Skip to main content

Privacy Policy

Version 1.0 — effective the date you first access the service.

A note on wording. Throughout this policy, "Plan" (or "Plans") refers to any scheduled activity you create or are invited to in CircleNest — playdates, pickups, classes, practices, parties, and the like. Our backend systems, data exports, and developer-facing fields may also call these "events"; the two terms refer to the same thing.

CircleNest™ · Patent Pending · © 2026 CircleNest LLC

Where CircleNest is available

CircleNest is currently offered only to residents of the United States. The sections below that describe rights under the EU/UK GDPR or India's DPDP Act are included to document our forward commitments; they will become operative when we expand to those regions. Until then, your primary protections are COPPA (for children under 13), CCPA/CPRA (for California residents), and the other US state privacy laws described below.

Operator

CircleNest is operated by CircleNest LLC, a US-based limited liability company (registered mailing address available on request — 8 The Green #13755, Dover, DE, 19901, United States). Privacy questions: contact@circlenestapp.com.

Who we are

CircleNest is a private family scheduling app. Parents and guardians use CircleNest to coordinate playdates, plans, and trusted family circles. This Privacy Policy explains what information we collect and how we use it.

Notice to Parents (COPPA Direct Notice)

This section is our Direct Notice to Parentsunder the Children's Online Privacy Protection Act (COPPA), 16 C.F.R. Part 312.

Who we are. CircleNest is operated by CircleNest LLC, a US-based limited liability company (registered mailing address available on request — 8 The Green #13755, Dover, DE, 19901, United States). Contact: contact@circlenestapp.com.

What we collect from children under 13. Only what a parent enters into a kid profile: first name (or nickname), birth month and year, optional photo, allergies, availability, and — if the parent sets one — a device PIN stored hashed with a one-way algorithm. If a parent enables an in-app kid login, we also store sign-in timestamps and the device the kid signs in from. We do not ask children to provide more than is reasonably necessary to participate.

How we use it. Solely to operate CircleNest — showing the kid in the parent's household, in circles the parent approves, on plans the parent invites them to, and in chats the parent authorizes. We do not use child data for advertising, behavioural profiling, or sale.

Disclosure. Child information is disclosed only to other adults the parent has approved into the same circle or plan, and to the service providers listed under "Third-party services we use" (hosting, error monitoring, analytics, push-notification delivery). We do not sell or share child data with advertisers.

Verifiable parental consent (COPPA). Because CircleNest does not disclose a child's personal information to the public or to third parties outside the service providers listed below, we rely on the FTC's "email plus" sliding-scale method for verifiable parental consent. When you add a kid profile, the consenting parent must (a) be signed in to a verified adult account tied to a working email address, (b) affirmatively accept this Privacy Policy and the Terms of Service, and (c) confirm the action from that same email address if we send a follow-up confirmation request. We will move to a stronger verification method (such as a government-ID check, signed consent form, or payment-card verification) before enabling any feature that would disclose a child's information outside CircleNest.

Parent rights. A parent may at any time (1) review the personal information we have collected from or about their child, (2) refuse to permit further collection or use, and (3) require us to delete it. Use Household → the kid profile, or email contact@circlenestapp.com. Deleting the kid profile or the parent account removes the child's data as described in "Data retention" below.

Kids aged 13–17 may receive their own login only if a parent invites them. We never knowingly collect personal information directly from a child under 13 outside the parent-managed flow above.

Children's privacy outside the US (forward-looking)

GDPR-K (EU/UK/Switzerland): When we open to those regions, we will apply the local age of digital consent (13–16 depending on country) and obtain verifiable parental consent for users below that age.

India DPDP Act 2023: When we open to India, we will obtain verifiable consent from a parent or lawful guardian before processing any personal data of a child (defined as anyone below 18). We do not track, profile, or target advertisements at children. Our processing is designed to meet the children's-privacy requirements of the regions we serve: child data is parent-managed, circle membership is parent-approved, and no behavioural monitoring or targeted advertising is directed at children.

Signing in with Google

If you choose to sign in with Google, Google shares your email address, name, and profile photo with CircleNest so we can create or look up your account. We do not receive your Google password, contacts, calendar, or any other Google data through sign-in. If you separately connect Google Calendar, we receive only the calendar access scopes you approve at that time, and you can revoke them from Settings or from your Google account at any time.

