Skip to main content

Privacy Policy

Version 2.19 — effective August 29, 2026.

A note on wording. "Plan" means any scheduled activity you create or are invited to — a playdate, pickup, class, practice, or party. Our data exports and developer-facing fields call the same thing an "event".

CircleNest™ · Patent Pending · © 2026 CircleNest LLC

Who we are

CircleNest is a private family coordination app. Parents and guardians use it to plan playdates and everyday logistics with people they trust. It is operated by CircleNest LLC, a US limited liability company at 8 The Green #13755, Dover, DE 19901, United States. Privacy questions: contact@circlenestapp.com. This policy explains what we collect, why, and what you can control.

Where CircleNest is available

CircleNest is currently offered only to residents of the United States. Your primary protections are COPPA (for children under 13), CCPA/CPRA for California residents, and the other US state privacy laws described below. The GDPR and India DPDP sections record commitments that become operative if we open those regions.

Notice to Parents (COPPA Direct Notice)

This section is our Direct Notice to Parentsunder the Children's Online Privacy Protection Act (COPPA), 16 C.F.R. Part 312.

Who we are. CircleNest LLC, 8 The Green #13755, Dover, DE 19901, United States. Contact: contact@circlenestapp.com.

What we collect from children under 13. Only what a parent enters into a kid profile: first name (or nickname), birth month and year, optional photo, allergies, availability, and — if the parent sets one — a device PIN stored hashed with a one-way algorithm. If a parent enables an in-app kid login, we also store sign-in timestamps and the device the kid signs in from. We do not ask children to provide more than is reasonably necessary to participate.

How we use it. Solely to operate CircleNest — showing the kid in the parent's household, in circles the parent approves, on plans the parent invites them to, and in chats the parent authorizes. We do not use child data for advertising, behavioural profiling, or sale.

Disclosure. Child information is disclosed only to other adults the parent has approved into the same circle or plan, and to the service providers listed under "Third-party services we use" (hosting, error monitoring, analytics, push-notification delivery). We do not sell or share child data with advertisers.

Verifiable parental consent (COPPA). Because CircleNest does not disclose a child's personal information to the public or to third parties outside the service providers listed below, we rely on the FTC's "email plus" sliding-scale method for verifiable parental consent. When you add a kid profile, the consenting parent must (a) be signed in to a verified adult account tied to a working email address, (b) affirmatively accept this Privacy Policy and the Terms of Service, and (c) confirm the action from that same email address if we send a follow-up confirmation request. We will move to a stronger verification method (such as a government-ID check, signed consent form, or payment-card verification) before enabling any feature that would disclose a child's information outside CircleNest.

Parent rights. A parent may at any time (1) review the personal information we have collected from or about their child, (2) refuse to permit further collection or use, and (3) require us to delete it. Use Household → the kid profile, or email contact@circlenestapp.com. Deleting the kid profile or the parent account removes the child's data as described in "Data retention" below.

Kids aged 13–17 may receive their own login only if a parent invites them. We never knowingly collect personal information directly from a child under 13 outside the parent-managed flow above.

Group schedule (parent-enabled). Only where a parent enables it, a child may read the title, date, time, place (where the plan shares it with them), cancelled state and their own answer for plans they are included in in that circle. Nothing is sent to the child, no new contact path is created, and no other household's information is shown beyond what those plans already disclose to the child.

Children's privacy outside the US (forward-looking)

GDPR-K (EU/UK/Switzerland): When we open to those regions, we will apply the local age of digital consent (13–16 depending on country) and obtain verifiable parental consent for users below that age.

India DPDP Act 2023: When we open to India, we will obtain verifiable consent from a parent or lawful guardian before processing any personal data of a child (defined as anyone below 18). We do not track, profile, or target advertisements at children. Our processing is designed to meet the children's-privacy requirements of the regions we serve: child data is parent-managed, circle membership is parent-approved, and no behavioural monitoring or targeted advertising is directed at children.

Signing in with Google

If you choose to sign in with Google, Google shares your email address, name, and profile photo with CircleNest so we can create or look up your account. We do not receive your Google password, contacts, calendar, or any other Google data through sign-in. If you separately connect Google Calendar, we receive only the calendar access scopes you approve at that time, and you can revoke them from Settings or from your Google account at any time.

Signing in with phone (SMS)

Phone sign-in is not offered today. CircleNest currently signs you in with an email address and password, or with Google. This section describes how phone sign-in would work if we enable it later: we would send a one-time code to that number via an SMS provider so you can verify it, store the phone number on your account, and use it only to sign you in. You would be able to switch back to email sign-in or remove the phone number at any time from Settings. We will update this policy before turning it on.

Photos you add from your device

When you add a memory, you can pick photos from your device's photo library or take a new one with the camera. On phones and tablets this uses the operating system's own picker or camera, so CircleNest never browses your library — we only receive the specific files you select. Those files are uploaded to our managed file storage and become memories you keep, subject to your household's storage allowance and per-upload limits.

We do not read location metadata (EXIF GPS) out of your photos to build a location history, and we do not run facial recognition on them. The people a photo is associated with are the people you tag. CircleNest does not support video yet; if you pick a video the app tells you it isn't supported and nothing is uploaded.

When you remove a kept photo it goes to Recently Removed and is permanently erased after the recovery window described under "Data retention". If more than one adult kept the same photo, removing your copy does not remove theirs.

Password safety

If you sign in with a password, we check it against a large public database of known-breached passwords at signup and when you change it, and refuse passwords that are known to be compromised. We never store your password in plain text. PINs that you set for kid devices are stored hashed with a one-way algorithm.

