Privacy Policy
Last updated: 11 September 2026
1. Who we are
NannyTank is a web application and website that helps au pairs and nannies log their working hours and kilometres, calculate monthly claims, and submit them to their employer. Employers can create their own account and, once an au pair connects them, view that au pair's hours and claims, approve claims, and share a schedule. NannyTank also runs a marketplace: au pairs can create a public profile to be found by families and can browse and apply to jobs; families and agencies can post jobs and browse au pair profiles. It is operated by Reynard du Toit (support@nannytank.co.za). This policy applies to everyone who uses NannyTank — whether as an au pair, an employer, or an agency, and whether you use the app or the website.
2. What data we collect
- Account data: Your email address and whether you use NannyTank as an au pair, an employer, or an agency, used to create and identify your account via Supabase Auth. You can create an account and set up a profile or listing either in the app or on the website — the data collected is the same.
- Log data (au pairs): Hours worked, kilometres driven, trip descriptions, and dates that you enter manually into the app.
- Settings: Your name and profile details. For au pairs this also includes employer name and email, vehicle, km rate, hourly rate, and working hours; for employers it includes your payment-reminder preferences. Entered by you in the Settings screen.
- Connections: When an au pair generates a pairing code and an employer enters it, we store the link between the two accounts so the employer can see that au pair's information (see section 3). Either side can disconnect at any time.
- Public profile (au pairs, optional): If you choose to create a marketplace profile, we store the display name, photo, headline, "about you" description, country and city/area, years of experience, availability, languages, skills, and the credentials you say you can provide (for example "police clearance" or "first aid") that you enter. When you publish it, this profile is shown publicly in the NannyTank directory (see section 3). It deliberately does not include your exact address, phone number or email, and your uploaded document files stay private — a profile only lists the credentials you choose to advertise, never the documents themselves.
- Job listings (employers & agencies, optional): If you post a job, we store the job title, the family or agency name you enter, the country and city/area, hours, start date, number and ages of children, pay, the requirements you're looking for, and the description you write. When you publish it, this listing is shown publicly on the NannyTank jobs board (see section 3).
- Agency teams (optional): An agency can work as a team rather than as one login. If you create one, we store the agency’s name and, if you add them, its description, website and logo — these appear publicly on the agency’s job listings. We also store who is on the team and what role they have, so that members see the same job posts and the same applications. When an owner invites a colleague we store the email address they typed, who sent the invite and when, and an expiry date — that address is used to send that one invite and nothing else. It is never added to a mailing list and never used for marketing. An invite expires after seven days and works once.
- Contact requests and applications: When a family or agency contacts an au pair, or an au pair applies to a job, we store the name, email address, phone number (if given) and message that the sender chooses to share, and pass them to the other person so they can reply (see section 3).
- Shared schedule (optional): Calendar entries you create in the in-house schedule — title, date and time, location and notes. These are visible to the au pair and their connected employer.
- Schedule photos (optional): If you use the photo-scan button on the Schedule tab, the picture — either one you take there and then, or one you pick from your device's photo library — is sent to our AI provider, Anthropic, which reads it and returns the dates and times it contains as draft entries. It is usually a family schedule on a whiteboard or fridge, a printed term planner, a handwritten note, or a screenshot of one. Because these are household schedules, they often mention children by name, along with their activities, schools and times — please only scan a photo you are comfortable sharing for this purpose. The whole picture is sent, not just the part with the schedule on it, so if something else happens to be in the frame, crop it first. We do not store the photo: it is sent for the reading and then discarded, and under Anthropic's commercial terms your content is not used to train their models. Nothing is added to your schedule until you review the draft entries and choose to save them; if you cancel, nothing is kept. We do keep a small record of each scan — which account ran it and when — so we can apply a daily limit.
- Comments (optional): Messages you leave on a shared schedule entry. These are visible to the au pair and their connected employer.
- Claim status: Whether a claim has been approved and marked paid by the employer, and marked as salary received by the au pair — so both sides can keep track. No card or bank details are involved (see section 5).
