Skip to main content
NestBoard
NestBoard
Start free
Privacy policy

Yours, only. Forever.

Households are intimate. Your data should feel that way too. This policy is the long version of a short promise: we don't train on your data, we don't sell it, and you can leave with everything.

1. The short version

NestBoard is a calmly designed shared calendar for households. We are paid for by subscriptions, not advertising, and we never sell your personal data.

We don't train AI models on your data. We don't read what isn't shared with us. We don't allow third-party trackers in our product surfaces.

You can export your household's data at any time, and you can delete your account and household with a single request.

2. What we collect

Account data: your name, email, the household name you create, and billing details. On the web, billing is handled by Stripe (we never see your card number). If you subscribe inside our iPhone or iPad app, the purchase is handled by Apple In-App Purchase, and we use RevenueCat to confirm and manage that subscription (we never see your card number there either).

Sign-in options: you can create an account with an email and password, or with Google or Apple. When you use Sign in with Google or Sign in with Apple, we store the account identifier the provider gives us along with your name and email (for Apple this may be an Apple private-relay address) so we can sign you back in.

Household contents: events, chores, medications, pantry items, alerts, and routines you and your household members add. This is yours, and it lives in your household. When you scan a grocery barcode to add a pantry item, the barcode number is sent to the Open Food Facts public database to look up the product. Only the barcode is sent.

Recipe import: when you import a recipe from a URL, we fetch that page directly to read its recipe data. If the site blocks our direct fetch, we send the recipe URL you pasted to Jina AI's reader (r.jina.ai) to retrieve the page's readable text, which is then turned into a recipe. Only the public recipe URL is shared with Jina AI, never your account or household data.

Health and emergency details: if you choose to fill them in, we store medical profile details for household members (including allergies, conditions, blood type, and insurance provider, policy, and group identifiers) and emergency contact information you enter (a contact name, relationship, phone, email, and address). These are optional, and they are treated as sensitive surfaces you can limit to specific members.

Comments and member groups: notes you leave on events (e.g. "running 10 minutes late") and the optional groupings you assign to family members are stored alongside the household. Comment authorship is recorded so the family can see who said what. The author name is preserved even if the member is later renamed or removed.

Connected calendar data: when you connect Google, Outlook, iCloud, or an ICS feed, we read events as you authorize. We do not read mail, contacts, or files.

Home location: if you set a home location (latitude/longitude or ZIP), we store it to power the weather widget (forecasts come from Open-Meteo) and to filter real-time lightning alerts down to your area (strike data streams from Blitzortung.org). Only the location itself is shared with those services, never your name, email, or household contents.

Robin inputs: text you paste, screenshots you attach, voice notes you send, and emails you forward to your private NestBoard inbox. Robin only acts on what you give it.

Product diagnostics: crash logs and performance metrics, processed through Sentry. We scrub names, email addresses, and household contents from error payloads before they leave the server, though an error report may include your IP address. No content from your household is included.

Product analytics: we use PostHog to understand which features get used and where the app gets confusing, on both the marketing site and inside the app. It is cookieless (it uses local storage, not a tracking cookie), session replay is off, it identifies you only by an internal account id (never your email), any sign-in token in a page address is stripped before it is recorded, and no household content is collected.

Keeping you signed in: on the web, a single strictly-necessary session cookie keeps you signed in. In our Android and iPhone apps, that same sign-in is kept by a session token stored privately in the app's own local storage on your device and sent with each request. It is never shared with third parties and is cleared when you sign out. Inside NestBoard there are no advertising, analytics, or cross-site tracking cookies, ever.

Push notifications: once you allow notifications on your device, NestBoard sends push notifications for things like dose reminders, chore nudges, and lightning alerts. New households also start with Robin's morning check-in, a friendly once-a-day push to help plan the day, which you can retime or turn off in Settings. If a household goes quiet for a few days we may send one gentle reminder push to help you pick back up. To deliver any of these we store a device push identifier (a token issued by Apple, Google, or your browser's push service) for each device you enable. These tokens carry no household content, are used only to route notifications to your device, and are removed when you turn notifications off or sign out.

Account and onboarding emails: beyond the verification emails above, we may send a small number of onboarding and re-engagement emails in your first days, for example a short welcome note and, if your household goes quiet, one reminder that your calendar is waiting. These come from NestBoard, never contain third-party ads, and you can reply to reach us or ask us to stop.

