Account data: your name, email, the household name you create, and billing details. On the web, billing is handled by Stripe (we never see your card number). If you subscribe inside our iPhone or iPad app, the purchase is handled by Apple In-App Purchase, and we use RevenueCat to confirm and manage that subscription (we never see your card number there either).
Sign-in options: you can create an account with an email and password, or with Google or Apple. When you use Sign in with Google or Sign in with Apple, we store the account identifier the provider gives us along with your name and email (for Apple this may be an Apple private-relay address) so we can sign you back in.
Household contents: events, chores, medications, pantry items, alerts, and routines you and your household members add. This is yours, and it lives in your household. When you scan a grocery barcode to add a pantry item, the barcode number is sent to the Open Food Facts public database to look up the product. Only the barcode is sent.
Recipe import: when you import a recipe from a URL, we fetch that page directly to read its recipe data. If the site blocks our direct fetch, we send the recipe URL you pasted to Jina AI's reader (r.jina.ai) to retrieve the page's readable text, which is then turned into a recipe. Only the public recipe URL is shared with Jina AI, never your account or household data.
Health and emergency details: if you choose to fill them in, we store medical profile details for household members (including allergies, conditions, blood type, and insurance provider, policy, and group identifiers) and emergency contact information you enter (a contact name, relationship, phone, email, and address). These are optional, and they are treated as sensitive surfaces you can limit to specific members.
Comments and member groups: notes you leave on events (e.g. "running 10 minutes late") and the optional groupings you assign to family members are stored alongside the household. Comment authorship is recorded so the family can see who said what. The author name is preserved even if the member is later renamed or removed.
Connected calendar data: when you connect Google, Outlook, iCloud, or an ICS feed, we read events as you authorize. We do not read mail, contacts, or files.
Home location: if you set a home location (latitude/longitude or ZIP), we store it to power the weather widget (forecasts come from Open-Meteo) and to filter real-time lightning alerts down to your area (strike data streams from Blitzortung.org). Only the location itself is shared with those services, never your name, email, or household contents.
Robin inputs: text you paste, screenshots you attach, voice notes you send, and emails you forward to your private NestBoard inbox. Robin only acts on what you give it.
Product diagnostics: crash logs and performance metrics, processed through Sentry. We scrub names, email addresses, and household contents from error payloads before they leave the server, though an error report may include your IP address. No content from your household is included.
Product analytics: we use PostHog to understand which features get used and where the app gets confusing, on both the marketing site and inside the app. It is cookieless (it uses local storage, not a tracking cookie), session replay is off, it identifies you only by an internal account id (never your email), any sign-in token in a page address is stripped before it is recorded, and no household content is collected.
Keeping you signed in: on the web, a single strictly-necessary session cookie keeps you signed in. In our Android and iPhone apps, that same sign-in is kept by a session token stored privately in the app's own local storage on your device and sent with each request. It is never shared with third parties and is cleared when you sign out. Inside NestBoard there are no advertising, analytics, or cross-site tracking cookies, ever.
Push notifications: once you allow notifications on your device, NestBoard sends push notifications for things like dose reminders, chore nudges, and lightning alerts. New households also start with Robin's morning check-in, a friendly once-a-day push to help plan the day, which you can retime or turn off in Settings. If a household goes quiet for a few days we may send one gentle reminder push to help you pick back up. To deliver any of these we store a device push identifier (a token issued by Apple, Google, or your browser's push service) for each device you enable. These tokens carry no household content, are used only to route notifications to your device, and are removed when you turn notifications off or sign out.
Account and onboarding emails: beyond the verification emails above, we may send a small number of onboarding and re-engagement emails in your first days, for example a short welcome note and, if your household goes quiet, one reminder that your calendar is waiting. These come from NestBoard, never contain third-party ads, and you can reply to reach us or ask us to stop.
Cookies on our marketing site: our public pages (the pages you see before you sign in) use the Meta Pixel and the Pinterest Tag so we can understand how people find NestBoard and measure our marketing. They fire standard page-view events, plus a single signup event when you join the waitlist (Meta only, with no personal details attached). They never send your email address or anything from your household, and neither one runs inside the app. You can limit how Meta uses this at facebook.com/adpreferences and how Pinterest uses it at pinterest.com/settings.