Skip to main content
NestBoard
NestBoard
Start free
Privacy policy

Yours, only. Forever.

Households are intimate. Your data should feel that way too. This policy is the long version of a short promise: we don't train on your data, we don't sell it, and you can leave with everything.

1. The short version

NestBoard is a calmly designed shared calendar for households. We are paid for by subscriptions, not advertising, and we never sell your personal data.

We don't train AI models on your data. We don't read what isn't shared with us. We don't allow third-party trackers in our product surfaces.

You can export your household's data at any time, and you can delete your account and household with a single request.

2. What we collect

Account data: your name, email, the household name you create, and billing details. On the web, billing is handled by Stripe (we never see your card number). If you subscribe inside our iPhone or iPad app, the purchase is handled by Apple In-App Purchase, and we use RevenueCat to confirm and manage that subscription (we never see your card number there either).

Sign-in options: you can create an account with an email and password, or with Google or Apple. When you use Sign in with Google or Sign in with Apple, we store the account identifier the provider gives us along with your name and email (for Apple this may be an Apple private-relay address) so we can sign you back in.

Household contents: events, chores, medications, pantry items, alerts, and routines you and your household members add. This is yours, and it lives in your household. When you scan a grocery barcode to add a pantry item, the barcode number is sent to the Open Food Facts public database to look up the product. Only the barcode is sent.

Recipe import: when you import a recipe from a URL, we fetch that page directly to read its recipe data. If the site blocks our direct fetch, we send the recipe URL you pasted to Jina AI's reader (r.jina.ai) to retrieve the page's readable text, which is then turned into a recipe. Only the public recipe URL is shared with Jina AI, never your account or household data.

Health and emergency details: if you choose to fill them in, we store medical profile details for household members (including allergies, conditions, blood type, and insurance provider, policy, and group identifiers) and emergency contact information you enter (a contact name, relationship, phone, email, and address). These are optional, and they are treated as sensitive surfaces you can limit to specific members.

Comments and member groups: notes you leave on events (e.g. "running 10 minutes late") and the optional groupings you assign to family members are stored alongside the household. Comment authorship is recorded so the family can see who said what. The author name is preserved even if the member is later renamed or removed.

Connected calendar data: when you connect Google, Outlook, iCloud, or an ICS feed, we read events as you authorize. We do not read mail, contacts, or files.

Showing NestBoard events in Google Calendar: this is off unless a household adult turns it on in Settings under Calendar Sync. When you do, you grant NestBoard permission to create one calendar of its own inside your Google account, named NestBoard, and we copy your NestBoard events into it so they appear on your phone and laptop within seconds. The permission we ask for covers only calendars this app creates. It gives us no access to calendars you made yourself, so we cannot read, change, or delete anything in them, and we never add guests to a copy or send invitations on your behalf. Each copy carries a private marker identifying it as ours, and we act only on events carrying that marker. Google receives the event details you chose to copy and handles them under its own privacy policy. We do not sell this data, use it for advertising, or use it to train models. Turning the setting off deletes the NestBoard calendar from your Google account along with the copies inside it, and disconnecting Google entirely removes it as well. There is one case we cannot clean up for you: if you remove the NestBoard permission on the Google permissions page before turning the setting off here, we no longer have permission to touch that calendar, so it stays in your account until you delete it yourself. NestBoard tells you when that has happened and what to remove.

Alexa: if a household adult enables the NestBoard skill and links it, we store a hashed copy of the link token Amazon uses to reach your household (we cannot read the token back, only recognize it), which household it maps to, and, when someone introduces themselves on an Echo by saying "I'm ..." with their name, an opaque speaker identifier Amazon assigns to that voice so chores finished by voice credit the right family member. That identifier is a random Amazon code, not a recording; we never receive or store audio. What Amazon receives from us is the spoken response to each request, for example today's agenda or a confirmation that milk was added to the list, and Amazon handles it under its own privacy policy. You can disconnect at any time in Settings under Alexa: every link and speaker mapping for the household is deleted immediately, and voice requests stop reaching NestBoard from that moment.

