Privacy Policy
Effective 5 October 2026
Nestly (nestlydom.ru) is a personal, non-commercial project: a place to keep track of what you have at home, how much, and where. This page explains what data we receive, why, how we keep it and how to have it deleted. Questions go to nikita.pechenyi@gmail.com.
What we receive
- When you sign in with Google: your Google account identifier, email address and profile name. We do not receive your password, contacts, files or any other Google account data, and we do not ask for access to them.
- When you sign in with Apple: the Apple ID identifier for Nestly, your email address (or the hidden Apple address, if you chose it) and your name, if you chose to share it. If the address matches one you already signed in with through Google, Apple becomes another way into the same account.
- Your profile: nickname and NestlyTag, and a profile photo if you upload one.
- Encrypted home content: home, place, item and group names, descriptions, notes, tags, aliases, shopping titles, place icons and home photos. Members encrypt these on their devices; the server receives ciphertext.
- Inventory data: quantities, units, thresholds, expiry dates, consumable and shortage flags, shopping statuses and sources are encrypted on-device. Older records migrate automatically when a member with editing rights and the key opens the home. Until migration succeeds, their old values remain readable by the server and service operator; afterward, ciphertext and a technical record revision remain. Migration verifies decryption and does not overwrite concurrent edits. Item-to-place and group relationships, order and the storage tree remain readable metadata.
- Place types and colours are now encrypted on-device. Older values migrate when a member with editing rights and the key opens the home. Until migration succeeds, legacy values remain readable by the server; sealed replacements preserve concurrent edits.
- Keys: your devices’ public keys and the home keys sealed to them; if you choose, your key wrapped by your passkey (Face ID, fingerprint) or a recovery code. None of them opens without your device, passkey or code.
- Membership: who belongs to which home, in what role, until when guest access lasts, and invitations.
- House chat: encrypted messages, attachments, filenames and media types, and message keys wrapped for recipients. Readable metadata includes the house, sender and recipients, timestamps, ciphertext sizes, delivery acknowledgements and reading cursor. Devices encrypt the text and files; the server keeps ciphertext for offline participants.
- Push notifications: your categories and chat privacy choice, browser subscription endpoint and transport keys. Permission is requested only after a button press. Chat previews are hidden by default. If you enable sender or text previews, your device decrypts them and may show them on its lock screen.
- Activity and audit history: action type, participant and time remain readable by the server. Inventory operation content, including names and quantity changes, is encrypted under the home key. An editing member migrates older history and notification copies on-device; old values remain readable until migration succeeds.
- Feedback: the text you send us and any photos or video you attach; our answer comes to «Support» in the app. All of it is stored encrypted. An anonymous message is kept with no link to your account, and we cannot answer it. Only we read these messages.
- Technical data: the session cookie, your chosen language and home, and web server logs (IP address, time and requested address) needed to run and protect the service.
Why we need it
- To sign you in and to make your homes, search, shopping lists, QR labels and notifications work.
- So that the members of a home can see what it holds.
- To protect the service from abuse and to fix problems.
We do not sell data, show ads, profile you or pass your data to third parties for their own purposes.
Data from Google
Nestly uses data received through Google APIs only to sign you in and to link your account to your profile. Nestly's use and transfer of this information adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Who can see your data
- What is in a home is visible to its members, invited by the owner, and to guests while their access lasts.
- Your nickname and NestlyTag are visible to people you share a home with and to someone looking you up by tag to invite you.
- The server runs at a hosting provider that stores data on our behalf. Apart from delivery of push notifications you enable, described below, we share data with nobody else except where the law requires it.
- If you enable push, your browser delivery provider receives the subscription endpoint and an encrypted notification. Chat previews are also end-to-end encrypted inside it; plaintext names and messages are not sent to the provider.
How we store and protect it
- Connections to the site are protected by HTTPS.
- The encrypted fields and home photos listed above use end-to-end encryption: members hold the key on their devices and the server never receives it in plaintext. Search and label printing run on-device. This does not hide readable metadata, accounts, membership or activity times.
- Your email, nickname, name, profile photo and notification text (without any names from your homes) are stored encrypted with the server’s key, which the server can read: signing in and invitations need that.
- The web app downloads code from the server. Encryption protects the listed fields against reading the database or its copy without members’ keys, not against malicious changes to site code, a compromised device or access to an already unlocked app.
- Chat encryption uses current participant public keys supplied by the authenticated relay. It does not provide cryptographic sender signatures or forward secrecy. Messages, files and keys already downloaded to another device cannot be revoked.
- An invitation creator can separately share earlier messages and attachments with a new participant. This choice starts disabled. Available participant devices transfer wrapped message keys; the server does not receive plaintext decryption keys. History transfer may be partial or wait for a device with the keys.
- Database access is limited row by row: a query only sees the homes its user belongs to.
- The deployment script creates a compressed database backup on the server with restricted filesystem permissions. The archive itself is not encrypted with a separate key: sealed fields remain ciphertext, and readable metadata remains readable.
- Migrating older data to end-to-end encryption does not rewrite existing backups. Older readable values can remain in those backups until they are deleted.
Cookies and browser storage
- The session cookie and the sign-in cookies — signing in does not work without them.
- hk_locale and hk_house — your chosen language and home.
- Browser storage keeps your device’s key, where you are in the introduction and your recent searches. They never leave your device, except when you move the key to another device of your own.
- House chat draft text is encrypted under the account key on this device, separately for each home. Drafts are not sent to the server or synced between devices. Attachments and the original payload of an uncertain send are not restored after reload.
- Recently fetched chat history and its metadata are encrypted on this device, separately for each account, home, membership and key. Clear in the participant sheet removes this local copy, not messages on the server or other devices. Later fetches can populate the cache again.
- Microphone and camera access is requested only after pressing Record. Until attached, previews are temporary browser data; sent voice and video recordings are encrypted like other attachments.
- The device push subscription is bound to the current account. Sign-out removes the local subscription and displayed notifications. The service worker does not cache private pages or responses.
There are no third-party counters, analytics or advertising cookies.
How long we keep it and how to delete it
- Account data is kept while you have an account; what is in a home is kept while the home exists.
- Encrypted messages and sent attachments remain while the home and sender account exist. Leaving without deleting the account does not remove them from other participants. Unsent file reservations expire after 24 hours; recorded blobs are then removed by background cleanup. Undelivered push jobs are removed within seven days. Subscriptions are removed when disabled, on sign-out or when the provider confirms an invalid endpoint.
- To delete your account, write to nikita.pechenyi@gmail.com from the address you signed in with. We delete the account, profile and photo within 30 days. Homes where you are the only owner are deleted with everything in them; in shared homes, what you added stays with the other members.
- Write to the same address to ask for a copy of your data or to correct it.
- You can revoke Nestly's access to your Google account in your Google settings: myaccount.google.com/permissions.
- Deleted data may remain in existing backups until those backups are removed. Once a database reference is deleted, a background worker removes the file; storage failures are retried.
- If you lose every device, passkey and your recovery code and nobody else is in a home, nobody — us included — can recover what is in it.
Children
The service is not meant to be used on their own by children under 14.
Changes
If this policy changes, we update the date on this page and announce significant changes in the app.