- Documents (optional, au pairs): Personal and work documents you choose to upload — for example a police clearance, first-aid certificate, driver's licence, ID or passport, CV, or contract — as PDFs or images. Because these can be sensitive identity documents, we treat them as strictly private: they are held in a private storage area with no public web address, protected by database-level access rules, and can be opened only by you and an employer you have connected — no other user and no member of the public (see section 6). You can delete any document at any time.
- Google Calendar data (optional): If you choose to connect Google Calendar on the Schedule tab, we request read-only access to your calendar events. We use this solely to display upcoming events inside the app. We do not store your calendar events in our database.
- Push notification subscription: A browser/device token used to deliver optional reminders and alerts you turn on — for example a daily logging reminder for au pairs, or a new-claim alert and a payment-day reminder for employers. No message content is stored beyond the subscription endpoint.
- Profile photo (optional): By default we show the picture from your Google account. If you upload your own — as an au pair or an employer — it is stored in Supabase Storage and shown in your own profile in the app.
- Reviews and ratings (optional): If you rate or review NannyTank in the app, we store your star rating, any comment you write, the display name you choose, and whether you've consented to your review being featured.
- Location (optional): When you use the Quick Status feature and choose to share your location, we access your device's location to put a map link in the WhatsApp message you send your employer. Your location is not stored — it only goes into the message you choose to send.
- Payment and purchase data: When you buy NannyTank, your card details are entered directly with our payment processor — Paystack in South Africa, Paddle elsewhere — and NannyTank never sees or stores your full card number. We store your billing email, whether you are on a trial or have purchased, how many photo scans you have left, and the reference the processor gives us so we can confirm the payment. We do not store a card, and there is nothing recurring to manage.
- Digital resource purchases (no account needed): If you buy a document from our resources shop, we store the email address you gave at checkout, which product you bought, the amount and currency, the country you were billed in, the country edition you chose, and whether and when your files were delivered. We also store the wording of the confirmation you ticked before paying, and the date you ticked it — that record exists so that, if there is ever a dispute about what you agreed to, we can both see exactly what was on the screen.
- Free downloads from our blog: If you ask us to email you a free checklist or sheet, we store your email address, which file you asked for, the article you asked from, the country you chose, whether you separately opted in to marketing, and the exact consent wording you were shown. The marketing opt-in is separate and never pre-ticked; if you leave it unticked we send you the file and nothing else.
- Licences bought for somebody else: A family can buy an au pair a NannyTank licence. When they do we store the licence code, the buyer’s email address, and — if the buyer gives it to us so we can send them the code — the au pair’s email address. We also store which licence has been redeemed, by which account, and whether it is still running. If your employer gave us your address, you did not give it to us yourself, so the first email you get from us says exactly that, says who gave it, and tells you that ignoring it costs you nothing (POPIA section 18).
- Authorised claim addresses (families who bought a licence): The email address a family bought under, plus any further addresses they choose to add — a partner, an accountant, a new work address — so that a claim sent to one of them is expected. These are addresses the family types in themselves.
- “Ask your employer” recommendations: If an au pair asks us to recommend NannyTank to the family they work for, we store the address they give us, the name they ask us to use, and the date, so that we send it once and never again. That address is kept only as the record of that one email. It is never added to a mailing list, never used for marketing, and never merged with any other list we hold.
- Product reviews: If you review something you bought, we store your rating, your written comment, the display name you choose (optional), and a link to your order so we can confirm you actually bought it. A published review shows your rating, comment and display name — never your email address.
3. How we use your data
- To display your logged hours and km on the Log and History screens.
- To generate your monthly Excel claim and email it to your employer when you request it.
- To show your family's shared Google Calendar events on the Schedule tab (if connected).
- To let a connected employer view that au pair's hours, kilometres, days off, and claims, approve or record payment of claims, and share a schedule with them (see below).
- To send optional push notifications you turn on — a daily logging reminder for au pairs, and new-claim and payment-day reminders for employers.
- To include your live location in a status message to your employer — only when you choose to send one.
- To manage your 14-day free trial and, if you buy NannyTank after it, process your one-time payment through Paystack or Paddle.
- To collect your feedback through in-app ratings and reviews, and — only if you choose to feature it — to display your review and chosen display name publicly (see below).
- To run the marketplace: to show a profile or job listing you choose to publish, to let you browse profiles and jobs, and to pass on a contact message or a job application to the person — or the agency team — you send it to (see below).
