Privacy policy
Effective October 8, 2026
This policy explains what Nectar, the baby sleep app for iPhone, and this website collect, where that information goes, how long it is kept, and what you can ask us to do with it. It describes the app as it is today.
Who we are
Nectar is published by Inservio Strategies Inc., a company incorporated in Ontario, Canada ("Inservio", "we" or "us"). Inservio decides how personal information in Nectar and on this website is used, and is responsible for it.
The person in charge of protecting personal information at Inservio is the President of Inservio Strategies Inc. For any privacy question, request or complaint, write to support@mangocare.app, which reaches the President.
In short
- Nectar works without an account. Until you sign in, what you log about your baby stays on your phone.
- When you sign in, your baby's information is stored with Supabase in the United States, so it is backed up and shared with the caregivers you invite.
- Nectar sends usage analytics to PostHog, including your first name once you sign in and a location PostHog works out from your IP address, and crash reports to Sentry. Both keep the data in the United States.
- Photos, faces and Memories never leave your phone.
- We don't sell personal information and don't show ads.
- To delete your account and everything kept with it, email support@mangocare.app.
Information you give about your baby
Nectar is for parents and other caregivers. Everything Nectar holds about a baby is entered by a parent or caregiver about their own baby, or by a caregiver that parent invited. Babies and children do not use Nectar and give it nothing themselves.
What stays on your phone
Everything you enter is kept on your phone in Nectar's own storage, which Nectar's widgets and Apple Watch app share.
If you never sign in, your baby's information stays on your phone. The usage analytics and crash reports described below are still sent.
Your baby's photo, the photos you pick for Memories, and the face recognition Nectar uses to find your baby in them all stay on your phone. Memories reads your photo library and recognizes faces on the phone itself, and none of it is sent anywhere.
What reaches our servers when you sign in
You sign in with Apple. Once you have signed in, the app stores the following with Supabase, our database service, and keeps it in step across your phones and with the caregivers you invite.
About you and each caregiver
- The email address Apple gives Nectar, which can be an Apple private relay address that forwards to your own, your name as Apple shares it, and the display name you choose.
- Your role for each baby (primary, partner, family or nanny), and the invitations you send and accept, with when each was sent, accepted and expires.
- For each of your phones, its push notification token and Apple's identifier for Nectar on that phone (the vendor device ID).
- Your reminder settings and care reminder settings.
- When you were last active with each baby.
- Which caregiver added each baby and logged each entry in Nectar.
Caregivers of the same baby see the baby's information and each other's names.
About each baby
- Name, birth date, sex and weeks born early.
- The day's start and end times, the expected number of naps, whether your baby is moving between nap schedules, and which schedule you prefer.
- Every sleep: when it started and ended, whether it was a nap or night sleep, whether it was timed live or added afterwards, whether it ended as a false start, and each time your baby woke during it (night wakings).
- Every care entry: nursing with the time on each side, bottles with the amount and milk type, pumping with the amount from each side, and diapers with their type, each with its start and end times.
- Every weight, with when it was measured.
- The optional note you write on a feed, diaper, pumping or weight entry.
- The nap and bedtime predictions Nectar works out for your baby, your prediction settings, and the calibration records that compare predicted and actual sleeps.
Imports from Huckleberry
If you import the export file Huckleberry emails you, Nectar reads the file on your phone and keeps its sleeps, feeds, pumping, diapers and weights as entries like any other, with the notes on its feeds, diapers, pumping and weights. With each imported entry it keeps which import it came from and your phone's time zone at the time, and it records which caregiver imported or removed an import, and when. The file itself never leaves your phone, and who logged each row in Huckleberry is not kept.
Beta testers on our test list
If Inservio adds you to its test list in a TestFlight build, the Test Run screen in Settings can send your answers to test steps, with your notes on them, your phone's model and system version, the app's version, and the part of the app's diagnostic log for each step, linked to your account.
Services that receive information
Nectar uses these services. Each one gets only what is listed here.
Supabase
Stores everything listed under What reaches our servers, and the diagnostic logs you send with Upload Logs in Settings. Upload Logs sends the app's recent diagnostic log with your phone's model, its system version, a general device name and the vendor device ID; logs are kept by that device ID, not by account, in a private store only Inservio can open.
Where: the United States, in Amazon Web Services' Northern California region. How long: until it is deleted, as described under Keeping and deleting.
PostHog
Receives usage analytics from the app, whether or not you have an account. Events sent before you sign in carry a random ID, and once you sign in they are linked to your Nectar account. PostHog gets:
- What you do in the app, such as a sleep started or ended, a feed, diaper or weight logged, a night waking, a prediction shown, an invitation sent or accepted, a partner nudge sent, a memory being made, and the onboarding steps you view or skip, plus the app being opened, installed, updated or sent to the background. Each event is stamped with when it happened, so PostHog has an event, with its time, for each sleep, night waking, feed, diaper, pumping and weight you log.
