Privacy policy
1. Who processes your data
The controller of your data is CAPRI Adam Czarnowski, ul. Leśna 14, 67-100 Nowa Sól, Poland, tax ID 8992959335 — the maker of Pairnest. Write to privacy@pairnest.app about anything concerning your personal data; we answer within 30 days at the latest. We have not appointed a data protection officer, because the scale of our processing does not require one.
2. What we collect
Account data: your email address, plus your name and profile photo if you add them. The content you create: shopping lists, notes, calendar events and the activity trail inside your nest. Your pairing: who shares a nest with whom. Technical data: the device token needed to deliver a notification, your account ID and the error description inside crash reports, and your subscription status. We do not collect location, contacts, your device calendar or browsing history, and payment is handled by the store — we never see your card details.
3. Why, and on what legal basis
Your account, syncing content between your devices and running your subscription — without these we cannot perform our contract with you (GDPR Art. 6(1)(b)). Push notifications — on your consent, which you can withdraw at any time in your Profile (Art. 6(1)(a)). Security, abuse prevention and fixing bugs — our legitimate interest in keeping the app working and safe (Art. 6(1)(f)). We do not make decisions about you by automated means alone, and we do not profile you.
4. Who we share it with
Content you mark as shared is visible to the other person in your nest — that is the point of the app. Private content stays invisible to them, and the database enforces that, not just the interface. Beyond that we do not sell your data and we share it with nobody for marketing. We use processors under data processing agreements: Supabase (database, sign-in, files), Sentry (crash reports), Expo (notification delivery), RevenueCat (subscription management) and Cloudflare (email on the pairnest.app domain, and carrying analytics events to our own server). Apple and Google process payment data as independent controllers, under their own policies. We disclose data to public authorities only where the law requires it.
5. Transfers outside the European Economic Area
Some of our processors are based in the United States. We transfer data to them under Standard Contractual Clauses approved by the European Commission (GDPR Art. 46(2)(c)) or under the adequacy decision for the EU–U.S. Data Privacy Framework. We will send you a copy of those safeguards on request — write to privacy@pairnest.app.
6. How long we keep it
We keep your account data and content for as long as the account exists. Once you delete it, we remove it from live systems immediately and backups expire within 30 days. When a pair separates, shared content waits 30 days so each of you can claim your part — after that it is gone. The notification queue and the offline operation log clear after 30 days, the device token is removed when you sign out or uninstall the app, and Sentry keeps crash reports for 90 days.
7. Your rights
You have the right to access your data, to rectify, erase and restrict processing of it, to data portability, to object to processing based on our legitimate interest, and to withdraw consent at any time — withdrawal does not undo what we lawfully did before it. You can export your data and delete your account yourself in your Profile, without writing to us. If you believe we process your data unlawfully, you may lodge a complaint with the President of the Personal Data Protection Office, ul. Stawki 2, 00-193 Warsaw, Poland.
8. How we protect it
The connection to our server is encrypted with TLS, data at rest in the database is encrypted, and your session lives in the iOS Keychain or the Android Keystore. The split between shared and private content is enforced by the database itself, through row-level access rules, so it cannot be bypassed by changing a request from the app. Notifications deliberately carry neither the text of a note nor the name of the person who changed something.
9. Age
The app is for people aged 16 and over. We do not aim it at children and we do not knowingly collect their data. If we learn that an account belongs to someone younger, we delete it.
10. Changes to this policy
We will tell you in the app about every material change and ask you to accept it again before you carry on. The date at the top of the document tells you which version you are reading. The current version always lives at https://pairnest.app/legal/privacy.
11. Signing up for launch news
On pairnest.app you can leave an email address to hear from us when the app reaches the stores. The basis is your consent (GDPR Art. 6(1)(a)), and the address is used for that ONE message only — it goes on no marketing list and is not linked to any account in the app. Withdraw consent by writing to privacy@pairnest.app and we erase the address at once. We also erase it ourselves once the launch message has gone out. We additionally keep a hashed form of your IP address to limit how many signups come from one place — the address itself is never stored, and the hashes expire after an hour.