How we identify accounts (and duplicates)

We identify you by the sign-in credentials you choose — your email address and/or phone number. We do not fingerprint your device or cross-match accounts by name, date of birth, or other personal details, and we do not run any global "is this the same person?" linking across households. That means it is technically possible for the same human (adult or child) to appear in CircleNest more than once — for example, an adult who signs up with two different email addresses, or a child who has a separate kid profile in each of two households that don't share custody coordination.

For adults this is the same model used by most consumer apps. For kids, we additionally offer a co-parent grantso two adults can share one canonical kid profile rather than create two separate ones; see "Co-parents, trusted adults, and caregivers" below. Erasing a kid profile in your household does not affect a separate kid profile the same child may have in another family's household — you would ask that household to erase their copy.

We refuse adult-account creation on an email address that a parent has sent a pending kid-invite to, so the recipient ends up in the right place (a kid profile under the inviting parent's household) instead of an autonomous adult account.

What we collect

  • Account: name, email, optional phone number, avatar, country (used to determine your region tier).
  • Kid profiles you create: name, birth month and year (used to derive their age tier — we do not collect the exact day), photo, allergies, availability, and a hashed device PIN if you set one.
  • Co-parent, trusted-adult, and caregiver grants: who you granted access to, the access level (co-parent vs trusted-adult vs caregiver), scopes, expiry, and any pending destructive-action queue or demotion appeal.
  • Relationship descriptions between two adults in a household (e.g. partner, spouse, legal guardian, other): who suggested it, who confirmed it, and whether it is confirmed, unconfirmed or withdrawn. These are self-described, are not verified by CircleNest, change no permissions, and are never read by any access decision. A decline is recorded only as "not confirmed" — never as an explanation or a time-stamped rejection shown to the other person.
  • Connection-request history: a private record of trusted-family requests you sent or received, including declines. We use this to throttle repeat requests so a recipient who has declined twice is not pressured by further requests for a short cooldown.
  • Plans, circles, messages, and RSVPs you create or receive. Plan locations are optional and visible to invited families.
  • Photos and files you share in circle or household chats (stored securely; only members of that chat can access them).
  • Household lists and shared sticky notes: your default shopping list, any custom lists you create, and free-form household notes (title, body, color label). Visible to all adults in your household.
  • Kid art: drawings a kid sends from kid mode are stored as PNG images in our private file storage. Only adults with authority over that kid can view them. They are removed automatically after 90 days unless you save one to the kid's timeline. Teens (age 13+) can re-view their own drawings from the last 30 days inside Kid Mode (read-only, no save/hide indicators, no parent activity surfaced).
  • "My things" (child disclosure projection): a parent or other adult with authority over a child may choose to show that child specific items about them — the child's own creations, or a saved memory whose only subject is that child — inside Kid Mode. This creates no new data: it is a read-only view, re-checked on every load against the adult's current authority and the item's own access rules, and it disappears immediately if the sharing is turned off or the adult's authority ends. Children cannot add, edit, delete, save or forward anything from it, nothing about their viewing is recorded, and it is unavailable for the youngest band (under 4) and for kids aged 13+.
  • Moments: short photo posts (up to 4 photos per moment) with an optional caption, shared with your trusted families. Includes any reactions other adults add. Moments expire automatically after 7 days (extendable once, up to 14 days), after which the photos, the moment row, and its reactions are deleted.
  • Vibes: a single-emoji 24-hour ambient status. Someone in your audience can send you one private reaction; only you see it. Vibes auto-clear after 24 hours.
  • "Free to meet" windows: a coarse availability signal you can share or ask about with your trusted families (e.g. "free this afternoon" or "anyone around?"). No location and no precise times are stored; rows are purged shortly after the window ends.
  • Free-to-meet guest links and replies: if you share a free window or ask as a link with someone who has no account, we store the link token, the window, the optional one-line note you typed, and any reply ("free," "maybe," or "can't"), plus the name the responder types and one optional short note they add. A reply also carries an anonymous, random credential scoped to that one link, kept only as a one-way digest, so the responder's own browser can correct that reply instead of creating a second one; it is never shown to you, never reused for another link, and never used to identify or track anyone. We record a coarse rate-limit signal (including the responder's IP address) to stop abuse of the public link. We do not build a profile of the responder, do not track them across sites, and do not email or notify them. Links, credentials and replies are deleted shortly after the window expires or when you revoke the link.
  • "My Goals" (private, self-owned by a young person aged 10+): a short title, an optional target date, and a few step labels the young person types, plus whether each is marked done. This is visible only to that young person: there is no parent or caregiver view of it, no notification or reminder is generated from it, and nothing about it is scored, measured, ranked, or copied into timelines, yearbooks, or memories. Entries are kept until the young person deletes them or the account is deleted. The text is screened by the same controls as other text a child or teen writes in CircleNest.
  • "My Things" and "My Vault" for young people aged 13 and over (self-owned): files and images the young person uploads for themselves — the file itself, a display name they choose, its size and type, and the date. These are theirs: household adults get no inventory, count, index, preview or activity signal from them, and there is no adult browsing view. The young person can view, download, rename or delete their own items. Uploads use the same file types, size limits, scanning and family storage allowance as every other upload in CircleNest, and video is not accepted. Items are kept until the young person deletes them or the account is deleted, and they stay with that same person if their account later becomes an adult account. Lawful parental requests, account/data export and safety escalation remain unchanged — those are explicit, audited routes, never an ambient view.
  • Memories a parent shows a young person aged 13 or over: an adult who kept a memory whose only subject is that young person may choose to show it to them. This creates no copy and gives no ownership: it is a pointer, re-checked on every load against the adult's current authority, the memory's own access rules, and the young person's eligibility. It is view-and-download only — the young person cannot rename it, delete the original, or pass it on — and it disappears immediately when the adult turns sharing off or their authority ends.
  • Kid plan signals (internal field name: "kid event signals"): a private "excited" / "unsure" marker a kid may set on an upcoming plan, visible only to adults with parental authority over that kid.
  • Kid requests: titles, notes, suggested dates, and request types your kids send to adults in the household.
  • Future letters: time-locked letters you write to a child, stored until the unlock month you set (up to 50 years out).
  • Pets in your household: name, optional species/breed, and any short notes you add (e.g. who feeds them, vet basics). Visible to other adults in your household, caregivers you grant, and — only if you add a pet to a circle or plan — trusted families in that surface.
  • Legacy contacts: the name and email of the adult you nominate to step in if something happens to you, plus their accept/decline status. Used only to reach them if a memorialization request is opened on your account.
  • Archived kid profiles: when you archive a kid profile, we keep its data in a paused state (no notifications, no surfaces, no caregiver or trusted-adult access) until you unarchive it or delete it.
  • Timeline pins: which timeline entries you have pinned.
  • Optional Google Calendar tokens (only if you connect calendar sync).
  • External calendars you add and, if you choose to share one with your household, that sharing choice. A calendar you share is visible to the other adults in your household: they can see its events (labelled as shared) and who added it. Sharing is per calendar, off unless you turn it on, and you can stop sharing at any time. Reminder and digest preferences for a shared calendar stay personal to each adult — the other adults do not see yours.
  • Week Ahead calendar choices: for each calendar you've connected, imported or subscribed to, whether you asked for it to be counted in your Week Ahead. Calendars you leave switched off are not included. These choices are yours alone; other people, including families you're connected to, never see them.
  • Reminders for events from your own calendars: if you ask to be reminded about a specific upcoming occurrence, we store which calendar and event occurrence it refers to, the offset you chose (30/60/120 minutes, or day-before / morning-of for an all-day event) and whether that reminder has been sent. Each occurrence is stored separately, and the reminder is deleted when the occurrence passes or stops appearing in the source calendar.
  • Push notification subscriptions: if you opt in, your browser's push endpoint and encryption keys are stored so we can deliver plan reminders and invites.
  • Peace of Mind (presence, not tracking) — only if a parent turns it on for a specific kid: the latitude, longitude and radius a parent saves for a place they name (set from the parent's own device), plus, for that kid, one single row holding the current state only (present, likely, outside saved places or paused), which saved place it refers to, a battery-low flag, and the time it was last updated. The kid's device does the matching itself: no coordinate from a kid's device is ever transmitted to or stored by CircleNest. There is no location history, no trail, no map, no route, no speed and no "last seen" counter. We also store the kid's one-tap replies ("I'm okay", "Running late", "Please call me") and a count of parent "Checking in" nudges for rate-limiting.
  • Browser storage: small items in localStorage (theme, last-seen flags, your accepted terms version) and standard session cookies for sign-in.
  • Audit log of sensitive actions on kid profiles (who did what and when) for safety and abuse investigations. Readable only by CircleNest operators.
  • Basic technical data (device, browser, error stack traces, page URL, IP address) to keep the app running and to debug crashes.
  • Product analytics (feature usage, page views, button clicks, conversion funnels) to understand how people use the app and improve it.

