Privacy Policy

Effective date: August 5, 2026 Last updated: September 4, 2026

This policy explains what AlienTech Services LLC d/b/a Nest Patrol Tech (“NestPatrol,” “we,” “us”) collects, why we collect it, who we share it with, and what control you have.

It covers nestpatrol.com, app.nestpatrol.com, the parent app, the supervised-device app, and our support channels.

Children’s information is covered in more detail in our Children’s Privacy Notice. Washington residents should also read Section 13 and our Consumer Health Data Privacy Policy.


1. The short version

  • NestPatrol is built for visible supervision by a parent or legal guardian. It is not covert monitoring software.
  • We collect account information from parents and device, activity, and content signals from supervised devices.
  • We do not sell your information. We do not share it for cross-context behavioral advertising. We do not serve ads.
  • We do not use identifiable family content to train general-purpose AI models.
  • The parent who created the account controls what is collected, who can see it, and when it is deleted.
  • We are a United States service. Do not use NestPatrol from outside the United States.

2. Information we collect

Parent account information

  • Name, email address, phone number if you provide it, password hash.
  • Household and plan details.
  • Billing information. Card numbers go directly to our payment processor. We receive the last four digits, card brand, expiration, and billing zip code. We do not store full card numbers.

Child profile information you enter

  • First name or nickname, date of birth, and any notes or profile details you add. The date of birth sets an age band that selects age-appropriate crisis resources, the wording of on-device safety check-ins, and recommended protection presets, and supervision ends automatically at the age of majority.

Supervised-device information

  • Device make, model, operating system version, device identifiers, battery level, storage, network state, and app inventory.
  • Installed keyboards and input methods, so that supervision rules never disable the child’s ability to type or to place a call.
  • App usage, foreground time, screen-time totals, and unlock events.
  • Permission changes, offline periods, install and uninstall events, and tamper signals.

Safety signals and content

  • Text visible on the supervised device’s screen, and the text of notifications the device receives. NestPatrol reads this through Android’s accessibility and notification listener services and checks it for the categories described on our Features page, including cyberbullying, grooming, self-harm language, sexting, explicit content, threats, and scams. This can include messages written by people who are not NestPatrol users. We analyze this text to detect risk. Where an alert is created, we store the excerpt that triggered it. We do not deliver a transcript of the child’s conversations to the parent.
  • Web addresses visited in the browser on a supervised device, when web filtering is enabled. These are checked against Google Safe Browsing to identify phishing and malware sites. The address and the result are recorded in the parent account.
  • The alert record itself: category, severity, confidence, timestamp, source app, review status, and supporting excerpts.
  • Screenshot evidence. This capability is off by default. It captures a picture of the supervised device’s screen only when a safety trigger fires, only on eligible plans, and only after a parent turns it on and completes the separate consent step for it. General supervision consent does not enable it. Screenshots are retained for 30 days. See Section 8.

Contact list and call protection (collected only when the Contacts & call protection permission is granted on the child’s device)

  • The names and phone numbers saved in the supervised device’s contact list. These are shown to the parent in the dashboard and Parent App, where the parent can approve, block, or remove any number. Contact lists include the phone numbers of people who are not NestPatrol users; we process them solely to provide this parental review, and never for marketing, enrichment, or resale.
  • Numbers the parent blocks or removes, and support contacts the parent assigns. Assigned support contacts are written into the supervised device’s own contact list so the child sees a familiar name when that person calls.
  • Call protection decisions made on the device, such as a blocked number being prevented from ringing. Call screening works from the phone number alone. We do not record calls, do not listen to call audio, and do not collect the content of phone conversations or SMS messages. Emergency calls always go through and are never screened.

Family messages and requests

  • Messages your child sends to you through the app, your replies, and requests such as extra screen time, an app unblock, or an uninstall, together with the reason your child gives and your decision.

Location information

  • Precise device location and geofence records, only when a parent enables location.

Emergency SOS information

  • Location, battery, device details, time, and any optional message the child includes.

Support and communications

  • Messages you send us, waitlist and early-access signups, and marketing preferences.

Site and product analytics

  • IP address, browser and device type, pages viewed, referring URL, and cookie or SDK identifiers. See Section 14.

3. Where the information comes from

  • Directly from you, when you create an account, enter a profile, or contact support.
  • From supervised devices, after a parent installs the app and grants permissions.
  • From our payment processor and other service providers listed in Section 7.
  • From cookies and analytics tools on our website.

4. How we use information

We use the information above to:

  • Create and secure accounts and authenticate users.
  • Operate supervision, alerts, screen-time rules, location features, reports, timelines, and summaries.
  • Pause or restrict apps on a supervised device according to the rules a parent sets. NestPatrol never restricts the phone dialer, emergency calling, the keyboard, or core system functions.
  • Run automated analysis that flags possible risks and assigns category, severity, and confidence.
  • Show the parent the supervised device’s contact list and apply the parent’s approve, block, and remove decisions to calls on that device.
  • Deliver your child’s messages and requests to you and your replies and decisions back to the device.
  • Deliver notifications, including SOS notifications.
  • Process payments, manage subscriptions, and handle refunds.
  • Provide support and respond to your requests.
  • Detect fraud, abuse, and unauthorized use, and protect the security of the Service.
  • Improve accuracy, reliability, and performance, as limited by Section 5.
  • Comply with law and enforce our Terms.
  • Send service messages. Marketing email is optional and you can unsubscribe at any time.