Calendar subscription feed: you can optionally turn on a feed URL that lets another calendar app (Google Calendar, Apple Calendar, Outlook) subscribe to your household calendar. That URL contains a secret token, so treat it like a password: anyone who has the URL can read your household calendar, except events marked adults-only, which are never included in the feed. You can regenerate the URL at any time, which revokes the old link instantly.

Home location: if you set a home location (latitude/longitude or ZIP), we store it to power the weather widget (forecasts come from Open-Meteo) and to filter real-time lightning alerts down to your area (strike data streams from Blitzortung.org). Only the location itself is shared with those services, never your name, email, or household contents.

Robin inputs: text you paste, screenshots you attach, voice notes you send, and emails you forward to your private NestBoard inbox. To answer questions and take actions for you, Robin can also read your household's own NestBoard records, things like the calendar, chores, lists, and medications, and update them when you ask. That access stays inside your household's boundary: Robin never reads another household's data, and it never reaches outside NestBoard for yours.

Operational access to Robin conversations: in limited cases, NestBoard staff can review Robin conversations to investigate a safety concern, debug a problem you report, or verify that Robin is answering accurately. These reviews are rare and purpose-limited, every access is logged with who looked and why, and conversations are never shared, used for advertising, or used to train models. You can ask whether your household has ever been accessed by emailing hello@mynestboard.com.

Product diagnostics: crash and error reports, processed through Sentry. These come from two places. When something breaks on our servers, we scrub names, email addresses, and household contents out of the report before it leaves the server, though it may include your IP address. When the app itself crashes or hits an error on your device, the report goes from your device straight to Sentry so we can see failures that never reach our servers, such as an app that will not start. Those device reports include the error, the app version, the screen you were on, basic device and operating-system information, and your IP address, and because they do not pass through our servers first, the server-side scrubbing does not apply to them. We keep the collection narrow instead: performance tracing and session replay are turned off, and the app is configured not to attach personal information by default. No content from your household is included in either case. Sentry itself does not run on our public marketing pages; errors there are recorded by PostHog, described next.

Product analytics: we use PostHog to understand which features get used and where the app gets confusing, on both the marketing site and inside the app. It uses local storage rather than a tracking cookie, session replay is off, it identifies you only by an internal account id (never your email), any sign-in token in a page address is stripped before it is recorded, and no household content is collected. If you are in the UK, the EEA, or Switzerland, none of it runs until you say yes, and we ask with a banner the first time you visit. The section below on the UK and Europe has the detail.

Browser errors: PostHog also records errors the page itself hits, on the marketing site and inside the app, so we can find and fix breakage we would otherwise never hear about. A report contains the error type, the error message, and the stack trace showing which of our code files and line numbers were involved. It does not include anything your browser printed to its console, and the message is scrubbed on your device before it is sent, stripping email addresses, the names of members in your household, and any sign-in token, exactly as page addresses already are. When the failure came back from one of our own servers, the message text is dropped entirely and only the error code is kept, because a server message can quote something you typed. No calendar entries, chore names, lists, notes, or messages are sent.

Product analytics: we also use HeyCatch to measure how people find NestBoard and how new households get started, and we split it deliberately. On our public marketing pages, the pages you see before you sign in, their script records page views and clicks and uses local storage plus a first-party cookie to recognize the same visitor between visits. Inside the signed-in app their script does not run at all. Instead our own servers report a short, fixed list of milestones, things like finishing signup, completing setup, or starting a subscription, with only counts, dates, and fixed labels attached, such as how many members were added or which payment method was used. We made that change in August 2026: their script records the text of whatever you click, and inside NestBoard that text can be a family member's name. Either way you are identified only by an internal account id, never your email, session recording is off, and no calendar entries, chore names, lists, notes, messages, or member names are sent.

Keeping you signed in: on the web, a single strictly-necessary session cookie keeps you signed in. In our Android and iPhone apps, that same sign-in is kept by a session token stored privately in the app's own local storage on your device and sent with each request. It is never shared with third parties and is cleared when you sign out. Inside NestBoard there are no advertising or cross-site tracking cookies, ever. The only analytics cookie is the first-party HeyCatch cookie described above, and it is set on our public marketing pages rather than inside the app; it stays on our site, is never shared with advertisers, and carries no household content.

