Legal
Privacy Policy
Effective date: July 23, 2026
What we collect
- Your account: email address, and a name if you give us one.
- What you write: messages, journal entries, expense descriptions, info-bank cards, files you upload.
- What you do: every sign-in, every message opened, every schedule change requested and answered, every export taken. These are recorded in your family's permanent record — that auditability is a feature of the product, and it applies to you as well as to the other parent.
- Where you check in: if you use exchange check-ins, the coordinates and accuracy you allow your browser to share, at the moment you tap the button. We do not track your location at any other time.
- Your children: whatever you choose to put in their profile.
Who can see what
| You | The other parent | Professionals you invite | Us | |
|---|---|---|---|---|
| Your messages | yes | yes | if granted | yes — see below |
| Your journal | yes | never | never | yes — see below |
| Your vault files | yes | never | never | yes — see below |
| Calendar, expenses | yes | yes | if granted | yes |
| Info cards marked private | yes | no | no | yes |
"Us" means: we can technically read your data. Your message bodies, journal entries, and vault files are encrypted when stored, but we hold the key. We are not a zero-knowledge service and we will not claim to be one. In practice we do not read your content, and nobody at Connecting Nests browses journals — but you should choose what to write knowing that the encryption protects you from a stolen backup, not from us.
What we never do
- We do not sell your data. There is no version of this business where we do.
- We do not show you ads, and we do not let anyone target you.
- We do not read your messages to train anything.
- We do not tell the other parent what you write in your journal, that you wrote one, or that one exists.
Your records, and why deletion works differently here
You can close your account. Your records stay — see the Terms. They belong to the family's shared record, and the other parent relies on them.
You can delete: your vault files, your info cards, and your journal entries.
You cannot delete: messages, expense agreements, swap requests and refusals, check-ins, or any other record in the chain. Nobody can, including us.
Backups
Encrypted, nightly, and retained for 14 days — on our own server and on the off-site copy alike. When the 14 days are up, both copies are deleted.
The off-site copy is stored with Wasabi Technologies, in their US East 1 region (Ashburn, Virginia, United States). Wasabi is our only sub-processor for your data. The backups we send them are encrypted before they leave our server and the decryption key never goes with them, so Wasabi cannot read your data — they hold an opaque archive.
If we ever change backup providers, we will name the new one and its region here.
Security, honestly
- Everything is served over TLS.
- Message bodies, journals, and vault files are encrypted at rest (AES-256-GCM).
- Records are append-only and hash-chained; nobody can alter them.
- Sign-in is passwordless; you can turn on two-factor authentication.
- The limitation: our encryption key lives on the same server as the data. This protects you if a backup or a disk is stolen. It does not protect you from someone who compromises the server itself, and it does not stop us reading your data.
Contact
See also our Terms of Service.