Signing in with phone (SMS)

If you choose to sign in with your phone number, we send a one-time code to that number via our SMS provider so you can verify it. We store the phone number on your account and use it only to sign you in. You can switch back to email sign-in or remove the phone number at any time from Settings.

Password safety

If you sign in with a password, we check it against a large public database of known-breached passwords at signup and when you change it, and refuse passwords that are known to be compromised. We never store your password in plain text. PINs that you set for kid devices are stored hashed with a one-way algorithm.

How we identify accounts (and duplicates)

We identify you by the sign-in credentials you choose — your email address and/or phone number. We do not fingerprint your device or cross-match accounts by name, date of birth, or other personal details, and we do not run any global "is this the same person?" linking across households. That means it is technically possible for the same human (adult or child) to appear in CircleNest more than once — for example, an adult who signs up with two different email addresses, or a child who has a separate kid profile in each of two households that don't share custody coordination.

For adults this is the same model used by most consumer apps. For kids, we additionally offer a co-parent grantso two adults can share one canonical kid profile rather than create two separate ones; see "Co-parents, trusted adults, and caregivers" below. Erasing a kid profile in your household does not affect a separate kid profile the same child may have in another family's household — you would ask that household to erase their copy.

We refuse adult-account creation on an email address that a parent has sent a pending kid-invite to, so the recipient ends up in the right place (a kid profile under the inviting parent's household) instead of an autonomous adult account.

What we collect

  • Account: name, email, optional phone number, avatar, country (used to determine your region tier).
  • Kid profiles you create: name, birth month and year (used to derive their age tier — we do not collect the exact day), photo, allergies, availability, and a hashed device PIN if you set one.
  • Co-parent, trusted-adult, and caregiver grants: who you granted access to, the access level (co-parent vs trusted-adult vs caregiver), an optional self-chosen relationship label on a household member (e.g. partner, spouse, legal guardian, other) that is descriptive only and does not change permissions, scopes, expiry, and any pending destructive-action queue or demotion appeal.
  • Connection-request history: a private record of trusted-family requests you sent or received, including declines. We use this to throttle repeat requests so a recipient who has declined twice is not pressured by further requests for a short cooldown.
  • Plans, circles, messages, and RSVPs you create or receive. Plan locations are optional and visible to invited families.
  • Photos and files you share in circle or household chats (stored securely; only members of that chat can access them).
  • Household lists and shared sticky notes: your default shopping list, any custom lists you create, and free-form household notes (title, body, color label). Visible to all adults in your household.
  • Kid art: drawings a kid sends from kid mode are stored as PNG images in our private file storage. Only adults with authority over that kid can view them. They are removed automatically after 90 days unless you save one to the kid's timeline. Teens (age 13+) can re-view their own drawings from the last 30 days inside Kid Mode (read-only, no save/hide indicators, no parent activity surfaced).
  • Moments: short photo posts (up to 4 photos per moment) with an optional caption, shared with your trusted families. Includes any reactions other adults add. Moments expire automatically after 7 days (extendable once, up to 14 days), after which the photos, the moment row, and its reactions are deleted.
  • Vibes: a single-emoji 24-hour ambient status with up to 6 emoji reactions from your audience. Vibes auto-clear after 24 hours.
  • "Free to meet" windows: a coarse availability signal you can broadcast to your trusted families (e.g. "free this afternoon"). No location and no precise times are stored; rows are purged shortly after the window ends.
  • Kid plan signals (internal field name: "kid event signals"): a private "excited" / "unsure" marker a kid may set on an upcoming plan, visible only to adults with parental authority over that kid.
  • Kid requests: titles, notes, suggested dates, and request types your kids send to adults in the household.
  • Future letters: time-locked letters you write to a child, stored until the unlock month you set (up to 50 years out).
  • Pets in your household: name, optional species/breed, and any short notes you add (e.g. who feeds them, vet basics). Visible to other adults in your household, caregivers you grant, and — only if you add a pet to a circle or plan — trusted families in that surface.
  • Legacy contacts: the name and email of the adult you nominate to step in if something happens to you, plus their accept/decline status. Used only to reach them if a memorialization request is opened on your account.
  • Archived kid profiles: when you archive a kid profile, we keep its data in a paused state (no notifications, no surfaces, no caregiver or trusted-adult access) until you unarchive it or delete it.
  • Timeline pins: which timeline entries you have pinned.
  • Optional Google Calendar tokens (only if you connect calendar sync).
  • Push notification subscriptions: if you opt in, your browser's push endpoint and encryption keys are stored so we can deliver plan reminders and invites.
  • Browser storage: small items in localStorage (theme, last-seen flags, your accepted terms version) and standard session cookies for sign-in.
  • Audit log of sensitive actions on kid profiles (who did what and when) for safety and abuse investigations. Readable only by CircleNest operators.
  • Basic technical data (device, browser, error stack traces, page URL, IP address) to keep the app running and to debug crashes.
  • Product analytics (feature usage, page views, button clicks, conversion funnels) to understand how people use the app and improve it.

