nuvio Privacy Policy
Version 1.6, 24 September 2026
This Privacy Policy explains what nuvio does with information when you use the app. It forms part of, and uses the same defined terms as, our Terms of Use. In it, "nuvio", "we", "us" means BubsNest UK Ltd., Flat 11, Marzell House, 120 North End Road, London W14 9PP, United Kingdom.
nuvio is for people aged 13 or older. If you are under 18, you need a parent or legal guardian's permission to use it, and they must supervise your use. If you monitor a child, you must be their parent or legal guardian or have that parent or guardian's permission.
1. Our approach, in one paragraph
nuvio is designed to keep monitoring private by default. Listening and watching happen on the monitor device unless you choose a feature that uploads selected media, such as cloud processing, cloud clips, sharing, support, or backup. We do not sell your data or use your media for advertising. A small amount of service data passes through our servers so that alerts reach you, remote viewing works, monitoring health can be checked, and subscriptions can be managed. This policy describes what that is.
2. What stays on your device
The following is created and stored on your own devices, and shared only within your paired household unless you explicitly enable or use a cloud feature for selected media:
- Live audio and video from the monitor.
- Cry detection, sleep tracking, movement, and expression analysis. These run on the monitor device using on-device machine learning by default.
- Recordings, snapshots, and keepsake "Moments".
- Your activity logs: feeds, nappies, sleep, temperatures, symptoms, medicines, milestones, and notes.
- Subject names, dates of birth where relevant, and household labels.
Within a household, devices share this information directly with each other (over your home WiFi, or peer to peer over the internet when you are away). The monitor device acts as the hub.
Because most information is kept on your devices and not in our cloud, it is only as durable as your devices unless you enable cloud storage or backup. If you reset, wipe, lose, or replace a device, or uninstall the app, data held only on that device may be lost to us and cannot be recovered by us. Data that has synced to another device in your household still lives there. If you want a lasting copy, export or save what matters, keep more than one household device paired, or use cloud features when available.
3. What passes through our servers, and why
To deliver alerts and remote access, a limited amount of service data reaches our servers (hosted on Amazon Web Services; see Section 7). We keep this to the minimum needed to run the service:
- Household and device identifiers. A household id and a per-device id link your devices so alerts go to the right phones and your subscription can cover the right number of devices. A device role (monitor or parent phone) and an optional device name you choose are stored alongside.
- Push notification tokens. Your device's Apple (APNs) or Google (FCM) push token, so a cry alert or a "monitor offline" warning can reach your phone when you are off WiFi or the app is closed.
- Connection signalling. To start a live video or audio connection between your devices, they exchange technical connection details (including network addresses) through our server for a short time. This is how two devices find each other; it is not the audio or video itself.
- Relay for streaming. When your devices cannot connect directly, the encrypted stream may be relayed through a relay server. The stream is encrypted end to end, so the relay cannot see or hear its contents.
- Liveness and diagnostics. While monitoring, the monitor device posts a short status every ~30 seconds (for example, whether the app is active and detection is running) so we can warn you if the monitor goes silent, and so we can diagnose reliability problems. Bounded connection-quality summaries may include app/build, device class, OS major version, network type, decoded-frame timing, LAN/direct/relay path, and the two-letter region from the device's configured locale. They do not include media, IP addresses, precise location, carrier, network name, or raw connection candidates.
- Alert records. When an alert is sent, we log basic details of the send (such as the alert type, monitor name, and title) so that alerting can be made reliable. We do not include audio or images unless you choose a feature that uploads selected media.
- Subscription and seat data. Your subscription tier and the devices sharing it, so a household plan can be enforced across your phones.
- Support messages and attached diagnostics. If you contact us through in-app feedback, we receive what you write, including any details you choose to share. The form also tells you that it attaches a small, issue-specific technical snapshot, such as app/build, device class, OS major version, scalar device health, current connection/monitor state, and counts of relevant fault categories from the preceding five minutes. Privacy questions and ordinary product ideas receive a more limited snapshot without health, monitor state, or recent fault history. The attachment never contains audio, video, images, transcripts, names, activity records, network addresses, or raw logs.
4. AI insights and the third parties involved
If you use AI summaries, insights, cloud processing, or cloud clips, the information needed to provide that feature may be sent to our processors. This can include subject names, age where relevant, recent activity summaries, selected images, selected clips, or selected audio snippets. It is used to provide the feature and is not used to train third-party foundation models. If you do not use these features, this data is not sent for them.
