Overview & Commitment

At FamilyNest, we treat your family's data with the same care we would our own. As a platform serving parents, caregivers, and children, we recognize the heightened responsibility that comes with handling sensitive personal and family information. This document outlines our security architecture, data retention timelines, compliance frameworks, and your rights regarding your data.

📌 Key Principle: We collect only what is necessary to provide our services, retain it only as long as required by law or service necessity, and never sell or share your data with third-party advertisers.

Security Practices

We implement industry-leading technical and organizational measures to protect your data against unauthorized access, alteration, disclosure, or destruction.

🔐 Data Encryption

  • In Transit: All data is encrypted using TLS 1.3 or higher.
  • At Rest: Databases and backups use AES-256 encryption with key rotation every 90 days.
  • Authentication: Multi-factor authentication (MFA) enforced for all admin and support access.

Access Control & Infrastructure

Our infrastructure is hosted on certified cloud providers with strict zero-trust architecture. Access to production databases follows the principle of least privilege, with all access logged, time-bound, and reviewed quarterly. Our development and staging environments never contain production data.

Vulnerability Management

We conduct automated penetration testing monthly, third-party security audits annually, and maintain a responsible disclosure program. All critical vulnerabilities are patched within 48 hours of identification.

Data Retention Policy

We retain your data only for as long as necessary to provide our services, comply with legal obligations, resolve disputes, and enforce agreements. Once the retention period expires, data is securely deleted or anonymized.

Data Type Retention Period Deletion Method
Account & Profile Data Until account deletion + 30 days Secure cryptographic erasure
Pregnancy & Child Milestones While account is active Immediate deletion upon request
Community Forum Posts Indefinite (unless reported) Manual removal or anonymization
Payment & Billing Records 7 years (tax/legal compliance) Archived securely, masked after 3 years
Support Tickets & Logs 2 years Automated secure wipe
Device & Usage Analytics 90 days (aggregated/anonymized) Automated rotation & hashing
⚠️ Account Deletion: When you delete your FamilyNest account, all personal data is permanently removed within 30 days. Some anonymized, aggregated data may be retained for service improvement and legal compliance.

Compliance & Standards

FamilyNest adheres to rigorous international privacy and security standards, particularly those governing family and child-related data:

  • GDPR & GDPR-K (EU): Full compliance with data subject rights, lawful processing bases, and data protection impact assessments.
  • COPPA (USA): Strict verification for users under 13, parental consent mechanisms, and restricted data collection for minors.
  • CCPA/CPRA (California): Transparency in data collection, opt-out mechanisms, and sale/sharing restrictions.
  • SOC 2 Type II: Annual audits verifying security, availability, and confidentiality controls.
  • ISO 27001: Certified information security management system.

We conduct bi-annual compliance reviews and maintain up-to-date records of processing activities (ROPA).

Child Data Protection

Because FamilyNest serves families, we enforce additional safeguards for any data associated with minors:

  • Children under 13 cannot create independent accounts. Parental/guardian accounts are required.
  • Child profiles (milestones, photos, preferences) are never used for advertising or profiling.
  • Facial recognition, biometric scanning, and behavioral tracking are strictly prohibited.
  • Parents retain full export, modification, and deletion rights for all child-associated data.
✅ Parental Control: You can set data visibility permissions, disable location tracking, and restrict third-party integrations at any time in your account settings.

Incident Response & Transparency

Despite robust security measures, we maintain a formalized incident response protocol aligned with NIST and ISO standards:

  1. Detection & Triage: Automated monitoring and security team review within 1 hour.
  2. Containment & Eradication: Isolate affected systems, apply patches, and revoke compromised credentials.
  3. Notification: Affected users notified within 72 hours of confirmed breach per GDPR/COPPA requirements.
  4. Recovery & Post-Mortem: Restore services, publish transparency report, and implement corrective controls.

We publish annual security transparency reports detailing incident counts, response times, and systemic improvements.

Your Rights & Controls

Depending on your jurisdiction, you may have the following rights regarding your personal data:

  • Access & Portability: Download a complete copy of your data in JSON/CSV format.
  • Correction: Update inaccurate or outdated information instantly.
  • Deletion: Request permanent erasure of your account and associated data.
  • Restriction: Limit processing while disputes are resolved.
  • Opt-Out: Disable marketing communications and analytics tracking.

To exercise these rights, visit your Account Settings → Privacy & Data dashboard, or contact our Data Protection Officer directly.

Security & Privacy Inquiries

Have questions about our security practices, need to report a vulnerability, or wish to submit a data request? Our trust & safety team is here to help.

📧 Contact Our Security Team

We respond to all security and privacy inquiries within 2 business days.