EveryNest

Privacy Policy

Version 1.0 · Effective 10 August 2026

At a glance

This is the short version. The full detail is below — please read it.


Who we are and how to contact us

EveryNest is operated by:

Pivotal Finance S.à r.l.-S 32 rue Buurg, 5425 Gostingen, Luxembourg Luxembourg trade and companies register: B289140

For the purposes of the EU General Data Protection Regulation (GDPR), we are the data controller for personal data processed through the EveryNest app and website.

You can reach us about anything in this policy at:

We are not currently required to appoint a designated Data Protection Officer under GDPR Article 37, based on our current scale and the nature of our processing. We keep this position under regular review and will appoint a DPO if our processing scale or risk profile changes.


What this policy covers

This policy applies to personal data we collect when you:

It does not cover third-party services you may use alongside EveryNest (for example, your own email provider or device operating system). Those services have their own privacy policies.


Where we offer EveryNest

EveryNest is offered to users located in the European Economic Area (EEA) and the United Kingdom. This Privacy Policy is drafted for that geographic scope. If you are not located in the EEA or the UK, EveryNest is not currently offered to you, and you should not create an account.

For users in the EEA, we process personal data under the EU General Data Protection Regulation (EU GDPR) and applicable national data protection laws. For users in the United Kingdom, we process personal data under the UK GDPR and the Data Protection Act 2018. Where this policy refers to "GDPR" without qualification, it means whichever regulation applies to you.

Because Pivotal Finance S.à r.l.-S is established in Luxembourg but not in the United Kingdom, we have appointed a UK Article 27 representative to act as our contact point for UK data subjects and the UK Information Commissioner's Office. See §8A below.


The accounts in EveryNest and what we collect

EveryNest is designed for whole families. There are three types of account, and each one collects different information.

Parent accounts

A Parent is an adult (aged 18 or older) who administers a household. A household may have more than one Parent — the founding Parent who creates the household, and any additional adult invited by an existing Parent to co-administer. We collect the same data from every Parent regardless of whether they founded the household or were invited into it:

Household Owner. One Parent in each household — the Parent who first created it — is designated as the Household Owner. Household Owner is not a separate account tier; it is an attribute of one specific Parent's account. The Household Owner holds three controls that other Parents in the household do not:

Any Parent — Household Owner or not — can carry out every other function in the app, including adding or removing minor members subject to the parental consent process described in §7.

Teen accounts

A Teen account is created when a Parent invites a teenager (typically aged 13–17) into the household. The Parent must record their explicit consent at the moment they generate the invite (see §7 below). We collect:

We do not collect a teen's phone number, address, photo, geolocation, biometric data, or contacts.

Child accounts

A Child account is for younger children. The Parent generates a one-time pairing code on their own device, and the child enters it on the device they will use. We collect:

We do not collect from a child: email address, password, phone number, real name (unless the parent puts it in the display name), address, photo, geolocation, biometric data, contacts, or any contact details. A child cannot directly contact us; their parent does so on their behalf.

The pairing code itself expires after 30 minutes and is deleted from our systems once used or expired.

Source of the data and categories we do not collect

We collect personal data directly from you at the point you create an account or use the app. We do not receive data about you from data brokers, marketing networks, or any third party. The only exception is the limited subscription-status information we receive from Apple and Google when you start, change, or cancel a subscription — they tell us "this user has an active subscription," not your card number or bank details.

We do not process special category data as defined by GDPR Article 9: we do not collect data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, health data, or data concerning sex life or sexual orientation. The EveryNest service is not designed to collect such data and we ask you not to volunteer it in free-text fields (such as task descriptions or display names).

Provision of your data: contractual basis

Where data is required to operate EveryNest (your email, password, household details), providing it is a contractual requirement — the service cannot function without it. If you decline to provide it, we cannot create or maintain your account. Where data is optional (such as ticking the product-updates box, or completing a free-text field), the consequence of not providing it is only that the relevant optional feature is unavailable.


Why we use your data (purposes and lawful bases)

Under GDPR Articles 6 and 9, we must have a lawful basis for each thing we do with your data. Here is a complete list.

