Privacy Policy
Last updated August 14, 2026
Nido is a family organizer: a shared chore board and calendar that runs on a wall tablet, a phone, and the web. This policy explains what Digital Indoorsmen ("we", "us") collects when you use Nido, why we collect it, who we share it with, and how you get it back or delete it.
The short version. We collect what the app needs to work: your account, your household's chores and events, and — only if you connect it — a read-only copy of your Google Calendar. We do not sell your data, we do not run ads, and we do not use your family's information to train machine-learning models. You can download everything we hold, or delete your account outright, from Settings → Data & privacy on the web or in the app — no email to us required.
1. Information we collect
Information you give us
- Account details. Your name, email address, and a hashed password. If you enable two-factor authentication or a passkey, we store the credential needed to verify it — never a copy of your biometrics.
- Household details. Your household name, time zone, and the tokens that let a kiosk screen or an invited family member reach your household.
- Children's profiles. The first name, display color, optional birth date, and optional avatar image you add for each child. Children do not have their own accounts, email addresses, or passwords — a parent creates and controls every profile.
- Family activity. Chores and their schedules, completions, eggs earned and spent, rewards you define and redemptions you approve, vacation periods, and any events you create directly in Nido.
- Weather location. If you turn on the kiosk weather panel, we store the place name and its approximate latitude and longitude. This comes from the location you type in — Nido does not read your device's GPS.
Information from Google (only if you connect it)
- The email address of the Google account you connect, so you can tell which account is linked.
- OAuth access and refresh tokens, stored encrypted, so Nido can keep reading your calendar without asking you to sign in again.
- The list of calendars on that account, and the events in the date ranges Nido is displaying — titles, times, locations, and all-day flags.
Information collected automatically
- Session and device data. Your IP address and browser user agent, kept with your login session for security and abuse prevention.
- API tokens. When you sign in to the mobile app, we issue and store a token identifying that device.
- Server logs. Ordinary request and error logs used to keep the service running and to diagnose failures.
Billing information
Paid subscriptions are processed by Stripe. Stripe collects and holds your card details — we never see or store your full card number. What we keep is a Stripe customer identifier, your subscription status and plan, and the card brand and last four digits so you can recognize the card on file.
2. How we use information
- To operate the app: show the board, merge calendars, track chores, eggs, and rewards.
- To authenticate you and keep unauthorized people out of your household.
- To bill you, if you subscribe to Nido Premium.
- To send account email — verification, password resets, and important service notices.
- To diagnose bugs, prevent abuse, and keep the service secure and available.
- To comply with the law when we are legally required to.
We do not sell or rent personal information, we do not share it with advertisers, and we do not use your family's data to train machine-learning or AI models. We do not make decisions about you by automated means that produce legal or similarly significant effects, and we do not profile you.
Our legal bases (EU/UK GDPR)
If you are in the EU or UK, we must name a lawful basis for each use. Ours are:
- Performance of a contract (Art. 6(1)(b)) — running your household, authenticating you, sending account email, and billing you if you subscribe. Without this data there is no service to provide.
- Consent (Art. 6(1)(a)) — connecting your Google Calendar, turning on the weather panel, and product emails. You can withdraw any of these at any time (disconnect Google, turn weather off, unsubscribe) without affecting anything else.
- Legitimate interests (Art. 6(1)(f)) — keeping the service secure and available, preventing abuse, and diagnosing failures. We have weighed these against your interests; the data involved is session and log data, not family content.
- Legal obligation (Art. 6(1)(c)) — keeping billing and tax records, and responding to lawful requests.
A child's profile is added by their parent as part of running the household, so it rests on the contract with the parent. We do not ask children for consent, and we do not rely on a child's consent for anything.
3. Google user data and Limited Use
Nido requests the read-only Google Calendar scope
(https://www.googleapis.com/auth/calendar.readonly) plus basic sign-in scopes
(openid, email, profile). Read-only means Nido
cannot create, edit, or delete anything in your Google Calendar.
Nido's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, calendar data obtained through Google APIs is:
- used only to display your family's events inside Nido — the dashboard, the kiosk, and the mobile app;
- never sold, and never transferred to third parties except as needed to run the service, for security, or where the law requires;
- never used for advertising, ad targeting, or personalization;
- never used to train generalized machine-learning or AI models;
- never read by a human, except with your explicit permission for support, for security purposes, or where required by law.
Fetched events are held briefly in a server-side cache (roughly ten minutes) so the kiosk stays responsive. Your OAuth tokens are stored encrypted and are used only to refresh that read access.
