Skip to main content
NestBoard
NestBoard
Start free
Subprocessors

The full list, no hedging.

Our Privacy Policy promises to publish every third party that processes household data on NestBoard's behalf. This is that list, kept current, with the actual data each one sees and where they sit.

EFFECTIVE DATE: JUNE 11, 2026 · LAST REVIEWED: AUGUST 24, 2026 · SUBPROCESSORS: 30

If we add a new subprocessor, we will update this list and notify paying customers via email at least 30 days before the change takes effect. If we remove one, we will note the change here.

Some subprocessors are engaged only when you opt in (for example, we don't talk to Google Calendar unless you connect a Google Calendar). Those are flagged below.

Railway

Railway Corp.
railway.com/legal/privacy
Purpose
Application hosting and managed Postgres. The NestBoard API container and primary database run on Railway. This is where everything in your household physically lives at rest.
Data shared
All household data: accounts, members, events, chores, comments, medications, lists, notes, attachments, push tokens, and connected-calendar tokens. Server logs and request metadata.
Location
United States (US-West / US-East regions).

Google Cloud Storage

Google LLC
cloud.google.com/terms/cloud-privacy-notice
Purpose
Offsite backup storage. Once a day we take a compressed backup of the entire NestBoard database and store a copy with a cloud provider separate from our main host, so a failure at the host cannot take your household data with it.
Data shared
A complete encrypted-at-rest copy of the production database, which means everything in your household. This copy is never read in the ordinary course of business. It exists to restore the service after a disaster and is deleted on the backup rotation schedule.
Location
United States.

GitHub Actions

GitHub, Inc. (Microsoft Corporation)
docs.github.com privacy statement
Purpose
Automation that runs the daily offsite backup described above. The backup job runs on a GitHub-hosted machine, which reads the database and streams it to backup storage.
Data shared
The database backup passes through the job while it runs. Nothing is retained on the machine after the job finishes.
Location
United States.

Stripe

Stripe, Inc.
stripe.com/privacy
Purpose
Subscription billing, payment processing, and tax handling. Stripe stores your card on its servers, so we never see the full number.
Data shared
Billing email, name, country, card token, subscription status, charge history. Card numbers, CVC, and full payment instruments stay with Stripe.
Location
United States (with regional processing in the EU and UK for customers there).

Apple In-App Purchase

Apple Inc.
apple.com/legal/privacy
Purpose
Subscription billing and payment processing for purchases made inside the iPhone and iPad app. App Store rules require subscriptions sold in the iOS app to go through Apple, so on iOS we present Apple's native purchase sheet instead of Stripe. Apple stores your payment method. We never see it.
Data shared
Your Apple account, payment method, and purchase / subscription status are held by Apple. NestBoard receives only a confirmation that the subscription is active (via RevenueCat), tied to an opaque app user id. We never see your card number.
Location
United States and global Apple infrastructure.
When
Only engaged if you subscribe inside the iPhone or iPad app.

RevenueCat

RevenueCat, Inc.
revenuecat.com/privacy
Purpose
In-app purchase and subscription management for iPhone and iPad. RevenueCat validates Apple In-App Purchase receipts and tells NestBoard when an iOS subscription starts, renews, or lapses, so we can keep the household's access in sync.
Data shared
An opaque app user id (your NestBoard account id), the purchased product, and subscription status and expiry. No name, email, household contents, or card number is sent. Payment details stay with Apple.
Location
United States.
When
Only engaged if you subscribe inside the iPhone or iPad app.

Microsoft Graph email

Microsoft Corporation
privacy.microsoft.com
Purpose
Transactional and broadcast email delivery. Every email NestBoard sends (verification, password resets, invites, billing receipts, opt-in task reminder emails, founder updates) is dispatched via Microsoft Graph.
Data shared
Recipient email address, sender (hub@mynestboard.com), subject, message body, and any inline content (e.g. invite link, household name).
Location
United States and European Union (Microsoft 365 multi-region tenancy).

Microsoft Outlook Calendar sync

Microsoft Corporation
privacy.microsoft.com
Purpose
Read-only calendar sync: importing events from your Outlook / Microsoft 365 calendar into NestBoard, when you connect it.
Data shared
Calendar event titles, times, locations, descriptions, and attendees on the calendars you authorize. We do not read mail, contacts, or files.
Location
United States and European Union.
When
Only engaged if you connect an Outlook / Microsoft 365 calendar in Settings.