What we use it for Whose data Lawful basis
Creating and operating your account Parent Performance of a contract with you (Art. 6(1)(b))
Creating and operating Teen and Child accounts in your household Teen, Child Performance of the household-service contract entered into by the Parent for the benefit of the family members (Art. 6(1)(b)); parental consent under Art. 8 GDPR operates as the safeguard authorising the inclusion of the minor in that contract
Delivering the core features (tasks, calendar, lists, rewards) All members Performance of the household-service contract (Art. 6(1)(b)) for Parent and minor beneficiaries; legitimate interests in delivering the family service as expected (Art. 6(1)(f)) for incidental processing not strictly contractual
Sending essential service emails (password reset, account notifications, security alerts) Parent, Teen Performance of a contract (Art. 6(1)(b))
Sending optional product updates and feedback requests Parent only, and only if they have opted in Consent (Art. 6(1)(a)) — you can withdraw at any time
Publishing your first name on the public OG Nester page (optional, opt-in only, adult subscribers only) Household Owner only, and only if they have opted in Consent (Art. 6(1)(a)) — you can withdraw at any time
Keeping the service secure (preventing fraud, abuse, unauthorised access) All Legitimate interests (Art. 6(1)(f))
Keeping basic error logs to diagnose problems All Legitimate interests (Art. 6(1)(f))
Meeting our legal obligations (tax, accounting, responding to lawful requests from authorities) All Legal obligation (Art. 6(1)(c))

Note on parental consent and Article 8. Article 8 GDPR is not itself a lawful basis for processing. It is a condition that protects children when information society services are offered directly to them. EveryNest does not offer its service directly to children — children participate in EveryNest as beneficiaries of a household-service contract entered into by their Parent. We nevertheless capture explicit parental consent before creating any minor account, both because Article 8 applies wherever consent is the basis for any processing element, and because parental authorisation is the right safeguard for a service of this kind. Parental consent therefore functions as authorisation, age verification, and safeguarding measure — not as the sole legal basis for the underlying processing.

We do not use your data for any of the following, ever:

The OG Nester public listing (opt-in only)

If you are among the first 500 paying subscribers, your household qualifies as an "OG Nester." As part of that, you may choose to have your first name listed on a public OG Nester page on the EveryNest website. This is entirely optional:

Children specifically

We treat the UK Age-Appropriate Design Code as a reference for best practice and we apply the Irish Data Protection Commission's Fundamentals for a Child-Oriented Approach to Data Processing. The following standards from those sources guide how we handle minors using EveryNest:


The points feature

EveryNest includes a points feature that parents can use to reward family members for completing tasks. Points are an in-app scoring feature only. They have no monetary value, cannot be exchanged for cash or anything outside the app, cannot be transferred between households, and can only be redeemed for rewards your own family configures inside the app.

Records of points granted, earned, and redeemed are stored as part of your household's data and follow the same retention rules as the rest of your activity (§10).


Parental consent for Teen and Child accounts

Where information society services are offered directly to a child and rely on consent as the lawful basis for processing, GDPR Article 8 requires that consent to be given or authorised by a person with parental responsibility. The digital age of consent varies by country across the European Economic Area and the United Kingdom, from 13 to 16.

Regardless of whether Article 8 would require parental authorisation in every circumstance, EveryNest requires explicit parental authorisation before any Teen or Child account is created. The primary lawful basis for processing a minor's data is the performance of the household-service contract (see §5), and parental consent operates as the safeguard for that processing. Parental authorisation is required for every minor account regardless of the child's age or country, and regardless of whether local law would permit a child of that age to consent independently.

The consent is captured in a dedicated screen at the moment the Parent generates an invite or pairing code, and is stored as a record showing:

A Parent can withdraw their consent at any time by deleting the Teen or Child account from Settings → Family Members. Subject to any overriding legal or security obligations that require us to retain limited records (for example, accounting records of subscriptions paid, security logs, or evidence of a previously-given consent), withdrawal results in immediate removal of the minor's member record. Related activity data — such as tasks the minor completed, points earned within the household ledger, calendar events the minor created, or shopping list items added — remains associated with the household as part of its shared history. A Parent can request full deletion of any specific activity data by contacting hello@everynest.app.