When the separate model-improvement sharing control applies, the app may send small, privacy-preserving learning packets containing bounded model scores, device/runtime context, and inferred outcome labels (for example "cry" or "cooing"). These never contain audio, video, images, transcripts, names, household/device IDs, network addresses, activity records, or support-message text. A random, resettable learning identifier may link episodes from one installation so that adjacent samples can be kept out of different training/evaluation splits; it is not used as a household identity.
5. What we do not do
- We do not sell your audio, video, images, or activity logs.
- We do not sell or rent your personal information.
- We do not use your data for third-party advertising, and we do not embed advertising trackers.
- We do not track you across other apps or websites.
6. Diagnostics and analytics
To keep a monitoring app reliable, we use crash reporting and basic, privacy-preserving product analytics. These record events and technical information (such as a crash, an app version, a device model, or that a monitoring session started or a reconnection happened), tied only to a random, resettable install identifier. They do not include audio, video, images, names, or activity logs. Where the law requires it, we ask for your consent before using non-essential analytics, and you can opt out in the app's settings.
7. Where your data is processed
We use the following processors to run the service:
- Amazon Web Services, for our database, signalling, liveness, service delivery, and—only when you choose the relevant feature—cloud storage or AI processing.
- Apple Push Notification service and Google Firebase Cloud Messaging, to deliver notifications.
- PostHog EU, for the basic product analytics described in Section 6 when that setting is enabled.
- Google Firebase Crashlytics, for crash reporting when that setting is enabled.
- A TURN relay provider, for relayed connections (encrypted content only).
Some of these providers may process data in countries outside your own, including the United States. Where we transfer personal data internationally, we rely on appropriate safeguards such as the providers' standard contractual clauses.
8. How long we keep it
We keep service data only as long as needed for the purpose it was collected:
- Signalling data is short-lived and is deleted soon after a connection is set up.
- Push tokens are kept while your device is part of a household and refreshed as they change; when a device leaves a household, its token for that household is removed.
- Diagnostic, liveness, and alert-log data is kept for a limited period to run and troubleshoot the service, then deleted or aggregated. The diagnostic capsule attached to an in-app feedback request and its media-free fleet-analysis copy expire after 90 days; the written support request follows the support-message retention period below.
- Support messages are kept for as long as needed to help you and to keep a record of support.
- On-device data (recordings, logs, Moments) stays until you delete it or uninstall the app. Uploaded media is kept only for the feature you chose and under that feature's controls.
9. Children's privacy
nuvio is for users aged 13 or older and is not directed to children under 13. People aged 13 to 17 may use the app only with a parent or legal guardian's permission and supervision. If you monitor a child, the app processes limited information about that child (such as a first name, date of birth, and activity a carer logs) so that an authorised carer can monitor and keep records. The household can manage or delete this information (Section 10). We do not knowingly collect personal information directly from children under 13 as app users.
10. Your rights and choices
Depending on where you live, you may have rights to access, correct, delete, export, or restrict the use of your personal data, and to object to certain processing. Because most of your data lives on your own devices, you can exercise many of these rights directly:
- Access and export: your logs, recordings, and Moments are on your device and can be viewed and shared from within the app.
- Correction and deletion: you can edit or delete logs, recordings, Moments, subject profiles, and paired devices in the app.
- Remove a device or leave a household: this frees its seat and removes its push registration for that household.
- Reset: uninstalling the app removes the app's on-device data from that device.
To delete the service data we hold that is linked to your household or devices (Section 3), or to make any other privacy request, contact us at hello@bubsnest.co and we will action it, usually within 30 days. If you are in a region with a supervisory authority for data protection, you also have the right to complain to it.
11. Legal bases
Where the UK or EU GDPR applies, we process personal data on these bases: to perform our contract with you (running the monitor, alerts, and subscriptions); our legitimate interests (keeping the service reliable and secure, and improving detection using non-identifying data); your consent (for non-essential analytics, and for AI features you choose to use); and to comply with legal obligations.
12. Security
We protect your information with encryption of live streams in transit, on-device storage of your recordings and logs, access controls on our servers, and household credentials that limit access to your monitor and data to the devices you have paired. No system is perfectly secure, so we also give you controls (removing devices, resetting identifiers) to protect yourself. If a breach affects your personal data, we will notify you and any regulator as the law requires.
13. Changes to this policy
We may update this policy. Material changes will be shown in the app, and the current version is always available in the app and at our published policy link. The "Version" and date at the top show when it last changed.
14. Contact
Questions or privacy requests: hello@bubsnest.co. Postal: BubsNest UK Ltd., Flat 11, Marzell House, 120 North End Road, London W14 9PP, United Kingdom. For data protection matters, this is also how to reach the person responsible for privacy at BubsNest UK Ltd.