Third-party services we use

  • Cloud infrastructure provider — hosts the app, database, file storage, and authentication.
  • Content-delivery network & edge security provider — sits in front of CircleNest to deliver the app and apply rate limits and automated abuse protections. Processes connection metadata (IP address, request headers, TLS handshake) to do so.
  • Error-monitoring provider — receives crash and error reports (stack traces, browser info, page URL, IP address) so we can fix bugs. We configure this tool to exclude plan content, messages, and kid profile data.
  • Product-analytics provider — receives feature usage, page views, and conversion events to help us understand and improve the app. We configure this tool to exclude plan content, messages, and kid profile data.
  • AI gateway provider — if you use the optional AI Assistant, your prompt and minimal app context are routed through an AI gateway to third-party AI model providers; see the AI Assistant section below. No chat message contents are sent for suggestions or recommendations.
  • Google Calendar — only if you connect calendar sync.
  • Email-delivery provider — sends the account-and-safety emails described in the Transactional emails section.
  • Payment provider & Merchant of Record (Paddle.com) — if you purchase a paid plan, Paddle acts as the seller of record. Paddle receives the billing information you enter at checkout (name, billing address, email, and payment-method details) and processes the payment, tax, invoicing, and any refunds. We receive from Paddle only the information needed to activate and manage your subscription (customer ID, subscription status, plan, and a redacted payment reference); we never see your full card number. See Paddle's privacy notice for their handling.
  • Web Push — your browser's push service (e.g. Apple, Google, Mozilla) delivers notifications you opted in to.

How we use it

To run the service: showing your circles, syncing plans, delivering notifications, and keeping accounts secure. We do notsell your data, and we do not show third-party ads.

Who can see your family's data

Your kid profiles are visible only to you, your co-parents (when you have confirmed them visible in a given circle), trusted adults you have granted (a stepped-back parent, step-parent, or live-in grandparent — visibility only, no authority), active caregivers within the data window you allowed, and other adults who are approved members of the same circles you include those kids in. When you add a kid to a circle or invite a kid to a plan, other approved adults in that circle can see the kid's name, age tier, photo, and availability. Co-parents are hidden from other families by default until you confirm them.

