Skip to main content
NestBoard
NestBoard
Start free
Subprocessors

The full list, no hedging.

Our Privacy Policy promises to publish every third party that processes household data on NestBoard's behalf. This is that list, kept current, with the actual data each one sees and where they sit.

EFFECTIVE DATE: JUNE 11, 2026 · LAST REVIEWED: JUNE 11, 2026 · SUBPROCESSORS: 20

If we add a new subprocessor, we will update this list and notify paying customers via email at least 30 days before the change takes effect. If we remove one, we will note the change here.

Some subprocessors are engaged only when you opt in (for example, we don't talk to Google Calendar unless you connect a Google Calendar). Those are flagged below.

Railway

Railway Corp.
railway.com/legal/privacy
Purpose
Application hosting and managed Postgres. The NestBoard API container and primary database run on Railway. This is where everything in your household physically lives at rest.
Data shared
All household data: accounts, members, events, chores, comments, medications, lists, notes, attachments, push tokens, and connected-calendar tokens. Server logs and request metadata.
Location
United States (US-West / US-East regions).

Stripe

Stripe, Inc.
stripe.com/privacy
Purpose
Subscription billing, payment processing, and tax handling. Stripe stores your card on its servers, so we never see the full number.
Data shared
Billing email, name, country, card token, subscription status, charge history. Card numbers, CVC, and full payment instruments stay with Stripe.
Location
United States (with regional processing in the EU and UK for customers there).

Apple In-App Purchase

Apple Inc.
apple.com/legal/privacy
Purpose
Subscription billing and payment processing for purchases made inside the iPhone and iPad app. App Store rules require subscriptions sold in the iOS app to go through Apple, so on iOS we present Apple's native purchase sheet instead of Stripe. Apple stores your payment method. We never see it.
Data shared
Your Apple account, payment method, and purchase / subscription status are held by Apple. NestBoard receives only a confirmation that the subscription is active (via RevenueCat), tied to an opaque app user id. We never see your card number.
Location
United States and global Apple infrastructure.
When
Only engaged if you subscribe inside the iPhone or iPad app.

RevenueCat

RevenueCat, Inc.
revenuecat.com/privacy
Purpose
In-app purchase and subscription management for iPhone and iPad. RevenueCat validates Apple In-App Purchase receipts and tells NestBoard when an iOS subscription starts, renews, or lapses, so we can keep the household's access in sync.
Data shared
An opaque app user id (your NestBoard account id), the purchased product, and subscription status and expiry. No name, email, household contents, or card number is sent. Payment details stay with Apple.
Location
United States.
When
Only engaged if you subscribe inside the iPhone or iPad app.

Microsoft Graph email

Microsoft Corporation
privacy.microsoft.com
Purpose
Transactional and broadcast email delivery. Every email NestBoard sends (verification, password resets, invites, billing receipts, founder updates) is dispatched via Microsoft Graph.
Data shared
Recipient email address, sender (hub@mynestboard.com), subject, message body, and any inline content (e.g. invite link, household name).
Location
United States and European Union (Microsoft 365 multi-region tenancy).

Microsoft Outlook Calendar sync

Microsoft Corporation
privacy.microsoft.com
Purpose
Read-only calendar sync: importing events from your Outlook / Microsoft 365 calendar into NestBoard, when you connect it.
Data shared
Calendar event titles, times, locations, descriptions, and attendees on the calendars you authorize. We do not read mail, contacts, or files.
Location
United States and European Union.
When
Only engaged if you connect an Outlook / Microsoft 365 calendar in Settings.

Google Sign-In and Calendar sync

Google LLC
policies.google.com/privacy
Purpose
Google Sign-In (account creation and login) and read-only calendar sync (importing your Google Calendar events) when you connect it.
Data shared
Sign-In: your Google account email, name, profile picture, and a verified ID token. Calendar sync (only when you connect it): event titles, times, locations, descriptions, and attendees on the calendars you authorize. We never request mail, contacts, drive, or other scopes.
Location
United States and global Google infrastructure.

Calendar feeds you add yourself (iCal / ICS / webcal)

mynestboard.com/privacy
Purpose
Read-only calendar import: when you paste an external calendar link (an .ics or webcal:// URL) into Settings, Calendar Sync, NestBoard's server periodically fetches that link and imports its events onto your family calendar.
Data shared
NestBoard's server sends a request to whatever host you choose, so that host can see the request and our server's IP address. We do not send it any of your household data. The events the feed returns are stored on your family calendar. The host is the operator of the URL you provide (for example Apple iCloud, a school portal, or a sports-league app), which you choose, not a NestBoard-contracted subprocessor.
Location
Wherever the calendar you subscribe to is hosted (you choose the URL).
When
Only engaged for feed URLs you add yourself in Settings, Calendar Sync.

Apple Sign-In

Apple Inc.
apple.com/legal/privacy
Purpose
Sign in with Apple (account creation and login) when you choose to use it.
Data shared
Your Apple account identifier, the name you share on first sign-in, and your email address or an Apple private-relay address that forwards to your real inbox. We never request any other Apple data.
Location
United States and global Apple infrastructure.
When
Only engaged if you choose Sign in with Apple.