You can disconnect at any time. In Nido, go to Calendars → Disconnect: we delete the stored tokens, the connected email address, and the calendar list for your household. You can also revoke Nido's access from your Google account at myaccount.google.com/permissions.
4. Children's information (COPPA)
Nido is a service for parents. It is not directed at children as a destination of their own: there is no child sign-up, no child account, no email address or password for a child, no messaging, no public profile, and nothing a child can share outside the household. Only an adult account holder can create a household, add children, or change settings.
What we collect about a child, and who provides it
A parent provides it, not the child. The first name, display color, and optional birth date and photo on a child's profile are typed in by the account holder. We do not ask a child for their name, address, email, phone number, or any other contact information, and there is nowhere in the app for a child to enter one.
What a child in kid mode generates. Kid mode locks a device to one child and shows only their chores, their egg balance, Rewards, and the family calendar; leaving it requires a parent's PIN. A child using it can tick a chore off and ask to spend eggs on a reward their parent defined. That produces timestamps, egg movements, and redemption requests attached to the profile their parent created. It does not produce any contact information, free-text about themselves, precise location, photos, or audio, and none of it leaves the household.
Parental consent and control
Because a child's information is supplied by their own parent for use inside their own household, the parent's act of entering it is the consent for it. We do not use that information for any purpose beyond running the household, and we will not do so without first getting the parent's separate consent.
As the account holder, you can at any time:
- Review everything we hold about your child — visible in the app, and included in the data export described in section 10.
- Correct or delete a child's profile from Manage → Kids. Deleting it removes that child's profile, photo, chore history, egg ledger, and redemptions.
- Refuse further collection by turning off kid mode, or by deleting the profile.
- Delete everything by deleting your account, which erases the whole household (section 10).
We never condition a child's participation on giving us more information than is reasonably necessary — the birth date and photo are optional, and everything works without them.
What we never do with children's information
- We do not show advertising to children, and we run no ad or tracking SDKs in the app.
- We do not sell, rent, or disclose a child's information, except to the service providers in section 5 who need it to run the service.
- We do not use it to train machine-learning or AI models.
- We do not build profiles of children or use their data for any purpose outside their household.
- We do not knowingly let a child create their own account. If we learn a child has, we delete it.
If you believe we hold information about your child that you did not provide or no longer want us to have, email hello@digitalindoorsmen.com and we will delete it.
5. Who we share information with
We use a small number of service providers, each handling only what their job requires:
- Google — calendar data you choose to connect (read-only).
- Stripe — payment processing and subscription management.
- Open-Meteo — weather forecasts. We send approximate coordinates for the location you chose, and nothing that identifies you.
- Our hosting, database, storage, and email providers — running the servers, storing avatars, and delivering account email.
We may also disclose information when the law requires it, to protect our rights or someone's safety, or as part of a merger or acquisition — in which case we will tell you before your information becomes subject to a different privacy policy.
6. Where your data is stored
Nido runs on servers operated by our hosting provider, and our service providers (including Google and Stripe) may process data in other countries, including the United States. Data stored in another country may be accessible to that country's courts and authorities.
Where data covered by the EU or UK GDPR leaves that jurisdiction, the transfer is covered by the European Commission's Standard Contractual Clauses (and the UK Addendum) in our agreements with those providers, or by an adequacy decision covering the destination. Canada, where we operate, is the subject of an adequacy decision for commercial data. Write to us if you would like details of the safeguards for a particular transfer.
7. How long we keep it
We keep your household's data for as long as your account is open, and no longer than we need it:
- Account and household data — including children's profiles, chores, completions, eggs, rewards, and events: until you delete your account, then erased as described in section 10.
- Google OAuth tokens and calendar list — until you disconnect, or your account is deleted, whichever comes first. Fetched calendar events are held in a server-side cache for roughly ten minutes and are never stored permanently.
- Session and device data, and API tokens — until the session or token expires, you sign out, or your account is deleted.
- Server logs — retained for a short operational period, then rotated out.
- Data exports — the generated file is deleted automatically 48 hours after it is created.
- Encrypted backups — copies may persist for up to 30 days after deletion before aging out. We do not restore deleted accounts from backups.
- Billing records — kept as long as tax and accounting law requires, which is separate from and longer than your account. This is a legal obligation and survives an erasure request.
8. Security
Traffic to Nido is encrypted in transit with TLS. Passwords are hashed, never stored in readable form, and Google OAuth tokens are encrypted at rest. Each household's data is isolated: every query is scoped to your household, and kiosk links use unguessable tokens. No system is perfectly secure, so please use a strong, unique password and enable two-factor authentication.
A note on kiosk mode: a kiosk link stays signed in on purpose, so anyone with physical access to that screen, or with the link, can see your family's board. Treat the kiosk URL as a secret and regenerate it from Settings if it gets out.
9. Your rights and choices
- Access. See what we hold about you and your family. Most of it is visible in the app, and all of it is in the data export described in section 10.
- Correction. Fix anything inaccurate — profiles, names, dates, and settings are all editable in the app. Ask us for anything that isn't.
- Deletion (erasure). Delete a child, a chore, a calendar connection, or your whole account. See section 10.
- Portability. Get a machine-readable copy of your household's data to take elsewhere. See section 10.
- Withdraw consent. Disconnect Google, turn off weather, or unsubscribe from product emails at any time. Withdrawing does not affect processing that already happened.
- Object and restrict. Object to processing we base on legitimate interests, or ask us to pause processing while a dispute about accuracy or lawfulness is resolved.
- Complain. Take a complaint to your data protection authority — in Canada the Office of the Privacy Commissioner, in the EU your national authority, in the UK the Information Commissioner's Office. We would rather you came to us first, but you do not have to.
Exercising any of these costs nothing and will not get your account treated differently. Email hello@digitalindoorsmen.com for anything you cannot do in the app; we respond within 30 days, and sooner where the law requires it. We may need to confirm you are the account holder before acting on a request — we do that through the email address on the account, and never by asking for additional identity documents we do not otherwise hold.
Depending on where you live you may have further rights under Canada's PIPEDA, the EU/UK GDPR, California's CCPA/CPRA, or similar laws. Under the CCPA: we do not sell or share personal information as those terms are defined, we do not use it for cross-context behavioural advertising, and we collect no sensitive personal information for the purpose of inferring characteristics.
10. Deleting your account and exporting your data
Deleting your account
You can delete your account yourself, from the web at Settings → Data & privacy or from the mobile app at Settings → Data & privacy. You do not need to email us, and you do not need to cancel a subscription first — deletion cancels it. Step-by-step instructions are on our account deletion page.
What happens depends on whether anyone else is in your household:
- If you are the only parent, the whole household goes: every child's profile, photo and birth date; all chores, completions, eggs, rewards and redemptions; the events you created; your connected Google Calendar; and every parent account on it.
- If another parent remains, only your own account is deleted. The household, your children's profiles, and the family history stay with them — they are that family's records too, and we will not erase another parent's data on your request. One of the remaining parents becomes the household owner.
There is a 30-day grace period. Your account is locked the moment you ask — signed out on every device, and unusable — but nothing is erased yet. Signing back in during that window lets you cancel the request and pick up where you left off. After 30 days the erasure runs and is irreversible: we cannot restore an account from backups afterwards. The grace period exists so that a mistake, or someone else reaching your unlocked phone, is recoverable.
The erasure also revokes Nido's access to your Google account and cancels any active subscription. Encrypted backups age out within 30 days, and billing records are kept as long as tax law requires (section 7).
Exporting your data
From the same screen you can request a copy of your household's data. We build a JSON file containing your children's profiles, chores and completions, the egg ledger, rewards and redemptions, your events, your calendar settings, and your household settings, then email you a private download link. The link expires after 48 hours, the file is deleted with it, and you have to be signed in to use it.
The export deliberately leaves out credentials — password hashes, two-factor secrets and recovery codes, API tokens, Google OAuth tokens, and your kiosk and invite links — because the file travels and those are keys, not information about you. It also does not copy your Google Calendar events, which stay in your Google account and can be exported with Google Takeout.
11. Cookies
Nido sets only the cookies it needs to function: a session cookie to keep you signed in, a CSRF token to protect form submissions, and a preference cookie remembering light or dark mode. We do not use advertising or cross-site tracking cookies, and we do not run third-party analytics that profile you.
12. Changes to this policy
If we change this policy we will update the date at the top of this page, and for material changes we will notify account holders by email or in the app before the change takes effect.
13. Contact us
Questions, requests, or complaints about privacy: hello@digitalindoorsmen.com.
Nido is operated by Digital Indoorsmen in Canada, which is the data controller for the information described in this policy. We are a small operation and are not required to appoint a data protection officer; privacy requests go to the address above and are handled by us directly.
See also our Terms of Service.