Trusted adults can see the kid's schedule, household notes, the chat threads they are included in, the family memory wall (milestones, kid art, future letters, yearbooks, timeline journal), and the caregivers list. They cannot change kid settings, approve requests, grant other adults, or queue destructive actions. The grant is permanent until you remove it.

Caregivers see only what is needed to actually care for the kid during their window: basic profile, safe places (drop-off, allergies), and the plan chats they are staffed on. They do not see the family's private memory wall (milestones, kid art, future letters, yearbooks, timeline journal), and they lose access automatically when the grant expires, when you revoke it, or after 60 days of inactivity.

Household adults who are not co-parents on a given kid(e.g. a roommate, adult sibling, or a new partner not yet co-parenting) see household-level surfaces such as shared lists, household notes, and groceries. They do not see that kid's private memory wall (milestones, kid art, future letters, yearbooks, timeline journal).

Circle chats and plan conversations are visible only to members of that circle or plan. Photos and files shared in chats are accessible only to members of that specific chat.

"Notes to self" (your private self-chat) is visible only to you. Even for a teen (age 13+) who uses CircleNest, the contents of their own self-chat are not readable by their parents or co-parents — it is treated as a private journal. Younger children do not have access to a self-chat at all.

"Us 💛" (the optional 2-person space between adult household co-members) is created only when both adults choose it — one asks, the other accepts — and it is kept separate from the rest of the household: no other member, and no household administrator, gets access to it by virtue of belonging to or administering the household. Like the rest of CircleNest it is encrypted in transit and at rest, but it is not end-to-end encrypted. It is never surfaced in family chat, timelines, summaries, search, or assistant features, and we do not generate counts, streaks, sentiment, relationship indicators, or comparisons from it, or use participation to infer marital status, partnership status, or any marketing segment. If one of you later leaves the household (for example, after a separation or a member removal), the space is sealed — both sides keep read access to prior history, but no new messages can be sent and the leaver loses access to anything posted afterward.

The Household Admin is an operational role that keeps a household container running: household invites and membership, household display settings, and the household subscription. It is not a family, parenting, custody, guardianship or relationship authority. It grants no access to another adult's Us 💛 space, direct messages, notes to self, or private data; it cannot act as another adult, cannot change anyone's parenting or caregiving grants, and carries no broader export rights than any other adult. Admin can be transferred only when the person nominated confirms it. Payment details — payment method, billing address, and invoices — are visible only to the adult who set up payment, and are not shown to the Household Admin or any other member; other adults see only the plan facts that govern what the household can do (tier, status, renewal date, whether it is set to cancel).

Relationship descriptions between two adults (for example partner, spouse, legal guardian, other) apply only when both adults confirm them. They are how the two of you describe your relationship in CircleNest — they are self-described, are not verified by CircleNest, are not a legal determination of marriage, partnership, guardianship or custody, and are never read by any permission or access decision. Either adult can withdraw a confirmed description at any time, an unconfirmed suggestion simply expires, a decline is not explained or announced, and leaving the household clears the shared description.

Plan locations are visible to all invited families.

Household lists and kid requests are visible to all adults in your household. Kids can see and create their own requests; accepted requests may be added to your default shopping list.

Future letters are visible to you (the author) before the unlock date. After the unlock date, they become visible to the child they were written for and to the adults with parental authority on that kid (you, your co-parents, and any trusted-adult co-parents). Caregivers and other household adults do not see them.

Timelines and yearbooks. Each adult has a personal timeline. Every entry is private by default — only you can see it. When you save a new entry, you may choose to share that single entry with adults who share parental authority with you (your co-parent on a kid you both parent). This choice is made at the moment of savingand is per-entry; entries cannot be retroactively shared or unshared from the timeline view. Each kid has a household timeline that only the kid themselves, the primary parent, and active co-parents can read (caregivers and connected families cannot).

Per-kid yearbook PDFs compile a single kid's timeline entries for a chosen year. They are stored in our private file storage and only downloadable by adults with authority over that kid (primary parent or active co-parent). A stored yearbook file is kept for 30 days so you can re-download it, and is then removed from our storage. The timeline entries it was built from are unaffected, and you can build the yearbook again later.

Household yearbook PDFs compile a chronological, author-labeled merge of the timelines you select (yourself, kids you have authority over, and optionally a co-parent — for whom only entries they explicitly marked shared are included). The PDF is generated on demand from data you can already see in the app, returned directly to your device, and is not stored on our servers after generation. Public share links for timelines and yearbooks have been removed — there is no link-based sharing for either feature.

AI Assistant

Status. The in-app AI Assistant is an optional feature currently on probation. It may be changed, limited, or removed based on usage evidence and cost review. When it is enabled for your household, you can ask it in plain language to help draft plans, messages, or RSVPs.

What is sent. Only the messages you type in the Assistant thread and a small set of read-only app context (for example, your circles, upcoming plans, and open conversations) are sent to third-party AI model providers through an AI gateway. The Assistant does not read the contents of your family chats, your notes-to-self, your "Us 💛" thread, timeline entries, photos, drawings, or future letters for suggestions or recommendations.

What it can do. The Assistant returns structured drafts — such as a proposed plan, a proposed message, or a proposed RSVP. It cannot write anything directly to your account. A human must review and confirm every draft before it is saved, sent, or posted. If any cost or safety limit is reached, the Assistant returns a deterministic, non-AI fallback instead.

Limits and controls. Use of the Assistant is capped per user, per household, and app-wide, with a master kill switch. Under our gateway agreements, providers process requests to return a result and do not use this content to train their models. Avoid putting sensitive personal information in prompts.

Push notifications & quiet hours for kids

Push notifications sent to a kid device never include message previews on the lock screen — only a generic "CircleNest / Something new — tap to open" placeholder. Kid devices are also silenced automatically between 9:00 PM and 7:00 AM in the kid's local time. Notifications to children under 13 are blocked entirely.