Push notifications: once you allow notifications on your device, NestBoard sends push notifications for things like dose reminders, chore nudges, and lightning alerts. New households also start with Robin's morning check-in, a friendly once-a-day push to help plan the day, which you can retime or turn off in Settings. If a household goes quiet for a few days we may send one gentle reminder push to help you pick back up. To deliver any of these we store a device push identifier (a token issued by Apple, Google, or your browser's push service) for each device you enable. These tokens carry no household content, are used only to route notifications to your device, and are removed when you turn notifications off or sign out.

Account and onboarding emails: beyond the verification emails above, we may send a small number of onboarding and re-engagement emails in your first days, for example a short welcome note and, if your household goes quiet, one reminder that your calendar is waiting. These come from NestBoard, never contain third-party ads, and you can reply to reach us or ask us to stop.

Task reminder emails: you can optionally have NestBoard email you a separate reminder for each chore or event at its reminder time. This is off by default and strictly opt-in, per person, and only adults in a household can turn it on. Each reminder email contains the task or event title and its timing, and goes only to your own verified account address, never to anyone else. You can turn it off at any time in Settings, under Notifications and Sounds.

Email open and click tracking: some of the emails we send, such as our weekly update email and the occasional one-to-one note from the founder, include a tiny invisible image and links that pass through our own server on the way to their destination. When your mail app loads that image, or you click one of those links, we record that the email was opened or the link was clicked, when it happened, and which email address it was sent to. We use this to learn whether our updates are actually being read, and to stop mailing people who never open them. This measurement is entirely first-party: it runs on our own servers, no ad network or outside tracking service is involved, and it never touches your household content. Everyday account emails such as verification and password reset messages carry none of this.

If your household timezone puts you in the UK, the EEA, or Switzerland, we leave the invisible image out of your copy entirely, so opens are not recorded for you at all. You get the same email, we just do not measure it. If we cannot tell where a household is, we leave the image out as well. The links in the email still route through our server so we know a link was clicked, which records an action you chose to take and stores nothing on your device.

Cookies on our marketing site: our public pages (the pages you see before you sign in) carry no advertising or cross-site tracking tags at all. We used to run the Meta Pixel and the Pinterest Tag there. We removed both, along with the data they sent to Meta and Pinterest. The only measurement on those pages is the same PostHog and HeyCatch product analytics described above, which stay on our own site and carry no household content.

3. What we don't do

We don't train models on your data, yours or anyone else's in NestBoard.

We don't sell, rent, or share your data with advertisers, data brokers, or any third party for marketing.

We don't run advertising in NestBoard. There is no ad model and there will not be one.

We don't read your inbox, browse the web on your behalf, or scrape your messages. Robin works from what you hand it and from your household's own NestBoard records, nothing outside them.

Google user data specifically: NestBoard's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. That policy is published at https://developers.google.com/terms/api-services-user-data-policy.

In plain terms: the calendar data we read from Google, and the events we copy into the NestBoard calendar we create inside your Google account, are used only to provide and improve the calendar features you chose to turn on. We do not transfer that data to anyone else except where it is needed to provide those features, where the law requires it, or in a merger or acquisition where these same commitments carry over. We never use it for advertising, and we never sell it. No person at NestBoard reads it, unless you ask us to look at something to fix a problem you reported, we need to for security, or the law compels it.

4. How long we keep your data

Active household: as long as you and your household members use NestBoard.

Unverified signups: if you create an account but never confirm your email address, we send up to two verification reminder emails, and then we automatically delete the unverified account (and the empty household created with it) 30 days after signup. Every reminder includes a one-click link to remove the account right away if you did not sign up.

Account deletion: your live data is removed within 30 days of your request. Backup copies take longer to disappear. We keep our host's own backups plus one daily offsite backup with a separate cloud provider, so that a failure at the host cannot take your data with it, and both roll off on their normal rotation. Until they do, a copy of your data still exists in those backups. We do not go back into a backup to use your data for anything.

Connected calendar tokens: revoked immediately on disconnect or account deletion.

Robin conversations: kept for 12 months, then deleted automatically by a job that runs every day. We keep them that long deliberately. It is what lets Robin remember your household across a school year, so you are not re-explaining who has practice on Tuesdays every few weeks. Robin's chat belongs to the household, so everyone in your household sees the same conversation.