Google Sign-In and Calendar sync

Google LLC
policies.google.com/privacy
Purpose
Google Sign-In (account creation and login); calendar sync (importing your Google Calendar events) when you connect it; and, only if a household adult switches it on, copying your NestBoard events out into a calendar NestBoard creates inside your Google account.
Data shared
Sign-In: your Google account email, name, profile picture, and a verified ID token. Calendar sync in (only when you connect it): event titles, times, locations, descriptions, and attendees on the calendars you authorize. Showing NestBoard events in Google Calendar (off unless a household adult turns it on): the titles, times, locations, descriptions, and participant names of the NestBoard events we copy into the calendar we create in your account. That permission covers only calendars this app creates, so we cannot read, change, or delete the calendars you made yourself. We never request mail, contacts, drive, or other scopes.
Location
United States and global Google infrastructure.

Calendar feeds you add yourself (iCal / ICS / webcal)

mynestboard.com/privacy
Purpose
Read-only calendar import: when you paste an external calendar link (an .ics or webcal:// URL) into Settings, Calendar Sync, NestBoard's server periodically fetches that link and imports its events onto your family calendar.
Data shared
NestBoard's server sends a request to whatever host you choose, so that host can see the request and our server's IP address. We do not send it any of your household data. The events the feed returns are stored on your family calendar. The host is the operator of the URL you provide (for example Apple iCloud, a school portal, or a sports-league app), which you choose, not a NestBoard-contracted subprocessor.
Location
Wherever the calendar you subscribe to is hosted (you choose the URL).
When
Only engaged for feed URLs you add yourself in Settings, Calendar Sync.

Apple Sign-In

Apple Inc.
apple.com/legal/privacy
Purpose
Sign in with Apple (account creation and login) when you choose to use it.
Data shared
Your Apple account identifier, the name you share on first sign-in, and your email address or an Apple private-relay address that forwards to your real inbox. We never request any other Apple data.
Location
United States and global Apple infrastructure.
When
Only engaged if you choose Sign in with Apple.

Firebase Cloud Messaging

Google LLC
firebase.google.com/support/privacy
Purpose
Delivery of push notifications to the Android app (reminders, comments, chore nudges, founder pings).
Data shared
FCM device token, notification title and body, and a small payload (e.g. household id, event id) used to deep-link into the app.
Location
United States and global Google infrastructure.
When
Only engaged on the Android app and only after you accept the system notification permission.

Apple Push Notification service

Apple Inc.
apple.com/legal/privacy
Purpose
Delivery of push notifications to the iPhone and iPad app (dose reminders, chore nudges, comments, lightning alerts). We send these straight to Apple rather than through Firebase, so no Google service is involved in iOS push.
Data shared
The APNs device token for each device you enable, the notification title and body, and a small payload (e.g. household id, event id) used to deep-link into the app.
Location
United States and global Apple infrastructure.
When
Only engaged on the iPhone and iPad app and only after you accept the system notification permission.

Browser push services

mynestboard.com/privacy
Purpose
Delivery of push notifications when you enable them in a web browser rather than in our app. Web push is routed through whichever push service your browser vendor operates (for example Google for Chrome, Mozilla for Firefox, Apple for Safari). Which one is used is determined by the browser you chose, not by us.
Data shared
The browser push subscription endpoint and the notification payload, which is encrypted so the push service cannot read its contents.
Location
Determined by your browser vendor.
When
Only engaged if you turn on notifications in a web browser and accept the browser permission prompt.

Pwned Passwords (Have I Been Pwned)

haveibeenpwned.com/Privacy
Purpose
Breached-password screening. When you set or change a password, we check it against a public database of passwords known to have leaked in past breaches, so we can stop you reusing one that attackers already have.
Data shared
Your password is never sent. We hash it on our server and send only the first five characters of that hash, which match many millions of different passwords, then do the actual comparison ourselves against the list that comes back. The service cannot tell what your password is, who you are, or that the check came from your account.
Location
Cloudflare global network.
When
Only engaged when you create a password or change an existing one.

OpenAI

OpenAI, L.L.C.
openai.com/policies/privacy-policy
Purpose
Robin AI inference (the default model is gpt-4o-mini), content moderation on Robin inputs, and voice-dictation transcription (Whisper) on devices without on-device speech (iPhone/iPad). Robin's tool-calling layer runs against the OpenAI Chat Completions API. Also powers meal plan suggestions, automatic pantry item categorization, and structuring recipes imported from a PDF.
Data shared
The text, screenshots, and forwarded-email contents you give Robin, plus the household context Robin needs to answer (e.g. a list of upcoming events). On iPhone/iPad, the short audio clip from a voice dictation is sent to OpenAI for transcription and not retained. API usage runs under an enterprise/no-training agreement, so prompts, completions, and audio are not used to train OpenAI models. For meal and pantry features we also send pantry item names and quantities and any meal request you type, and, when you import a recipe from a PDF, the text extracted from that PDF. The same no-training agreement applies.
Location
United States.