We do not use family data to build profiles for advertising, to score creditworthiness, or to sell to data brokers.

5. Automated analysis and AI

Alerts and summaries are produced by automated systems. They can be wrong in both directions. They are not medical, clinical, legal, or emergency determinations. You decide what an alert means.

Some analysis runs on the device. Some runs on our servers or with a processor listed in Section 7. Content sent to a processor is used only to return a result to your account. It is not retained by the processor for its own purposes and is not used to train that provider’s models.

We do not use identifiable family content to train general-purpose AI models. To improve our own safety classifiers, we use aggregated or de-identified signals, or specific alert feedback you choose to send us.

Automated analysis does not produce legal effects or similarly significant effects about you. If a state law gives you the right to opt out of profiling, contact us at support@nestpatrol.com. Turning off analysis will disable the core safety features of the Service.

6. What we do not do

  • We do not sell personal information, and we have not sold personal information in the past 12 months.
  • We do not share personal information for cross-context behavioral advertising or targeted advertising.
  • We do not sell, rent, or disclose children’s information for advertising or marketing.
  • We do not collect the Android advertising ID from a supervised device, and the supervised-device app contains no advertising or analytics identifiers.
  • We do not record phone calls, listen to call audio, or collect the content of SMS messages. Call protection works from phone numbers only.
  • We do not use consumer health data for advertising.
  • We do not read your family’s messages for any purpose other than operating the Service, complying with law, or investigating abuse of the Service.

7. Who we share information with

Service providers. We use vendors to run the Service. Our current providers are:

  • Spaceship — cloud hosting, storage, databases, and backups. United States.
  • Google Firebase Cloud Messaging — delivery of push and emergency notifications. Receives device push tokens and notification content.
  • Google Safe Browsing — web address safety checks. Receives web addresses visited on a supervised device when web filtering is enabled. Google does not receive the child’s identity through this check.
  • Groq — AI classification of safety signals. Receives the text being analyzed. Groq does not retain this content for its own purposes and does not use it to train its models.
  • Payment processing — added before paid subscriptions open. We will update this list and give notice before that change takes effect.

We require service providers to use information only to provide contracted services to NestPatrol and to protect it appropriately. If we add or change a provider that receives family content, we will update this section.

Within your household. If you invite an additional guardian, that adult may see supervised-device information according to the access granted by the account owner.

Legal and safety. We may disclose information to comply with law, a subpoena, or a court order, to enforce our Terms, to investigate fraud or abuse, or when we believe in good faith that disclosure is necessary to prevent serious harm to a person.

NCMEC. If we learn of apparent child sexual abuse material on our systems, we may report it to the National Center for Missing and Exploited Children and to law enforcement as required by 18 U.S.C. section 2258A.

Business transfers. If we are involved in a merger, acquisition, financing, or sale of assets, information may transfer as part of that transaction. Any buyer must honor this policy for information collected before the transfer, or give you notice and a choice before applying different terms.

We do not disclose personal information to any other third party without your direction.

8. How long we keep information

We keep personal information only as long as reasonably necessary for the feature, account, security, support, legal, billing, or dispute purpose for which it was collected.

Our current retention periods are:

Data Kept for
Account records Life of the account
Child profiles and supervised-device records Life of the account, or until the parent deletes the child or removes the device
Alerts, safety events, and timeline entries 12 months
Screenshot evidence, when enabled 30 days
Location history and geofence records Up to 90 days; parents can choose a shorter window in Location settings
Emergency SOS records 12 months
Activity and screen-time data 12 months
Support messages 24 months
Security and audit logs 12 months
Billing records 7 years, as required by tax law
Encrypted backups 30 days

When you delete your account, data is removed from live systems within 30 days and from backups within 90 days, except records we must keep for the legal, security, or billing reasons above. See how to delete your account and data.

9. Security

We use encryption in transit and at rest, access controls, least-privilege permissions, logging, and periodic review. Access to family content is limited to staff who need it to operate the Service, and access is logged.

No system is perfectly secure. We cannot guarantee that unauthorized access will never occur. If a breach affects your information, we will notify you as required by law.

Report a vulnerability through our Responsible Disclosure page. Do not include family data in the report.

10. Your choices and controls

You can:

  • Turn optional settings, including location, screenshot evidence, and specific alert categories, on or off in the parent portal.
  • Turn contact-list sharing and call protection off at any time by revoking the Contacts permission on the child’s device. Deleting a child profile deletes that child’s stored contact list.
  • Remove a device. Supervision stops immediately.
  • Delete a child profile and its associated records.
  • Export your family data in a machine-readable format.
  • Close your account and request deletion of everything associated with it. See Delete your account and data, which explains exactly what is removed and what is kept.
  • Unsubscribe from marketing email using the link in any message.