Third-party services we use

  • Cloud infrastructure provider — hosts the app, database, file storage, and authentication.
  • Content-delivery network & edge security provider — sits in front of CircleNest to deliver the app and apply rate limits and automated abuse protections. Processes connection metadata (IP address, request headers, TLS handshake) to do so.
  • Error-monitoring provider — receives crash and error reports (stack traces, browser info, page URL, IP address) so we can fix bugs. We configure this tool to exclude plan content, messages, and kid profile data.
  • Product-analytics provider — receives feature usage, page views, and conversion events to help us understand and improve the app. We configure this tool to exclude plan content, messages, and kid profile data.
  • AI gateway provider — processes AI Assistant prompts and Smart Suggestions inputs by routing them to third-party AI model providers; see the AI features section below.
  • Google Calendar — only if you connect calendar sync.
  • Email-delivery provider — sends the account-and-safety emails described in the Transactional emails section.
  • Web Push — your browser's push service (e.g. Apple, Google, Mozilla) delivers notifications you opted in to.

How we use it

To run the service: showing your circles, syncing plans, delivering notifications, and keeping accounts secure. We do notsell your data, and we do not show third-party ads.

Who can see your family's data

Your kid profiles are visible only to you, your co-parents (when you have confirmed them visible in a given circle), trusted adults you have granted (a stepped-back parent, step-parent, or live-in grandparent — visibility only, no authority), active caregivers within the data window you allowed, and other adults who are approved members of the same circles you include those kids in. When you add a kid to a circle or invite a kid to a plan, other approved adults in that circle can see the kid's name, age tier, photo, and availability. Co-parents are hidden from other families by default until you confirm them.

Trusted adults can see the kid's schedule, household notes, the chat threads they are included in, the family memory wall (milestones, kid art, future letters, yearbooks, timeline journal), and the caregivers list. They cannot change kid settings, approve requests, grant other adults, or queue destructive actions. The grant is permanent until you remove it.

Caregivers see only what is needed to actually care for the kid during their window: basic profile, safe places (drop-off, allergies), and the plan chats they are staffed on. They do not see the family's private memory wall (milestones, kid art, future letters, yearbooks, timeline journal), and they lose access automatically when the grant expires, when you revoke it, or after 60 days of inactivity.

Household adults who are not co-parents on a given kid(e.g. a roommate, adult sibling, or a new partner not yet co-parenting) see household-level surfaces such as shared lists, household notes, and groceries. They do not see that kid's private memory wall (milestones, kid art, future letters, yearbooks, timeline journal).

Circle chats and plan conversations are visible only to members of that circle or plan. Photos and files shared in chats are accessible only to members of that specific chat.

"Notes to self" (your private self-chat) is visible only to you. Even for a teen (age 13+) who uses CircleNest, the contents of their own self-chat are not readable by their parents or co-parents — it is treated as a private journal. Younger children do not have access to a self-chat at all.

"Us 💛" (the optional 2-person thread between adult household co-members) is visible only to the two of you. It is never surfaced in family chat, timelines, the AI Assistant, or any other view. We do not generate counts, streaks, or comparisons from it. If one of you later leaves the household (for example, after a separation or a member removal), the thread is automatically sealed — both sides keep read access to prior history, but no new messages can be sent and the leaver loses access to anything posted afterward.

Plan locations are visible to all invited families.

Household lists and kid requests are visible to all adults in your household. Kids can see and create their own requests; accepted requests may be added to your default shopping list.

Future letters are visible to you (the author) before the unlock date. After the unlock date, they become visible to the child they were written for and to the adults with parental authority on that kid (you, your co-parents, and any trusted-adult co-parents). Caregivers and other household adults do not see them.

Timelines and yearbooks. Each adult has a personal timeline. Every entry is private by default — only you can see it. When you save a new entry, you may choose to share that single entry with adults who share parental authority with you (your co-parent on a kid you both parent). This choice is made at the moment of savingand is per-entry; entries cannot be retroactively shared or unshared from the timeline view. Each kid has a household timeline that only the kid themselves, the primary parent, and active co-parents can read (caregivers and connected families cannot).

Per-kid yearbook PDFs compile a single kid's timeline entries for a chosen year. They are stored in our private file storage and only downloadable by adults with authority over that kid (primary parent or active co-parent).

Household yearbook PDFs compile a chronological, author-labeled merge of the timelines you select (yourself, kids you have authority over, and optionally a co-parent — for whom only entries they explicitly marked shared are included). The PDF is generated on demand from data you can already see in the app, returned directly to your device, and is not stored on our servers after generation. Public share links for timelines and yearbooks have been removed — there is no link-based sharing for either feature.

AI features

AI Assistant. When you use the in-app AI Assistant, your prompt and minimal app context are sent to third-party AI model providers via an AI gateway to generate a response. Under our gateway agreements, providers process requests to return a result and do not use this content to train their models. Avoid putting sensitive personal information in prompts.

Smart Suggestions. To suggest possible milestone-worthy moments to save to a timeline, we send the last 30 days of messages from your own self-chat (always) and — only if an adult in your household has explicitly turned it on for "My Family" chat — the last 30 days of family-chat messages to the same AI gateway. Suggestions appear only to you (or to adults with authority over the kid in question); they are not posted, shared, or used to train models. You can dismiss any suggestion, and the household toggle can be turned off at any time. The "Us 💛" thread is never sent to AI.

Push notifications & quiet hours for kids

Push notifications sent to a kid device never include message previews on the lock screen — only a generic "CircleNest / Something new — tap to open" placeholder. Kid devices are also silenced automatically between 9:00 PM and 7:00 AM in the kid's local time. Notifications to children under 13 are blocked entirely.

Love taps. A parent may send a kid a "love tap" — a small heart with no message content. Love taps are not counted, streaked, or shown with a read receipt, and they never include text on the kid's lockscreen.

External links in chat

URLs shared in chat messages are rendered client-side as plain text chips. CircleNest does not fetch, preview, or extract metadata from linked websites. Adults who tap a link see an interstitial reminder before the site opens. Kids cannot navigate to external sites from chat — tapping a link shows a blocked dialog instead. We do not track which links you click, and we do not share link data with third parties.

Transactional emails

We send a small number of account-and-safety emailsfrom notify.circlenestapp.com: sign-in verification codes and magic links, password resets, account-data deletion confirmations, notice that a co-parent grant has been received, notice that a destructive action has been queued for the 48-hour hold, notice that a co-parent reset a kid's PIN, and notice that a co-parent demotion has been initiated (with the 7-day appeal window). These are operational messages required to use CircleNest safely; they are not marketing and you cannot unsubscribe from them while your account is active. Routine in-app activity (plan invites, RSVPs, chat, love taps, kid art) is delivered as push notifications, not email.

Public plan links

A host may choose to share a plan with people who are not on CircleNest by generating a public RSVP link. Public links are blocked for any plan that has a child attached — they're only available for adult-only plans such as a parents' dinner or birthday. The public RSVP page shows only the plan title, time, host-chosen location string, host's first name, and any notes the host marks for sharing — never other invitees, attendance counts, household composition, or any child's information. Recipients submit name, optional email (for updates only), response, guest count, and an optional note. We store the responder's IP briefly for abuse prevention. Public-link RSVP responses are retained while the link is active and are deleted automatically when the host revokes the link, when the host deletes the plan, or within 60 days after the plan ends — whichever comes first. The host can revoke the link at any time. For this specific sharing act, the host is the data controller of the contact details they collect via the link; CircleNest acts as processor. Public pages are markednoindex and have no link previews to avoid leakage in group chats.

Moments, Vibes & Free to meet (adults only)

Moments (short photo posts) are visible only to you and the trusted families you've connected with. Reactions on a moment are visible to the same audience. Kids never see Moments and there are no kid-authored Moments.

Vibes (24-hour ambient status) are visible to a single audience you pick as your default in Settings — either your circles or your trusted families. Reactions on a vibe are visible to the same audience.

Free to meet windows are visible only to your accepted trusted families and only while the window is live. We do not broadcast them via push or email. Teens (13+) in your household may see their own household's window and those of already-connected trusted families, read-only.

Parent Peek

From a kid's profile, an adult with parental authority can open a read-only "Parent Peek" — a summary of that kid's upcoming plans, open jobs, and pending requests. Parent Peek does not show the kid's private chats, drawings, notes-to-self, PIN, or any other private surface, and it does not bypass kid-mode protection on the kid's own device.

Memorialization & future letters

If your account is memorialized, any scheduled future letters pending delivery are paused by default. Your legacy contact may choose to allow delivery on the original schedule, hold them indefinitely, or have them deleted unsent. See our memorialization process for full details.

Kid plan actions

Kids in Kid Mode may take two plan-related actions that follow our standing rule: any kid-initiated cross-family signal goes to the kid's own household first, never to the other family.

Say thanks 💛. For up to 48 hours after a plan ends, an eligible kid can send a thank-you. It is delivered to the adults in the kid's own household only. The host family is not notified, and we do not surface counters like "X kids thanked you."

Private "excited / unsure" pre-react. On an upcoming plan, a kid may set a private signal. It is visible only to adults with parental authority over that kid (primary parent and active co-parents). The host, other families, caregivers, and trusted adults never see it, and no notifications are sent when it is set or cleared.

Kid allowances (per-feature restrictions)

A primary parent or co-parent may restrict a single capability for a kid (for example, free-text chat or voice notes) from the kid's Controls → Allowances. Adding a restriction takes effect immediately. Lifting a restriction is immediate when the primary parent does it; when a co-parent lifts a restriction, it enters the standard 48-hour destructive-action hold so the primary parent (or another co-parent) has a chance to review or cancel before it takes effect.

Co-parent demotion & appeal window

Demoting a co-parent (to trusted-adult, or removing the grant entirely) enters a 7-day appeal window before it takes effect, during which the affected co-parent is notified and either side may cancel the demotion in the app. Other sensitive actions a co-parent initiates — removing a trusted family, leaving or removing the kid from a circle, lifting an allowance — enter a 48-hour hold as described elsewhere in this Policy.

Pets

Pets you add to your household are part of your household profile. They are visible to other adults in your household, to caregivers you grant (so a sitter knows who to feed), and to trusted-adult grantees. Pets are not surfaced to other families unless you choose to mention them in a circle, plan, or chat. Pets do not have their own logins, push tokens, or any independent data footprint — they are descriptive entries you maintain.

Archiving a kid profile

Archiving a kid profile pauses everything tied to that kid: invites, requests, kid-mode access, caregiver and trusted-adult grants, future letters scheduled for them, notifications, and timeline activity. The profile stops appearing on family pages and rosters. No data is deleted by archiving. You can unarchive at any time and surfaces resume where they paused. If you delete an archived kid profile from Trash, the standard 30-day recoverable-deletion window applies.

Memorialization & legacy contacts

Legacy contacts. You may nominate an adult who already has a CircleNest account as your legacy contact. They are notified and must accept. Their role is narrow: if you become permanently unreachable, they may request that your account be memorialized, pause your scheduled future letters, and help coordinate a hand-off of any kid profiles you parent to a co-parent or guardian. A legacy contact does not gain access to your messages, notes-to-self, "Us 💛" thread, or timelines while you are alive, and even after memorialization they do not get login-level access to your private content.

Memorialization request. A legacy contact, a household co-parent, or a verified next of kin may open a memorialization request from the in-app flow. We require documentation appropriate to the request (for example, a death certificate or a court order) before any memorialization action is taken. While a request is in review, future letters scheduled to deliver in the near term are paused so they don't send before the situation is confirmed.

What a memorialized account looks like. The account is set to a read-restricted state: no new sign-ins, no outbound messages, no scheduled posts. Co-parented kid profiles transfer primary-parent status to the surviving co-parent so kids stay on the platform with their day-to-day adult. Future letters previously written by the account holder are released on their original schedule unless a legacy contact or the kid's primary parent asks us to pause or cancel a specific letter. Adults named on the account or in your household may request memorial-only access to view non-private memories the account holder had marked shareable; the account holder's private notes-to-self, "Us 💛" thread, and unsaved drafts are not released.

