This Privacy Policy describes how Nestli ("we", "our", or "the app"), a mobile
application for tracking baby care activities, collects, uses, stores, and
shares information about you when you use the app. It should be read
alongside our Terms & Conditions.
1. Information We Collect
We collect the following categories of information:
- Account information — email address, username, and password (stored in hashed form) provided during sign-up. A user identifier (UUID) is generated server-side to identify your account.
- Baby profile data — baby name, date of birth, sex, birth measurements, and cover photo that you voluntarily enter.
- Care logs — feeding, diaper, sleep, growth, health, and milestone records that you create in the app.
- Photos — images you choose to upload from your device camera or photo library. Three sizes (original, preview, thumbnail) are generated on-device and stored in our private photo bucket. By uploading any photo to Nestli, you confirm that you own or have the necessary rights to that image, and — where the image depicts a child — that you are the parent or legal guardian of the child or have authority from them. See section 5 of the Terms & Conditions for the full responsibilities and warranties that apply to content you upload.
- Voice recordings (optional) — when you use the voice-log feature, audio is sent to our server for transcription into a care log. Audio is processed in memory only and is not persisted by Nestli. See section 5 for the third-party transcription provider.
- Subscription data (if you subscribe) — which plan you hold, when it renews or expires, and the purchase identifiers issued by the app store. Payment is taken by Apple or Google; Nestli never receives your card or bank details.
- Diagnostics and crash reports — when the app crashes or misbehaves, a report is sent to our error-tracking provider containing the error and its stack trace, the app version, and basic device and operating-system information. A sample of performance traces (screen loads and network timings) is collected the same way so we can find slowdowns. Your account identifier is never attached to these reports, and we use no advertising or user-profiling SDKs.
- Device identifiers — a push notification token, so that reminders you switch on can reach your device, together with installation identifiers generated by our error-tracking and subscription providers. These identify an installation of the app, not you personally.
2. Camera, Photo Library, and Microphone Access
Nestli requests access to your device camera and photo library so that you
can capture or select photos of your baby to attach to your records. Microphone
access is requested only when you use the voice-log feature. These permissions
are used only when you explicitly invoke the corresponding feature inside
the app.
You can deny or revoke any of these permissions at any time via your device
settings. Denying them will disable the relevant features but will not affect
other parts of the app.
3. How We Use Information
- To provide the core features of the app — storing and displaying your baby care records.
- To authenticate you and keep your account secure.
- To send transactional emails such as email verification, password reset, email change notifications, and family invites.
- To provide the optional AI+ assistant feature, which sends a summary of recent log activity (not raw data, not photos) to a third-party AI provider to generate responses to your questions. You can attach a photo to an AI question if you choose to; that photo is sent for that single request.
- To transcribe voice-log recordings into care logs via a third-party transcription provider.
- To diagnose problems and improve reliability.
We do not sell your personal information. We do not use your data for advertising.
4. Data Storage and Security
Text records (feeding, diaper, sleep, growth, etc.), account data, and
authentication are stored on Supabase, a managed backend provider,
using encrypted connections and row-level security so that only you and the
family members you explicitly invite can access your baby records.
Photos are stored on Amazon Web Services (AWS S3) in the Asia
Pacific (Sydney) region, in a private bucket that is not publicly readable.
They are served to your device through Amazon CloudFront, a
global content delivery network, using short-lived signed URLs — this lets
users in different regions (including mainland China, via CloudFront edge
locations in Hong Kong, Tokyo, or Singapore) load photos quickly without
making the bucket public.
Photos uploaded to Nestli pass through an automated image-moderation step
that screens for content that breaches our policies or applicable law.
This screening is automated and best-effort: we do not warrant that it
will catch every prohibited image, and we may remove a photo we
subsequently determine to be in breach. Concerns about a specific photo
can be reported to the contact address in section 12.
All data is encrypted in transit (HTTPS). Supabase and AWS S3 encrypt data
at rest using their standard provider-managed keys.
5. Third-Party Service Providers
Nestli uses the following service providers to operate the app. Limited user
data is shared with each only as required for the listed purpose, and none of
them sell your data.
- Supabase — application database, authentication, and serverless functions.
- Amazon Web Services (AWS) — Amazon S3 photo storage, Asia Pacific (Sydney) region.
- Amazon CloudFront — global content delivery network that serves photos from edge locations closer to your device.
- OpenAI — processes AI+ chat requests and voice-log transcriptions. Baby context data is sent per your questions; voice audio is sent per your recordings. OpenAI states that data submitted via its API is not used to train models.
- Xiaomi (MiMo) — fallback AI provider for AI+ chat requests, including any non-medical photos you attach, used when the primary provider is unavailable. Outside mainland China the service is operated by Xiaomi Technologies Singapore Pte. Ltd., which holds overseas user data in Europe and Singapore.
- Resend — sends transactional emails such as verification codes, password resets, email-change notifications, and family invites.
- Sentry — error tracking and performance monitoring. Receives crash reports, stack traces, the app version, and device and operating-system information when something goes wrong. Nestli does not send your account identifier to Sentry.
