Privacy Policy
Privacy Policy
LittleNest is a private family memory service. This Policy explains what information we process, why we process it, who can see it, and the choices available to you.
In short: LittleNest does not sell personal information, show behavioral advertising, or use private family content for third-party advertising. Content saved in a Nest is shared with the members of that Nest, not published as a public social feed.
- Who We Are and Scope
- Age Requirement and Family Profiles
- Information We Collect
- How We Use Information
- Sharing Within a Nest
- Service Providers and Other Disclosures
- No Sale or Targeted Advertising
- Device Permissions
- Retention and Deletion
- Security and International Processing
- Your Choices and Privacy Rights
- Website Data
- Changes to This Policy
- Contact Us
1. Who We Are and Scope
LittleNest is operated by Cai Lujia (蔡露佳), an individual developer using the developer name “Cailujia Studio” and based in Zhengzhou, Henan Province, People's Republic of China. In this Policy, “LittleNest,” “we,” “us,” and “our” mean Cai Lujia and the LittleNest service.
This Policy applies to the LittleNest mobile application, the public pages at little-nest.app, and related reporting, support, and account-deletion services. It covers information processed when you create or use an account, create or join a family space called a “Nest,” save or view family content, report a Moment or member, submit feedback, contact us, or visit this website.
Apple, Google, Supabase, Cloudflare, Expo, Resend, app stores, device manufacturers, and other independent services may process information under their own privacy policies. This Policy describes LittleNest's practices and our use of those providers.
2. Age Requirement and Family Profiles
You must be at least 13 years old to hold and use a LittleNest account. Before an account can create a Nest or join one with a code, we ask for the account holder's full date of birth to apply this age requirement. If the date indicates that the account holder is under 13 and the user confirms it is correct, LittleNest prevents use of the family service and deletes the account.
LittleNest is a family product and family content may include children. An account holder may create a profile for a family member who does not have an account. That profile may describe a child, baby, adult, or pet; LittleNest does not infer which of those the profile represents. A non-account profile may include a name or nickname, avatar, birthday, role or relationship label, and content in which the family member is tagged.
Creating a non-account family profile does not create an account for that person and does not allow that person to sign in. Account holders are responsible for having the authority and permissions needed to add information or content about other people, including children, to a Nest.
If you believe a person under 13 has created or is using an account, contact [email protected]. We will investigate and take appropriate steps, which may include restricting access and deleting the account.
3. Information We Collect
Account and authentication information
We process a unique account identifier, email address, email verification status, authentication provider, sign-in and account status, session information, and related timestamps. Email authentication uses a one-time email code. If you choose Apple or Google sign-in, we receive the provider identifier, email address and verification status, basic authentication metadata, and tokens needed to establish a LittleNest session. We do not receive your Apple or Google password.
Account profile information
You may provide a display name, profile photo, and full date of birth. We use the account birthday to apply the 13+ requirement and may use it for birthday reminders and age-related family-memory features. The birthday is entered through the family creation or joining flow and is read-only elsewhere in the app. Your display name, avatar, and birthday information may be visible to members of Nests you join.
The app also derives a country or region setting from the device locale and reads the device locale and timezone. This is used for dates, formatting, birthday calculations, reminders, and family settings. We do not use GPS to infer your country or region.
Nests, relationships, invitations, and member profiles
We process Nest names and cover images; membership, creator, and role information; invitation codes and expiration information; join requests and approval status; and non-account family member profiles. Depending on the feature, records may include display names, avatars, birthdays, relationship labels, account email addresses, and relevant timestamps.
Moments and family content
We process content that users choose to add, including photos, videos, Live Photos, captions, notes, titles, dates, and family-member tags. To store and display media, we also process technical information such as file type, size, dimensions, duration, thumbnails, display copies, storage paths, upload state, and creation or modification timestamps.
Location information
If you choose to add a location to a Moment, LittleNest may read location metadata embedded in selected media, let you search for or select a place on a map, or—with permission—use the device's current location. We may process and save coordinates, place names, addresses, accuracy, altitude, location source, and map-related search information. A saved Moment location is visible to members of the relevant Nest. LittleNest does not continuously track your location or request background location access.