Anthropic

Anthropic, PBC
anthropic.com/legal/privacy
Purpose
Anthropic Claude models power the blog-writing agent and some Robin code paths (e.g. long-form drafting). Engaged via the Anthropic Messages API.
Data shared
Prompts and context sent to Claude. For the blog agent that is research notes and outline drafts. For Robin paths that route through Anthropic, the same inputs OpenAI would otherwise see. Runs under a no-training data agreement.
Location
United States.

Sentry

Functional Software, Inc. (dba Sentry)
sentry.io/privacy
Purpose
Error and crash monitoring, in two places. On our servers, when the API throws, Sentry receives the stack trace so we can fix it before it hits another household. In the NestBoard app (web, Android, and iPhone/iPad), Sentry also reports crashes and unhandled errors directly from your device so we can see failures that never reach our servers, such as an app that crashes on launch. Our public marketing pages have no crash reporting at all.
Data shared
From our servers: error stack traces, request paths, HTTP status codes, user id (opaque), household id (opaque), and IP address. We scrub email addresses, names, household contents, and message bodies from those payloads before they leave the server. From your device: the crash or error stack trace, the app version, the screen or page address where it happened, and basic device and operating-system information, plus your IP address. Reports sent from your device do not pass through our servers first, so the server-side scrubbing above does not apply to them. We turn off Sentry features that would collect more: performance tracing and session replay are both disabled, and the SDK is configured not to attach personal information by default. No household content is sent.
Location
United States.

Open-Meteo

Open-Meteo (Patrick Zippenfenig, Switzerland)
open-meteo.com/en/terms
Purpose
Weather forecasts and geocoding for the home dashboard weather card and Robin’s "what’s the weather?" answers.
Data shared
Only a place name or latitude/longitude that you (or Robin acting on your request) ask about. No account identifier, email, or household data is sent.
Location
European Union (Switzerland / Germany).

Open Food Facts

Open Food Facts (non-profit association, France)
openfoodfacts.org/terms-of-use
Purpose
Product lookup for the pantry barcode scanner. When you scan a grocery barcode, the product's barcode number is sent to the Open Food Facts public database to retrieve its name, brand, and category.
Data shared
Only the scanned product barcode (UPC or EAN). No account identifier, email, name, or household contents are sent. Because the lookup runs from your device, your device IP address reaches Open Food Facts.
Location
European Union (France).
When
Only engaged when you scan a barcode in the pantry.

Jina AI

Jina AI GmbH
jina.ai/legal
Purpose
Reader fallback for recipe import. When a recipe site blocks our direct fetch, the recipe URL you pasted is sent to Jina AI's reader (r.jina.ai) to retrieve the page's readable text, which is then parsed into a recipe.
Data shared
Only the public recipe URL you chose to import. No account info or household data.
Location
United States.
When
Only engaged when you import a recipe from a URL and the site blocks our direct fetch.

Blitzortung.org

Blitzortung.org (community lightning detection network)
blitzortung.org
Purpose
Real-time lightning strike data for the storm / lightning alert feature. NestBoard streams strike events and filters them down to your area so we can warn you when lightning is close.
Data shared
Only the approximate home location / region (latitude/longitude) used to filter the strike stream down to your area. No account identifier, email, name, or household contents are sent.
Location
European Union (community-operated detection network).

OpenStreetMap Nominatim

OpenStreetMap Foundation
wiki.osmfoundation.org privacy policy
Purpose
Address lookup. When you type a place into a location box, such as the home location or an event address, we ask the OpenStreetMap search service to turn what you typed into a suggestion list and coordinates.
Data shared
The text you type into a location field, and, because the lookup runs from your device, your device IP address. No account identifier, email, or household contents are sent.
Location
European Union (OpenStreetMap Foundation infrastructure).
When
Only engaged while you are typing in a location field.

Amazon Alexa

Amazon.com, Inc.
amazon.com privacy notice
Purpose
Voice control. If your household connects NestBoard to Alexa, Amazon's Echo devices and speech services process what you say to the NestBoard skill, turn it into a structured request (the command plus the words you filled in, like an item name or an event name and date), and send that request to our server. Amazon also delivers NestBoard's spoken reply back to your Echo.
Data shared
What Amazon sends us: the recognized command and its details (for example "add milk", an event name and date, or a chore name), opaque Amazon account and speaker identifiers, and, during pairing, the code exchange. What Amazon holds on its side: your voice recordings and their transcripts, under your Amazon account and Amazon's own privacy controls. We never receive audio. What we send Amazon: the text NestBoard speaks back, which can include household data you asked for out loud, like today's events or what's for dinner.
Location
United States and global Amazon infrastructure.
When
Only engaged if a household adult connects NestBoard to Alexa.

Geoapify

Geoapify GmbH
geoapify.com/privacy-policy
Purpose
Address autocomplete. When you type a place into a location box, such as the home location or an event address, Geoapify turns what you typed into a suggestion list with coordinates. It has real United States residential address coverage, which is why it sits in front of the OpenStreetMap lookup listed below (used as the fallback when Geoapify is not configured).
Data shared
The text you type into a location field, and, because the lookup runs from your device, your device IP address. No account identifier, email, or household contents are sent.
Location
European Union (Germany).
When
Only engaged while you are typing in a location field.

Google Fonts

Google LLC
policies.google.com/privacy
Purpose
Typeface delivery for some of our visual themes. When a theme uses a font we do not ship ourselves, your browser fetches it from Google.
Data shared
Your device IP address and browser user-agent reach Google when the font file is fetched, which is unavoidable for any file a browser downloads from another host. No account identifier, email, or household contents are sent.
Location
United States and global Google infrastructure.
When
Only engaged on themes that use a remotely hosted font.

Google Play Integrity

Google LLC
policies.google.com/privacy
Purpose
Abuse prevention on Android. At signup the Android app can ask Google to confirm that it is a genuine, unmodified copy of NestBoard running on a genuine device, which helps us tell real families from automated signup abuse.
Data shared
A signed verdict from Google about the app and device. We record the verdict. We do not receive an advertising identifier, and the Android app explicitly removes the advertising-ID permission.
Location
United States and global Google infrastructure.
When
Only engaged in the Android app.

App install attribution (Apple Search Ads and Google Play)

Apple Inc. and Google LLC
apple.com/legal/privacy
Purpose
Working out which advert or listing an app install came from, so we know where to spend a small marketing budget. On iPhone and iPad this uses Apple's AdServices attribution. On Android it uses the Google Play install referrer.
Data shared
On iOS, an Apple-issued attribution token that we exchange with Apple for a campaign-level report. On Android, the referrer string Google Play recorded for the install. This is campaign information, not a profile of you. We do not use the iOS advertising identifier and do not ask for tracking permission, and the Android app removes the advertising-ID permission entirely.
Location
United States and global Apple / Google infrastructure.
When
Only engaged once, when the app is first installed and opened.

PostHog

PostHog, Inc.
posthog.com/privacy
Purpose
Product analytics and browser error monitoring. Understanding which features get used, where the app gets confusing, and which errors the page hits, on both the marketing site and inside the app.
Data shared
Anonymized usage events keyed to an internal account id (never your email). It is cookieless (local storage, not a tracking cookie), session replay is off, any sign-in token in a page address is stripped before it is recorded, and no household content is collected. Error reports carry the error type, message, and stack trace, with console output excluded and the message scrubbed on the device.
Location
United States.

HeyCatch

HeyCatch, Inc.
heycatch.ai/privacy
Purpose
Product analytics. Measuring how people find NestBoard on our public marketing pages, and which milestones a household reaches after signing up.
Data shared
Two separate streams, split on purpose. On our public marketing pages, where nobody is signed in, their script records page views and clicks automatically, including the text of the thing clicked. On those pages that text is our own marketing copy. Inside the signed-in app their script does not run at all. The app reports from our own servers instead, sending a short, fixed list of milestone events, things like signup completed, setup finished, and subscription started, keyed to an internal account id (never your email), with only counts, dates, and fixed labels attached, such as how many members were added or which payment method was used. Your subscription status is held as a profile field on that id. No calendar entries, chore names, shopping lists, notes, messages, or member names are sent, and there is no automatic click capture inside the app. We removed their in-app script in August 2026, because it recorded the text of whatever you clicked and inside NestBoard that text can be a family member's name, and some members are children. We had already stopped sending the account email and display name as profile fields, for the same reason. Account ids are resolved to people in our own database. Their script uses local storage and a first-party cookie to recognize the same visitor between visits on the marketing pages, and session recording is off.
Location
United States.

Questions about a specific subprocessor?

Email privacy@mynestboard.com. We answer within one business day.

Start your household See features