Privacy policy
Version 2026-08-03 · Effective 2026-08-03
Who we are
UNICORNZ Zbigniew Czarnecki (“we”, “us”) is the data controller for the Nini family rhythm companion and related Nini Bot services (Nini, Nini Bot).
Established in Poland. This notice is written for caregivers in the EU/EEA and elsewhere using the service in English.
Privacy contact: privacy@nini.app. Product support: pilot-support@nini.app.
Summary
Nini helps caregivers in a household log infant care, coordinate handovers, and see shared rhythm context. We do not sell personal data. Nini is not a medical device and does not provide diagnosis or treatment.
Care data stays within your household unless you choose to share (invites, optional expert links) or we use subprocessors listed below to run the service.
What we process
- Account: email address, display name, household membership and role (owner, parent, caregiver, or read-only expert).
- Child profile: display name, date of birth, optional due date / gestation — used for age-appropriate guidance, not for advertising profiles.
- Care logs: sleep, feeding, diaper, soothing, symptoms (optional free-text notes), context tags, timers, and who logged each event.
- Household coordination: handover notes, plan steps, guidance feedback, safety escalation acknowledgements, and timezone/locale preferences for routines.
- Authentication: one-time passcodes (hashed on our servers), session tokens (httpOnly cookie), optional trusted-device flag, and basic device metadata (e.g. user agent) for session management.
- Notifications (optional): Web Push subscription keys and your notification preferences; payloads avoid symptom prose and care note bodies.
- Optional expert share links: time-limited links you create in Settings with selected sections; sensitive notes excluded by default.
- Privacy operations: export/deletion requests, audit entries for security and privacy actions (no care record bodies in status emails).
Purposes and legal bases (GDPR)
We rely on different legal bases depending on the processing. You can manage optional purposes in Settings → Data & purposes.
- Provide the service (contract): account, household sharing, care logging, plans, guidance, sync, and handovers.
- Authentication and security (contract / legitimate interest): passwordless OTP sign-in, session cookies, RBAC, audit logs, and abuse prevention.
- Safety prompts (vital interest / care safety): surfacing escalation flags before schedule advice; audit until acknowledged.
- Optional symptom or research/marketing choices (consent): optional symptom notes; separate toggles for research and marketing — not combined by default.
- Web Push and install prompts (consent): browser permission plus in-app choices; deferrable prompts after valuable actions.
- Product analytics (consent or legitimate interest by region): scrubbed events such as session start, care logged (type only), sync, plan steps — never note text or child names.
- Hosting analytics (legitimate interest): Vercel Web Analytics on page views via @vercel/analytics (no care data).
- Legal obligation / rights requests: exports, deletion scheduling, and compliance records.
Sensitive fields (inventory)
The following fields are documented in our product inventory and shown in Settings. Retention below reflects active accounts unless deletion is requested.
- Child date of birth (required): Age-band guidance and safety rules. Basis: Contract / care service delivery. Retention: While account active + 30 days after deletion request.
- Child display name (optional): Personalize shared care screens. Basis: Contract / care service delivery. Retention: While account active.
- Caregiver email (required): Authentication and household invites. Basis: Contract / authentication. Retention: While account active + audit window.
- Symptom free-text notes (optional): Caregiver memory within household only. Basis: Consent (optional field). Retention: While account active; excluded from telemetry.
- Handover note (required): Partner handoff of current care context. Basis: Contract / care coordination. Retention: While household account is active.
- Safety escalation details (required): Surface safety flags before schedule advice. Basis: Vital interest / care safety. Retention: Until acknowledged + 1 year audit retention.
- Web Push subscription keys (optional): Deliver consented notifications. Basis: Consent. Retention: Until unsubscribe or account deletion.
Subprocessors
We use vetted providers to run Nini. Typical data and agreements:
- Vercel — application hosting, edge/runtime, environment secrets, request metadata and operational logs.
- Neon — managed PostgreSQL; all household application data at rest (encryption managed by Neon).
