request.
10. Complaints
If you believe we have breached the Australian Privacy Principles, please contact us first at hello@smallhours.app. We will acknowledge your complaint promptly and aim to resolve it within 30 days.
If you are not satisfied with our response, you can contact the Office of the Australian Information Commissioner (OAIC):
- Website: oaic.gov.au
- Phone: 1300 363 992
11. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes we will notify you by email and/or by an in-app notice at least 14 days before the changes take effect. The “Last updated” date at the top of this policy reflects the latest version.
12. Contact Us
For privacy questions, requests, or complaints:
J W Horneman Pty Ltd (ABN 23 607 125 217)
Email: hello@smallhours.app