Neiliro
Features Live demo GitHub
RU Join waitlist

Privacy Policy

Effective September 10, 2026 · Applies to the hosted Neiliro service and this website

Neiliro is a household organizer built around a simple promise: your family's data belongs to your family. This policy describes what we actually collect, where it lives, and what you can do with it — in plain language, because a privacy policy you can't read isn't one.

Who we are

Neiliro is operated by Denis Burtsev. For anything in this policy: [email protected].

This policy covers the hosted service (your family's space at yourfamily.neiliro.com), the public demo, and this website. The self-hosted edition runs on your own server under your own control — nothing from it ever reaches us.

What we collect

  • Waitlist: your email address, and nothing else.
  • Account: your name, email address, and a one-way hash that lets us check your password — we never store the password itself, and your browser no longer sends it: it sends a key derived from the password, and that is what the hash is of. Your family's encryption key, stored only inside sealed envelopes that a member's password, the family's recovery code or another member's device can open, and we cannot. If you enable two-factor authentication, its secret. If you link Google sign-in, the permanent identifier Google gives us for your account. On the hosted service, the moment you accepted the Terms and this policy when the account was created — the documents are dated, so that timestamp says which version you agreed to.
  • Sign-in housekeeping: whether your login address has been confirmed, and the one-time links we mail you — for confirming an address or resetting a password. Those are stored hashed, never in readable form, and expire (a week for a confirmation, an hour for a reset). We keep the fact that a password was reset and when, because "was my account recovered by someone else?" deserves an answer.
  • Your family's content: the tasks, notes, calendar entries, financial records, uploaded files, and mail received at your family's address. This is your data, stored so the product can show it back to you — we do not read it, analyze it, or use it for anything else. Since September 10, 2026 the words in it are encrypted in your browser with a key we do not hold, so this is engineering as well as conduct; see Who can read your family's content for what that covers and what it does not.
  • Support messages: if you write to us through support.neiliro.com, the message, the address to reply to, and the family address you name — kept while we work on it and for a year afterwards, so "we discussed this before" has somewhere to look. The form also stores a shortened, one-way digest of your IP address, which exists to stop a public form being used to flood a mailbox and identifies nobody.
  • Technical records: server logs (which never include the contents of your requests), your active sessions with IP address and last-seen time (shown to you under Devices, so you can spot an unfamiliar login), and a daily per-family activity count — how many requests, how many people signed in that day, and which sections were opened; never what was in them, and never who did what.

What we deliberately don't do

  • No analytics scripts, no trackers, no advertising — on this site or in the app. That's why there is no cookie banner: the only cookies are the ones that keep you signed in.
  • No email open or click tracking, and no newsletters or product mail you didn't ask for. Mail your family receives is not inspected beyond automated spam and size limits.
  • No selling or sharing of data with anyone, for any purpose. There is no version of Neiliro's business that involves your data being the product.

Who can read your family's content

Since September 10, 2026: not us. Everything your family writes — the text of notes, the names of events, tasks, accounts, categories and lists, the notes on transactions, the names and contents of files, the letters received at your family's address — is encrypted in your browser with a key that never reaches our servers. What we store is ciphertext and the key's sealed envelopes: one per member, opened by that member's password, and one opened by a recovery code the app shows your family exactly once. Invitations and re-admission links carry the key in the part of the address after the # sign, which browsers never send to any server. Neither we nor anyone who takes our disks or backups can open any of it. The design and the code are public — the decision record and the tracking issue.

What stays readable, and why. Dates, amounts, currencies, statuses and the links between records — that an event exists and when, that a payment was made and how much, which note a file belongs to — stay in the clear, because that is what lets the server add up a budget, repeat an event or send a reminder. Members' names and login addresses are readable, since they identify accounts, and so a birthday reminder carries a readable name. A file's size and type are readable; its name and its bytes are not. A letter keeps its arrival time, size and Message-ID readable, the last because threading needs it; the sender, subject, body and attachments are sealed. Wishlists are readable on purpose: they exist to be shown to people outside the family, and the wishlist page says so.