- Resend — delivers sign-in and privacy reauthorization emails to your address (from Nini <codes@nini.app>).
- Browser push infrastructure (e.g. Apple, Google/Mozilla push services) — subscription endpoints and minimal notification payloads you consent to.
- Vercel Web Analytics — anonymous page-view telemetry loaded after first paint (DeferredAnalytics); separate from in-app product analytics.
International transfers
Your data may be processed in the regions where Vercel and Neon operate for your project. We rely on vendor DPAs and standard contractual clauses where required. Contact us if you need a copy of relevant safeguards available to us.
Retention
Account deletion: after OTP reauthorization you may schedule deletion with a 14-day reversible hold (Settings → Export & deletion). Partner impact is explained before you confirm.
Backups: daily point-in-time recovery windows; weekly full snapshot expiry. Neon managed backups follow project PITR settings. After account erasure completes, backup expiry continues on the documented Neon retention window so deleted tenant rows age out of restore points without a separate manual wipe step.
- care_events: up to 1095 days — Core care events while account active, then 3-year archive max.
- symptom_notes: up to 730 days — Optional notes retained while useful for household memory.
- telemetry: up to 90 days — Scrubbed product telemetry only.
- audit_logs: up to 730 days — Security and privacy operation audits.
- push_subscriptions: up to 30 days — Removed on unsubscribe; residual cleanup within 30 days.
- notification_receipts: up to 30 days — In-app Recent updates history; safe template copy only.
Cookies, local storage, and offline data
- Session cookie (nini_session): httpOnly, SameSite=Lax, secure in production — keeps you signed in (12 hours untrusted device, 30 days if you trust the device).
- Browser localStorage: theme, analytics consent/region, optional research/marketing purpose choices, PWA install/push deferral state, timeline view preference, offline care outbox queue, offline snapshots of Now/Plan, and cached knowledge articles for offline reading.
- IndexedDB: durable outbox for care commands waiting to sync (household-scoped, no auth tokens in payloads).
- Service worker: caches static assets and supports offline-first logging; does not bypass household access controls on the server.
Product analytics detail
In-app product analytics uses pseudonymous account and household identifiers, event names, and scrubbed metadata. Forbidden fields (notes, symptoms, child names, etc.) are stripped before ingest.
Region policy: EU/EEA/UK — EU/EEA/UK: product analytics requires explicit analytics consent separate from product care. US — US default: scrubbed product analytics under legitimate interest with opt-out; marketing stays consent-only. Other — Default-conservative: require analytics consent when region is unknown.
You can change region and analytics consent under Settings → Product analytics. We do not load third-party advertising SDKs in the care app.
Your rights
- Access / portability: JSON export and portable CSV/JSON package from Settings → Export & deletion (parent/owner roles).
- Erasure: schedule account deletion with reversible hold; cancel within the window if you change your mind.
- Restrict / object: adjust optional purposes, push notifications, analytics, and expert links in Settings.
- Withdraw consent: turn off push, analytics, research, or marketing choices without affecting core care logging you still use.
- Complaint: you may lodge a complaint with your supervisory authority; we encourage you to contact us first at privacy@nini.app.
Security
- TLS for data in transit; Neon-managed encryption at rest.
- Household isolation enforced on the server for every care API.
- Passwordless OTP codes expire quickly and are stored hashed.
- Sessions are revocable from Settings → Security / devices.
- Status emails for privacy operations do not attach care records.
Children’s data
Nini is used by adults caring for infants. Information about a child is entered by caregivers with parental responsibility. We minimize fields, avoid public profiles, and apply retention limits described above.
Changes
Version 2026-08-03. We will update this page when processing changes materially and note the effective date. Continued use after notice may require renewed consent where GDPR requires it.
Contact
Controller: UNICORNZ Zbigniew Czarnecki.
Privacy: privacy@nini.app. Support: pilot-support@nini.app.
Signed-in caregivers can also use Settings → Data & purposes and Settings → Export & deletion.