Love taps. A parent may send a kid a "love tap" — a small heart with no message content. Love taps are not counted, streaked, or shown with a read receipt, and they never include text on the kid's lockscreen.

Peace of Mind — presence, not tracking

Not a safety device. CircleNest cannot locate your child, cannot tell you whether they are safe or being pressured, and may not update if their phone is off, out of signal, or has location turned off. iPhone browsers cannot report presence while the app is closed. In an emergency, call your child, then your local emergency number.

Peace of Mind is off by default for every child, every plan and every region. A parent with authority over the child must turn it on and accept the disclaimer above, and the child must grant their device's own location permission — which they can withdraw at any time. Children aged 16–17 must additionally give their own affirmative in-app agreement before presence turns on. Children can pause presence themselves at any time. Where local children's-data rules require further review, the feature is blocked entirely.

How it works. A parent names a place (e.g. "School") and saves its coordinates from their own device. The child's device compares its own location to those saved places locally, in the browser, and sends CircleNest only a place reference and a state. We never receive, log, or store a coordinate reported by a child's device.

Who can see it. Only authority adults — the primary parent and an active co-parent. Never caregivers, trusted adults, grandparents, coaches, other households, or any connected family. Suspended co-parents are excluded.

Silence is never a signal. No missed check-in badge, no escalation, no notification when a child does not reply. A child's tap is recorded as an event ("Emma checked in — running late"), never as a verdict that they are safe. "Please call me" is the one message that bypasses adult quiet hours.

Our commitment. CircleNest does not build live family maps, location history, breadcrumb trails, speed or driving scores, location behaviour analytics, or location-based advertising, and does not show a child's presence to any adult outside the authority adults above. We have no plans to change this. If we ever did, we would notify you in advance under “Changes to this notice” below and, where the law requires it, obtain consent first.

External links in chat

URLs shared in chat messages are rendered client-side as plain text chips. CircleNest does not fetch, preview, or extract metadata from linked websites. Adults who tap a link see an interstitial reminder before the site opens. Kids cannot navigate to external sites from chat — tapping a link shows a blocked dialog instead. We do not track which links you click, and we do not share link data with third parties.

Transactional emails

We send a small number of account-and-safety emailsfrom notify.circlenestapp.com: sign-in verification codes and magic links, password resets, account-data deletion confirmations, notice that a co-parent grant has been received, notice that a destructive action has been queued for the 48-hour hold, notice that a co-parent reset a kid's PIN, and notice that a co-parent demotion has been initiated (with the 7-day appeal window). These are operational messages required to use CircleNest safely; they are not marketing and you cannot unsubscribe from them while your account is active. Routine in-app activity (plan invites, RSVPs, chat, love taps, kid art) is delivered as push notifications, not email.

Public plan links (guests)

A host may choose to share a plan with people who are not on CircleNest by generating a public RSVP link. Public links are blocked for any plan that has a child attached — they're only available for adult-only plans such as a parents' dinner or birthday. The guest page shows only the plan title, time, the host's first name, the place as the host typed it (or simply “Private location” — see below), and any notes the host marks for sharing — never other invitees, attendance counts, household composition, or any child's information. Guests submit a name, an optional email (for updates only), their answer, and how many people are coming. Guests cannot write free-form notes, send messages, upload photos, or see anyone else's reply. We store the responder's IP briefly for abuse prevention.

Every guest link has an absolute expiry. A guest link stops working 14 days after the plan ends, and also stops immediately if the host revokes it or deletes or archives the plan — whichever comes first. After that the page simply says the link is no longer active. Guest responses are deleted when the link is revoked, when the plan is deleted, or within 60 days after the plan ends.

Private locations. A host can mark a place as private (for example, a home address). In that case the guest page shows only “Private location”. The actual place is revealed to a guest only after they reply, and only if the host turned that reveal on. Hosts see exactly what a guest will see before sharing.

Calendar, QR and keeping a plan. A guest can add the plan to their own calendar; that produces a plain calendar file containing the same limited fields shown on the page. A host can display the shareable summary as a QR code — the code is generated on the host's own device and contains only that same summary text. If a guest later creates a CircleNest account, they may choose to keep the plan: nothing is imported unless the guest explicitly taps to claim it, and claiming links only their own reply to their new account.

For this specific sharing act, the host is the data controller of the contact details they collect via the link; CircleNest acts as processor. Guest pages are markednoindex and carry no images, avatars or link previews, so nothing leaks into a group-chat preview. Requests from link-preview bots and scanners are recognised and never treated as a person, never reveal a private location, and never change anything. For guest pages we keep only aggregate daily counts (how many pages were served, how many replies completed, how many links were stale) — no per-guest analytics profile.

Moments, Vibes & Free to meet (adults only)

Moments (short photo posts) are visible only to you and the trusted families you've connected with. Reactions on a moment are visible to the same audience. Kids never see Moments and there are no kid-authored Moments.

Vibes (24-hour ambient status) are visible to a single audience you pick as your default in Settings — either your circles or your trusted families. A reaction to a vibe is private from sender to recipient: only the recipient sees it, and no one can see reaction counts, who viewed a vibe, or when it was set.

Free to meet windows are visible inside CircleNest only to your accepted trusted families and only while the window is live. We do not broadcast them via push or email. Teens (13+) in your household may see their own household's window and those of already-connected trusted families, read-only.

