Introduction
This Privacy Policy explains how Nanny ("we", "us", "our") collects, uses, stores, and shares personal data when you use our websites, applications, and related services (collectively, the "Services").
We take privacy seriously. This Policy is designed to help you understand what we process, why we process it, and the choices available to you.
If you do not agree with this Policy, please do not use the Services.
Who is responsible for your data?
The data controller for personal data processed through the Services is the legal entity operating Nanny. For privacy requests and questions, contact us at admin@nanny.live.
For the messages and other content you choose to monitor — including data relating to the child and to other participants in those communications — you are the party responsible for that data (for example, the “controller” under applicable data-protection law) and Nanny processes it on your behalf and on your instructions to provide the Services, as described in the Terms of Service.
Scope
This Policy applies to parents and guardians who register accounts, configure monitoring features, and receive alerts or summaries through Nanny.
The Services are intended for lawful parental or guardian use in connection with minors for whom the account holder has appropriate authority. You are responsible for ensuring your use complies with applicable laws (including wiretap, surveillance, employment, and children's privacy laws in your jurisdiction).
Transparency and consent
Nanny is built for transparent, consent-based family safety — not covert surveillance. We encourage you to tell the child, in an age-appropriate way, that Nanny is active, to explain what it does, and where possible to set it up together.
The Services are intended for protecting minors over whom you hold lawful parental or guardian authority. They are not designed or licensed for secretly monitoring other adults — including partners, spouses, family members, or employees — without their knowledge and consent. Using the Services to do so may be unlawful and is prohibited under our Terms.
Within the product, protection status is visible to the account holder, alerts and the messages that triggered them are shown to you transparently, and you can pause protection or disconnect a child at any time from Settings.
Personal data we collect
Depending on how you use Nanny, we may process the following categories of information:
- Account and authentication data — such as identifiers issued by our authentication providers (for example Firebase Authentication), phone numbers when phone sign-in is used, email addresses when email sign-in is used, and basic profile details connected to those credentials.
- Household and child profile data — such as child nicknames or labels, approximate ages or grades where you provide them, platform selections (for example WhatsApp), sensitivity preferences, and onboarding questionnaire responses.
- Monitoring-related content and derived signals — when you enable features that analyze communications sources you connect, we may process message text, metadata (such as timestamps or sender labels where available), attachments or links when technically processed, and outputs such as alerts, risk summaries, safety scores, or thread excerpts presented to you inside the product.
- Sensitive or special-category data — messages you choose to have analyzed may themselves reveal sensitive information (for example relating to health, sexuality, religion, or beliefs). We process such content only to detect safety risks and present alerts to you, retain only what is needed for that purpose (for example the excerpt that triggered an alert rather than full transcripts), and apply additional care to it.
- Co-parent links — if you invite a co-parent, we store the link between your accounts so that agreed alerts and child profiles can be shared with them.
- Device and technical data — such as IP address, device type, operating system, browser type, app version, diagnostic logs, crash reports, and security telemetry.
- Usage and product analytics — such as funnel events (for example onboarding progress), screen views, feature interactions, and performance metrics.
- Billing data — when you purchase a paid plan, our payment processor may provide limited billing identifiers, subscription status, and transaction references to us.
- Support communications — information you send when you contact us.
Sources of personal data
We collect personal data directly from you when you register, complete onboarding, configure settings, contact support, or otherwise interact with the Services.
We also receive personal data from subprocessors that provide authentication, hosting, analytics, error reporting, or payment processing.
Purposes and legal bases
We process personal data as necessary to provide and operate the Services, including linking accounts, configuring monitoring, generating alerts, securing sessions, troubleshooting issues, and communicating service-related notices.
We process analytics and usage data to understand product performance, improve reliability, and reduce onboarding friction.
We process billing information to fulfill subscriptions you purchase.
Depending on where you live, applicable law may require us to identify a legal basis (such as performance of a contract, legitimate interests balanced against your rights, or consent where required). Where consent is the basis — for example for certain optional communications or non-essential cookies — you may withdraw consent without affecting processing that does not rely on it.
WhatsApp and third-party platforms
WhatsApp is a service offered by Meta Platforms, Inc. and its affiliates ("Meta"). Nanny is not affiliated with, endorsed by, or sponsored by Meta.
If you choose to connect or analyze WhatsApp-related data through Nanny, Meta may process information under its own policies independent from ours. You should review Meta's terms and privacy disclosures.
You represent that you connect only accounts you are lawfully entitled to monitor and that you comply with applicable laws and platform rules.
Children
Nanny is designed for use by adults who are parents or legal guardians (or who otherwise have lawful authority). Account holders must be at least 18 years old (or the age of majority where they live). We do not knowingly market the Services directly to children, and we do not allow children to create their own accounts.
Where the child you protect is below the age of digital consent in their country (for example under 16 in parts of the European Union, or under 13 in the United States), the parent or guardian provides and manages any required consent on the child's behalf and is responsible for handling the child's information lawfully.
Information about minors may appear in your account because you lawfully monitor communications involving them. If you believe we have collected information from a child in violation of applicable law, contact us at admin@nanny.live and we will take appropriate steps.
Cookies and similar technologies
We may use cookies, local storage, or similar technologies that are strictly necessary for authentication, security, load balancing, language preferences, or basic session continuity.
Where required by law, we will obtain consent before using non-essential cookies or cross-site tracking technologies.
Sharing, subprocessors, and recipients
We share personal data with vendors who process it on our behalf and only as needed to provide the Services (subprocessors). Categories typically include cloud hosting and databases, authentication providers, analytics and monitoring tools, customer communications infrastructure, and payment processors.