- With those events: counts, durations in minutes, where in the app or on the phone something was logged (a screen, widget, Live Activity, Control, Siri or the watch), your baby's age band, and the hour of day.
- Your phone's model and name, its system version, your language and region settings, whether you are on cellular or wifi, and the app's version.
- The IP address the events come from, which PostHog keeps and uses to work out a location: city, postal code, province or state, country, time zone, and approximate latitude and longitude.
- Once you sign in: your account's ID, your first name taken from the name Apple shares, your role, your baby's age band, how many babies you track, whether there is a partner, and whether notifications are on.
PostHog does not get your baby's name, your notes, or the amounts and weights you log.
Where: the United States, in Virginia. How long: one year, the period Nectar's PostHog plan keeps events.
Sentry
Receives crash and performance reports from Nectar on a phone: what the app was doing when it crashed or slowed down, the app's version, and your phone's model and system version. Each report is tagged with the same analytics ID PostHog uses. Nectar does not turn on Sentry's collection of IP addresses or other personal details.
Where: the United States, in Iowa. How long: 30 days, the period Nectar's Sentry plan keeps reports.
Apple
- Sign in with Apple gives Nectar your email address, which can be a private relay address, and your name.
- Apple's push notification service delivers partner nudges to your phone, and silent signals that keep your phones, widgets and caregivers in step. A partner nudge shows the sender's name and the baby's name.
- If you test the Nectar beta through TestFlight, Apple passes Inservio your crash reports, which include your time zone, battery level and connection type, how many sessions you have had, and any feedback and screenshots you send.
Apple handles this under its own privacy policy, and says it generally stores personal data in the United States.
How long: Apple's privacy policy says it keeps personal data only as long as needed for the purposes it was collected for, or as the law requires. Inservio keeps the TestFlight reports and feedback Apple passes to it until Inservio deletes them, and deletes none of them on a schedule.
Cloudflare
Runs this website and keeps what its form collects. See What this website keeps.
What this website keeps
When you send the form on the home page, we keep your email address, whether you asked to join the beta, and when you last sent it. Once we add a beta tester, we mark their request approved.
We use your email only to tell you when Nectar launches and, if you asked to join the beta, to add you to the TestFlight beta, whose invitation Apple emails you. We keep it until you ask to be removed: email support@mangocare.app. After we delete an entry, Cloudflare can still restore the database to an earlier point for 7 days, after which the entry is gone for good.
The form's entries are kept in a Cloudflare database we asked Cloudflare to place in eastern North America. Cloudflare does not say whether that is in the United States or Canada, so it may be either.
Each send passes Cloudflare Turnstile's check against automated sign-ups, which receives your IP address and details of your browser. Cloudflare also processes the IP address and traffic details of every visit to serve this website and protect it from attacks. Cloudflare serves visits from its network around the world and says it stores information primarily in the United States and the European Economic Area. Its privacy policy says it keeps personal information only as long as the business purposes it was collected for, or the law, require, and then deletes it. This website uses no analytics and no advertising.
Why we use it, and on what basis
- Running the app, keeping your baby's information in step between your phones and the caregivers you invite, and working out predictions and reminders. Under the GDPR this is needed to provide the service you ask for. Your baby's sleep, care and weight entries also rest on your consent, which you give by choosing to log them and to sign in, and which you can withdraw.
- Usage analytics with PostHog, to understand how Nectar is used and make it better. Under the GDPR this rests on our legitimate interest in improving the app.
- Crash reports with Sentry and TestFlight, to find and fix problems. Under the GDPR this rests on our legitimate interest in keeping the app working.
- Diagnostics you send with Upload Logs or Test Run, to look into a problem you raise or a test you run. This rests on your consent, given when you choose to send them.
- The website's form, to tell you when Nectar launches and to add you to the beta. This rests on your consent, given when you send the form.
- Keeping records the law requires, such as records of privacy incidents, and answering your requests. Under the GDPR this rests on Inservio's legal obligations.
In Canada, Inservio relies on your consent for each of these uses. You can withdraw it at any time by emailing support@mangocare.app. Some of Nectar cannot work without some of it, and we will tell you what withdrawing would mean.
You don't have to give us any of this. Nectar works without an account; signing in is needed only to back up your information and share it with other caregivers.
Predictions and automated decisions
Nectar works out nap and bedtime predictions from your baby's age and the sleeps you log. They are estimates for you to plan with. Nectar makes no automated decision about you.
Location and usage profiles
PostHog works out a location from the IP address of the app's analytics: a city, postal code, province or state, country, time zone, and approximate latitude and longitude. This can locate a person to their city or part of it. It is on for every user, and the app has no setting to turn it off. The analytics also build a profile of how you use Nectar, linked to your account once you sign in. To have the analytics linked to your account deleted, email support@mangocare.app.
Where your information is processed
Inservio is in Canada, and the services it uses keep information in the United States: Supabase in Northern California, PostHog in Virginia, Sentry in Iowa, and Apple generally in the United States. The website's form entries are in eastern North America, in the United States or Canada, and Cloudflare serves visits from its network around the world. So your information is processed outside Canada and outside Quebec, and for people in the European Union, outside the Union. While it is in the United States, courts, law enforcement and national security authorities there may be able to reach it under United States law.