A Parent declaring that they are a parent or legal guardian of the child is responsible for the truth of that declaration. EveryNest does not verify parental relationships beyond this declaration. We consider this approach proportionate given the low-risk nature of the service: there are no open social features, no advertising, no geolocation processing, no public sharing, no direct contact between unrelated users, and no profiling of any user. The data we collect from minors is the minimum needed to deliver a family-shared service, and remains visible only within the household. This is consistent with the proportionality principle recommended by the European Data Protection Board and by national data protection authorities for low-risk services where children participate as part of a family unit.

Full digital-age-of-consent table by country in the European Economic Area and the United Kingdom:

Age of digital consent Countries
13 (lowest in scope) Belgium, Denmark, Estonia, Finland, Latvia, Malta, Norway, Portugal, Sweden, United Kingdom
14 Austria, Bulgaria, Cyprus, Italy, Lithuania, Spain
15 Czech Republic, France, Greece, Slovenia
16 (highest) Croatia, Germany, Hungary, Iceland, Ireland, Liechtenstein, Luxembourg, Netherlands, Poland, Romania, Slovakia

Where a country's setting has changed recently, we apply the most stringent current requirement. Regardless of the country-specific setting, EveryNest requires parental authorisation for every minor account.


What members of your household can see

EveryNest is built around the household. Members of the same household see each other's activity in the app; members of different households cannot see anything about each other. We want to be explicit about what household members can see, particularly for teenagers.

What everyone in the household can see

What the Parent can see that others cannot

What the Household Owner can see and do that other Parents cannot

What a Teen can see

What a Child can see

What no household member can see

A note for teenagers

If you are a Teen using EveryNest, your Parent (the household administrator) can see what you do in the app — tasks you complete, calendar entries you create, points you earn. We want you to know this clearly. If you have concerns about something the Parent in your household can see about you, you can raise them with us directly at hello@everynest.app and we will assess them in line with your rights under data protection law (see §11 and §11A).


Who we share your data with

We share data with a small number of trusted service providers who help us run EveryNest. Each one is bound by a written data processing agreement under GDPR Article 28. They can only use the data to provide the service to us — they cannot use it for their own purposes.

Provider What they do Where data is processed
Supabase Database, authentication EU region
Vercel Web and app hosting EU edge network (primary)
OpenXchange (via smtp.openxchange.eu) Transactional email delivery (account emails, password resets, subscription notifications) Germany
Google Cloud Pub/Sub Real-time notification transport used to receive subscription-status updates from Google Play Billing Google Ireland Limited (EU)
Google Play (Google Ireland Limited) Android app distribution, merchant of record for subscription purchases on Android EU + United States
Sentry Error monitoring; configuration strips personal data from event reports before transmission EU (Frankfurt) region
Apple (Apple Distribution International Ltd., Ireland) — Phase 1.something onwards, when iOS launches iOS app distribution, merchant of record for subscription purchases on iOS EU + United States

We do not share your data with:

We may share data without your consent only when legally required: for example, in response to a valid court order or law enforcement request. We will only disclose what is strictly required, and we will tell you about it unless legally prevented from doing so.

We will not share children's data with any party other than the service providers above. We do not respond to advertising-related requests of any kind.


UK representative

Because Pivotal Finance S.à r.l.-S is established in the European Union and not in the United Kingdom, and because we offer EveryNest to users in the United Kingdom, UK GDPR Article 27 requires us to designate a UK-based representative to act as our contact point for UK data subjects and the UK Information Commissioner's Office (ICO).

Our UK representative is:

Prighter Ltd 20 Mortlake, Mortlake High Street London SW14 8JN United Kingdom

Acting as representative in the United Kingdom in accordance with Article 27 UK GDPR.

You can contact the UK representative directly on any matter relating to how EveryNest processes personal data of users in the United Kingdom via app.prighter.com. You can equally contact us directly at hello@everynest.app; you are not required to route through the UK representative if you prefer to contact us.

Designating a UK representative does not limit our own responsibilities or your rights under UK GDPR. It provides you and the ICO with an additional UK-based point of contact.


International transfers

Most of your data is processed within the European Economic Area (EEA). Specifically: Supabase processes EveryNest data in its EU region, and Vercel routes EveryNest traffic primarily through its EU edge network. Sentry processes error reports in the European Union (Frankfurt region).