Reversal. If a memorialization is opened in error, the account holder (or a legal representative with authority) can request reversal from contact@circlenestapp.comand we will restore the account on verified request.

Shared plans on your calendar

Your calendar may show plans from three layers: (1) plans you host, (2) plans you were invited to and RSVP'd, and (3) plans another household chose to share with you for context as a read-only "FYI" (for example, a co-parent's plan with your shared kid, or a trusted family letting you know what they're up to). Layer (3) entries are read-only on your side — the owning household controls edits, attendance, and deletion, and the host's name and household are always shown alongside the plan so you can tell which household owns it. FYI shares are only ever fanned out to adult household members; kids never see another household's FYI plans. You can hide any FYI plan from your own calendar at any time without affecting the source plan or anyone else's view, and when a trusted-family connection is removed, FYI shares between those households are automatically cleaned up.

Cookies & browser storage

CircleNest does not use advertising cookies, cross-site tracking, or behavioural profiling. We use a small number of strictly first-party items:

  • Session cookies set by our authentication provider so you stay signed in.
  • localStorage for your theme preference, your accepted terms version, your cookie-notice acknowledgement, and a few last-seen flags so we don't re-show dismissed notices.
  • Service Worker cache if you install CircleNest as an app, so it works briefly offline.

We show a one-time, dismissible cookie notice on first visit. You can clear all of this at any time from your browser's site-data settings, or by signing out and deleting your account.

Security of your data

We use industry-standard administrative, technical, and physical safeguards designed to protect your information — including encryption in transit, encryption at rest for our managed database and file storage, role-based access controls, automated abuse protections, and breach-detection tooling. However, no method of transmission over the internet or method of electronic storage is perfectly secure, and we cannot guarantee absolute security.You also have an important role: use a strong, unique password, do not share your sign-in credentials, and let us know promptly if you believe your account has been compromised.

Data retention

Individual items you delete (kid profiles, plans, circles, and timeline entries) are held in a recoverable trash for 30 days and can be restored from your Profile; after that they are permanently erased. We keep your account data while your account is active. When you request to delete your account, we hold it for a 30-day grace period during which you can sign back in and cancel the deletion. After the 30 days, your profile, plans you hosted, circles you created, messages you sent, and any kid profiles you parent who have no other parent on the account are erased. Kids with a co-parent are not deleted — primary-parent status is transferred to the co-parent so the kid's account, circles, and history stay intact. Encrypted database backups may retain a copy for up to 30 days after that before being overwritten on their normal rotation. Chat text messages are retained for 2 years (730 days) from when they were sent, then automatically deleted. Messages you mark as "Keep" are exempt and stay until you unsave or delete them. Chat photos and file attachments are deleted from storage after 365 days; an "Attachment expired" placeholder remains for up to 90 more days (455 days total) before the row is purged. Saved attachments are exempt. Event group chats are purged 30 days after the plan's date, regardless of the chat floors above. Voice notes sent in chat are automatically deleted after 30 days, even if you do not delete your account. Kid art that you do not save to a kid timeline is automatically deleted after 90 days; the kid-only view of recent drawings inside Kid Mode is limited to teens (age 13+) and to the last 30 days. Plans (events) and their invites, RSVPs, carpool offers, and duty assignments are kept for 2 years after the plan's date, then automatically deleted. Moments are deleted automatically when their expiry passes (default 7 days; up to 14 days if the author extended once). Vibes auto-clear after 24 hours. "In the moment" free-windows (a coarse signal like "free now," "this afternoon," or "this weekend" that you can broadcast to your trusted families) auto-expire at the time you set, and the row is purged within 7 days of expiry. We do not store location, exact times, or any kid data on these windows. Kids age 13+ in Kid Mode may see a read-only "Families free" strip showing the same coarse bucket (e.g. "Free now," "This evening") for households your family has connected with as a trusted family. Kids cannot set, change, or broadcast a window — only adults can. Audit log entries are kept up to 2 years for security-relevant actions (authentication, role changes, kid data operations, destructive changes) and 180 days for routine activity, then automatically purged. Kid activity log (the per-kid action feed parents can review) is retained for 2 years. Notifications are kept for 90 days once read, and unread notifications auto-mark-read after 180 days with a 30-day grace before deletion. Push subscriptions are deleted immediately when you turn notifications off or sign out. Proof of consent (the version of the Terms and Privacy Policy you accepted, the timestamp, your IP address, and your browser user-agent) is retained for the life of your account as evidence that you agreed to the policy in effect at that time, and is deleted with the rest of your account on request.