Reports, feedback, support, and diagnostics
If you report a Moment or account-backed family member, we process the reporting account identifier, reported account identifier where available, relevant Nest, Moment or member identifiers, selected reason, report status, resolution information, and review timestamps. If you submit feedback or contact support, we process the message, category, contact email, screenshots or attachments you choose to provide, account identifier where available, app version, platform, and basic diagnostics included with the request. LittleNest does not automatically attach your private photos, videos, or Moment content to feedback.
App and service records
LittleNest and its providers generate operational records needed to authenticate users, authorize access, synchronize data, send email, maintain limited widget access, secure the service, and diagnose failures. These can include timestamps, record identifiers, IP addresses in provider logs, request and error information, app version, operating system, device or widget identifier, and credential status. LittleNest does not use an advertising identifier and does not include a separate advertising, analytics, customer-support, or crash-monitoring SDK in the first release.
4. How We Use Information
We use information to:
- register and authenticate accounts and maintain sessions;
- apply the minimum account age requirement;
- create, join, display, switch, and manage Nests;
- manage memberships, invitations, join requests, roles, and access;
- upload, store, organize, display, edit, and delete Moments and media;
- provide timelines, albums, calendars, birthday reminders, recaps, memory cards, and widgets;
- provide user-selected location and people-tagging features;
- send authentication codes, security notices, and necessary service communications;
- receive and review reports, answer support requests, and process feedback;
- protect accounts and Nests, prevent abuse, investigate security problems, and maintain reliability;
- enforce our Terms of Service and comply with legal obligations.
5. Sharing Within a Nest
A Nest is private from the general public, but it is a shared space among its members. Active Nest members can generally see the Nest profile, member profiles, Moments, media, captions, dates, saved locations, people tags, timelines, albums, and memory features associated with that Nest. LittleNest does not currently provide per-Moment visibility controls.
Only invite people you trust. Nest members may view, copy, capture, or otherwise retain content using their devices. LittleNest cannot control what another member does with information after that member has lawfully viewed or downloaded it.
6. Service Providers and Other Disclosures
We disclose information only as needed to operate LittleNest, follow your instructions, protect the service, or comply with law.
- Supabase: authentication, Postgres database, file storage, controlled server functions, access control, platform logs, and database backups. Supabase stores the primary LittleNest account and family data.
- Apple: Sign in with Apple if selected, Apple Maps and device location services on iOS, App Store distribution, and related platform services.
- Google: Google sign-in if selected, Google Maps and related location services on Android, Google Play distribution, and related platform services.
- Resend: delivery of email authentication codes and other necessary authentication messages through Supabase. This may include the recipient address, message content, sending time, and delivery status.
- Cloudflare: hosting, delivery, and security of LittleNest's public website and legal pages. LittleNest does not use Cloudflare R2 for family media in the first release.
- Expo/EAS: development and production build infrastructure, build logs and artifacts, and—if enabled—management of app-signing credentials. Routine EAS builds do not require access to family content stored in Supabase.
We may also disclose information when reasonably necessary to comply with applicable law or valid legal process; protect the rights, safety, or security of users, children, LittleNest, or others; investigate fraud, abuse, or security incidents; enforce our Terms; or complete a financing, merger, acquisition, reorganization, or transfer of the service subject to appropriate protections.
7. No Sale or Targeted Advertising
LittleNest does not sell personal information. We do not share personal information for cross-context behavioral advertising or use private family content for third-party advertising. The first release does not display third-party advertisements.
8. Device Permissions
LittleNest requests access only when it is needed for a feature you choose:
- Photos and videos: On Android, the system photo picker gives LittleNest access only to the photos or videos you select; LittleNest does not request permission to read your entire Android photo or video library. Android may separately ask whether LittleNest can read location metadata from selected photos so that a Moment can automatically use the photo's capture location. This permission does not expand LittleNest's access to unselected photos. On iOS, you choose the level of photo-library access provided by the system. LittleNest uses selected media and available metadata, such as capture date or embedded location, to create a Moment. LittleNest requests write access only when you expressly choose to save media to your library.
- Camera: to take photos and scan a family invitation QR code. LittleNest does not request microphone access and does not record video in the app.
- Location while using the app: to use your current location when you expressly choose that option for a Moment. LittleNest does not request background location access.
You can deny or later change permissions in device settings. The related optional feature may not work without its permission. Uploading an existing video from your library does not require microphone access.
9. Retention and Deletion
We generally retain account information, family relationships, family content, reports, feedback, and support records while the relevant account, Nest, profile, Moment, report, or request remains active or while the record is reasonably needed for its stated purpose. LittleNest is not a permanent archive, and we do not guarantee that content can always be preserved or recovered. Keep your own copies of important memories.
