Security and privacy at NestliCare

How NestliCare protects child and family data. Encryption, who can see what, where data lives, backups, and what happens when you leave.

overviewUpdated 2026-09-07 Raw markdown

You are trusting NestliCare with records about children and families. Here is how that data is protected, in plain terms. The full legal versions are the Privacy Policy, the Data Processing Agreement, and the Security page.

Who can see what

Every login has a role, and the role decides what is visible:

  • Parents see only their own children: the feed, messages with their child's teachers, invoices, and pickup.
  • Teachers see the rooms they are assigned to. They cannot open another room's children, and they never see billing or pay rates.
  • Center admins and owners see their own organization. Finance pages can be limited further per admin.

Each daycare's data is isolated from every other daycare on the platform. Nobody at another organization can reach your records, and parents can never see other families. See Can parents see other families? and What can each staff role do?.

Encryption and hosting

  • Data is encrypted in transit (TLS 1.2 or newer) and at rest (AES-256).
  • NestliCare runs on Amazon Web Services in the United States. Media such as photos and signed documents is stored there too.
  • Card and bank account numbers never touch NestliCare. Parents enter them directly with the payment processor (Stripe, or Adyen where enabled). NestliCare keeps only a reference, the card brand, and the last four digits.

Sign-in protection

  • Passwords are never emailed. Invitations carry a one-time link to set a password.
  • Failed sign-ins lock the account temporarily, and bot protection runs on signup and login.
  • Sensitive administrative actions (settings changes, agreement acceptance, deletions) are written to an audit log with the user, time, and IP address.

No selling, no advertising

Child, family, and daycare records are never sold, never shared with advertisers, and never used for advertising. The signed-in dashboard and the mobile apps carry no third-party advertising or analytics trackers. Analytics runs only on the public marketing pages, which hold no customer data.

Backups and retention

  • The database has point-in-time recovery for roughly the last 7 days, and nightly encrypted archive copies that expire after about 31 days.
  • Records you keep for licensing (attendance, incidents, health) are never purged automatically. You control them. An optional record-retention setting under Settings can purge old records on a schedule you choose.
  • In-app notifications are removed after at most 180 days, and AI-generated daily summaries after 30 days.

You can also have periodic CSV reports and signed-document copies emailed to you, so a copy of your records lives outside NestliCare. See Email reports and backups.

Organizations are required to obtain parental consent before photos or videos of a child are uploaded. In the European Union, the United Kingdom, and Switzerland, staff photo features stay off until per-child consent is in place (Ireland already runs in consent mode). Photo consent is recorded per child and granted by the parent, so a family can keep their child out of group photos that other families see.

Your data is yours

  • Export reports, invoices, payments, and payroll as CSV any time, or ask support for a complete copy of everything your organization holds. See How do I get my data out?.
  • Parents and staff can download a copy of their own data from the app and can request account deletion. See How do I close my account?.
  • Every organization is covered by a Data Processing Agreement. Organizations in the EU, EEA, UK, and Switzerland accept it once at signup. See Accept the Data Processing Agreement.
  • If you stop using NestliCare, your records stay until you ask us to delete them, so you can still export or come back. A verified deletion request from the owner is completed within 90 days.

Compliance questions

  • GDPR and UK GDPR: NestliCare processes organization data under the DPA with Standard Contractual Clauses for transfers to the United States. For EU and UK residents, NestliCare has appointed DataRep as its data protection representative; contact details are in the Privacy Policy.
  • PIPEDA (Canada) and Australian Privacy Principles: the same rights to access, correct, and delete apply. Direct requests about records your daycare entered to the daycare first, since it controls them.
  • HIPAA: daycares are not HIPAA covered entities, so no Business Associate Agreement is needed. State confidentiality rules for child records still apply, and NestliCare's access controls are built for them.
  • Breach notification: if a breach ever affects your organization, we notify you promptly with the scope, the impact, and what we did about it.

Security questions or a vulnerability to report: [email protected].

Related: Is NestliCare really free?, Where does NestliCare work?.

Related articles

Was this article helpful?