Your rights

  • Export your data — Profile → Account → Export my data.
  • Delete your account and your kids' profiles — Profile → Account → Delete account.
  • Disconnect Google Calendar at any time from Settings.
  • Turn off push notifications at any time from Settings → Notifications or in your browser settings.
  • India DPDP rights: If you are in India, you have the right to access, correct, update, and erase your personal data; the right to grievance redressal; and the right to nominate another individual to exercise your rights in case of death or incapacity. Contact us to exercise any of these rights.

EEA, UK & Swiss rights (GDPR)

If you are in the European Economic Area, the United Kingdom, or Switzerland, you have the right to (a) access the personal data we hold about you, (b) correct inaccurate data, (c) erase your data ("right to be forgotten"), (d) restrict or object to certain processing, (e) receive your data in a portable format, and (f) withdraw consent at any time without affecting prior lawful processing. Our legal bases for processing are your consent (for kid profiles, push notifications, calendar sync, and AI Assistant), performance of our service contract with you (running your account), and our legitimate interest in keeping the app secure and debugging crashes. You also have the right to lodge a complaint with your local supervisory authority.

California rights (CCPA / CPRA)

If you are a California resident, you have the right to know what personal information we collect, the right to delete it, the right to correct it, the right to data portability, the right to limit the use of sensitive personal information, and the right not to be discriminated against for exercising any of these rights. We do not sell or share your personal information for cross-context behavioural advertising, and we do not use or disclose sensitive personal information for any purpose other than running CircleNest. To exercise any of these rights, contact us at the email below.

Global Privacy Control (GPC). Because we do not sell or share personal information for cross-context behavioural advertising, there is no opt-out for us to honor in response to a GPC browser signal — your data is already not sold or shared. If that ever changes, we will treat a GPC signal as a valid opt-out request under the CCPA/CPRA and equivalent state laws.

Other US state privacy rights

If you are a resident of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), Oregon (OCPA), Montana, Delaware, Iowa, New Jersey, New Hampshire, Tennessee, or another US state with a comprehensive privacy law, you generally have the right to (a) confirm whether we process your personal data and access it, (b) correct inaccuracies, (c) delete personal data you provided or that we obtained about you, (d) obtain a portable copy, and (e) opt out of (i) targeted advertising, (ii) the sale of personal data, and (iii) profiling in furtherance of solely automated decisions with legal or similarly significant effects.

CircleNest does not engage in targeted advertising, does not sell personal data, and does not use automated decision-making that produces legal or similarly significant effects, so the opt-out rights above are satisfied by default. To exercise access, correction, deletion, or portability rights — or to appeal a decision we make on a privacy request — email contact@circlenestapp.com. We will respond within the timeframe required by your state's law (typically 45 days, extendable once).

Data breach notification

If we become aware of a security incident that compromises your personal information, we will investigate promptly and notify affected users and the appropriate regulators in line with applicable law — including, where required, within 72 hours of becoming aware (GDPR / UK GDPR), without unreasonable delay (most US state laws and India's DPDP Act), and through the in-app notice and email channels you have provided. Our notification will describe what happened, what data was involved, what we are doing in response, and the steps you can take to protect yourself.

Grievance officer (India)

Under the Digital Personal Data Protection Act, 2023, users in India may raise concerns about personal data processing through our grievance mechanism. Please reach out via Send feedback and mark the subject as "Data Grievance — India". We will acknowledge your complaint within 48 hours and aim to resolve it within 30 days. You may also escalate unresolved grievances to the Data Protection Board of India.

Changes to this policy

When we make material changes we update the date above and ask you to re-accept on next app load. Continued use after that means you agree to the updated policy.

Contact

Questions, privacy requests, or rights requests (GDPR, CCPA, COPPA, DPDP)? Email contact@circlenestapp.com or send a note from Send feedback. We aim to respond within 30 days.

See also our Terms of Service, Refund Policy, and our Privacy summary for kids.