Inservio stays responsible for your information wherever it is processed. These are the safeguards each transfer rests on:
- Supabase: its data processing addendum, part of its terms with Inservio, including the European Union's standard contractual clauses.
- PostHog: a data processing agreement Inservio signed with PostHog on October 8, 2026, including the standard contractual clauses, and PostHog's participation in the EU-U.S. Data Privacy Framework.
- Sentry: a data processing amendment Inservio signed with Sentry on October 8, 2026, and Sentry's participation in the EU-U.S. Data Privacy Framework, with the standard contractual clauses if the Framework does not apply.
- Cloudflare: its data processing addendum, part of its terms with Inservio for personal data of people in Europe, including the standard contractual clauses.
- Apple: Apple's own privacy policy, under which its transfers of personal data from the European Economic Area, the United Kingdom and Switzerland rest on standard contractual clauses.
- From the European Union to Inservio in Canada: the European Commission's decision that Canada protects personal data adequately for organizations subject to Canada's federal private sector privacy law.
Who can see it
At Inservio, only the President has access to personal information. Supabase, PostHog, Sentry, Cloudflare and Apple hold it as service providers, to run their services for Nectar. The caregivers you invite see your baby's information and your name. We don't sell personal information or share it for advertising, and we disclose it to anyone else only when the law requires it.
How it is protected, and the risks
Information travels between the app and its services encrypted. Our database lets each caregiver read only the babies they have been given access to, the diagnostic logs sit in a private store, and only the President can open the website's list of sign-ups.
No system is perfectly secure. If a service holding Nectar's data were breached, someone could see your baby's name, birth date, entries and notes, or your email address and name. The analytics also link your first name to an approximate location.
Keeping and deleting
- Inservio deletes nothing on a schedule from its own stores: the database, the diagnostic log store, and the website's form database. Information there is kept until you or Inservio delete it.
- When you delete an entry in the app, it is not erased from our servers. It is kept as a deletion marker, so your other phones and your caregivers remove it too.
- To delete your account and all its data, email support@mangocare.app, and Inservio deletes it by hand. The app does not have a delete button yet.
- PostHog keeps analytics events for one year, and Sentry keeps crash reports for 30 days, the periods Nectar's plans with them set.
- Apple and Cloudflare keep what they handle for as long as their own privacy policies say, as described under Services that receive information and What this website keeps.
- The website's entries are kept until you ask to be removed, and can be restored for 7 days after we delete them.
Your rights
You can ask us to:
- tell you what personal information we hold about you and give you access to it,
- correct it,
- delete it,
- give you a copy in a structured, commonly used format,
- stop a use you consented to, by withdrawing your consent,
- stop or restrict a use you object to.
To use any of these rights, email support@mangocare.app, ideally from the email address you sign in with so we can confirm the request is yours. We answer within 30 days, and it costs nothing.
Complaints
If you are unhappy with how we handle your information, email support@mangocare.app. The President reads every complaint, looks into it, answers you in writing within 30 days, and fixes what is wrong.
You can also complain to the Office of the Privacy Commissioner of Canada, to Quebec's Commission d'accès à l'information, or, in the European Union, to the data protection authority where you live or work.
How Inservio looks after it
- Roles: the President is the only person at Inservio with access to personal information, and answers for this policy, for requests and for complaints.
- Keeping and destroying: information is kept and deleted as described under Keeping and deleting.
- Complaints: handled as described under Complaints.
- Incidents: Inservio records every privacy incident and keeps those records for at least two years. When an incident creates a real risk of significant harm, we report it to the Office of the Privacy Commissioner of Canada or Quebec's Commission d'accès à l'information, and tell the people affected as soon as we can.
Consumer health data (Washington)
This section is Nectar's consumer health data privacy policy under Washington's My Health My Data Act.
- What we collect: weeks born early, sleeps, night wakings, feeds (nursing and bottles), diapers, pumping and weights, and the notes on them, entered by you or a caregiver you invite, or imported from a Huckleberry export you choose. We also keep the predictions worked out from them.
- Why: to show your baby's history, work out nap and bedtime predictions and reminders, and share them with the caregivers you invite; and, through the analytics described under PostHog, to understand how Nectar is used.
- Who it is shared with: Supabase, which stores it; PostHog, which gets an event stamped with its time for each sleep, night waking, feed, diaper, pumping and weight you log, with its kind, whether a sleep was a nap or night sleep, and its duration, but not amounts, sides, notes or your baby's name; and the caregivers you invite. We don't sell it.
- Your rights: you can ask us to confirm whether we collect your consumer health data, see it, delete it, and withdraw your consent. Email support@mangocare.app. We delete it within 45 days of your request.
Changes to this policy
When this policy changes, the new version is posted on this page with the date it takes effect.