Nesty Privacy Policy
Effective date: 18 July 2026 Last updated: 21 August 2026
Nesty ("Nesty", "we", "us", or "our") is a baby and child tracking app for children ages 0–7, published by Eodin Studio. This Privacy Policy explains what information we collect, how we use it, who we share it with, and the choices and rights you have. It applies to the Nesty mobile app and related services (collectively, the "Service").
By using Nesty you agree to the practices described here. If you do not agree, please do not use the Service.
1. Who this policy is for — and a note about children
Nesty is designed for parents, guardians, and the caregivers they invite ("you"). Nesty is not directed to children and children do not create accounts or use the app. All account holders must be adults (18 or older, or the age of majority where you live).
The app is used to record information about a child (for example feeding, sleep, diaper, and growth entries). That child information is entered by you, the adult account holder, or by caregivers you have invited. When you create a child profile you confirm that you are the child's parent or legal guardian, or that you have that person's authorization to record the child's information.
Because a child's information is provided by an adult and is never collected directly from a child, we handle it under this policy. If you believe a child's data has been added to Nesty without proper authorization, contact us at official@eodin.app and we will help you remove it.
2. Information we collect
2.1 Information you provide
- Account information. When you sign in with Google or Apple through Firebase Authentication, we receive your email address and a unique account identifier, and optionally your display name. Your password is never handled by Nesty — sign-in is delegated to Google or Apple.
- Profile & preferences. Your display name and the family name you choose (both are shown to the caregivers in your family), your locale and unit preference (metric/imperial), your subscription state, and when you last opened the reminders list (so the "new" marker matches on every device you sign in to).
- Child profile information. The child's name (or nickname), date of birth, and sex (optional). Date of birth and sex are used only to compute age-appropriate features such as WHO growth percentiles and the starting point for sleep-prediction wake windows (which is then adjusted on your device using your own recent logs — see "How we use information").
- Care log information. The entries you and your caregivers record: feeding (breast durations, formula/combo volume, times), sleep (nap/night, start/end), diaper (type, optional color), and growth measurements (height, weight, date).
- Caregiver sharing. If you invite another caregiver, we process the invite and the link between that caregiver's account and your family — that is, every child profile you own. A caregiver you invite joins your family rather than a single child, so a child you add later is shared with them too.
- Reminder history. When Nesty sends a reminder about your child — a likely next sleep or feed, or an occasional nudge to add height and weight — we record that it was sent, which kind it was, and when it was due. This is the list you see under Reminders, and it is shared with your caregivers the same way your care logs are, so everyone caring for the child sees the same history. It never contains the child's name. We do not record whether a notification actually appeared on any particular phone — that follows each phone's own settings, which we do not collect. We do record when you last opened the reminders list (see "Profile & preferences" above), which is what keeps the "new" marker consistent across your devices; it is stored per person, so another caregiver opening the list does not change yours.
- Communications. If you contact us (for example by email), we receive what you send us.
2.2 Information collected automatically
- Usage & product analytics. We use the Eodin SDK and Firebase Analytics to understand how features are used (for example: a log was created, a paywall was shown, a prediction notification was sent). These analytics events are subject to a strict no-personal-information rule: they never contain a child's health entries, name, date of birth, or a caregiver's personal information. Events carry only non-identifying product signals (such as event type, source surface, how long an interaction took — for example, how many seconds passed between opening a log and saving it — your device platform, and, when you start a subscription, the plan you chose with its price and currency as reported by the app store). Analytics and crash reporting are on by default and you can turn them off at any time in Settings → Share usage & crash reports; turning them off stops all analytics and crash collection on your device.
- Device & diagnostic information. Standard technical data such as app version, device model, operating system, language, a per-installation analytics identifier (a random ID our analytics providers assign to this installation of the app — not to you, and never joined by us to your Nesty account), your IP address (needed to deliver the request; our analytics provider also derives an approximate region from a masked form of it and then discards it — we never receive or store your precise location), and crash diagnostics (via Firebase Crashlytics), used to keep the app stable. Crash reports carry only technical error information — never a child's data.
- Advertising identifier (iOS). Nesty shows no ads, so we do not use your device's advertising identifier (IDFA) for advertising. On iOS 14+ we ask for App Tracking Transparency permission; the identifier is used to help measure app usage only if you grant that permission, and it stays off if you decline. Analytics that do not rely on the advertising identifier still follow the on/off control described above.