Free-to-meet guest links are the one exception, and only when you deliberately create one. The page a guest opens shows your name as it already appears in CircleNest, the window you chose, and your optional one-line note — nothing about your address, your kids, your circles, your other availability, or who else replied. The link is revocable, expires with the window, and a reply never creates a plan by itself.

Parent Peek

From a kid's profile, an adult with parental authority can open a read-only "Parent Peek" — a summary of that kid's upcoming plans, open jobs, and pending requests. Parent Peek does not show the kid's private chats, drawings, notes-to-self, PIN, or any other private surface, and it does not bypass kid-mode protection on the kid's own device.

Designated circle conversation (approved teens)

Where a parent enables it for a child aged 13 or over, that child can read messages written in one designated circle conversation from the moment access starts, and — if the parent chose can write — write plain text messages there. Everything written in that conversation is visible to the adults in that conversation and to a qualifying parent in the child's family. It is not private notes: a teen's own notes-to-self elsewhere in CircleNest are unaffected by this and are not covered by it.

After a parent turns it off, or if the qualifying parent's ability to read that exact conversation ends, the child can no longer read or write there. Messages already sent stay in the conversation for the adults who could already see them; a qualifying parent's ability to read the earlier history follows the same rule as the rest of that conversation — it is neither silently extended nor silently removed.

Under an export or data request, designated circle conversation content appears in the export of the household whose member wrote it, and in the record of the conversation for the households that could already read it. Because a conversation is shared, a deletion request from one participant is normally handled by removing their own content rather than by editing another household's record of the conversation; where the law that applies to you requires more, we handle the request under the process described in this policy. When a household leaves the circle, or the circle itself is archived or deleted, that content follows the retention that applies to circle conversations.

A message written by an adult in that conversation may have a file attached. For an approved teen the file itself is not delivered: the teen's view shows only that a file was attached, and we issue no access link, no download and no preview image for it. A teen cannot attach a file. No notification of any kind is sent to a teen about that conversation — access is pull-only.

Memorialization & future letters

If your account is memorialized, any scheduled future letters pending delivery are paused by default. Your legacy contact may choose to allow delivery on the original schedule, hold them indefinitely, or have them deleted unsent. See our memorialization process for full details.

Kid plan actions

Kids in Kid Mode may take two plan-related actions that follow our standing rule: any kid-initiated cross-family signal goes to the kid's own household first, never to the other family.

Say thanks 💛. For up to 48 hours after a plan ends, an eligible kid can send a thank-you. It is delivered to the adults in the kid's own household only. The host family is not notified, and we do not surface counters like "X kids thanked you."

Private "excited / unsure" pre-react. On an upcoming plan, a kid may set a private signal. It is visible only to adults with parental authority over that kid (primary parent and active co-parents). The host, other families, caregivers, and trusted adults never see it, and no notifications are sent when it is set or cleared.

Kid allowances (per-feature restrictions)

A primary parent or co-parent may restrict a single capability for a kid (for example, free-text chat or voice notes) from the kid's Controls → Allowances. Adding a restriction takes effect immediately. Lifting a restriction is immediate when the primary parent does it; when a co-parent lifts a restriction, it enters the standard 48-hour destructive-action hold so the primary parent (or another co-parent) has a chance to review or cancel before it takes effect.

Co-parent demotion & appeal window

Demoting a co-parent (to trusted-adult, or removing the grant entirely) enters a 7-day appeal window before it takes effect, during which the affected co-parent is notified and either side may cancel the demotion in the app. Other sensitive actions a co-parent initiates — removing a trusted family, leaving or removing the kid from a circle, lifting an allowance — enter a 48-hour hold as described elsewhere in this Policy.

Pets

Pets you add to your household are part of your household profile. They are visible to other adults in your household, to caregivers you grant (so a sitter knows who to feed), and to trusted-adult grantees. Pets are not surfaced to other families unless you choose to mention them in a circle, plan, or chat. Pets do not have their own logins, push tokens, or any independent data footprint — they are descriptive entries you maintain.

Archiving a kid profile

Archiving a kid profile pauses everything tied to that kid: invites, requests, kid-mode access, caregiver and trusted-adult grants, future letters scheduled for them, notifications, and timeline activity. The profile stops appearing on family pages and rosters. No data is deleted by archiving. You can unarchive at any time and surfaces resume where they paused. If you delete an archived kid profile from Trash, the standard 30-day recoverable-deletion window applies.

Memorialization & legacy contacts

Legacy contacts. You may nominate an adult who already has a CircleNest account as your legacy contact. They are notified and must accept. Their role is narrow: if you become permanently unreachable, they may request that your account be memorialized, pause your scheduled future letters, and help coordinate a hand-off of any kid profiles you parent to a co-parent or guardian. A legacy contact does not gain access to your messages, notes-to-self, "Us 💛" thread, or timelines while you are alive, and even after memorialization they do not get login-level access to your private content.

Memorialization request. A legacy contact, a household co-parent, or a verified next of kin may open a memorialization request from the in-app flow. We require documentation appropriate to the request (for example, a death certificate or a court order) before any memorialization action is taken. While a request is in review, future letters scheduled to deliver in the near term are paused so they don't send before the situation is confirmed.

What a memorialized account looks like. The account is set to a read-restricted state: no new sign-ins, no outbound messages, no scheduled posts. Co-parented kid profiles transfer primary-parent status to the surviving co-parent so kids stay on the platform with their day-to-day adult. Future letters previously written by the account holder are released on their original schedule unless a legacy contact or the kid's primary parent asks us to pause or cancel a specific letter. Adults named on the account or in your household may request memorial-only access to view non-private memories the account holder had marked shareable; the account holder's private notes-to-self, "Us 💛" thread, and unsaved drafts are not released.