Firebase Cloud Messaging

Google LLC
firebase.google.com/support/privacy
Purpose
Delivery of push notifications to the Android app (reminders, comments, chore nudges, founder pings).
Data shared
FCM device token, notification title and body, and a small payload (e.g. household id, event id) used to deep-link into the app.
Location
United States and global Google infrastructure.
When
Only engaged on the Android app and only after you accept the system notification permission.

OpenAI

OpenAI, L.L.C.
openai.com/policies/privacy-policy
Purpose
Robin AI inference (the default model is gpt-4o-mini), content moderation on Robin inputs, and voice-dictation transcription (Whisper) on devices without on-device speech (iPhone/iPad). Robin's tool-calling layer runs against the OpenAI Chat Completions API. Also powers meal plan suggestions, automatic pantry item categorization, and structuring recipes imported from a PDF.
Data shared
The text, screenshots, and forwarded-email contents you give Robin, plus the household context Robin needs to answer (e.g. a list of upcoming events). On iPhone/iPad, the short audio clip from a voice dictation is sent to OpenAI for transcription and not retained. API usage runs under an enterprise/no-training agreement, so prompts, completions, and audio are not used to train OpenAI models. For meal and pantry features we also send pantry item names and quantities and any meal request you type, and, when you import a recipe from a PDF, the text extracted from that PDF. The same no-training agreement applies.
Location
United States.

Anthropic

Anthropic, PBC
anthropic.com/legal/privacy
Purpose
Anthropic Claude models power the blog-writing agent and some Robin code paths (e.g. long-form drafting). Engaged via the Anthropic Messages API.
Data shared
Prompts and context sent to Claude. For the blog agent that is research notes and outline drafts. For Robin paths that route through Anthropic, the same inputs OpenAI would otherwise see. Runs under a no-training data agreement.
Location
United States.

Sentry

Functional Software, Inc. (dba Sentry)
sentry.io/privacy
Purpose
Server-side error and performance monitoring. When the API throws, Sentry receives the stack trace so we can fix it before it hits another household.
Data shared
Error stack traces, request paths, HTTP status codes, user id (opaque), household id (opaque), and IP address. We scrub email addresses, names, household contents, and message bodies from error payloads before they leave the server.
Location
United States.

Open-Meteo

Open-Meteo (Patrick Zippenfenig, Switzerland)
open-meteo.com/en/terms
Purpose
Weather forecasts and geocoding for the home dashboard weather card and Robin’s "what’s the weather?" answers.
Data shared
Only a place name or latitude/longitude that you (or Robin acting on your request) ask about. No account identifier, email, or household data is sent.
Location
European Union (Switzerland / Germany).

Open Food Facts

Open Food Facts (non-profit association, France)
openfoodfacts.org/terms-of-use
Purpose
Product lookup for the pantry barcode scanner. When you scan a grocery barcode, the product's barcode number is sent to the Open Food Facts public database to retrieve its name, brand, and category.
Data shared
Only the scanned product barcode (UPC or EAN). No account identifier, email, name, or household contents are sent. Because the lookup runs from your device, your device IP address reaches Open Food Facts.
Location
European Union (France).
When
Only engaged when you scan a barcode in the pantry.

Jina AI

Jina AI GmbH
jina.ai/legal
Purpose
Reader fallback for recipe import. When a recipe site blocks our direct fetch, the recipe URL you pasted is sent to Jina AI's reader (r.jina.ai) to retrieve the page's readable text, which is then parsed into a recipe.
Data shared
Only the public recipe URL you chose to import. No account info or household data.
Location
United States.
When
Only engaged when you import a recipe from a URL and the site blocks our direct fetch.

Blitzortung.org

Blitzortung.org (community lightning detection network)
blitzortung.org
Purpose
Real-time lightning strike data for the storm / lightning alert feature. NestBoard streams strike events and filters them down to your area so we can warn you when lightning is close.
Data shared
Only the approximate home location / region (latitude/longitude) used to filter the strike stream down to your area. No account identifier, email, name, or household contents are sent.
Location
European Union (community-operated detection network).

PostHog

PostHog, Inc.
posthog.com/privacy
Purpose
Product analytics. Understanding which features get used and where the app gets confusing, on both the marketing site and inside the app.
Data shared
Anonymized usage events keyed to an internal account id (never your email). It is cookieless (local storage, not a tracking cookie), session replay is off, any sign-in token in a page address is stripped before it is recorded, and no household content is collected.
Location
United States.

Meta Platforms: Facebook Pixel

Meta Platforms, Inc.
facebook.com/privacy/policy
Purpose
Marketing measurement on the public marketing site, so we can understand how people find NestBoard.
Data shared
Standard page-view events, plus a single signup event when someone joins the waitlist (no personal details attached), fired on the public pages only. It never sends your email address or anything from your household, and the pixel never runs inside the app.
Location
United States and global Meta infrastructure.
When
Only engaged on the public marketing pages, never inside the logged-in app.

Pinterest Tag

Pinterest, Inc.
policy.pinterest.com/privacy-policy
Purpose
Marketing measurement on the public marketing site, so we can understand how people find NestBoard. Standard page-view events only.
Data shared
Standard page-view events fired on the public pages only. It never sends your email address or anything from your household, and the tag never runs inside the app.
Location
United States and global Pinterest infrastructure.
When
Only engaged on the public marketing pages, never inside the logged-in app.

Questions about a specific subprocessor?

Email privacy@mynestboard.com. We answer within one business day.

Start your household See features