To make a request, use the parent portal or email support@nestpatrol.com from the address on the account. We verify identity before acting. We respond within 45 days and may extend once by 45 days where law allows.

11. Children’s privacy

NestPatrol is intended to be set up and controlled by a parent or legal guardian. Children may not create accounts.

We collect information from a supervised child’s device only after the parent or guardian creates the account, verifies the account email, confirms legal authority over the child and the device, completes our consent step, and enrolls the device. We record the account, device, date, time, and consent version.

Before child-device collection begins, the parent must receive direct notice and complete the consent process presented during enrollment. The method may vary based on the information collected, how it is used or disclosed, and applicable law. Trial access does not waive these requirements. See the Children’s Privacy Notice for detail.

The supervised-device app shows the child, in plain language, what it collects and sends to the parent. That disclosure is available in the app at any time, and it states whether screenshot evidence is currently on. The app never hides its icon or its running notification.

Parents may request review, correction, or deletion of a child’s information at any time, and may withdraw consent by removing the device or closing the account. The production withdrawal workflow must stop further collection and remains a release requirement before public child-device collection.

We do not condition a child’s participation on collecting more information than is reasonably necessary. We do not disclose children’s information to third parties for their own purposes. See the Children’s Privacy Notice for full detail.

12. State privacy rights

Residents of California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, Virginia, and other states with comprehensive privacy laws have rights to:

  • Know what we collect and how we use and disclose it.
  • Access a copy of their personal information.
  • Correct inaccurate personal information.
  • Delete personal information.
  • Obtain a portable copy.
  • Opt out of sale, targeted advertising, and certain profiling. We do not sell information or run targeted advertising.
  • Limit the use of sensitive personal information.
  • Be free from discrimination for exercising these rights.

Sensitive personal information. We collect precise geolocation, the content of communications where we are not the intended recipient, the content of notifications received on a supervised device, and information about minors. We use it only to provide the Service and for the purposes listed in Section 4. We do not use or disclose it to infer characteristics about anyone.

Notice at collection. The categories in Section 2, the purposes in Section 4, the recipients in Section 7, and the retention periods in Section 8 describe NestPatrol’s current practices.

Appeals. If we deny a request, you may appeal by replying to our decision or emailing support@nestpatrol.com with “Privacy Appeal” in the subject. We respond within 45 days. If we deny the appeal, you may contact your state attorney general.

Authorized agents. An agent may submit a request with written authorization. We may ask you to verify the agent’s authority.

13. Washington My Health My Data Act notice

This section applies to Washington residents and to consumer health data we may collect about Washington residents.

Some information we process may qualify as consumer health data. That includes signals related to self-harm language, mental or behavioral health, and precise location that could identify an attempt to receive health services.

  • What we collect. The safety signals, alert records, and location information described in Section 2.
  • Why we collect it. Only to detect and surface possible risks to the parent account, as described in Section 4.
  • Who we share it with. Only the service providers named in Section 7 and the legal recipients in Section 7. We do not sell consumer health data. We do not use it for advertising.
  • Your rights. You may confirm whether we collect your consumer health data, learn who we shared it with, withdraw consent, and request deletion. Email support@nestpatrol.com with “My Health My Data” in the subject. We will delete the data from live systems, backups, and processor systems on the schedule allowed by law.

NestPatrol requires separate parent consent before collecting consumer health data. The production consent record and withdrawal workflow remain release requirements. Affected public collection and processing must remain disabled until those controls are implemented and verified.

14. Cookies and site analytics

Our website uses cookies and similar browser storage for sign-in, session protection, form security, fraud prevention, rate limiting, and load balancing. We do not use advertising cookies or third-party ad trackers. Optional analytics or marketing cookies are not active unless we configure them, disclose them, and update our Cookie Policy and consent controls first.

You can control cookies in your browser. Blocking cookies may break sign-in.

We honor Global Privacy Control signals as an opt-out request where state law requires it.

15. Marketing and the update list

If you join our update list, we use your email to send product news and updates. We do not sell that address. Unsubscribe at any time using the link in any message. Service and transactional messages continue while you have an account.

16. Location of processing

We store and process information in the United States. The Service is offered only in the United States. If you access it from another country, you are responsible for compliance with local law.

17. Changes to this policy

We may update this policy. We will post the new version with a new effective date. If a change is material, we will notify you by email or in the product at least 30 days before it takes effect. Where a change expands the collection or use of children’s information or consumer health data, we will obtain new consent before it applies.

18. Contact us

AlienTech Services LLC d/b/a Nest Patrol Tech
PO Box 777
Woodinville, WA 98072
support@nestpatrol.com

Privacy requests: email support@nestpatrol.com with “Privacy Request” in the subject.