- RevenueCat — manages AI+ subscription state. Receives your Nestli user identifier and the purchase receipt issued by the app store, so the app knows which plan you hold.
- Apple App Store and Google Play — take subscription payments and issue the purchase receipts. Your payment details are handled by them, never by Nestli.
- Expo, with Apple Push Notification service (iOS) and Firebase Cloud Messaging (Android) — deliver the reminder notifications you switch on. They receive a push token for your device and the contents of the notification.
By using the Service you agree to these sub-processors being used. The list
may be updated as our infrastructure evolves; material additions will be
communicated in-app.
6. Family Sharing
You may invite other users (for example, a partner or caregiver) to view or
edit records for a specific baby. Invited members only gain access after
accepting an invite code or email invitation. You can revoke their access at
any time from the app. Revoking access removes a member's ability to view
future data but does not erase entries they previously created.
7. Children's Privacy
Nestli is designed for use by adult caregivers to record information about
their own children. The app is not directed at children under 13, and we do
not knowingly collect personal information directly from children. The data
stored about an infant or child within Nestli is provided by the parent or
legal guardian on behalf of that child.
8. Your Rights
You can:
- Access, update, or delete your records from within the app.
- Delete your account, which will remove your profile and associated records from our systems.
- Contact us to request a copy or deletion of your data.
9. European Economic Area, United Kingdom, and Switzerland
This section applies if you use Nestli from the European Economic Area (EEA),
the United Kingdom, or Switzerland, and supplements the rest of this policy.
Where the two differ, this section governs for those users.
9.1 Who is responsible for your data
The controller of your personal data is Xin Chen, trading as
Nestli, 2 Cassinia Way, Thornleigh NSW 2120, Australia. Data protection
enquiries go to [email protected].
Representative in the Union (Article 27 GDPR). Nestli has no
establishment in the European Union. Our designated representative is:
not yet appointed. This entry is to be completed before Nestli is
offered to users in the EEA.
9.2 The legal bases we rely on
- Running your account and providing the app — performance of our contract with you (Article 6(1)(b)).
- Baby health records, photos, voice notes, and AI+ — your explicit consent (Articles 6(1)(a) and 9(2)(a)). Feeding, sleep, growth, vaccination, and illness records are data concerning health, a special category under Article 9. Nothing obliges you to record them, and AI+ stays off until you turn it on and accept the in-app data-sharing notice.
- Security, abuse prevention, crash diagnostics, and photo moderation — our legitimate interests in keeping the service working and safe (Article 6(1)(f)).
- Meeting record-keeping duties and responding to lawful requests — compliance with a legal obligation (Article 6(1)(c)).
Where we rely on consent you may withdraw it at any time, and withdrawing it
does not affect anything we did while it was in force.
9.3 Sending data outside the EEA
Nestli is operated from Australia and uses providers in several countries.
Neither Australia nor Singapore is covered by a European Commission adequacy
decision, so those transfers rely on the Commission's Standard Contractual
Clauses.
- Australia — photos are stored in Amazon S3 in the Asia Pacific (Sydney) region and served through Amazon CloudFront.
- United States — OpenAI (AI+ answers and voice transcription), Sentry (crash reports), RevenueCat (subscription state), and Resend (transactional email).
- Europe and Singapore — Xiaomi MiMo, used only when the primary AI provider is unavailable, operated outside mainland China by Xiaomi Technologies Singapore Pte. Ltd.
9.4 Your rights
Under the GDPR and the UK GDPR you may:
- Access the personal data we hold about you (Article 15).
- Correct data that is wrong or incomplete (Article 16) — most records are editable in the app.
- Erase your data (Article 17) — Settings → My Account → Delete account removes your profile and records, or ask us and we will do it.
- Restrict our processing in the circumstances Article 18 sets out.
- Port the data you gave us, in a structured, commonly used, machine-readable form (Article 20). Settings → Data exports your care records as a spreadsheet; for anything that export does not cover — photos, milestones, family membership, and AI+ chat history — email us and we will supply it.
- Object to processing we base on legitimate interests (Article 21).
- Withdraw consent — turn AI+ off in Settings, revoke camera, photo, or microphone access in your device settings, or delete the records in question.
Write to [email protected] to
exercise any of these. We reply within one month, and will tell you if we need
the further two months that Article 12(3) allows.
We take no decisions about you by automated means that produce legal or
similarly significant effects (Article 22). AI+ produces informational
answers; it decides nothing about you.
9.5 Complaints
You may lodge a complaint with your national supervisory authority (Article
77). The European Data Protection Board lists them at
edpb.europa.eu;
in the United Kingdom the authority is the Information Commissioner's Office
(ico.org.uk). You do not have to contact us
first, though we would rather you did.
10. Data Retention
We retain your data for as long as your account is active. When you delete
your account, your personal information and uploaded photos are removed from
live systems within a reasonable period. Routine backups may retain data for
up to 30 days before being purged. Voice-log audio is not retained at all by
Nestli — it is passed through to the transcription provider in memory and
discarded.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be
communicated through the app or by email. Continued use of Nestli after a
change constitutes acceptance of the updated policy.
12. Contact
Questions about this policy or your data can be sent to:
[email protected]