Reversal. If a memorialization is opened in error, the account holder (or a legal representative with authority) can request reversal from contact@circlenestapp.comand we will restore the account on verified request.

Shared plans on your calendar

Your calendar may show plans from three layers: (1) plans you host, (2) plans you were invited to and RSVP'd, and (3) plans another household chose to share with you for context as a read-only "FYI" (for example, a co-parent's plan with your shared kid, or a trusted family letting you know what they're up to). Layer (3) entries are read-only on your side — the owning household controls edits, attendance, and deletion, and the host's name and household are always shown alongside the plan so you can tell which household owns it. FYI shares are only ever fanned out to adult household members; kids never see another household's FYI plans. You can hide any FYI plan from your own calendar at any time without affecting the source plan or anyone else's view, and when a trusted-family connection is removed, FYI shares between those households are automatically cleaned up.

Cookies & browser storage

CircleNest does not use advertising cookies, cross-site tracking, or behavioural profiling. We use a small number of strictly first-party items:

  • Session cookies set by our authentication provider so you stay signed in.
  • localStorage for your theme preference, your accepted terms version, your cookie-notice acknowledgement, and a few last-seen flags so we don't re-show dismissed notices.
  • Service Worker cache if you install CircleNest as an app, so it works briefly offline.
  • An on-device photo cache (browser IndexedDB, or private app storage on native) holding copies of photos you have already been shown, so revisiting them is instant instead of re-downloading. It is size-bounded, evicts the oldest items automatically, and is cleared when you sign out or switch accounts. It is a speed layer only: it never grants access to anything you are not currently allowed to see, and if access is revoked the cached copy stops being shown.

We show a one-time, dismissible cookie notice on first visit. You can clear all of this at any time from your browser's site-data settings, or by signing out and deleting your account.

Security of your data

We use industry-standard administrative, technical, and physical safeguards designed to protect your information — including encryption in transit, encryption at rest for our managed database and file storage, role-based access controls, automated abuse protections, and breach-detection tooling. However, no method of transmission over the internet or method of electronic storage is perfectly secure, and we cannot guarantee absolute security.You also have an important role: use a strong, unique password, do not share your sign-in credentials, and let us know promptly if you believe your account has been compromised.

Data retention

Individual items you delete (kid profiles, plans, circles, and timeline entries) are held in a recoverable trash for 30 days and can be restored from your Profile; after that they are permanently erased. We keep your account data while your account is active. When you request to delete your account, we hold it for a 30-day grace period during which you can sign back in and cancel the deletion. After the 30 days, your profile, plans you hosted, circles you created, messages you sent, and any kid profiles you parent who have no other parent on the account are erased. Kids with a co-parent are not deleted — primary-parent status is transferred to the co-parent so the kid's account, circles, and history stay intact. Encrypted database backups may retain a copy for up to 30 days after that before being overwritten on their normal rotation. Chat text messages are retained for 2 years (730 days) from when they were sent, then automatically deleted. Messages you mark as "Keep" are exempt and stay until you unsave or delete them. Chat photos and file attachments are deleted from storage after 365 days; an "Attachment expired" placeholder remains for up to 90 more days (455 days total) before the row is purged. Saved attachments are exempt. Event group chats are purged 30 days after the plan's date, regardless of the chat floors above. Voice notes sent in chat are automatically deleted after 30 days, even if you do not delete your account. Kid art that you do not save to a kid timeline is automatically deleted after 90 days; the kid-only view of recent drawings inside Kid Mode is limited to teens (age 13+) and to the last 30 days. Plans (events) and their invites, RSVPs, carpool offers, and duty assignments are kept for 2 years after the plan's date, then automatically deleted. Moments are deleted automatically when their expiry passes (default 7 days; up to 14 days if the author extended once). Vibes auto-clear after 24 hours. "In the moment" free-windows (a coarse signal like "free now," "this afternoon," or "this weekend" that you can broadcast to your trusted families) auto-expire at the time you set, and the row is purged within 7 days of expiry. We do not store location, exact times, or any kid data on these windows. Kids age 13+ in Kid Mode may see a read-only "Families free" strip showing the same coarse bucket (e.g. "Free now," "This evening") for households your family has connected with as a trusted family. Kids cannot set, change, or broadcast a window — only adults can. Audit log entries are kept up to 2 years for security-relevant actions (authentication, role changes, kid data operations, destructive changes) and 180 days for routine activity, then automatically purged. Kid activity log (the per-kid action feed parents can review) is retained for 2 years. Notifications are kept for 90 days once read, and unread notifications auto-mark-read after 180 days with a 30-day grace before deletion. Push subscriptions are deleted immediately when you turn notifications off or sign out. Proof of consent (the version of the Terms and Privacy Policy you accepted, the timestamp, your IP address, and your browser user-agent) is retained for the life of your account as evidence that you agreed to the policy in effect at that time, and is deleted with the rest of your account on request. Peace of Mind presence is stored as a single current-state row per child that is overwritten in place — there is no history to retain. It is deleted when a parent turns the feature off, when the child's profile is archived or erased, and with the rest of your account. Parent-saved place coordinates live only as long as the saved place itself. One-tap check-in replies and parent nudge counters are kept for 30 days, then purged.

No indefinite retention. We keep personal information only as long as needed for the specific purposes described in this policy, or for as long as a legal, tax, security, or dispute-related obligation requires. We do not retain personal information indefinitely for unspecified “business purposes.” This applies with particular force to children's information: a child's data is kept to operate the child's profile for the parent who created it, is deleted on the schedules above, and is deleted when the parent deletes the profile or withdraws consent (unless another parent on the account keeps the profile active).

