Nidly Privacy Policy
Last updated: September 20, 2026. Nidly is a family organizer for iPhone and Android, made by VibeApps ("we", "our", "us"). This policy says exactly what the app collects, which companies process it on our behalf, and how to get rid of it.
The short version
- We collect what the app needs to work for your household, plus anonymous product analytics. Nothing else.
- We do not sell your data, we do not share it with anyone for their own purposes, and Nidly contains no advertising and no advertising identifier.
- Your phone's own calendar is read on the device and never uploaded.
- Photos you scan to create an event or a recipe are sent to our AI provider, read once, and not stored by anyone.
- You can delete your account and its data from inside the app at any time.
What we collect
Your account
- On Android, you sign in with Google. On iPhone, you sign in with Apple or Google. We receive and store your email address and your first name from whichever provider you chose. If you use Apple's Hide My Email, we only ever see the relay address.
- A Firebase user ID that identifies your account to our database.
Your household's content
Everything you and your household create in the app is stored in our database so it can sync between your family's devices:
- Calendar events you create in Nidly, including any location you attach to one.
- Tasks, their due dates and repeats, who they're assigned to, and reminders.
- Meals you plan, recipes you save or import, and grocery lists and items.
- Rewards, the coin ledger, and who earned or spent what.
- Your household's name, its join code, and the family-member profiles in it — each a name, a colour, and optionally a photo.
- Photos you attach to a recipe, a reward or a member profile, stored in Firebase Cloud Storage.
Purchases
If you subscribe to Nidly Premium, the store — Google Play or Apple — handles the payment. We never see a card number, a billing address, or any payment instrument. We store the state of your subscription so the app knows your household is premium: which product you bought, which store it came from, when it expires, the store's own transaction identifier, and the amount and currency of the transaction for our revenue reporting. Google Play also receives a one-way hash of your user ID from us, so a purchase can be matched to the right account and to detect fraud.
Analytics and your device
We use PostHog for product analytics — to learn which screens people use and where they get stuck. What is sent is deliberately narrow:
- Which events happened, from a fixed list: viewing the sign-in screen, starting, failing or completing sign-in, creating or joining a household, finishing setup, creating or completing a task, seeing the empty Tasks screen, seeing the upgrade screen, connecting two households, and sharing an item.
- Categories about those events, never their contents. For example, a completed task reports which bucket it was in and whether it carried coins — never its title. Household size is reported in bands (1 / 2 / 3–4 / 5+) rather than as a number.
- Which screen you're on, your device model, OS version and app version, and when the app is installed, opened and backgrounded.
- A persistent anonymous device identifier, which we link to your Firebase user ID once you sign in, and reset when you sign out.
We never send task titles, event titles, grocery items, recipes, household names, email addresses or display names to our analytics provider. PostHog does not collect an advertising ID.
For notifications, we store a device push token and a Firebase installation ID against your account, so a reminder can reach the right phone.
If Nidly crashes, we collect the crash report — the technical trace of where the code failed, the type of error, the error's own message, and the device and app version it happened on. It goes to PostHog, the same analytics provider above, and it is what lets us fix a crash we can't reproduce. A crash report only exists if the app actually crashes, so most people never generate one.
We never put your household's content into a crash report — no event, task, recipe or member names. One caveat we'd rather state than gloss: the error message comes from whichever piece of software failed, and a message written by the operating system or a library can quote what it was working on at the time — for example, a recipe link you shared into Nidly that turned out to be unreachable. We don't send that deliberately and we don't use it for anything but fixing the crash.
We do not collect performance traces, ANRs, or any other diagnostics.
What we read but never store
Your phone's calendar
If you allow it, Nidly reads your device calendar so your existing appointments appear alongside your family's. This is read-only — Nidly never writes to your calendar — and those events never leave your phone. They are not uploaded to our database, they are not sent to any third party, and revoking calendar permission removes them from the app immediately. This is also how a Google, Outlook or Exchange calendar you already sync to your phone shows up in Nidly.
Photos you scan
When you photograph a party invitation or a cookbook page for Nidly to read, the image is sent from your phone to our server and on to Anthropic, whose Claude model extracts the details. The image and the extracted text are not saved by us or by Anthropic — only a counter of how many scans your household has used. The event or recipe that comes back is saved only if you choose to save it.