Some processing necessarily occurs outside the EEA. The principal transfers are:

For each transfer, we rely on one or more of the following safeguards approved under GDPR Chapter V:

You can request a copy of the safeguards in place for any specific transfer by emailing us at hello@everynest.app.

We monitor legal developments affecting international transfer mechanisms — for example, future challenges to the EU-US Data Privacy Framework — and will implement alternative safeguards if any of the mechanisms we rely on cease to be valid.


How long we keep your data

We keep data only as long as we need it. Our retention schedule is:

Data Retention
Active account data (Parent, Teen, Child) For as long as the household's subscription is active
Account data after subscription ends (whether by cancellation, non-conversion at end of trial, or non-recovery of a failed payment) Preserved for 12 months from your last active session. If you resubscribe within that window, all your data is restored and you continue where you left off. If you do not resubscribe, your account and all household data are scheduled for deletion at the end of the 12-month window and are removed through our regular data-lifecycle review, normally within 30 days but no later than the end of the following calendar month.
A Teen or Child member removed by the Parent from Settings → Family Members The member record itself is removed immediately. Activity the member contributed to the household (tasks they completed, points earned within the household ledger, calendar events they created, shopping list items they added) remains associated with the household as part of its shared history. A Parent can request full deletion of specific activity data by contacting hello@everynest.app.
Pairing codes for child accounts Deleted once used, or after 30 minutes if unused
Parental consent records Kept for as long as the related Teen/Child account exists, plus 6 years after deletion. Retained solely for legal defence and compliance purposes (evidence of consent given and lawful basis for the processing that occurred). Once the linked minor member is deleted, the consent record's reference to that specific member is set to null; the record itself is preserved, and the linkage back to the specific minor can be reconstructed from the surrounding evidence (payment records, family contact) if needed.
Subscription event records held in EveryNest's own systems (billing webhook audit trail) Retained for the duration of the household's active period plus the 12-month post-subscription window, then reviewed for deletion as part of our regular data-lifecycle review. Retention specifics may be refined as part of post-launch operational work.
Transactional email log (records of service emails sent to you, such as password resets and subscription confirmations) Retained for the duration of the household's active period plus the 12-month post-subscription window, then reviewed for deletion as part of our regular data-lifecycle review. Retention specifics may be refined as part of post-launch operational work.
Subscription and payment records held by Google Play (and Apple once iOS launches, subject to their retention policies as merchants of record) 10 years from the date of payment for our own accounting reference, as required by Luxembourg accounting law. We do not hold your payment card or bank details.
Customer support emails 2 years from last contact
Product-updates and feedback opt-in records Until you withdraw consent, plus a short suppression record after withdrawal
OG Nester public listing opt-in records Until you withdraw consent, plus a short record of the withdrawal so we can honour it consistently
Server and security logs Ephemeral; hosted on Vercel with standard platform retention (typically up to 90 days)
Error monitoring data (Sentry) 30 days, then automatically deleted
Anonymised, aggregate usage statistics Indefinitely (these contain no personal data)

What happens at each stage of the 12-month post-subscription window

We do not send scheduled reminder emails during the 12-month window. If you would like to resubscribe or exercise a right, please act at a time that works for you; we will respond promptly.

When data is deleted, it is removed from our active systems within the regular data-lifecycle review cycle. Encrypted backups are rotated on a rolling basis and any deleted data is fully purged from backups within a further 60 days.

Some retention windows and lifecycle mechanics are set to be refined as part of our post-launch operational work. Where a specific retention window in the table above is described as "reviewed for deletion as part of our regular data-lifecycle review," this reflects that automation for the specific data type is not yet in place; the operational purge is currently manual and performed on a periodic basis. This has no effect on your rights — you can request deletion of your own data at any time, and we will action requests within the one-month statutory window.


Your rights

Under GDPR, you have a set of rights over your personal data. You can exercise all of them by emailing hello@everynest.app.

For Children and Teens: A parent or legal guardian may normally exercise these rights on behalf of a minor in their household. However, where applicable law recognises that a minor is capable of exercising their own rights — for example, where a teenager has reached the digital age of consent in their country, or where they have independent privacy interests in particular data — we may assess a request in light of the minor's age, maturity, and best interests, and we may seek to balance the minor's wishes against the Parent's request. From within the app (Settings → Family → tap a member), a Parent can export or delete any Teen or Child account in their household; a Teen who has reached the digital age of consent in their country can also exercise these rights themselves by contacting us directly at hello@everynest.app.