- Subscription events. Purchase and subscription status through RevenueCat and the app stores (Apple App Store / Google Play), which are the source of truth for billing. When a subscription starts, the plan, its price and its currency are also recorded as an analytics event, so they reach the two analytics providers named above (Eodin and Firebase Analytics) as well. No payment method, card details or billing address ever leaves the store — Nesty never receives them.
2.3 What we do not do
- No advertising. Nesty ships no third-party ads on any screen or tier, and includes no advertising SDK and no ad tracking or profiling.
- No sale of your data. We do not sell your or your child's personal information, and we do not share it for cross-context behavioral advertising.
3. How we use information
We use the information above to:
- Provide the core Service — record, display, edit, and sync your care logs across your devices and your invited caregivers.
- Offer age-appropriate features such as WHO growth charts and sleep-prediction reminders.
- Personalise those predictions to your child. Sleep and feeding estimates start from published age tables and are gradually adjusted using your own recent care logs (the last 14 days), so the app describes your child's pattern rather than the average child's. This happens entirely on your device — no derived pattern is uploaded, and the estimate is not used for any purpose other than the guidance shown on the card. The card tells you which of these it is currently using.
- Send prediction and reminder notifications you have enabled. These are scheduled and shown by your own device — Nesty runs no push server and sends no remote push messages. Sleep-prediction notifications are free and can be turned off in Settings.
- Operate subscriptions, trials, and restore-purchase flows (via RevenueCat and the app stores).
- Maintain, secure, debug, and improve the Service (aggregate, non-identifying analytics and crash diagnostics).
- Comply with legal obligations and enforce our Terms.
We do not use your child's care data to build advertising or marketing profiles. The only profiling of any kind is the on-device prediction personalisation described above, which never leaves your device.
4. Legal bases for processing (EEA / UK)
If you are in the European Economic Area or the United Kingdom, we process personal data on these legal bases:
- Performance of a contract — to provide the Service you sign up for.
- Consent — for optional notifications and, where required, for processing a child's data, which you provide as the child's parent/guardian. You may withdraw consent at any time.
- Legitimate interests — to secure, debug, and improve the Service, balanced against your rights.
- Legal obligation — where we must retain or disclose data by law.
Where we rely on consent for a child's data, that consent is given and managed by you as the responsible adult.
5. How we share information
We share information only with:
- Infrastructure and service providers who process data on our behalf under contract, limited to what is needed to run Nesty:
- Google Firebase — authentication, analytics, crash reporting, and remote configuration. Remote configuration is how we decide which of our own other apps, if any, to feature in the occasional "From Eodin" banner. It is a one-way download of that setting: it sends no information about you, your caregivers, or your child. Making the request does transmit a Firebase installation identifier, which identifies the app installation — not you — and which we do not use to build a profile of you or link to your Nesty account.
- Supabase — encrypted cloud database and realtime sync (row-level security isolates each child's data).
- RevenueCat and the Apple App Store / Google Play — subscription and billing.
- Eodin Studio's analytics (Eodin SDK) — product analytics under the no-personal-information rule described above.
- Caregivers you invite. Data for your children is visible to the caregivers you have explicitly invited into your family. You control these invitations, and removing a caregiver ends their access to all of your children at once. While your subscription is active, a caregiver you have invited can also read your children's full history and export it as a PDF or CSV file from their own device — for example to hand to a pediatrician. That export leaves their device through their phone's normal sharing options, so it is no longer covered by this policy once it does.
- Legal and safety. If required by law, or to protect the rights, safety, or property of users or the public.
- Business transfers. If Eodin Studio is involved in a merger, acquisition, or asset sale, data may transfer as part of that transaction, subject to this policy.
We do not share child care data with third parties for their own marketing.
6. Data storage, security, and international transfer
- Encryption. Your data is encrypted in transit (TLS) and at rest.
- Access control. Cloud data is isolated per child using row-level security, so a caregiver can only reach children in a family they were invited into.
- On-device data. Nesty is offline-first: logs are stored locally on your device — in an encrypted database — so the app works without a connection, and sync when you reconnect. If you use the home-screen widget or a paired watch, a small copy of what those surfaces show (your child's name and the most recent entry, plus any entries the watch has not yet sent to your phone) is kept in that device's protected app storage so they work offline. Both are cleared when you sign out or delete your account, and are excluded from device backups.
- International transfer. Our providers may process data in countries other than yours. Where required, we rely on appropriate safeguards (such as Standard Contractual Clauses) for these transfers.
No method of transmission or storage is perfectly secure, but we work to protect your information using industry-standard measures.
7. Data retention and deletion
- We keep your information for as long as your account is active or as needed to provide the Service.
- In-app deletion. Deleting a log is a soft delete that hides it and syncs the removal to your caregivers.
- Reminder history: 30 days in the app. The reminder history described in section 2.1 is shown for 30 days; each device removes its own copy once a reminder is older than that.
- What each deletion actually does. "Delete all entries" in Settings erases the entries and their reminder history from our servers, for every child you own. It covers the children you own only — entries you recorded in another family, as a caregiver they invited, are that family's records and are removed by that family's owner. Deleting a child profile marks that child and everything recorded for it as deleted: it disappears from every caregiver's app straight away, and the marked records are kept on our servers so the deletion also reaches devices that were offline. They are erased when you delete your account, or sooner if you ask us at official@eodin.app. Deleting your account erases all of it. Entries you recorded in another family remain in that family's records — they are that family's data — attributed to an account identifier that no longer exists.
- Delete your data / account. You can delete your data from Settings. When you delete your account, we delete or de-identify the associated personal information, except where we must retain limited records to meet legal, tax, security, or fraud-prevention obligations, within a commercially reasonable period.
- Analytics. Non-identifying analytics events are retained in aggregate and are not tied to a child's identity.
To request deletion or ask about retention, contact official@eodin.app.
8. Your rights and choices
Depending on where you live, you may have the right to:
- Access the personal information we hold about you.
- Correct inaccurate information (you can edit most data directly in the app).
- Delete your information (available in-app and on request).
- Export / portability — export your logs as CSV or PDF from within the app (a Nesty Pro feature). If you do not have a subscription, email us at official@eodin.app and we will provide a copy of your data free of charge.
- Object to or restrict certain processing, and withdraw consent for notifications or other consent-based processing.
- Not be discriminated against for exercising your rights.
To exercise any right, use the in-app controls or email official@eodin.app. We will respond within the timeframe required by applicable law. You also have the right to lodge a complaint with your local data protection authority.
Notifications. You can turn prediction and reminder notifications on or off in Settings and in your device's system settings.
Ongoing nap. While a sleep session is running, Nesty pins a live timer to your phone — the notification shade on Android, the lock screen and Dynamic Island on iOS. It shows your child's name so you can tell which child it is counting for. You can turn the name off in Settings → Notifications → Show your child's name; the timer itself stays.
Home-screen widget. The widget shows your child's name and their most recent entry, so it is visible to anyone holding the phone. Remove the widget from your home screen if you would rather it were not.
Analytics & crash reports. You can turn anonymous usage analytics and crash reporting off (or back on) at any time in Settings → Share usage & crash reports. On iOS, you also control the App Tracking Transparency permission in Settings.
9. Children's privacy (COPPA / GDPR-K)
Nesty is a tool for adults to track a child's care. It is not directed to children, and we do not knowingly collect personal information directly from children.
- A child's information is provided by you, the parent/guardian (or an authorized caregiver you invite), and is used only to deliver Nesty's features to you.
- We do not require a child to provide any information to use the Service, and we do not condition a child's participation on disclosing more than is reasonably necessary.
- We do not use a child's information for advertising, profiling, or any purpose other than providing the Service.
- As the responsible adult, you can review, edit, export, and delete a child's information at any time in the app, and revoke any caregiver's access.
If you have questions about how a child's information is handled, or wish to review or delete it, contact official@eodin.app.
10. Third-party services
Sign-in and some features rely on third parties (Google, Apple, Supabase, RevenueCat, and the app stores). Their handling of information they collect directly from you is governed by their own privacy policies. We encourage you to review them.
11. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date and, where appropriate, notify you in the app. Your continued use of the Service after an update means you accept the revised policy.
12. Contact us
Eodin Studio — Nesty Email: official@eodin.app
If you have any questions or concerns about this Privacy Policy or your data, please reach out. We take the trust you place in us with your family's data seriously.