Cookies on our marketing site: our public pages (the pages you see before you sign in) use the Meta Pixel and the Pinterest Tag so we can understand how people find NestBoard and measure our marketing. They fire standard page-view events, plus a single signup event when you join the waitlist (Meta only, with no personal details attached). They never send your email address or anything from your household, and neither one runs inside the app. You can limit how Meta uses this at facebook.com/adpreferences and how Pinterest uses it at pinterest.com/settings.

3. What we don't do

We don't train models on your data, yours or anyone else's in NestBoard.

We don't sell, rent, or share your data with advertisers, data brokers, or any third party for marketing.

We don't run advertising in NestBoard. There is no ad model and there will not be one.

We don't read your inbox, browse the web on your behalf, or scrape your messages. Robin only sees what you explicitly share.

4. How long we keep your data

Active household: as long as you and your household members use NestBoard.

Unverified signups: if you create an account but never confirm your email address, we send up to two verification reminder emails, and then we automatically delete the unverified account (and the empty household created with it) 30 days after signup. Every reminder includes a one-click link to remove the account right away if you did not sign up.

Account deletion: your live data is removed within 30 days of your request. Backup copies roll off on our hosting provider's standard backup cycle.

Connected calendar tokens: revoked immediately on disconnect or account deletion.

Robin context: rolling 30-day retention for assistant context. Older inputs are discarded automatically.

Crash and error logs: automatically purged after 90 days.

Audit trail: security and administrative audit records are retained for 12 months.

5. Sharing within a household

Anything you add to a household is visible to that household's members, by design.

Sensitive surfaces (medications, money, calendar items marked private) can be limited to specific members. Caregivers see what you choose to share, and nothing else.

Member groups (e.g. "Kids", "Grandparents") are visible to everyone in the household. They exist to make filtering and addressing easier, not to hide people from each other.

Removing a member from a household revokes their access immediately.

6. Subprocessors

We use a small set of trusted providers: Stripe (web billing), Apple (In-App Purchase billing on iPhone and iPad) with RevenueCat (iOS subscription management), Railway (hosting), Microsoft (transactional email via Microsoft Graph), OpenAI / Anthropic (Robin AI inference and meal and pantry suggestions, with no-training data agreements), Sentry (error monitoring), PostHog (product analytics), Open-Meteo (weather), Open Food Facts (pantry barcode lookup), Jina AI (reader fallback for recipe import from a URL), and Blitzortung.org (real-time lightning alerts). Our public marketing pages also use the Meta Pixel and the Pinterest Tag to understand how people find NestBoard and measure our marketing.

We publish the full list (with the exact data each one sees and where it sits) at mynestboard.com/subprocessors, and we notify you 30 days before adding any new one.

7. Your rights

Export: download all your household data as JSON and ICS at any time.

Correction: edit your own profile anytime, or ask us to correct anything else.

Deletion: delete your account in Settings, or email privacy@mynestboard.com.

Portability: ICS export works with any other calendar, and JSON export documents the full schema.

EU/UK/CA residents have additional rights under GDPR, UK GDPR, and PIPEDA. Contact us to exercise them.

8. Children

Kid-mode seats are designed for use by minors under parental supervision. They cannot sign up independently and have no public profile, no messaging, and no AI access by default.

We follow COPPA and equivalent regulations. Parents can request deletion of a kid-mode seat at any time.

9. Security

Data is encrypted in transit (TLS 1.3) and at rest.

Accounts are protected by strong password rules (including a check against known breached passwords), automatic lockout after repeated failed sign-in attempts, and an email alert when a new device signs in. You can also sign in with Google or Apple, which add their own protections.

Our security overview and vulnerability disclosure policy are published at mynestboard.com/security.

10. Changes & contact

The service is provided by NestBoard LLC, a Florida limited liability company based in the USA. NestBoard LLC is the data controller responsible for your personal information under applicable privacy laws.

We will email all account holders at least 30 days before any material change to this policy.

Privacy questions: privacy@mynestboard.com. General questions and bug reports: hello@mynestboard.com. A real person answers within a day.

Effective date: June 11, 2026.

Plain promises. Plainly written.

If anything here is unclear, write to us. We'll fix it.

Start your household See features