Privacy policy
Bercio · Téqui Studio (Charles Grimont EI)
Last updated: October 11, 2026LanguagesEnglish
Translation provided for information: in case of discrepancy, only the French version is authoritative.
In short
Bercio helps you follow your baby's day: the sleeps, feeds and diapers you log, and when the next nap is likely. The baby log needs an account, which lets you share it with the other parent or someone close and get it back on a new phone.
The baby log is end-to-end encrypted, on your phones, with a key the publisher never has. The publisher's server only keeps unreadable blocks of it: the publisher cannot read what you record, and the baby log is never used for advertising.
Bercio can also link two of your phones to watch over your baby: one stays in the nursery (baby device), the other goes with you (parent device). The baby monitor works without an account.
Picture and sound travel from one phone to the other, end-to-end encrypted: directly most of the time, through the publisher's relay when the network requires it. The publisher can neither see nor hear them, and does not record them.
The app is free, funded by Google AdMob ads, which never show on the monitoring screen or on the baby device. The optional Premium purchase removes all ads.
Data controller
The controller of the data described here is the publisher of Bercio, Téqui Studio (Charles Grimont EI), whose address is given in the legal notice. For any question about your data: support@tequi.app.
Account
The baby log needs an account; the baby monitor never does: the baby device does not sign in to any account. You sign in with Apple (on iPhone and iPad), with Google, or with a 6-digit code received by email, without a password. The publisher's account service (api.tequi.app) keeps:
- your email address, or Apple's relay address if you choose to hide yours, and the identifier Apple or Google gives you. Signing in with the same verified address, through Apple, Google or email, leads to the same account;
- the app's language, to write to you in your language, and the dates the account was created and last used;
- the versions of the baby log consent text you accepted, with the dates you first and last accepted each one (see “Legal bases”);
- the account's phones (20 at most): the name of each one (its model, or the name you gave it), a public key created by the app, and the dates it was added and last signed in;
- for each signed-in phone, a session: a hash of a sign-in token, valid for 180 days after its last use;
- if you sign in with Apple, the token Apple then gives the publisher, kept encrypted: it is only used to revoke your sign-in with Apple when you delete your account.
Apple and Google give the app a signed token that proves your identity; the account service only keeps your email address and your identifier from it, never your name or your photo.
For a sign-in by email, the code is sent by an email delivery provider, which only receives your address and the message. The code is valid for 10 minutes, for 5 attempts; the server only keeps a hash of it, in memory. The same provider sends the warning that comes before an unused account is deleted.
Household and sharing
A household brings together the accounts that share the baby log of one or more children: the other parent, a grandparent, the nanny. The server keeps the list of each household's members and the date they joined, pending invites and requests to join.
To invite someone, the app shows a QR code and a link, valid for 48 hours and for one person only. The secret they contain stays between your phones: it is never sent to the server, and the website page that receives the link does not pass it on anywhere.
Members of a household see the other members' email addresses, as well as the names of their phones and when they last signed in. They also see the email address and phone name of a person asking to join the household: this is how you can recognise who is asking before accepting them.
All members are equal: each one can invite, accept or decline a request, and remove a member.
End-to-end encrypted baby log
The baby log (each child's first name, date of birth and, where applicable, due date; sleeps, feeds and diapers) is encrypted on your phones with the household key, which the server never receives in the clear. Each phone has its own key, which never leaves it; the household key reaches it encrypted for that phone alone, from another phone of the household.
The server only keeps encrypted blocks of the baby log, numbered and dated, with the phone that uploaded them and their size. The publisher cannot read them: neither to give them back to you, nor to pass them on to anyone, nor for advertising.
The recovery key, shown by the app for you to write down, opens the baby log on a new phone. The server keeps the household key encrypted with it, never the recovery key itself.
These notes may reveal information about your child's health, a premature birth for example: they are treated as health data, with your explicit consent (see “Legal bases”).
Camera and microphone
On the baby device, the camera and microphone film and listen to the nursery while monitoring. The stream is sent live, end-to-end encrypted (WebRTC, DTLS-SRTP), only to the parent devices you have paired. Nothing is recorded.
On the parent device, the camera is only used to scan the pairing QR code, and the microphone for the “Talk” button, while you hold it.
Detection on the device
Cry recognition (Google's YAMNet model, run by MediaPipe), noise detection and motion detection work on the baby device, offline. Only results are sent to the parent device: sound level, scores for crying, babbling or laughter, motion score. Never the analysed audio.
Connecting the devices
For your two phones to find each other over the Internet, the app goes through the publisher's connection service, hosted by IONOS in the European Union and separate from the account service. It receives neither your name, nor your email address, nor the picture, nor the sound, and keeps no record of the connections:
- Connection (peer.tequi.app): receives a random identifier of the baby device (and, during pairing, an identifier derived from the code it shows) and each device's IP address, for the duration of the connection. To limit abuse of the relay, it also counts the requests from each IP address, in memory, for one hour at most.
- STUN (turn.tequi.app): sees the device's IP address, to tell it its public address.
- TURN relay (turn.tequi.app): when a direct connection is impossible, the stream goes through this relay. It stays end-to-end encrypted: the relay can neither see nor hear it.
- App verification: to keep the relay for Bercio, the app proves to the server that it is the original app, installed from the App Store or Google Play, on a real phone. It does so through Apple's App Attest on iPhone and iPad, and Google's Play Integrity on Android, which check the app and the device under their own rules. The server keeps nothing of it: it gives the app a one-week pass that contains no identifier of the device.
Advertising (Google AdMob)
Ads are served by Google AdMob: a banner on the home, pairing, settings, night journal and baby log screens and, if you choose to watch it, a video that unlocks extra soothing sounds. No ad shows on the monitoring screen, nor on the baby device once Baby Mode is started. To serve them, Google processes:
- the device's advertising identifier;
- the IP address and the approximate location derived from it;
- interactions with the ads and diagnostic information.
The baby log is never passed on to Google or used for advertising: it is encrypted, and even the publisher cannot read it.
In the European Economic Area, the United Kingdom and Switzerland, a form asks for your consent to personalised advertising. You can review your choices at any time: Settings, “Manage ad choices”. On iOS, the app also asks for tracking permission (App Tracking Transparency); without it, ads are not personalised.
Ads are silent and limited to content suitable for most audiences with parental guidance.
With the Premium purchase, the app shows no ads at all and no longer calls on Google AdMob.
Google's policies: https://policies.google.com/technologies/partner-sites
Premium purchase
The optional Premium purchase goes through Apple's App Store or Google Play, which process the payment under their own privacy policies. The publisher receives neither your payment details, nor your name, nor your email address.
To know whether Premium is owned, the app asks the store from your phone at each launch; it only keeps a copy of the answer on the phone, to work offline. No purchase data is sent to the publisher.
Photos
The “Take a photo” button on the parent device captures the current picture. It stays on the phone, in a temporary folder of the app, until you share or save it through the phone's share menu. It is never sent to the publisher.
Data kept on your phone
The app keeps on each phone:
- your settings (language, sensitivity, video quality, theme…);
- the state of the Premium purchase and of the extra soothing sounds unlocked by a video;
- on the baby device, the room's identifier and name, and the name and secret key of each parent device you allowed;
- on the parent device, the paired rooms with their secret keys, and the night journal (crying, movement, noise and outages over the last 14 nights);
- if you use it, the full baby log, to work offline: each child's first name, date of birth and, for a baby born early, due date, and the sleeps, feeds and diapers recorded in the household. Nap estimates are calculated on the phone. Only an encrypted copy of it is kept on the server (see “End-to-end encrypted baby log”);
- with an account, in the iOS keychain or the Android Keystore: the phone's private key, the household key, the recovery key and the sign-in token.
Permissions
- Camera and microphone: monitoring, the QR code, the “Talk” button.
- Notifications: the alerts (crying, movement, noise, low battery, lost connection), created on the phone itself; on Android, the ongoing notification of screen-off monitoring.
- Photos (iOS, add only): saving a photo when you choose to.
- Background: keeping the baby's sound playing when the parent device's screen is off.
Legal bases
Each processing operation rests on a legal basis provided for by the GDPR:
- The account and the household (email address, the account's phones, members, invites), like the connection and relay of the baby monitor: performance of the contract formed by the terms of use (article 6.1.b).
- Your child's baby log, kept encrypted on the server and shared with the members of your household, which may reveal information about their health: your explicit consent (articles 6.1.a and 9.2.a). You give it at each sign-in by ticking the box provided, never ticked in advance, as the holder of parental responsibility for the child (their parent or guardian) or with their agreement. You can withdraw it at any time, in the app, by leaving the baby log or deleting your account (see “Retention and deletion”); withdrawal does not affect what was done before. The baby log then stays with the other members of the household, on the basis of the consent each of them has given; if you were its only member, it is erased from the server. The publisher keeps the version of the text you accepted and the dates you first and last accepted it, so as to be able to prove your consent.
- The security of the service (limiting abuse, closing a session whose token was copied, verifying the app): the publisher's legitimate interest in protecting the service and its users (article 6.1.f).
- Advertising: your consent to personalised advertising, collected through Google's form; failing that, non-personalised ads, in the publisher's legitimate interest in funding a free app.
Hosting and service providers
The account data and the encrypted baby log are kept on the publisher's server, in the European Union. The following are involved:
- IONOS, host of this server (connection, relay and account service), a virtual private server located in the European Union, as the publisher's processor;
- an email delivery provider, the publisher's processor, for sign-in codes and the warning before an unused account is deleted;
- Apple and Google, when you choose to sign in with them: they verify your identity under their own privacy rules, and know that you use Bercio;
- Cloudflare, host of the Bercio website (bercio.tequi.app), which sees visitors' IP addresses to serve them the pages. The account deletion page sends your address and your code directly to the account service; the invite page sends nothing.
Transfers outside the European Union
The publisher's server, which keeps the account data and the encrypted baby log, is in the European Union. Google (advertising, sign-in with Google), Apple (sign-in with Apple) and Cloudflare (website) may process data outside the Union, notably in the United States, with the safeguards provided for by the GDPR: the European Commission's adequacy decision for the EU–US Data Privacy Framework, or its standard contractual clauses.
What the publisher does not collect
Apart from the account described above, the publisher collects no data about you: it keeps no password, no name, no payment details, no usage statistics, no picture and no sound. Pictures of your child are only seen by the devices you have paired.
The account service keeps no IP address: it only uses them to limit abuse, in memory, for one hour at most. Its technical logs, kept for 7 days, contain no email address, no code and no identifier.
Bercio is meant for adults; it is not intended to be used by children.
Retention and deletion
- The night journal only keeps the last 14 nights; “Clear journal” empties it at once.
- The baby log keeps what you record until you delete it: one entry (“Delete”), or a child's whole log, from their profile; the deletion applies to every phone of the household. On the server, old encrypted blocks disappear when a phone uploads a complete state of the baby log, which replaces them.
- A session expires 180 days after its last use, a sign-in code after 10 minutes, an invite after 48 hours or as soon as it has been used, along with the requests made with it.
- An account unused for two years is warned by email, then deleted 30 days later if no one signs in to it again; an account without an email address, which cannot be warned, is deleted 30 days after those two years.
- Deleting your account: in the app (Baby log, “Shared with”, “Delete my account”), on https://bercio.tequi.app/delete-account with a code received by email, or by writing to support@tequi.app from the account's address. The account, its phones and its sessions are immediately erased from the server, and the sign-in with Apple is revoked with Apple. The baby log stays with the other members of the household; if you were its only member, it is erased too.
- “Sign out” erases the baby log from this phone and the server forgets this phone; “Leave this baby log” removes you from the household and erases the baby log from this phone. In both cases, the baby log stays with the other members of the household.
- “Remove”, on the pairing screen of the baby device, forgets a parent device and disconnects it.
- Uninstalling the app, or clearing its data in the phone's settings, deletes what it kept on that phone. On iPhone and iPad, iOS may keep the account's keys after the app is uninstalled: they are of no use without the app, which erases them on its first launch if it is installed again. Your account, however, stays on the server until you delete it.
- Data processed by Google for advertising follows Google's policies; the advertising identifier can be reset in the phone's settings.
Your rights (GDPR)
You have the rights of access, rectification, erasure, restriction, objection and portability, the right to withdraw your consent at any time, and the right to set guidelines on what happens to your data after your death.
You exercise them in the app (correcting or deleting an entry, leaving the baby log, deleting your account) or by writing to support@tequi.app from your account's address; the publisher replies within one month. As the publisher cannot read the baby log, its content can be viewed and copied from your phones (“Copy summary”). For advertising, these rights are exercised with Google.
You may also lodge a complaint with the CNIL, the French data protection authority: https://www.cnil.fr
Changes
This policy may change with the app. The date of its last update is shown below; the version in force is always published in the app and on its website.
Contact
For any question about this policy: support@tequi.app.
Last updated: October 11, 2026
Bercio © 2026