Getting rid of Robin's history: an adult in your household can clear it whenever they like, from Settings, then Privacy & Data, then Clear Robin's history. That deletes the household's entire Robin conversation right away, and it cannot be undone. Because Robin's chat is shared, it clears for every member, not just the one who pressed the button. Nothing else is touched: your calendar, chores, lists, and the rest of your NestBoard stay exactly as they are.

Deleting your account (Settings, then Privacy & Data, then Delete my account) also removes the entire conversation history, along with the rest of your household data. If you would rather we did it for you, email privacy@mynestboard.com from your account's email address and we will wipe it.

The short facts Robin picks up about your household (an allergy, a birthday, the dog's name) do not expire on the 12-month clock, because that is the part of Robin's memory worth keeping. They are deleted along with the conversation when you clear Robin's history, since they are what Robin drew out of those conversations. Removing a family member also deletes the facts tied to that person, and deleting your account deletes all of them. Clearing Robin does not touch the records you entered yourself, such as allergies saved on a medical profile or foods on your meal exclusions list.

Crash and error logs: automatically purged after 90 days.

Audit trail: security and administrative audit records are retained for 12 months.

5. Sharing within a household

Anything you add to a household is visible to that household's members, by design.

Sensitive surfaces (medications, money, calendar items marked private) can be limited to specific members. Caregivers see what you choose to share, and nothing else.

Member groups (e.g. "Kids", "Grandparents") are visible to everyone in the household. They exist to make filtering and addressing easier, not to hide people from each other.

Removing a member from a household revokes their access immediately.

6. Subprocessors

We use a small set of trusted providers: Stripe (web billing), Apple (In-App Purchase billing on iPhone and iPad) with RevenueCat (iOS subscription management), Railway (hosting), Google Cloud Storage with GitHub Actions (the daily offsite backup of our database), Microsoft (transactional email via Microsoft Graph), OpenAI / Anthropic (Robin AI inference and meal and pantry suggestions, with no-training data agreements), Sentry (error and crash monitoring, on our servers and in the app), PostHog (product analytics), HeyCatch (product analytics), Google Firebase Cloud Messaging and the Apple Push Notification service (delivering push notifications to Android and to iPhone and iPad respectively), Pwned Passwords (checking new passwords against known breaches, without ever sending us your password to them), Open-Meteo (weather), Open Food Facts (pantry barcode lookup), Jina AI (reader fallback for recipe import from a URL), and Blitzortung.org (real-time lightning alerts). No advertising network is on that list, on our marketing pages or anywhere else.

We publish the full list (with the exact data each one sees and where it sits) at mynestboard.com/subprocessors, and we notify you 30 days before adding any new one.

7. Your rights

Export: download all your household data as JSON and ICS at any time.

Correction: edit your own profile anytime, or ask us to correct anything else.

Deletion: delete your account in Settings, or email privacy@mynestboard.com.

Portability: ICS export works with any other calendar, and JSON export documents the full schema.

EU/UK/CA residents have additional rights under GDPR, UK GDPR, and PIPEDA. Contact us to exercise them, and see the next section for how.

8. If you are in the UK or Europe

This section applies if you are in the United Kingdom, the European Economic Area, or Switzerland. NestBoard LLC is the data controller for the personal information described in this policy. Where we act on your instructions inside your own household, we still hold controller responsibility for the service as a whole, so you can bring any request straight to us.

Why we are allowed to process your data (lawful basis). Running your household calendar, chores, lists, medications, and everything else you put into NestBoard: performance of our contract with you, because it is the service you signed up for. Billing, fraud prevention, and keeping records of what we sold: contract, and our legal obligations for tax and accounting. Sending verification, password reset, security alerts, and reminders you switched on: contract. Keeping the service secure, preventing abuse, fixing crashes, and running the audit trail: our legitimate interests in operating a safe and working product, balanced against your interests and limited by the scrubbing described in section 2. Product analytics and email open measurement: your consent, asked for separately, and withdrawable at any time without losing anything. Onboarding and re-engagement emails: legitimate interests, with a one-click way to stop them in every message. Health details, which are special category data under Article 9: your explicit consent, given by choosing to type them in, and used only to show them back to the household members you allowed.