If you are unhappy

We hope you'll tell us first so we can fix things, but you also have the right to complain to a data protection authority. You can complain to the authority in your country of habitual residence, the country where you work, or the country where any alleged infringement of your rights took place. The relevant authorities for our primary user countries are:

A note on household-level deletions

The right to delete your own personal data (Article 17 GDPR) is exercisable by any account holder. The deletion of an entire household — which removes all members' data, including other Parents, Teens, and Children — is a separate action, and only the Household Owner (see §4.1) can trigger it. If you are a Parent in a household but not the Household Owner, and you wish to leave, you can delete only your own individual account; the household continues without you. If the Household Owner wishes to hand over the role rather than delete the household, they can transfer Household Owner status to another Parent in the household from Settings.

A note on rights during the 12-month post-subscription retention window

During the 12 months when your data is retained after a subscription ends (see §10), you cannot sign in to EveryNest. You can still exercise all of the rights above by emailing us at hello@everynest.app. We will respond within one month as required by GDPR Article 12(3).


Security

We take the security of personal data seriously and apply technical and organisational measures appropriate to the risks, in particular the risks of processing children's data. Our measures include:

Technical measures: - All passwords hashed using bcrypt or equivalent algorithms; never stored in plain text - All data in transit encrypted using TLS 1.2 or above - All data at rest encrypted on our database infrastructure (Supabase) - Row-level security policies enforced at the database layer to isolate household data - Multi-factor authentication available on Parent accounts - Server-side validation of every privileged action; no client-trusted writes to consent or audit records - Error monitoring configured to strip personal data from event reports before transmission - Pairing codes for child accounts that expire within 30 minutes and are deleted after use - We do not store payment card details; these are handled exclusively by Apple App Store and Google Play

Organisational measures: - Access to production data restricted, logged, and reviewed - Written data processing agreements with every sub-processor under GDPR Article 28 - An internal record of processing activities is maintained under GDPR Article 30 - We conduct and maintain a Data Protection Impact Assessment under GDPR Article 35 for processing operations involving children's data, and refresh it when material changes to those operations occur - Reviews of our security posture conducted at least annually and after any material change to the service

If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours under GDPR Article 33 and, where the risk is high, will tell you directly under Article 34 without undue delay.


Cookies and similar technologies

The EveryNest app and website use a small number of cookies and local storage items, all of which are strictly necessary to make the service work (for example, to keep you signed in). We do not use advertising cookies, social plugins, or third-party tracking cookies.

For more detail, see our Cookie Policy (linked from the website footer).


Product updates and feedback requests

We send two kinds of email.

Transactional emails — for example, password resets, account notifications, security alerts, and notices when our policies change — go to everyone with an account. They are necessary to operate the service, so we do not ask for separate consent. You can't opt out of these without closing your account.

Product updates and feedback requests are optional. If you tick the relevant box at sign-up (or turn the setting on later in Settings), we'll occasionally email you about new features, EveryNest news, and short feedback requests where we ask what you'd find useful. You can change your preference at any time in Settings, or by using the unsubscribe link at the bottom of any such email.

We do not send product updates or feedback requests to Teen or Child accounts.


Automated decision-making and profiling

We do not carry out any automated decision-making producing legal effects or similarly significantly affecting you within the meaning of GDPR Article 22. We do not profile users to predict behaviour. We do not use algorithmic recommendation, targeting, or ranking systems on minor accounts. If we ever introduce automated decision-making with legal or similarly significant effects, we will update this policy, provide meaningful information about the logic involved, and obtain a fresh lawful basis where required.


Changes to this policy

If we make material changes to this policy, we will notify all Parent users at least 30 days in advance, by email and through a notice in the app. We will keep previous versions of this policy available so you can see what has changed.

The current version is: v1.0, effective 10 August 2026. Subsequent numbered versions (v1.1, v1.2, ...) will reflect material updates after this version.


About this policy

This policy is intended to comply with: