At a glance
This is the short version. The full detail is below — please read it.
- Who we are. EveryNest is a family organisation app run by Pivotal Finance S.à r.l.-S, a company registered in Luxembourg. We are the data controller for your information.
- Where we offer it. European Economic Area (EEA) and the United Kingdom.
- What we collect. For Parents: email, password, and household details. For Teens: email, password, and a display name. For Children: a display name only — no email, no password, no contact details.
- Why we collect it. To run your family's account, deliver the features you use, take payment for subscriptions, keep the service secure, and meet our legal obligations.
- Who sees it. Only members of your own household. We don't sell data. We don't run ads. We don't share data with anyone except a small number of trusted service providers needed to make the app work (listed below).
- Household Owner. One of the Parents in a household — the one who created it — is the Household Owner. They hold three additional controls: cancelling the subscription, transferring the household to another Parent, and deleting the whole household.
- Children. A Parent must explicitly consent before any Child or Teen account is created. A Parent can export or delete a Child or Teen's data at any time from Settings. We do not show advertising to anyone, and especially not to children. We do not profile children or send re-engagement notifications.
- If you cancel. Your data is preserved for 12 months so you can come back and pick up where you left off. If you do not return within 12 months, we delete your account and its data.
- Your rights. You can access, correct, export, or delete your data. You can withdraw consent. You can complain to a data protection authority (see §11).
- How to reach us. hello@everynest.app
Who we are and how to contact us
EveryNest is operated by:
Pivotal Finance S.à r.l.-S 32 rue Buurg, 5425 Gostingen, Luxembourg Luxembourg trade and companies register: B289140
For the purposes of the EU General Data Protection Regulation (GDPR), we are the data controller for personal data processed through the EveryNest app and website.
You can reach us about anything in this policy at:
- Privacy email: hello@everynest.app
- Postal: 32 rue Buurg, 5425 Gostingen, Luxembourg
- Data Protection Contact: Lola Kaneva (responsible for handling privacy enquiries and rights requests)
We are not currently required to appoint a designated Data Protection Officer under GDPR Article 37, based on our current scale and the nature of our processing. We keep this position under regular review and will appoint a DPO if our processing scale or risk profile changes.
What this policy covers
This policy applies to personal data we collect when you:
- Create an account or use the EveryNest app on iOS, Android, or the web
- Visit
everynest.appor related websites we operate - Join our waitlist or contact us by email
- Subscribe to EveryNest
It does not cover third-party services you may use alongside EveryNest (for example, your own email provider or device operating system). Those services have their own privacy policies.
Where we offer EveryNest
EveryNest is offered to users located in the European Economic Area (EEA) and the United Kingdom. This Privacy Policy is drafted for that geographic scope. If you are not located in the EEA or the UK, EveryNest is not currently offered to you, and you should not create an account.
For users in the EEA, we process personal data under the EU General Data Protection Regulation (EU GDPR) and applicable national data protection laws. For users in the United Kingdom, we process personal data under the UK GDPR and the Data Protection Act 2018. Where this policy refers to "GDPR" without qualification, it means whichever regulation applies to you.
Because Pivotal Finance S.à r.l.-S is established in Luxembourg but not in the United Kingdom, we have appointed a UK Article 27 representative to act as our contact point for UK data subjects and the UK Information Commissioner's Office. See §8A below.
The accounts in EveryNest and what we collect
EveryNest is designed for whole families. There are three types of account, and each one collects different information.
Parent accounts
A Parent is an adult (aged 18 or older) who administers a household. A household may have more than one Parent — the founding Parent who creates the household, and any additional adult invited by an existing Parent to co-administer. We collect the same data from every Parent regardless of whether they founded the household or were invited into it:
- Email address and password (you provide these at sign-up; the password is hashed and never stored in plain text)
- Display name (you choose this; it can be a first name or nickname)
- Household name (you choose this; e.g. "The Cool Cats")
- Subscription status (active, cancelled, expired) — payments themselves are processed by Google (Google Play Billing on Android) and, once iOS launches in a subsequent phase, by Apple (Apple In-App Purchase). We receive confirmation that a subscription is active or has ended; we do not see or hold your payment card or bank details.
- Things you create in the app — tasks, calendar events, shopping lists, rewards, points granted or redeemed
- Technical information — your IP address, and basic technical context (such as browser type) received in error reports to help us diagnose problems and keep the service secure. We do not collect device identifiers, app version fingerprints, or persistent tracking identifiers.
- Communications — if you email us or use a feedback form, we keep what you sent so we can reply
Household Owner. One Parent in each household — the Parent who first created it — is designated as the Household Owner. Household Owner is not a separate account tier; it is an attribute of one specific Parent's account. The Household Owner holds three controls that other Parents in the household do not:
- Cancelling the household's EveryNest subscription
- Transferring the Household Owner role to another Parent in the household
- Deleting the whole household (which deletes all members' data)
Any Parent — Household Owner or not — can carry out every other function in the app, including adding or removing minor members subject to the parental consent process described in §7.
Teen accounts
A Teen account is created when a Parent invites a teenager (typically aged 13–17) into the household. The Parent must record their explicit consent at the moment they generate the invite (see §7 below). We collect:
- Email address and password (the teen sets these when accepting the invite; password is hashed)
- Display name (chosen by the parent or the teen)
- Approximate age band (recorded by the parent at invite: Teenager 13+ — the only Teen age band captured)
- Things they do in the app — tasks they complete, points they earn or redeem, calendar events they create
- Technical information — IP address, and basic technical context received in error reports (such as browser type)
We do not collect a teen's phone number, address, photo, geolocation, biometric data, or contacts.
Child accounts
A Child account is for younger children. The Parent generates a one-time pairing code on their own device, and the child enters it on the device they will use. We collect:
- Display name (chosen by the parent). Even where the display name is a nickname rather than a real name (for example, "Little Bear"), it is personal data under GDPR because it identifies a specific child within a specific household. We protect it accordingly.
- Approximate age band (recorded by the parent at the moment the pairing code is generated: Child 7–12 — the only Child age band captured)
- Things they do in the app — tasks they complete, points they earn or redeem
- Technical information — IP address, and basic technical context received in error reports (such as browser type)
We do not collect from a child: email address, password, phone number, real name (unless the parent puts it in the display name), address, photo, geolocation, biometric data, contacts, or any contact details. A child cannot directly contact us; their parent does so on their behalf.
The pairing code itself expires after 30 minutes and is deleted from our systems once used or expired.
Source of the data and categories we do not collect
We collect personal data directly from you at the point you create an account or use the app. We do not receive data about you from data brokers, marketing networks, or any third party. The only exception is the limited subscription-status information we receive from Apple and Google when you start, change, or cancel a subscription — they tell us "this user has an active subscription," not your card number or bank details.
We do not process special category data as defined by GDPR Article 9: we do not collect data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, health data, or data concerning sex life or sexual orientation. The EveryNest service is not designed to collect such data and we ask you not to volunteer it in free-text fields (such as task descriptions or display names).
Provision of your data: contractual basis
Where data is required to operate EveryNest (your email, password, household details), providing it is a contractual requirement — the service cannot function without it. If you decline to provide it, we cannot create or maintain your account. Where data is optional (such as ticking the product-updates box, or completing a free-text field), the consequence of not providing it is only that the relevant optional feature is unavailable.
Why we use your data (purposes and lawful bases)
Under GDPR Articles 6 and 9, we must have a lawful basis for each thing we do with your data. Here is a complete list.
| What we use it for | Whose data | Lawful basis |
|---|---|---|
| Creating and operating your account | Parent | Performance of a contract with you (Art. 6(1)(b)) |
| Creating and operating Teen and Child accounts in your household | Teen, Child | Performance of the household-service contract entered into by the Parent for the benefit of the family members (Art. 6(1)(b)); parental consent under Art. 8 GDPR operates as the safeguard authorising the inclusion of the minor in that contract |
| Delivering the core features (tasks, calendar, lists, rewards) | All members | Performance of the household-service contract (Art. 6(1)(b)) for Parent and minor beneficiaries; legitimate interests in delivering the family service as expected (Art. 6(1)(f)) for incidental processing not strictly contractual |
| Sending essential service emails (password reset, account notifications, security alerts) | Parent, Teen | Performance of a contract (Art. 6(1)(b)) |
| Sending optional product updates and feedback requests | Parent only, and only if they have opted in | Consent (Art. 6(1)(a)) — you can withdraw at any time |
| Publishing your first name on the public OG Nester page (optional, opt-in only, adult subscribers only) | Household Owner only, and only if they have opted in | Consent (Art. 6(1)(a)) — you can withdraw at any time |
| Keeping the service secure (preventing fraud, abuse, unauthorised access) | All | Legitimate interests (Art. 6(1)(f)) |
| Keeping basic error logs to diagnose problems | All | Legitimate interests (Art. 6(1)(f)) |
| Meeting our legal obligations (tax, accounting, responding to lawful requests from authorities) | All | Legal obligation (Art. 6(1)(c)) |
Note on parental consent and Article 8. Article 8 GDPR is not itself a lawful basis for processing. It is a condition that protects children when information society services are offered directly to them. EveryNest does not offer its service directly to children — children participate in EveryNest as beneficiaries of a household-service contract entered into by their Parent. We nevertheless capture explicit parental consent before creating any minor account, both because Article 8 applies wherever consent is the basis for any processing element, and because parental authorisation is the right safeguard for a service of this kind. Parental consent therefore functions as authorisation, age verification, and safeguarding measure — not as the sole legal basis for the underlying processing.
We do not use your data for any of the following, ever:
- Behavioural advertising or ad profiling
- Selling or renting data to third parties
- Building profiles of users to predict behaviour or target marketing
- Tracking across other websites or apps
- Training third-party artificial intelligence models
The OG Nester public listing (opt-in only)
If you are among the first 500 paying subscribers, your household qualifies as an "OG Nester." As part of that, you may choose to have your first name listed on a public OG Nester page on the EveryNest website. This is entirely optional:
- The public listing is off by default. It only becomes active if the Household Owner explicitly opts in from Settings → Subscription.
- Only your first name is published. No other information about you, your household, or any family member is included on the public page.
- You can withdraw at any time from the same Settings screen. Withdrawal removes your name from the public page within a reasonable time (normally on the next scheduled update of the page, which happens at least weekly).
- Only the Household Owner can opt in for the household's listing. Minor members are excluded from the public listing under all circumstances; no first name of any Teen or Child appears on the public page at any time.
Children specifically
We treat the UK Age-Appropriate Design Code as a reference for best practice and we apply the Irish Data Protection Commission's Fundamentals for a Child-Oriented Approach to Data Processing. The following standards from those sources guide how we handle minors using EveryNest:
- Best interests of the child are a primary consideration in every product decision (UK Children's Code Standard 1; Irish DPC Fundamental 1). Before introducing any feature that affects minors, we consider whether the feature is necessary, proportionate, age-appropriate, and aligned with the best interests of the children who will be affected. The outcome of that consideration is recorded internally.
- Data minimisation: we collect only the minimum data needed for the feature to work (Standard 8; Fundamental 10).
- High-privacy defaults: all settings affecting privacy default to the most private state for minor accounts (Standard 7).
- No detrimental use of personal data (Standard 5).
- No profiling of children (Standard 12; Fundamental 14).
- No "nudge" techniques, streaks, or re-engagement notifications designed to extend a minor's use of the app (Standard 13).
- No behavioural advertising to anyone — and especially not to children (Standard 12).
- No geolocation processing for any minor account (Standard 10).
- Connected toys, devices, and third-party integrations involving minors are not part of EveryNest's design (Standard 14).
- Parental controls are integral to the product — every minor account is created, configured, and removable by their Parent (Standard 11).
- We do not share children's data outside the household, except with the limited service providers listed in §8 who are needed to make the app run.
The points feature
EveryNest includes a points feature that parents can use to reward family members for completing tasks. Points are an in-app scoring feature only. They have no monetary value, cannot be exchanged for cash or anything outside the app, cannot be transferred between households, and can only be redeemed for rewards your own family configures inside the app.
Records of points granted, earned, and redeemed are stored as part of your household's data and follow the same retention rules as the rest of your activity (§10).
Parental consent for Teen and Child accounts
Where information society services are offered directly to a child and rely on consent as the lawful basis for processing, GDPR Article 8 requires that consent to be given or authorised by a person with parental responsibility. The digital age of consent varies by country across the European Economic Area and the United Kingdom, from 13 to 16.
Regardless of whether Article 8 would require parental authorisation in every circumstance, EveryNest requires explicit parental authorisation before any Teen or Child account is created. The primary lawful basis for processing a minor's data is the performance of the household-service contract (see §5), and parental consent operates as the safeguard for that processing. Parental authorisation is required for every minor account regardless of the child's age or country, and regardless of whether local law would permit a child of that age to consent independently.
The consent is captured in a dedicated screen at the moment the Parent generates an invite or pairing code, and is stored as a record showing:
- Which Parent gave consent
- Which Teen or Child member it applies to
- The age band declared by the Parent (Child 7–12 or Teenager 13+)
- The version of this Privacy Policy and of the Parental Consent Notice they reviewed
- The date and time of consent
A Parent can withdraw their consent at any time by deleting the Teen or Child account from Settings → Family Members. Subject to any overriding legal or security obligations that require us to retain limited records (for example, accounting records of subscriptions paid, security logs, or evidence of a previously-given consent), withdrawal results in immediate removal of the minor's member record. Related activity data — such as tasks the minor completed, points earned within the household ledger, calendar events the minor created, or shopping list items added — remains associated with the household as part of its shared history. A Parent can request full deletion of any specific activity data by contacting hello@everynest.app.
A Parent declaring that they are a parent or legal guardian of the child is responsible for the truth of that declaration. EveryNest does not verify parental relationships beyond this declaration. We consider this approach proportionate given the low-risk nature of the service: there are no open social features, no advertising, no geolocation processing, no public sharing, no direct contact between unrelated users, and no profiling of any user. The data we collect from minors is the minimum needed to deliver a family-shared service, and remains visible only within the household. This is consistent with the proportionality principle recommended by the European Data Protection Board and by national data protection authorities for low-risk services where children participate as part of a family unit.
Full digital-age-of-consent table by country in the European Economic Area and the United Kingdom:
| Age of digital consent | Countries |
|---|---|
| 13 (lowest in scope) | Belgium, Denmark, Estonia, Finland, Latvia, Malta, Norway, Portugal, Sweden, United Kingdom |
| 14 | Austria, Bulgaria, Cyprus, Italy, Lithuania, Spain |
| 15 | Czech Republic, France, Greece, Slovenia |
| 16 (highest) | Croatia, Germany, Hungary, Iceland, Ireland, Liechtenstein, Luxembourg, Netherlands, Poland, Romania, Slovakia |
Where a country's setting has changed recently, we apply the most stringent current requirement. Regardless of the country-specific setting, EveryNest requires parental authorisation for every minor account.
What members of your household can see
EveryNest is built around the household. Members of the same household see each other's activity in the app; members of different households cannot see anything about each other. We want to be explicit about what household members can see, particularly for teenagers.
What everyone in the household can see
- The names and roles of all other household members
- The household calendar — events created by any member
- Shared shopping lists — items added by any member
- Tasks visible to that role — by default, tasks assigned to the member themselves, and tasks visible to the household
- Rewards the household has configured and points balances (depending on role)
What the Parent can see that others cannot
- All household activity by all members, including Teens and Children — tasks completed, points earned and redeemed, calendar entries, shopping items added
- The settings of every member's account — display name, role, age band
- The parental consent records they have given (each Parent can see their own consent records within their Data Export, downloaded from Settings → Your Data)
What the Household Owner can see and do that other Parents cannot
- Account and subscription information for the household (any Parent can see subscription status, but only the Household Owner can change it)
- The three Owner-exclusive controls: cancel the subscription, transfer the Household Owner role to another Parent, delete the whole household
What a Teen can see
- Their own activity in full
- The household calendar, shopping lists, and tasks visible to their role
- They cannot see the Parental consent records relating to them, but they can request a copy from the Parent or directly from EveryNest
What a Child can see
- Their own tasks, points, and rewards
- The household calendar and shopping lists where the Parent has chosen to share them
- Children see a simplified, child-appropriate view of the app
What no household member can see
- Email addresses or sign-in details of other household members (only the member themselves and EveryNest see these)
- Other households — every household is fully isolated
A note for teenagers
If you are a Teen using EveryNest, your Parent (the household administrator) can see what you do in the app — tasks you complete, calendar entries you create, points you earn. We want you to know this clearly. If you have concerns about something the Parent in your household can see about you, you can raise them with us directly at hello@everynest.app and we will assess them in line with your rights under data protection law (see §11 and §11A).
Who we share your data with
We share data with a small number of trusted service providers who help us run EveryNest. Each one is bound by a written data processing agreement under GDPR Article 28. They can only use the data to provide the service to us — they cannot use it for their own purposes.
| Provider | What they do | Where data is processed |
|---|---|---|
| Supabase | Database, authentication | EU region |
| Vercel | Web and app hosting | EU edge network (primary) |
| OpenXchange (via smtp.openxchange.eu) | Transactional email delivery (account emails, password resets, subscription notifications) | Germany |
| Google Cloud Pub/Sub | Real-time notification transport used to receive subscription-status updates from Google Play Billing | Google Ireland Limited (EU) |
| Google Play (Google Ireland Limited) | Android app distribution, merchant of record for subscription purchases on Android | EU + United States |
| Sentry | Error monitoring; configuration strips personal data from event reports before transmission | EU (Frankfurt) region |
| Apple (Apple Distribution International Ltd., Ireland) — Phase 1.something onwards, when iOS launches | iOS app distribution, merchant of record for subscription purchases on iOS | EU + United States |
We do not share your data with:
- Advertising networks
- Data brokers
- Social media platforms (we have no social login or share-to-social features)
- AI training services
We may share data without your consent only when legally required: for example, in response to a valid court order or law enforcement request. We will only disclose what is strictly required, and we will tell you about it unless legally prevented from doing so.
We will not share children's data with any party other than the service providers above. We do not respond to advertising-related requests of any kind.
UK representative
Because Pivotal Finance S.à r.l.-S is established in the European Union and not in the United Kingdom, and because we offer EveryNest to users in the United Kingdom, UK GDPR Article 27 requires us to designate a UK-based representative to act as our contact point for UK data subjects and the UK Information Commissioner's Office (ICO).
Our UK representative is:
Prighter Ltd 20 Mortlake, Mortlake High Street London SW14 8JN United Kingdom
Acting as representative in the United Kingdom in accordance with Article 27 UK GDPR.
You can contact the UK representative directly on any matter relating to how EveryNest processes personal data of users in the United Kingdom via app.prighter.com. You can equally contact us directly at hello@everynest.app; you are not required to route through the UK representative if you prefer to contact us.
Designating a UK representative does not limit our own responsibilities or your rights under UK GDPR. It provides you and the ICO with an additional UK-based point of contact.
International transfers
Most of your data is processed within the European Economic Area (EEA). Specifically: Supabase processes EveryNest data in its EU region, and Vercel routes EveryNest traffic primarily through its EU edge network. Sentry processes error reports in the European Union (Frankfurt region).
Some processing necessarily occurs outside the EEA. The principal transfers are:
- Apple and Google process in-app subscription purchases through their global infrastructure. Both companies are certified to the EU–US Data Privacy Framework, which the European Commission has confirmed provides adequate protection under GDPR Article 45 (Commission Implementing Decision (EU) 2023/1795 of 10 July 2023).
- Sentry is primarily EU-resident, but a limited volume of operational metadata may be routed through its US backbone. Sentry is certified to the EU–US Data Privacy Framework; we have additionally signed Sentry's standard Data Processing Agreement incorporating the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914 of 4 June 2021).
- Supabase operates additional infrastructure outside the EEA but our project is configured to use the EU region as the primary data location, and Supabase has signed the EU Standard Contractual Clauses with EveryNest.
For each transfer, we rely on one or more of the following safeguards approved under GDPR Chapter V:
- Adequacy decisions under Article 45 (notably the EU–US Data Privacy Framework)
- EU Standard Contractual Clauses under Article 46(2)(c)
- Supplementary measures under EDPB Recommendations 01/2020, including encryption in transit and at rest
You can request a copy of the safeguards in place for any specific transfer by emailing us at hello@everynest.app.
We monitor legal developments affecting international transfer mechanisms — for example, future challenges to the EU-US Data Privacy Framework — and will implement alternative safeguards if any of the mechanisms we rely on cease to be valid.
How long we keep your data
We keep data only as long as we need it. Our retention schedule is:
| Data | Retention |
|---|---|
| Active account data (Parent, Teen, Child) | For as long as the household's subscription is active |
| Account data after subscription ends (whether by cancellation, non-conversion at end of trial, or non-recovery of a failed payment) | Preserved for 12 months from your last active session. If you resubscribe within that window, all your data is restored and you continue where you left off. If you do not resubscribe, your account and all household data are scheduled for deletion at the end of the 12-month window and are removed through our regular data-lifecycle review, normally within 30 days but no later than the end of the following calendar month. |
| A Teen or Child member removed by the Parent from Settings → Family Members | The member record itself is removed immediately. Activity the member contributed to the household (tasks they completed, points earned within the household ledger, calendar events they created, shopping list items they added) remains associated with the household as part of its shared history. A Parent can request full deletion of specific activity data by contacting hello@everynest.app. |
| Pairing codes for child accounts | Deleted once used, or after 30 minutes if unused |
| Parental consent records | Kept for as long as the related Teen/Child account exists, plus 6 years after deletion. Retained solely for legal defence and compliance purposes (evidence of consent given and lawful basis for the processing that occurred). Once the linked minor member is deleted, the consent record's reference to that specific member is set to null; the record itself is preserved, and the linkage back to the specific minor can be reconstructed from the surrounding evidence (payment records, family contact) if needed. |
| Subscription event records held in EveryNest's own systems (billing webhook audit trail) | Retained for the duration of the household's active period plus the 12-month post-subscription window, then reviewed for deletion as part of our regular data-lifecycle review. Retention specifics may be refined as part of post-launch operational work. |
| Transactional email log (records of service emails sent to you, such as password resets and subscription confirmations) | Retained for the duration of the household's active period plus the 12-month post-subscription window, then reviewed for deletion as part of our regular data-lifecycle review. Retention specifics may be refined as part of post-launch operational work. |
| Subscription and payment records held by Google Play (and Apple once iOS launches, subject to their retention policies as merchants of record) | 10 years from the date of payment for our own accounting reference, as required by Luxembourg accounting law. We do not hold your payment card or bank details. |
| Customer support emails | 2 years from last contact |
| Product-updates and feedback opt-in records | Until you withdraw consent, plus a short suppression record after withdrawal |
| OG Nester public listing opt-in records | Until you withdraw consent, plus a short record of the withdrawal so we can honour it consistently |
| Server and security logs | Ephemeral; hosted on Vercel with standard platform retention (typically up to 90 days) |
| Error monitoring data (Sentry) | 30 days, then automatically deleted |
| Anonymised, aggregate usage statistics | Indefinitely (these contain no personal data) |
What happens at each stage of the 12-month post-subscription window
- When your subscription ends: we send you a confirmation email to the address on your account, letting you know your access has ended and your data is preserved for 12 months.
- During the 12 months: you cannot sign in to EveryNest. If you resubscribe through Google Play (or Apple, once iOS launches), your access is fully restored the moment payment is processed. To exercise any of your data subject rights during this window (see §11) — access, deletion, rectification, portability — please email us at hello@everynest.app. We treat these requests with the same one-month response commitment as any other rights request.
- When we delete at the end of the 12 months: we send you a purge-notification email confirming that your account and household data have been deleted. Records we are required by law to keep (for example, payment records under Luxembourg accounting law) remain retained per the schedule above.
We do not send scheduled reminder emails during the 12-month window. If you would like to resubscribe or exercise a right, please act at a time that works for you; we will respond promptly.
When data is deleted, it is removed from our active systems within the regular data-lifecycle review cycle. Encrypted backups are rotated on a rolling basis and any deleted data is fully purged from backups within a further 60 days.
Some retention windows and lifecycle mechanics are set to be refined as part of our post-launch operational work. Where a specific retention window in the table above is described as "reviewed for deletion as part of our regular data-lifecycle review," this reflects that automation for the specific data type is not yet in place; the operational purge is currently manual and performed on a periodic basis. This has no effect on your rights — you can request deletion of your own data at any time, and we will action requests within the one-month statutory window.
Your rights
Under GDPR, you have a set of rights over your personal data. You can exercise all of them by emailing hello@everynest.app.
- Right of access. You can ask for a copy of the personal data we hold about you. We will reply within one month.
- Right to rectification. You can ask us to correct anything that is inaccurate.
- Right to erasure ("right to be forgotten"). You can ask us to delete your data. We may need to keep some records for legal reasons (for example, payment records for accounting), and we will tell you which.
- Right to restrict processing. You can ask us to pause processing in certain circumstances.
- Right to data portability. You can ask for your data in a machine-readable format (we provide JSON export from Settings).
- Right to object. You can object to processing based on legitimate interests, including any direct marketing.
- Right to withdraw consent. Where we rely on consent, you can withdraw it at any time.
- Rights related to automated decision-making. We do not make automated decisions that have legal or similarly significant effects on you. If we ever do, we will tell you and explain your rights.
For Children and Teens: A parent or legal guardian may normally exercise these rights on behalf of a minor in their household. However, where applicable law recognises that a minor is capable of exercising their own rights — for example, where a teenager has reached the digital age of consent in their country, or where they have independent privacy interests in particular data — we may assess a request in light of the minor's age, maturity, and best interests, and we may seek to balance the minor's wishes against the Parent's request. From within the app (Settings → Family → tap a member), a Parent can export or delete any Teen or Child account in their household; a Teen who has reached the digital age of consent in their country can also exercise these rights themselves by contacting us directly at hello@everynest.app.
If you are unhappy
We hope you'll tell us first so we can fix things, but you also have the right to complain to a data protection authority. You can complain to the authority in your country of habitual residence, the country where you work, or the country where any alleged infringement of your rights took place. The relevant authorities for our primary user countries are:
- Luxembourg (our lead supervisory authority): Commission nationale pour la protection des données (CNPD) — cnpd.public.lu
- United Kingdom: Information Commissioner's Office (ICO) — ico.org.uk
- Ireland: Data Protection Commission (DPC) — dataprotection.ie
- Other EU/EEA countries: Your national data protection authority. A directory of EU/EEA authorities is maintained by the European Data Protection Board at edpb.europa.eu.
A note on household-level deletions
The right to delete your own personal data (Article 17 GDPR) is exercisable by any account holder. The deletion of an entire household — which removes all members' data, including other Parents, Teens, and Children — is a separate action, and only the Household Owner (see §4.1) can trigger it. If you are a Parent in a household but not the Household Owner, and you wish to leave, you can delete only your own individual account; the household continues without you. If the Household Owner wishes to hand over the role rather than delete the household, they can transfer Household Owner status to another Parent in the household from Settings.
A note on rights during the 12-month post-subscription retention window
During the 12 months when your data is retained after a subscription ends (see §10), you cannot sign in to EveryNest. You can still exercise all of the rights above by emailing us at hello@everynest.app. We will respond within one month as required by GDPR Article 12(3).
Security
We take the security of personal data seriously and apply technical and organisational measures appropriate to the risks, in particular the risks of processing children's data. Our measures include:
Technical measures: - All passwords hashed using bcrypt or equivalent algorithms; never stored in plain text - All data in transit encrypted using TLS 1.2 or above - All data at rest encrypted on our database infrastructure (Supabase) - Row-level security policies enforced at the database layer to isolate household data - Multi-factor authentication available on Parent accounts - Server-side validation of every privileged action; no client-trusted writes to consent or audit records - Error monitoring configured to strip personal data from event reports before transmission - Pairing codes for child accounts that expire within 30 minutes and are deleted after use - We do not store payment card details; these are handled exclusively by Apple App Store and Google Play
Organisational measures: - Access to production data restricted, logged, and reviewed - Written data processing agreements with every sub-processor under GDPR Article 28 - An internal record of processing activities is maintained under GDPR Article 30 - We conduct and maintain a Data Protection Impact Assessment under GDPR Article 35 for processing operations involving children's data, and refresh it when material changes to those operations occur - Reviews of our security posture conducted at least annually and after any material change to the service
If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours under GDPR Article 33 and, where the risk is high, will tell you directly under Article 34 without undue delay.
Cookies and similar technologies
The EveryNest app and website use a small number of cookies and local storage items, all of which are strictly necessary to make the service work (for example, to keep you signed in). We do not use advertising cookies, social plugins, or third-party tracking cookies.
For more detail, see our Cookie Policy (linked from the website footer).
Product updates and feedback requests
We send two kinds of email.
Transactional emails — for example, password resets, account notifications, security alerts, and notices when our policies change — go to everyone with an account. They are necessary to operate the service, so we do not ask for separate consent. You can't opt out of these without closing your account.
Product updates and feedback requests are optional. If you tick the relevant box at sign-up (or turn the setting on later in Settings), we'll occasionally email you about new features, EveryNest news, and short feedback requests where we ask what you'd find useful. You can change your preference at any time in Settings, or by using the unsubscribe link at the bottom of any such email.
We do not send product updates or feedback requests to Teen or Child accounts.
Automated decision-making and profiling
We do not carry out any automated decision-making producing legal effects or similarly significantly affecting you within the meaning of GDPR Article 22. We do not profile users to predict behaviour. We do not use algorithmic recommendation, targeting, or ranking systems on minor accounts. If we ever introduce automated decision-making with legal or similarly significant effects, we will update this policy, provide meaningful information about the logic involved, and obtain a fresh lawful basis where required.
Changes to this policy
If we make material changes to this policy, we will notify all Parent users at least 30 days in advance, by email and through a notice in the app. We will keep previous versions of this policy available so you can see what has changed.
The current version is: v1.0, effective 10 August 2026. Subsequent numbered versions (v1.1, v1.2, ...) will reflect material updates after this version.
About this policy
This policy is intended to comply with:
- EU General Data Protection Regulation (Regulation (EU) 2016/679)
- UK General Data Protection Regulation and Data Protection Act 2018
- ePrivacy Directive 2002/58/EC (as implemented in Luxembourg)
- Luxembourg Law of 1 August 2018 on the organisation of the National Commission for Data Protection and the general data protection framework
- Luxembourg Law of 30 May 2005 on electronic communications networks and services (as amended)
- Irish Data Protection Commission's Fundamentals for a Child-Oriented Approach to Data Processing
- EU Digital Services Act (Regulation (EU) 2022/2065), in particular Article 28 on protection of minors
- Apple App Store Review Guidelines (Section 5.1, Privacy) and Google Play Developer Policy (Personal and Sensitive Information; Families)
- UK Age-Appropriate Design Code (treated as a reference for best practice)