Privacy Policy
Last updated August 7, 2026
Nestli is a feeding, pumping and diaper log that you share with the people helping you raise your child. That means the app holds a detailed record of your daily routine and your baby's. We treat it accordingly. This page explains exactly what we store, who can see it, and how to get rid of it.
We do not sell your data, and we do not share your tracking entries with advertisers.
What we collect
Account information
Your email address, and a display name. If you sign up with an email and password, the password is stored only as a salted hash — we never see it. If you sign in with Google or Apple, we receive an account identifier and your email address from that provider, not your password.
Baby profiles
The name and optional birth date you enter for each child. You choose what to put here — a nickname works exactly as well as a legal name.
Tracking entries
The records you create: feeds (type, amount, duration, side, time and any notes), pumping sessions (amount, duration, side, time, notes) and diaper changes (type, time, notes). Each entry records which member of the baby's group created it and when.
Sharing invitations
When you invite a co-parent, we store the email address you invited and a single-use invitation token. Invitations expire after seven days.
Push notification subscriptions
Only if you turn on reminders. We store the subscription endpoint and encryption keys your browser issues, plus an optional device label so you can tell your devices apart. This lets us send a notification to that browser; it does not give us any other access to your device.
Usage analytics
We use Google Analytics to understand which pages people use and where the app is confusing. It records the page addresses you visit within Nestli, your browser and device type, and an approximate location derived from your IP address. Because it runs across the whole app, the page addresses it sees include the in-app screens you open while signed in. It does not receive the contents of your tracking entries, your baby's name, or your notes.
Who can see your entries
Every baby has an owner — the person who created it — and any members that owner has invited. Only those people can read or write that baby's entries. This is enforced in the database itself with row-level security, not just in the app, so a bug in the interface cannot expose one family's log to another.
Anyone you invite can see the full history for that baby, including entries recorded before they joined, and can add and edit entries. Invite people accordingly. The owner can remove a member at any time from Settings, which immediately ends their access.
Who we share data with
We use a small number of service providers to run Nestli. They process data on our instructions and are not permitted to use it for their own purposes.
- Supabase — Database and authentication hosting — stores your account and all tracking entries.
- Lovable — Application hosting, and the broker for Google and Apple sign-in.
- Google Analytics — Aggregate usage measurement — which pages are visited and how often.
- Browser push services — If you enable reminders, your browser vendor (Google, Apple or Mozilla) delivers the notification.
We will also disclose information if we are legally required to, or where it is necessary to protect someone's safety. Beyond that, your data stays with us.
How long we keep it
Tracking entries are kept until you delete them or until your account is deleted — the whole point of the app is the history, so nothing expires on its own. You can delete any individual entry yourself. To remove an entire baby profile along with its full history, or to close your account, email us and we will do it for you. Pending invitations expire after seven days.
Your rights
You can ask us to give you a copy of your data, correct it, or delete it. If you are in the UK, the EU or the EEA, you also have the right to object to or restrict how we process your data, and to complain to your local data protection authority. If you are in California, you have the right to know what we collect, to delete it, and not to be discriminated against for exercising those rights — and we confirm we do not sell or share personal information as those terms are defined under California law.
Some of this you can do yourself: edit or delete any entry from the History screen, and rename a baby or remove a member from Settings. For a full export, to delete a baby profile, or to close your account, contact us and we will action it within 30 days.
Children
Nestli is for parents and caregivers, and accounts are for adults aged 18 or over. It is not directed to children and we do not knowingly let children create accounts.
The records you keep are of course about your child. That information is entered by you, visible only to you and the people you invite, never used to build an advertising profile, and deleted when you delete it.
Security
Traffic is encrypted in transit, data is encrypted at rest by our database provider, and access to every table is restricted per-user at the database layer. No service can promise perfect security, but if we ever discover a breach affecting your data we will tell you.
Changes to this policy
If we change how we handle your data, we will update this page and move the date at the top. For anything significant — a new category of data, or a new party receiving it — we will tell you in the app before it takes effect.
Contact
If you have questions about this policy, want to exercise any of the rights above, or something here does not match what you are seeing in the app, please get in touch.