Who can see the pantry? A guide to household permissions
NestBoard · 2026-06-18
The short answer
When you add someone to your household, they can see almost everything. Pantry items, medication bottles, meal plans, savings goals. These are shared spaces, not personal ones. We built it this way because a household operates on shared information.
The exceptions are narrow and deliberate. Kid and guest profiles are kept out of billing, household settings, member management, and Robin. Any single event can be marked adults-only, which hides it from kids and from the wall display. A household PIN can sit in front of the wish list and the settings screen. But the baseline assumption is transparency.
One honest caveat on the Robin line. The block is on the profile, not on the person. A kitchen tablet is usually signed in as a grown-up, so anyone standing in front of it can type into Robin. That is why Robin also keeps its language family-appropriate rather than leaning on the profile gate alone.
Why shared by default
Imagine an app that treats every piece of information as one person's private business. One parent adds milk to the shopping list, the other never sees it, and the household ends up with two cartons. Anyone helping out for a week has to ask whether the kids have had their vitamins, because in that design the meds belong to whoever typed them in. NestBoard goes the other way: any adult or caregiver in the household reads the medication list without asking permission first.
Friction compounds. So we start from the opposite direction: if it's in the household, it's visible to the household.
That includes the pantry. Everyone can see what's stocked, what's expiring soon, and what's running low, and anyone can add or remove items. Whoever finishes the oat milk marks it gone. Whoever finds a forgotten jar of tahini at the back of the cupboard logs it.
What kids see
Kid accounts see the pantry, the meal plan, and their own chores. They can check what's for dinner, browse recipes you've saved, and mark off tasks when they're done. Medications are the one place the shared-by-default rule bends: a child or guest sees only the medications that are for them, not anyone else's, and the Health Profiles section does not appear for them at all.
What they can't reach is the money and the machinery: billing, the household's settings, adding or removing members, and Robin, which is for the grown-ups. That last one is enforced on our servers rather than hidden in the app, so a child profile is refused even if it reaches the Robin page. Everything else, calendar events that aren't marked adults-only, shared shopping lists, the pantry, the meal plan, is visible.
Why kid accounts work differently goes deeper into the reasoning, but the principle is consistency. Kids are part of the household. They see what the household is doing.
Medications are a little different
Meds work on a bottle model, not a person model. If you add a vitamin D bottle to the household, everyone who takes vitamin D can log doses from that same bottle. It's shared inventory, so there is one supply count no matter who takes the dose.
There is more on this in Shared bottles, shared meds: why we changed how supplements work. The upshot is that supply lives at the household level rather than the person level. The adults and caregivers in the household read the whole med list. A child or guest sees only their own.
When you want more control
There are two tools for limiting what's on screen. Settings, then Modules hides a whole section from everyone in the household, on every device. And a household PIN puts Wish Lists and Settings and Billing behind a code, so a kid on a tablet the family is already signed in to can't wander into them.
Kiosk mode is a different thing, and worth not confusing with those. Marking one device as a kiosk makes it behave like a wall display: the dashboard full screen, a photo slideshow when nobody is around, dimming at night. It doesn't hide pages. What it does do, because it's a shared screen anyone can walk up to, is filter every adults-only event off it entirely. Your own phone and laptop are untouched.
There is exactly one per-item control, and it's deliberately the only one: an event can be marked adults-only. Surprise parties and the conversation you're not having in front of the kids get somewhere to live, and nothing else does. We don't offer per-item toggles on the pantry, the lists, or the meal plan, and we probably never will. That kind of granularity makes sense for work software. It doesn't make sense for a household, where the question is usually "Does everyone know we're out of bread?" not "Who is authorized to know about the bread?"
The underlying idea
A household isn't a hierarchy. It's a group of people who need to coordinate around the same milk, the same calendar, the same front door. Shared visibility is the tool that makes coordination possible.
If you add someone to your NestBoard household, you're saying: this person is part of the operation. They can see what we have, what we need, and what we're planning. That's not a bug. It's the point.