Four places where our server does see words. We would rather list them than leave you to find out:

  • Mail arriving at your family's address reaches our server as plain text — that is how email works. The server seals it to your family's public key before writing anything; the plain text exists in the server's memory for milliseconds and is never stored or logged.
  • A reply to such a letter is written in your browser but sent by our server, which therefore sees that text at the moment of sending. The stored copy is sealed like an incoming letter, and the reply box says so.
  • Links that carry the key. A calendar subscription, a link to one event and a guest link to a shared list carry your family's key after the token, because a calendar app and a guest need words. When such a link is opened, our server uses the key to open those rows for that request only; it does not store the key and does not write it to a log. This also means the link is exactly as private as whoever holds it: hand your calendar subscription to Google Calendar and Google holds a key that opens your family's content, not just the feed. Any of these links can be revoked with one button in the app.
  • Rows written before the key. Content created before your family's key existed stays stored as it was until a member runs "Encrypt what was written before the key" under Settings → Family key — once per member, because private rows are visible only to their owner. For those rows, "we do not read it" means what it always did: we don't.

What this does not protect against. The key is only as safe as the passwords and devices that hold it; a device without the key sees placeholders instead of words, which is the point. A password reset restores your account, not the key — a new password cannot open an envelope the old one sealed — so keep the recovery code, or ask another member for a re-admission link. No web application can protect you from an operator who serves a tampered copy of the app itself; what protects you there is that the code is open and the build can be checked against it. And we say "encrypted with a key we do not hold", never "zero knowledge": the shape of your data — how much, when, how often — is visible to us, and the words that are not are listed above.

Email the service sends you

Four kinds of letter, all plain text, all from a no-reply address on our own mail domain, and nothing else — no newsletters, no product announcements, no "we miss you":

  • the invitation to set up a newly created family, sent to the administrator's address once, when we create the family;
  • a request to confirm the address an account signs in with, when the account is created;
  • the link that resets a forgotten password, only when someone asks for it;
  • a notice that this policy or the terms are about to change, sent to your family's administrator before the change takes effect, and only when something material changes.

We ask you to confirm the address because it is the key to recovering an account: a typo at signup would otherwise hand a stranger a working way into your family. A reset link is only ever mailed to a confirmed address, is single-use, and does not switch off two-factor authentication. Because a reset request must not reveal whether an address has an account here, the page says the same thing either way.

Signing in with Google

Google sign-in is optional and stays off until you link it yourself from settings. When you use it we ask Google for the minimum — that the sign-in happened, and which address it belongs to — and keep only Google's identifier for your account. We get no access to your Gmail, Drive, contacts, or anything else in your Google account, and Google is told nothing about what is inside your family's hub. Google does, of course, see that you signed in to Neiliro; if you'd rather they didn't, use a password — that path is always available.

Where your data lives

In the European Union. The hosted service runs on DigitalOcean servers in Amsterdam, Netherlands. Each family's data is a separate, isolated database. Backups are encrypted with a key that never touches the server, and expire within 14 days; the words inside them are already ciphertext from your browser. The server disk itself is not encrypted today.

We rely on three infrastructure providers (our only subprocessors):

  • DigitalOcean — servers (Amsterdam, EU)
  • Cloudflare — DNS, this website, the waitlist, and the support site
  • Mailgun (EU region) — receiving and sending email for your family's address, plus the four service letters above, processed and stored in the EU

Your rights — built in, not on request

  • Export: download your family's complete archive from settings, anytime, free, on any plan. It restores into a self-hosted Neiliro — leaving is always possible, by design.
  • Deletion: deleting your family removes its database and files; backups expire within 14 days after that.
  • Correction: everything is editable in the app.
  • For anything else GDPR grants you (access, restriction, objection, complaint to a supervisory authority), write to [email protected].

Children

Neiliro is made for households, and family spaces are created and managed by an adult administrator. Accounts for children exist only when a parent or guardian creates them inside their own family. The service is not directed to children, and we never knowingly collect data directly from a child under 13.

The public demo

The demo at demo.neiliro.com gives every visitor a throwaway sandbox that is deleted when you log out or after two hours of inactivity. We keep anonymous counters about demo visits (how many, which modules were opened, where visitors came from) — never who you are or what you typed.

If something goes wrong

If a breach affects your personal data, we will notify you and the relevant authority within 72 hours of discovering it, and tell you plainly what happened and what we're doing about it.

Changes

If this policy changes in any way that matters, we'll email your family's administrator before the change takes effect. The current version always lives at this address.

Neiliro
Privacy Terms Support Live demo По-русски

Built by a family, for families. © 2026 Neiliro