Privacy Policy
Last updated August 8, 2026
Nido is a family organizer: a shared chore board and calendar that runs on a wall tablet, a phone, and the web. This policy explains what Digital Indoorsmen ("we", "us") collects when you use Nido, why we collect it, who we share it with, and how you get it back or delete it.
The short version. We collect what the app needs to work: your account, your household's chores and events, and — only if you connect it — a read-only copy of your Google Calendar. We do not sell your data, we do not run ads, and we do not use your family's information to train machine-learning models.
1. Information we collect
Information you give us
- Account details. Your name, email address, and a hashed password. If you enable two-factor authentication or a passkey, we store the credential needed to verify it — never a copy of your biometrics.
- Household details. Your household name, time zone, and the tokens that let a kiosk screen or an invited family member reach your household.
- Children's profiles. The first name, display color, optional birth date, and optional avatar image you add for each child. Children do not have their own accounts, email addresses, or passwords — a parent creates and controls every profile.
- Family activity. Chores and their schedules, completions, eggs earned and spent, rewards you define and redemptions you approve, vacation periods, and any events you create directly in Nido.
- Weather location. If you turn on the kiosk weather panel, we store the place name and its approximate latitude and longitude. This comes from the location you type in — Nido does not read your device's GPS.
Information from Google (only if you connect it)
- The email address of the Google account you connect, so you can tell which account is linked.
- OAuth access and refresh tokens, stored encrypted, so Nido can keep reading your calendar without asking you to sign in again.
- The list of calendars on that account, and the events in the date ranges Nido is displaying — titles, times, locations, and all-day flags.
Information collected automatically
- Session and device data. Your IP address and browser user agent, kept with your login session for security and abuse prevention.
- API tokens. When you sign in to the mobile app, we issue and store a token identifying that device.
- Server logs. Ordinary request and error logs used to keep the service running and to diagnose failures.
Billing information
Paid subscriptions are processed by Stripe. Stripe collects and holds your card details — we never see or store your full card number. What we keep is a Stripe customer identifier, your subscription status and plan, and the card brand and last four digits so you can recognize the card on file.
2. How we use information
- To operate the app: show the board, merge calendars, track chores, eggs, and rewards.
- To authenticate you and keep unauthorized people out of your household.
- To bill you, if you subscribe to Nido Premium.
- To send account email — verification, password resets, and important service notices.
- To diagnose bugs, prevent abuse, and keep the service secure and available.
- To comply with the law when we are legally required to.
We do not sell or rent personal information, we do not share it with advertisers, and we do not use your family's data to train machine-learning or AI models.
3. Google user data and Limited Use
Nido requests the read-only Google Calendar scope
(https://www.googleapis.com/auth/calendar.readonly) plus basic sign-in scopes
(openid, email, profile). Read-only means Nido
cannot create, edit, or delete anything in your Google Calendar.
Nido's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, calendar data obtained through Google APIs is:
- used only to display your family's events inside Nido — the dashboard, the kiosk, and the mobile app;
- never sold, and never transferred to third parties except as needed to run the service, for security, or where the law requires;
- never used for advertising, ad targeting, or personalization;
- never used to train generalized machine-learning or AI models;
- never read by a human, except with your explicit permission for support, for security purposes, or where required by law.
Fetched events are held briefly in a server-side cache (roughly ten minutes) so the kiosk stays responsive. Your OAuth tokens are stored encrypted and are used only to refresh that read access.
You can disconnect at any time. In Nido, go to Calendars → Disconnect: we delete the stored tokens, the connected email address, and the calendar list for your household. You can also revoke Nido's access from your Google account at myaccount.google.com/permissions.
4. Children's information
Nido is designed for a parent or guardian to use on their family's behalf. Only an adult account holder can create a household, add children, or change settings. Kid mode shows a child only their own chores and the family calendar, and returns to the parent view with a PIN.
We ask for as little about children as possible — a first name, a color, and optionally a birth date and photo. We do not knowingly collect information directly from children, we do not show them advertising, and we do not sell or disclose their information. A parent can edit or delete a child's profile at any time from Manage → Kids, which removes that child's data from the household.
5. Who we share information with
We use a small number of service providers, each handling only what their job requires:
- Google — calendar data you choose to connect (read-only).
- Stripe — payment processing and subscription management.
- Open-Meteo — weather forecasts. We send approximate coordinates for the location you chose, and nothing that identifies you.
- Our hosting, database, storage, and email providers — running the servers, storing avatars, and delivering account email.
We may also disclose information when the law requires it, to protect our rights or someone's safety, or as part of a merger or acquisition — in which case we will tell you before your information becomes subject to a different privacy policy.
6. Where your data is stored
Nido runs on servers operated by our hosting provider, and our service providers (including Google and Stripe) may process data in other countries, including the United States. Data stored in another country may be accessible to that country's courts and authorities. We rely on our providers' contractual protections for those transfers.
7. How long we keep it
We keep your household's data for as long as your account is open. When you delete your account or your household, we delete the associated records — children, chores, events, calendar connections, and rewards. Encrypted backups may retain copies for up to 30 days before aging out. Billing records are kept as long as tax and accounting law requires.
8. Security
Traffic to Nido is encrypted in transit with TLS. Passwords are hashed, never stored in readable form, and Google OAuth tokens are encrypted at rest. Each household's data is isolated: every query is scoped to your household, and kiosk links use unguessable tokens. No system is perfectly secure, so please use a strong, unique password and enable two-factor authentication.
A note on kiosk mode: a kiosk link stays signed in on purpose, so anyone with physical access to that screen, or with the link, can see your family's board. Treat the kiosk URL as a secret and regenerate it from Settings if it gets out.
9. Your rights and choices
- Access and correction. Most of your data is visible and editable in the app. For anything else, ask us.
- Deletion. Delete a child, a chore, a calendar connection, or your whole account. Contact us if you need help erasing something.
- Export. Ask us for a copy of your household's data in a portable format.
- Withdraw consent. Disconnect Google, turn off weather, or close your account at any time.
Depending on where you live, you may have additional rights under laws such as Canada's PIPEDA, the EU/UK GDPR, or California's CCPA — including the right to object to certain processing and the right to complain to your data protection authority. Email jared@digitalindoorsmen.com and we will respond within the time the applicable law allows.
10. Cookies
Nido sets only the cookies it needs to function: a session cookie to keep you signed in, a CSRF token to protect form submissions, and a preference cookie remembering light or dark mode. We do not use advertising or cross-site tracking cookies, and we do not run third-party analytics that profile you.
11. Changes to this policy
If we change this policy we will update the date at the top of this page, and for material changes we will notify account holders by email or in the app before the change takes effect.
12. Contact us
Questions, requests, or complaints about privacy: jared@digitalindoorsmen.com. Nido is operated by Digital Indoorsmen in Canada.
See also our Terms of Service.