Cookies and similar storage. In the UK, the EEA, and Switzerland we store nothing on your device that is not strictly necessary until you have said yes. Non-essential storage means our product analytics and our email open measurement, and both are off by default for you. Strictly necessary storage keeps working either way, because without it the service cannot function: the session cookie or app token that keeps you signed in, your theme and layout preferences, the offline cache, and the record of the choice you made on the consent banner. You can change your answer at any time in Settings, under Privacy and Data. Saying no is one tap, exactly like saying yes, and nothing about NestBoard works differently afterwards.

How long we keep things. The retention periods in section 4 apply to you in full: household content for as long as the household is active, live data removed within 30 days of a deletion request with backups rolling off on their normal cycle after that, unverified signups deleted automatically after 30 days, Robin conversations for 12 months, crash and error logs for 90 days, and security and administrative audit records for 12 months. Billing records are kept for seven years because tax law requires it. Nothing is kept indefinitely by default.

Where your data is. Our servers are in the United States, and several of the providers listed at mynestboard.com/subprocessors are US companies. So when you use NestBoard your personal data is transferred out of the UK and the EEA. We rely on the European Commission Standard Contractual Clauses, together with the UK International Data Transfer Addendum for UK transfers and the Swiss addendum where Swiss law applies, in each contract that needs them. Where a provider is certified under the EU-US Data Privacy Framework and its UK extension, we rely on that instead. We keep the volume of data crossing the border as small as we can: the scrubbing described in section 2 runs before anything leaves our servers or your device, and no provider on that list receives your calendar entries, chore names, notes, or messages except the ones you can see are for exactly that purpose.

Your rights. You can ask us for a copy of your personal data, ask us to correct it, ask us to delete it, ask us to restrict or object to how we use it, ask us to hand it to another provider in a portable format, and withdraw any consent you have given. Several of these you can do yourself and immediately: export from Settings under Privacy and Data, delete your account from the same place, and turn analytics off there too. For anything else, email privacy@mynestboard.com from your account address. We answer within one month, and if a request is genuinely complicated we will tell you before that month is up rather than after. We do not charge for any of this.

Automated decisions. We do not make decisions about you by automated means that produce legal or similarly significant effects, and we do not profile you for advertising. Robin acts only on what you ask it to do, inside your own household.

Complaints. If you think we have got something wrong, tell us first at privacy@mynestboard.com, because we would rather fix it than argue about it. You also have the right to complain to a regulator without going through us. In the UK that is the Information Commissioner's Office (ico.org.uk, helpline 0303 123 1113, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF). In the EEA it is the supervisory authority in the country where you live or work, and the European Data Protection Board publishes the list at edpb.europa.eu. In Switzerland it is the Federal Data Protection and Information Commissioner.

Our representative in the UK and the EU. NestBoard LLC is based in the United States and has no office in the UK or the EU, so Article 27 of the UK GDPR and of the EU GDPR require us to name a representative you and your regulator can contact locally. We are appointing one, and this paragraph will carry their name and postal address as soon as that is in place. Until then, and afterwards as well, privacy@mynestboard.com reaches us directly and a real person answers within a day. Naming a representative does not change any of your rights or where you can complain.

9. Children

Kid-mode seats are designed for use by minors under parental supervision. They cannot sign up independently and have no public profile, no messaging, and no AI access by default.

We follow COPPA and equivalent regulations. Parents can request deletion of a kid-mode seat at any time.

10. Security

Data is encrypted in transit (TLS 1.3) and at rest.

Accounts are protected by strong password rules (including a check against known breached passwords), automatic lockout after repeated failed sign-in attempts, and an email alert when a new device signs in. You can also sign in with Google or Apple, which add their own protections.

Our security overview and vulnerability disclosure policy are published at mynestboard.com/security.

11. Changes & contact

The service is provided by NestBoard LLC, a Florida limited liability company based in the USA. NestBoard LLC is the data controller responsible for your personal information under applicable privacy laws.

We will email all account holders at least 30 days before any material change to this policy.

Privacy questions: privacy@mynestboard.com. General questions and bug reports: hello@mynestboard.com. A real person answers within a day.

Effective date: August 12, 2026.

Plain promises. Plainly written.

If anything here is unclear, write to us. We'll fix it.

Start your household See features