← Nesta · TinyKite
Privacy Policy
Nesta by TinyKite · Last updated: 13 July 2026
Summary
Nesta is a private family messenger. It needs an account, and it stores your family's messages and household details on our servers so everyone in the household can see them across devices. We do not run ads, we do not track you across other apps or websites, and we do not sell your personal data or profile your family. Children are added and fully controlled by a parent — we don't use a child's personal email address or collect a date of birth.
1. Who we are
Nesta is published by Tiny Kite LTD (“TinyKite”, “we”, “us”), company number 16825578, registered in England & Wales. We are the data controller for the personal data described here. We are registered with the UK Information Commissioner’s Office (ICO) and pay the data-protection fee (ICO registration reference: ZC196621).
Contact: support@tinykite.co.
This is Nesta’s own privacy policy and is the authoritative document for the Nesta app. TinyKite also publishes a company-wide privacy policy that covers TinyKite as a whole; where anything in it differs from this Nesta policy, this Nesta policy applies for the Nesta app.
2. What Nesta is
Nesta is a private messenger for a single household. Adults sign in with their own account; a parent or guardian creates and manages accounts for the children in the household. There is no public feed, no stranger discovery, and no way to be contacted by anyone outside your household — people join only by an invitation that an adult in the household controls.
3. Data we hold
We keep only what the app needs to work. There are three parts to it.
Adult account data (held in our shared TinyKite identity service):
- Email address, display name, and an optional phone number (only if you choose to verify one).
- Authentication data: a password hash (never your plain password), any passkeys/WebAuthn credentials you register, a TOTP secret if you turn on two-factor authentication, and the linked identities for any Google, Apple, or Microsoft sign-in you use.
- Security and session metadata: IP address, browser/device user-agent, device name, and timestamps — used to keep your account secure and to show you where you are signed in.
Child account data (created and controlled by a parent):
- A first name only, shown as the child’s display name, and a username we derive from it.
- We do not use a child's personal email address (the account is keyed to a service-generated alias with no inbox) and we do not collect a date of birth.
- The parent sets and controls how the child signs in — a password the parent manages and can reset, and/or a device the parent approves. The child never has to create their own credentials, and a child cannot create their own account.
- A parent creates the child account and stays in full control of it — they can rename it, reset how the child’s device connects, and remove it at any time.
Messages and household data (stored on our servers — this is cloud-stored, not only on your device):
- The messages members send within a household, including any photos, voice notes, or files attached to them.
- Household and family membership, member roles, and the devices registered to the household.
- When a member is removed, we keep a minimal “tombstone” record so their earlier messages still show a sender name to the rest of the family. It does not keep contact details or let the removed person back in.
Push notifications and anti-abuse:
- Device push tokens issued by Apple (APNs) and Google (FCM), so we can deliver message notifications to your devices.
- To protect account creation from bots and abuse we use Cloudflare Turnstile (a privacy-preserving CAPTCHA that does not track you across sites) and rate limiting.
4. How we use this data and why we’re allowed to
- To provide the messenger — deliver and sync your household’s messages across devices, manage membership, and send notifications. Legal basis: performance of our contract with you.
- To keep accounts secure — sign-in, two-factor authentication, session management, and abuse prevention. Legal basis: our legitimate interest in a secure service and, where required, our legal obligations.
- For children’s accounts — we act on the instructions and consent of the managing parent (see section 6). Legal basis: the parent’s consent and our contract with the household.
5. What we never do
- No advertising SDKs and no ads in the app.
- No analytics used for tracking you across other companies’ apps or websites.
- No sale of personal data.
- No profiling and no targeted advertising — to anyone, and especially not to children.
6. Children
Nesta is a family app and is meant to be set up and run by an adult. We handle children’s data to the strictest common standard, wherever the family lives.
- A parent or guardian creates the child’s account and provides consent on the child’s behalf: only an adult with their own verified account can add a child, and that adult receives notice of what we collect and stays in control of the account.
- We do not ask a child for a personal email address or a date of birth; the parent sets up and controls how the child signs in, and we do not knowingly let a child create their own account.
- We do not run behavioural tracking, profiling, or advertising for children — or for anyone.
This approach is designed to meet the US Children’s Online Privacy Protection Act (COPPA) for children under 13, the UK GDPR (Article 8) and the ICO Children’s Code around age 13, and India’s Digital Personal Data Protection Act 2023 for users under 18. A parent who wants to review or delete their child’s data can do so in the app or by emailing support@tinykite.co.
7. Who we share data with (sub-processors)
We do not sell or rent your data. We use a small set of service providers who process data on our behalf, under contract:
| Provider | What they do for us |
|---|---|
| Microsoft Azure | Hosting our servers and databases (EU regions — West/North Europe) |
| Azure Communication Services | Sending transactional email (e.g. sign-in and verification messages) |
| Apple | Push notifications (APNs) and Sign in with Apple |
| Push notifications (FCM) and Google sign-in | |
| Microsoft | Microsoft sign-in |
| Cloudflare | Turnstile (bot protection) and content delivery (CDN) |
8. Where your data is stored and international transfers
Your data is hosted in the European Union / EEA (Azure’s West and North Europe regions). Where data moves between the UK/EU and another region — for example when a push notification is delivered through Apple or Google — we rely on appropriate safeguards such as the UK/EU Standard Contractual Clauses.
9. How long we keep data
- Account and message data are kept until the account is deleted, plus the 30-day grace period described in section 11.
- Short-lived security tokens (for example, sign-in and invitation codes) expire automatically.
- Security audit logs are kept for a limited period for accountability, and may be retained where the law requires it.
10. Your rights
Under the UK/EU GDPR and equivalent laws you can ask us to give you access to your data, correct it, erase it, provide a portable copy, restrict our use of it, or object to our use of it. To exercise any of these, email support@tinykite.co. We aim to respond within one month. You also have the right to complain to the ICO (or your local data-protection authority).
11. Deleting your account
You can delete your account yourself in the app: Settings → Delete account. There is a 30-day grace period — your account is disabled immediately and permanently deleted after 30 days. If you sign back in during those 30 days, the deletion is cancelled. You can also request deletion from our account-deletion page or by emailing support@tinykite.co.
Deletion removes your identity record and your personal data across both the identity service and the messaging (“relay”) service. A parent deletes a child’s account the same way, from the child’s member settings. We may retain limited audit or security logs where the law requires it.
12. Push notifications
We use your device’s push token (from Apple APNs or Google FCM) only to deliver notifications about your household’s messages. You can turn notifications off at any time in your device settings.
13. Changes to this policy
If we change what we collect or how we use it, we will update this page and the date at the top before the change takes effect.
14. Contact
Questions or requests: support@tinykite.co
Support page: nesta.tinykite.co/support
Delete your account: nesta.tinykite.co/delete
Company: tinykite.co