Recipe links you share
When you share a recipe link into Nidly, that single URL is sent to our server, which fetches the page and extracts the recipe. We receive the one link you chose to share. We do not have, and never receive, your browsing history.
Who processes your data
These companies handle data on our instructions, for us, and for no purpose of their own. None of them is permitted to sell it.
| Company | What for |
|---|---|
| Google Firebase | Sign-in, database, file storage, server functions, and push notifications. Your household's content lives here. |
| PostHog | Product analytics, as described above. Data is processed in the United States. |
| Anthropic | Reads photographed invitations and cookbook pages, and imported recipe pages, and returns the structured result. Nothing is retained. |
| Google Play / Apple | Takes payment for a subscription and tells our server whether it is active. |
Stores you choose to send a list to
Two grocery features send data outside Nidly, and only at the moment you ask them to:
- Kroger. If you connect a Kroger account, your phone talks directly to Kroger's API. The grocery items you're sending, the store you picked and any ZIP code you typed to find that store go to Kroger. We hold the authorisation token Kroger issues so you don't have to sign in again; deleting your Nidly account erases it. Kroger's own privacy policy governs what they do with it.
- Walmart. We match your list against Walmart's catalogue on our server and hand you a Walmart cart link. No Walmart sign-in, no token, nothing stored.
Your household
Joining a household means the people in it see its shared content — the calendar, tasks, meals, recipes, lists, rewards and coin history — and see your member name and photo. If you connect your household to another one, the specific events or recipes you send are copied into theirs; they never gain access to the rest of your household.
What we do not collect
- Your location. Nidly requests no location permission and contains no location code. A ZIP code you type to find a store is text you entered, held on your device and sent only to Kroger when you ask.
- Your contacts. Nidly never reads them.
- Your microphone, or any audio.
- Health, fitness or financial-account data.
- An advertising identifier. Nidly has no ad SDK and no ads.
Why we're allowed to use it (UK and EEA users)
- Performing our contract with you — your account, your household's content, syncing it between devices, and running your subscription.
- Your consent — reading your device calendar, sending you notifications, and using your camera or photo library. Each is asked for separately, and you can withdraw any of them in your device settings.
- Our legitimate interests — product analytics to improve the app, and preventing fraudulent purchases. We keep this to the narrow, non-identifying set described above.
How long we keep it
Your household's content is kept while your account is active. When you delete your account we remove your personal data immediately, and operational backups containing it age out within 30 days. Analytics events expire on our analytics provider's retention schedule and are not linked to your account once you have deleted it.
Deleting your account
Open Nidly, tap the person icon on the Agenda tab, scroll to the bottom and tap Delete Account. It takes effect immediately. Full details of what is removed, including what stays behind when other people are still in your household, are on the delete-account page.
If you can't sign in, email nidlyapp@gmail.com from the address you signed up with and we'll handle it within 30 days.
Your rights
Wherever you are, you can ask us to give you a copy of your data, correct it, or delete it, and you can turn off notifications, calendar access, camera and photo access at any time in your device settings. Email nidlyapp@gmail.com and we'll respond within 30 days.
California residents have the rights to know, delete, correct and opt out of sale under the CCPA as amended. We do not sell personal information and do not share it for cross-context behavioural advertising, so there is nothing to opt out of. We will not discriminate against you for exercising any of these rights.
UK and EEA users have the rights of access, rectification, erasure, restriction, portability and objection under the UK GDPR and GDPR, and the right to complain to your data protection authority. Data is processed in the United States under the standard contractual clauses our processors provide.
Children
Nidly is for adults organizing a household, and accounts are intended for people 18 and over. We do not knowingly let a child create a Nidly account, and we do not knowingly collect personal information directly from children. A child can appear in Nidly as a family-member profile that an adult in the household created — a first name, a colour, and optionally a photo — and that adult can delete it at any time. If you believe a child has created an account, email us and we will remove it.
Changes, and how to reach us
If we change this policy in a way that matters, we'll say so in the app before the change takes effect, and the date at the top will move. Questions, requests, or anything you think this page gets wrong: nidlyapp@gmail.com.