Privacy & Data Safety
You trust us with sensitive financial information about your family. Here's exactly how we protect it and what we do — and don't do — with it.
What information we collect
To calculate your entitlements, NestWise asks for your combined household income, the number and ages of your children, the childcare fees and hours you pay, and your work or study hours per fortnight. For paid subscribers we also store your email address and billing details (handled securely by Stripe — we never see your full card number).
We do not collect your Tax File Number, Centrelink Customer Reference Number, Medicare number, or any government identity documents.
How your data is stored
Your profile data is stored in Supabase, an enterprise-grade database platform built on PostgreSQL. All data is encrypted at rest and in transit using industry-standard AES-256 encryption. Supabase infrastructure is hosted in Australia (Sydney region) and is SOC 2 Type II certified.
Access to your data is protected by row-level security — meaning even within our own database, queries can only return your data when you are authenticated as you.
What we do with your data
Your data is used for one purpose: to calculate and display your childcare entitlement estimates. We do not use your data for advertising, profiling, or marketing to third parties.
We may use anonymised, aggregated data (for example, average CCS rates across income bands) to improve the product — but this data cannot be traced back to you or any individual family.
Who can see your data
Only you can see your family's data. Adelante Technologies staff have extremely limited access to production data and only for the purpose of debugging issues you have reported. We do not share your data with Centrelink, the ATO, or any government body.
Our third-party service providers (Supabase for database, Stripe for payments, Resend for email, Vercel for hosting) each have their own privacy and security certifications and only process the data required for their specific function. Your primary database sits in Supabase's Sydney region so your data stays in Australia.
Where your data lives
Your NestWise database, backups, and application logs are hosted in Australian data centres (Supabase Sydney region for the database; Vercel for the app, which serves Australian users from Sydney and Melbourne edge nodes). We operate under the Australian Privacy Principles (Privacy Act 1988) and treat your family's information with that standard as the floor, not the ceiling.
Some supporting services — payment processing (Stripe) and outbound transactional email delivery (Resend / AWS SES) — may transit briefly through overseas infrastructure. In every case only the minimum needed to complete that specific function is sent (e.g. a card number for Stripe, an email address for a receipt). Financial figures, entitlement amounts, and profile detail never leave the Sydney database in ordinary operation.
In-app help and AI assistant
When you're signed in, you can ask NestWise a question from the help menu. Answers are generated by our own AI assistant (Anthropic's Claude Haiku, called from our servers) trained ONLY on the public NestWise guides at /guides. It's not a third-party chatbot vendor — no Intercom, no Zendesk, no OpenAI ChatGPT sitting alongside your conversation.
The assistant runs under strict safety rules: it MUST cite the guide it's answering from, and any dollar figure or percentage in its answer is server-side validated to appear verbatim in that guide before we show it to you. If it can't answer safely, it escalates to a human at hello@nestwise.net.au.
We DO NOT send your income, your ATI, your entitlement amounts, or any dollar figure from your profile to the AI assistant — the same data discipline the rest of the product uses. What the assistant sees is your question plus the relevant public guides, nothing more.
Every question is logged to our own database (guide_questions table) so we can improve the guides. Questions are stored in Australia alongside the rest of your data and are never sold or shared.
Payments and billing
Subscription payments are processed by Stripe, a PCI-DSS Level 1 certified payment processor. NestWise never stores or sees your full credit card number. Stripe handles all payment data in accordance with the highest level of payment security standards.
Your rights
You can export or delete your NestWise account and all associated data at any time by emailing hello@nestwise.net.au. We will process deletion requests within 7 business days. You can also update or correct any information stored in your profile at any time from the Profile page.
Cookies and analytics
NestWise uses TWO kinds of analytics, both kept minimal.
First-party product analytics: a small events table on our own database that records which calculators you opened and which wizard steps you completed. We use this to fix bugs and decide what to build next. The events we record only ever capture the event NAME plus a few non-sensitive properties (e.g. which tool was opened, which wizard step). They NEVER capture income, ATI, entitlement amounts, or any dollar figure — the /api/track route strips these defensively server-side.
Google Analytics: we use Google Analytics 4 to measure aggregate visitor traffic to our marketing pages (homepage, calculators, guides). It records standard browser-level signals — country, device type, the page URLs you opened, the source you arrived from. We have IP anonymisation enabled and advertising features turned off. Google Analytics does NOT receive any income, entitlement, or dollar figures from NestWise. You can opt out of GA tracking by installing Google's official browser opt-out (https://tools.google.com/dlpage/gaoptout) or by enabling Do Not Track in your browser.
We do NOT use Meta Pixel or any other third-party advertising tracking script. We use session cookies required for authentication; no advertising cookies, no cross-site tracking beyond GA's standard measurement.