Privacy Policy
On this page
Nesta is a pregnancy, postpartum and pelvic floor app. Much of what you tell it is health information, so we collect only what the app needs, we never sell it, and we never use it for advertising. This policy explains what we collect and why. Health data also has its own policy: the Consumer Health Data Privacy Policy.
1. Who we are
Nesta is provided by [Company legal name], [registered address, India] ("we", "us"). We decide how your personal data is used (we are the "data fiduciary" under India's Digital Personal Data Protection Act, and the "controller" or "business" under other laws).
Contact: [privacy email]. Grievance Officer: [name], [grievance email].
2. What we collect
| Kind | Examples | Where it comes from |
|---|---|---|
| Account | First name, email address, a scrambled (hashed) password if you use email sign-in, your Apple or Google account identifier if you use those | You; Apple or Google when you choose to sign in with them |
| Health and pregnancy data | Stage (trying, pregnant, postpartum, training), due date or the dates used to work it out, birth date and type, number of babies, symptoms, mood and energy, kick counts, contractions, water, caffeine, vitamins, blood pressure, weight (optional), meals and meal photos, goals, health conditions you choose to tell us, diet and allergies | You, when you answer questions or log things |
| Nesta AI | Questions you ask Nesta, meal photos you scan, and the answers | You, only if you turn on Nesta AI |
| Consent records | Which consents you gave or withdrew, the policy version, when, and the platform and app version | The app |
| Purchases | Whether you have a subscription, its plan and renewal date. We never see your card details. | Apple or Google, through [RevenueCat] |
| Technical | IP address (used briefly to stop abuse such as password guessing), device platform, app version, error reports | Your device |
| Support | What you write to us | You |
We do not use advertising identifiers, we do not track you across other apps or websites, and we do not use ad networks.
3. How we use it
- To provide Nesta (your account, plan, sessions, trackers, reminders, and Nesta AI if you turn it on). Basis: our contract with you, and your consent for health data.
- To keep your account safe (sign-in codes, stopping password guessing, spotting stolen sessions). Basis: legitimate interests and legal obligations.
- To check your password is not a known leaked one. We send only the first 5 characters of a hash of it to the Have I Been Pwned service, never the password itself.
- To improve Nesta with anonymous usage data, only if you allow it.
- To fix crashes, using error reports that do not contain your health data, name or email.
- To answer you when you contact us, and to meet legal obligations.
We do not sell your personal data, we do not share it for advertising, and we do not use it to make decisions that have legal or similarly significant effects on you.
4. Who we share it with
Only with service providers who process it for us under contract, and only what each one needs:
| Provider | What for | What they receive |
|---|---|---|
| Hostinger | The servers that run Nesta and store its database | Everything stored in your account (encrypted in transit; backups encrypted) |
| [Backblaze B2 or Cloudflare R2] | Encrypted off-site backups | Encrypted backup files they cannot read |
| Resend | Sending sign-in and password codes by email | Your email address and the code |
| OpenAI | Nesta AI answers and meal photo analysis, only if you turn Nesta AI on | Your question or photo, plus your stage and week. Not your name or email. See How Nesta AI works. |
| Apple and Google | Sign in with Apple or Google; App Store and Google Play purchases | What their sign-in and billing need |
| RevenueCat | Keeping track of subscriptions across iPhone and Android | An account identifier and purchase records |
| Sentry | Crash and error reports | Technical error details, without health data, name or email |
| Have I Been Pwned | Checking a new password against known leaks | The first 5 characters of a hash of the password |
We may also disclose data when the law requires it, to protect someone's safety, or as part of a merger or sale (you will be told first).
5. Where it is stored and transferred
Our servers are in [server location, e.g. the EU or India]. Some providers above process data in other countries, including the United States. Where the law requires it, we use contractual safeguards for these transfers.
6. How long we keep it
- Your account and logs: while your account exists. When you delete your account, we delete them within [30] days; encrypted backups roll off within 35 days.
- Sign-in and reset codes: 10 minutes. Sessions on a device: until you sign out, or 60 days without use.
- Consent records and the security audit log: [period] after the account is deleted, without your health data, to show what you agreed to.
- Server logs: [14] days. Error reports: [90] days.
7. How we protect it
- Encryption in transit (HTTPS) for every connection; backups are encrypted before they leave the server.
- Passwords are stored only as a strong one-way hash (Argon2id).
- Short-lived sign-in tokens, kept in your phone's secure storage; a stolen old token ends the whole session.
- Server logs leave out email addresses, tokens and health fields.
- Access to production data is limited to the people who need it, and actions on accounts are logged.
No system is perfectly secure. If a breach affects you, we will tell you and the authorities as the law requires.
8. Your rights and choices
Depending on where you live (for example India, the EU or UK, or US states such as California, Washington, Nevada and Connecticut), you can:
- See the data we hold about you, and get a copy (in the app: You → Export my data).
- Correct it.
- Delete it (in the app: You → Delete all my data, or on the web).
- Withdraw a consent at any time (You → Manage consents). Withdrawing does not affect what happened before.
- Object to or limit some uses, and appeal if we refuse a request.
- Nominate someone to act for you, and complain to a regulator (in India, the Data Protection Board).
Write to [privacy email]. We answer within [30] days and may need to confirm it is you. We will not treat you differently for using these rights.
9. Age
Nesta is for adults: you must be 18 or older. We do not knowingly collect data from anyone younger and delete it if we learn of it.
10. Changes
When we change this policy, we update the version at the top. If the change matters, the app asks you to read and agree again before you continue.
11. Contact and grievances
[Company legal name], [registered address, India]. Email [privacy email]. Grievance Officer: [name], [grievance email]; we acknowledge grievances within [48 hours] and resolve them within [30] days.