Deleting a Moment
Deleting a Moment is designed to delete its active database record and associated photos, videos, thumbnails, display copies, Live Photo motion file, saved location, people tags, and media records. There is no recycle bin or user-facing recovery feature.
Deleting a Nest
Only the Nest creator can delete the Nest. Nest deletion is designed to delete the family space and its memberships, non-account member profiles, invitations, join requests, Moments, media, locations, people tags, and related family records and files. An account holder's own profile photo may remain because it belongs to that account and may be used in another Nest.
Deleting an account
A creator must first delete every Nest they created. Account deletion removes the authentication account, account profile, active memberships, join requests made by that account, account profile media that the deletion process can identify, and local session and cache data. If the account uses Sign in with Apple, LittleNest also requests revocation of the connected Apple authorization before completing deletion.
Before confirming in-app account deletion, you choose whether LittleNest should permanently delete the Moments you shared across all Nests, including their associated media and tags, or leave copies in those family timelines without a link to your deleted account. Data selected for deletion cannot be recovered through LittleNest after deletion completes. Reports, feedback, support records, and a minimal record showing that a deletion request completed may remain after account deletion if they are no longer linked to an active account or are still needed for safety, support, security, legal, or recordkeeping purposes.
See the Account Deletion page for the available request methods.
Backups and limited exceptions
Our cloud provider may maintain restricted rolling database backups for disaster recovery according to the production service configuration. Deleted database records can remain in those backups until they rotate out. Backups are not used as an everyday product archive or restored to the active service except for disaster recovery. Supabase database backups contain Storage metadata but do not include the actual photo and video objects stored through the Storage service.
We may retain limited information for longer when reasonably necessary to comply with law, resolve a dispute, enforce agreements, maintain security, prevent abuse, or document a privacy request. Retention depends on the record and purpose; we do not retain all information indefinitely.
10. Security and International Processing
We use safeguards designed to protect information, including authentication, private storage, database and file-access policies, encrypted transport in production, and access limited according to Nest membership and operational need. No service can guarantee perfect security, and you are responsible for protecting access to your email account, Apple or Google account, device, and LittleNest session.
LittleNest is operated from China and uses providers that may process information in the United States and other countries. Information may therefore be transferred to and processed in countries whose privacy laws differ from those where you live. Where applicable law requires it, we use appropriate contractual or other safeguards.
11. Your Choices and Privacy Rights
You can manage many records directly in the app, including your display name, profile photo, memberships where permitted, non-account family profiles, Moments, and Nests you created. The account birthday is read-only after it is submitted; contact us if it is inaccurate.
Depending on where you live and whether a particular law applies to LittleNest, you may have rights to request access, correction, deletion, or a copy of personal information; to withdraw consent for optional processing; to appeal certain request decisions; or to receive equal service when exercising a privacy right. We do not discriminate against users for exercising applicable privacy rights.
Because LittleNest does not sell personal information or share it for cross-context behavioral advertising, there is no sale or targeted-advertising opt-out required for those practices. If our practices change, we will update this Policy and provide any required controls before the change applies.
To make a privacy request, email [email protected]. We may ask you to verify control of the relevant account or email address. An authorized agent may submit a request where permitted by law, but we may require proof of authorization and direct identity verification. You may also appeal a denied request by replying to our decision.
12. Website Data
LittleNest's public legal website does not require an account and does not provide forms for family content. Cloudflare and network providers may process IP address, browser or device information, requested URL, request time, security events, and server logs to deliver and protect the pages. We do not currently use website advertising, tracking pixels, or a separate web analytics service. Essential security or network technologies used by the hosting provider are not used by LittleNest for behavioral advertising.
13. Changes to This Policy
We may update this Policy to reflect changes in the service, providers, law, or security practices. We will post the updated version here and update the effective date. If a change is material, we will provide additional notice in the app, by email, or through another reasonable method before the change takes effect when required.
14. Contact Us
For privacy questions, requests, or concerns:
Operator: Cai Lujia (蔡露佳), an individual developer using the developer name “Cailujia Studio”
Mailing address: Room 803, Unit 1, Building 16, No. 3 Courtyard, Longxing Jiayuan, Longhu Street, Zhengzhou, Henan 450000, People's Republic of China
Email: [email protected]