We may disclose personal data if we reasonably believe disclosure is required to comply with law, enforce our Terms, protect users, or investigate fraud or security incidents.
If we are involved in a merger, acquisition, or asset sale, personal data may be transferred as part of that transaction. We will provide notice where required by law.
We do not sell your personal information as traditionally understood (no monetary exchange for personal data). If we engage in activities that certain jurisdictions classify as a sale or sharing for targeted advertising, we will provide legally required notices and choices.
The subprocessors we currently rely on include:
- Google / Firebase (Google LLC) — account authentication, database storage (Firestore), push notifications, and application hosting on Google Cloud.
- Resend — delivery of transactional and account emails.
- SUMIT — an Israeli payment processor and tax-invoicing provider that handles subscription billing and issues an invoice for each charge on our behalf; we (not SUMIT) are the merchant of record.
- Sentry — error monitoring and crash diagnostics.
- Meta Platforms (WhatsApp) — the third-party messaging platform you choose to connect, governed by Meta's own policies.
- Anthropic (Anthropic PBC) — the AI provider whose models analyze the message content you connect in order to classify it and generate alerts and summaries. Before content is sent for analysis we remove direct identifiers: phone numbers and email addresses are stripped from the text, sender and group names are replaced with non-identifying pseudonyms, and the only account reference attached is an irreversible hash rather than your name or number. Anthropic processes this content as our service provider under its commercial API terms.
International transfers
We may process and store personal data in Israel, the European Economic Area, the United Kingdom, the United States, or other countries where we or our subprocessors operate.
Where transfers require safeguards (such as Standard Contractual Clauses or equivalent mechanisms), we implement appropriate measures consistent with applicable law.
Retention
We retain personal data only as long as necessary for the purposes described in this Policy, unless a longer retention period is required or permitted by law.
Retention periods depend on the nature of the data and legal obligations. Account holders may request deletion subject to exceptions (for example retaining minimal billing records). Where deletion is technically asynchronous, we describe realistic timelines in our responses.
As a general guide:
- Account, authentication, and child-profile data — kept while your account is active.
- Alerts, safety scores, and the message excerpts that triggered them — kept while the child is connected and your account is active so you can review history; removed when you delete the alert, the child, or your account.
- Connected messages — recent connected messages are stored (with direct identifiers such as phone numbers and email addresses removed) so we can analyze them, build the limited thread context an alert needs, and show you recent activity. They are kept only as long as needed for those purposes.
- Billing records — retained as required by tax and accounting law (typically several years), even after account deletion.
- Diagnostic and security logs — kept for a limited period for reliability and abuse prevention.
- After account deletion — we delete or anonymize personal data within a reasonable period, except where retention is legally required; some deletions are processed asynchronously and propagate across our systems and subprocessors shortly after.
Safety, emergencies, and reporting
Nanny is not an emergency, crisis, or child-protection service. It does not monitor in real time and does not guarantee that any particular message is seen, analyzed, or acted on. If a child is in immediate danger, contact your local emergency services or a relevant child-safety or crisis hotline.
Where content processed through the Services indicates that a child may be in danger — for example apparent grooming, sexual exploitation, self-harm, or threats of violence — we may, to the extent required or permitted by applicable law, preserve relevant information and disclose it to law enforcement or to appropriate child-safety authorities or organizations, and cooperate with their lawful requests. Nothing here obligates us to monitor for, detect, or report any particular content.
Security
We implement administrative, technical, and organizational measures designed to protect personal data against unauthorized access, loss, or alteration.
No method of transmission over the Internet or electronic storage is completely secure. You are responsible for safeguarding your credentials and devices.
Your rights
Depending on your jurisdiction, you may have rights to access, rectify, delete, restrict processing, object to certain processing, port data, or withdraw consent.
You may also have the right to lodge a complaint with a supervisory authority.
To exercise rights, contact admin@nanny.live. We may need to verify your identity before fulfilling requests.
Accessing, exporting, and deleting your data
You can review and manage your data from within the product. From Settings you can export a copy of your account data and request deletion of your account and associated data.
You can also disconnect a child or pause protection at any time, which stops further analysis for that child.
Deletion removes your account and associated personal data, except limited records we must keep by law (such as billing records). Some deletions are processed asynchronously and may take a short time to fully propagate across our systems and subprocessors.
Data breach notification
If we become aware of a personal-data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority and affected users where and as required by applicable law, without undue delay.
Automated processing and AI analysis
We use automated analysis to review the messages you connect, classify them for potential safety risks (for example bullying, sexual content, grooming, or self-harm), assign indicative risk levels, and decide whether to raise an alert. To do this, connected message content is sent to our AI provider (Anthropic — see Sharing, subprocessors, and recipients) for classification. Lightweight automated checks run first and govern how much deeper analysis each message receives, but you should assume that the content of the messages you connect is processed by our AI provider.
Before any message is sent for AI analysis we remove direct identifiers as described in the subprocessors section. The classifications are probabilistic and can be wrong in either direction — they may miss real risks and may flag harmless messages or mischaracterize a person. They support your awareness as a parent or guardian and are not decisions that produce legal or similarly significant effects about anyone; the judgment about what to do with an alert remains yours. They are not a substitute for professional advice (medical, legal, therapeutic, or otherwise).
If you believe an alert about a person is inaccurate, you can contact us at admin@nanny.live.
Changes to this Policy
We may update this Policy from time to time. We will post the updated Policy and revise the effective date. Where changes are material and legally required, we will provide additional notice.
Contact
Questions about this Privacy Policy: admin@nanny.live