Subscription & billing records. If you purchase CircleNest Plus, we retain the subscription record we need to operate your entitlement (customer and subscription identifiers, plan, status, period dates, and a redacted payment reference) while the subscription is active and for up to 7 years afterwards where required for tax, accounting, and dispute records. Payment-method details, invoices, and refund records are held by Paddle as Merchant of Record under their own retention practices — we never hold your full card number.

What “private” means in CircleNest

When a surface is described as private (notes to self, Keeps, the “Us 💛” thread, a kid's drawings, a kid's private pre-reactions), it is visible only to the audience that feature defines, and those boundaries are enforced in the database, not only in the interface. It does not mean end-to-end encryption. Content is encrypted in transit and at rest, but our infrastructure providers necessarily store and transmit it, a small number of authorised personnel may access it only where strictly necessary to operate, secure, or support the service or to investigate an abuse or safety report, and we may disclose content where legally required or to address a credible risk to someone's safety. We log administrative access to kid data.

Staff access to your data

We do not claim that CircleNest is technically unable to see your content — that would not be true of any service that has to operate, back up, and support itself. What we do commit to is how that capability is used:

  • Access to an individual family's information is restricted by role on the server, not merely hidden in the interface.
  • Our operational dashboards are built around aggregates rather than individual records, so day-to-day running of the service does not involve reading family content.
  • Access to an individual family's information happens only for a specific purpose — a privacy or data-rights request, an abuse or safety report, a support investigation you have asked us to look into, or a security incident.
  • Sensitive administrative actions are recorded in an audit log.
  • We do not use bulk export of family content as a routine operational tool.

As the team grows, additional controls — least-privilege roles, a recorded reason for access, time-bounded elevation where practical, and strong administrator authentication — are prerequisites for granting anyone else this capability.

Your rights

  • Export your data — Profile → Account → Export my data.
  • Delete your account and your kids' profiles — Profile → Account → Delete account.
  • Disconnect Google Calendar at any time from Settings.
  • Turn off push notifications at any time from Settings → Notifications or in your browser settings.
  • India DPDP rights: If you are in India, you have the right to access, correct, update, and erase your personal data; the right to grievance redressal; and the right to nominate another individual to exercise your rights in case of death or incapacity. Contact us to exercise any of these rights.

EEA, UK & Swiss rights (GDPR)

If you are in the European Economic Area, the United Kingdom, or Switzerland, you have the right to (a) access the personal data we hold about you, (b) correct inaccurate data, (c) erase your data ("right to be forgotten"), (d) restrict or object to certain processing, (e) receive your data in a portable format, and (f) withdraw consent at any time without affecting prior lawful processing. Our legal bases for processing are your consent (for kid profiles, push notifications, calendar sync, and AI Assistant), performance of our service contract with you (running your account), and our legitimate interest in keeping the app secure and debugging crashes. You also have the right to lodge a complaint with your local supervisory authority.

California rights (CCPA / CPRA)

If you are a California resident, you have the right to know what personal information we collect, the right to delete it, the right to correct it, the right to data portability, the right to limit the use of sensitive personal information, and the right not to be discriminated against for exercising any of these rights. We do not sell or share your personal information for cross-context behavioural advertising, and we do not use or disclose sensitive personal information for any purpose other than running CircleNest. To exercise any of these rights, contact us at the email below.

Global Privacy Control (GPC). Because we do not sell or share personal information for cross-context behavioural advertising, there is no opt-out for us to honor in response to a GPC browser signal — your data is already not sold or shared. If that ever changes, we will treat a GPC signal as a valid opt-out request under the CCPA/CPRA and equivalent state laws.

Other US state privacy rights

If you are a resident of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), Oregon (OCPA), Montana, Delaware, Iowa, New Jersey, New Hampshire, Tennessee, or another US state with a comprehensive privacy law, you generally have the right to (a) confirm whether we process your personal data and access it, (b) correct inaccuracies, (c) delete personal data you provided or that we obtained about you, (d) obtain a portable copy, and (e) opt out of (i) targeted advertising, (ii) the sale of personal data, and (iii) profiling in furtherance of solely automated decisions with legal or similarly significant effects.

CircleNest does not engage in targeted advertising, does not sell personal data, and does not use automated decision-making that produces legal or similarly significant effects, so the opt-out rights above are satisfied by default. To exercise access, correction, deletion, or portability rights — or to appeal a decision we make on a privacy request — email contact@circlenestapp.com. We will respond within the timeframe required by your state's law (typically 45 days, extendable once).

Data breach notification

If we become aware of a security incident that compromises your personal information, we will investigate promptly and notify affected users and the appropriate regulators in line with applicable law — including, where required, within 72 hours of becoming aware (GDPR / UK GDPR), without unreasonable delay (most US state laws and India's DPDP Act), and through the in-app notice and email channels you have provided. Our notification will describe what happened, what data was involved, what we are doing in response, and the steps you can take to protect yourself.

Grievance officer (India)

Under the Digital Personal Data Protection Act, 2023, users in India may raise concerns about personal data processing through our grievance mechanism. Please reach out via Send feedback and mark the subject as "Data Grievance — India". We will acknowledge your complaint within 48 hours and aim to resolve it within 30 days. You may also escalate unresolved grievances to the Data Protection Board of India.

Changes to this policy

When we make material changes we update the date above and ask you to re-accept on next app load. Continued use after that means you agree to the updated policy.

Contact

Questions, privacy requests, or rights requests (GDPR, CCPA, COPPA, DPDP)? Email contact@circlenestapp.com or send a note from Send feedback. We aim to respond within 30 days.

See also our Terms of Service, Refund Policy, and our Privacy summary for kids.