We do not sell your personal information or use it for advertising. Aside from the third-party services listed below that help us run NannyTank, we share your personal information only in ways you control: with an employer you connect (below); through the marketplace, when you choose to publish a profile or job or to contact or apply to someone (below); and reviews you choose to feature (below).
Public profiles and job listings (optional). The marketplace is opt-in. A profile or job listing you create stays a private draft until you choose to publish it. Once published, it is shown publicly in the NannyTank directory or jobs board — on our website and in the app — and can be seen by anyone, including people who do not have an account, and may be cached or indexed by search engines. Published profiles and listings show only the details described in section 2 (for example a first name, city, experience and credential badges) — never your exact address, and never your uploaded document files. You can unpublish a profile or delete a listing at any time, which removes it from public view going forward.
Contacting and applying. When a family or agency gets in touch with an au pair, or an au pair applies to a job, the sender chooses to share their name, email, phone number (optional) and a message. We pass these details to the person or the agency you sent them to, so they can decide whether to reply. If the job was posted by an agency that works as a team, everyone on that team can see your application — your name, your email, your phone number if you gave one, and your message — not only the person whose name is on the listing. That is how an agency answers you when the person who posted the job is away. A job posted by a family, or by an agency that is one person, is seen only by them. After that introduction, the two of you communicate directly, outside NannyTank. We are not a party to and do not monitor those conversations. NannyTank does not verify the identity, background, credentials or documents of any user — please see our Terms of Service about doing your own checks before employing anyone or accepting a job.
Agency teams. An agency can put several people on one team. Everyone on the team sees the same job posts and the same applications to them, and can post, edit, publish and reply on the agency’s behalf; only the person who created a post, or an owner of the team, can delete it. Members can see each other’s email addresses and who created which post — that is what makes it a team rather than a shared password. An owner can remove a member, and a member can leave, at any time; either way that person immediately stops seeing the team’s posts and applications. Nothing about an au pair’s hours, claims, documents or connected-employer data is ever part of a team — a team is about job listings and the applications to them, and nothing else.
Sharing between au pairs and employers. NannyTank lets an au pair connect an employer. The au pair starts this by generating a pairing code and giving it to their employer; nothing is shared until the au pair does so. Once connected, the employer can see that au pair's logged hours and kilometres, days off, sick and vacation days, submitted claims and their amounts, the shared in-house schedule and any comments on it, and any documents the au pair has uploaded. Both people can add, edit and delete entries in the shared schedule and post comments, which the other can see. Either side can end the connection at any time (au pair: Settings → Connect my employer; employer: Account → disconnect), which stops any further sharing. We share this information only between the two connected accounts — never with other users.
Licences bought for you, and how one ends. When a family buys an au pair a licence, that licence is the right to log and it runs while that au pair is working for that family. To know whether that job is still going, we look at one thing and one thing only: the email address a claim was sent to. If it is the address the family bought under, or one they have added to their authorised list, nothing happens. If it is not, the claim still goes — it is never held up or blocked — and instead we email them to say which address it went to and what that means, and email the family to ask whether to add an address or whether the job has ended. Only if a second claim goes to an unauthorised address, at least seven days later, does new logging stop.
Two things about this matter more than the mechanism. We never tell the family which address a claim went to. If they have moved on, that address belongs to their new employer, and it is not ours to pass on — the family is asked to type an address they already know, or to tell us the job has ended. And this looks at nothing else: not their hours, not their location, not how often they log, not what a claim contains. It is one address, compared against a list the family wrote themselves. If a licence does end, everything they have logged stays theirs to read and export, and they can restore logging by buying NannyTank themselves or by redeeming a licence from whoever they work for next. If we have got it wrong, replying to any of those emails reaches a person who can put it back.
Reviews you choose to feature. When you submit a review you can tick a box to let us feature it. If you do, your review and your chosen display name may be shown publicly — on our website (such as nannytank.co.za) and in materials promoting NannyTank. Anything shown publicly can be seen by anyone and may be cached or indexed by search engines. We never feature a review without that consent, and you can withdraw it — or ask us to remove your featured review — at any time by emailing support@nannytank.co.za.
4. Google Calendar access
When you connect Google Calendar, NannyTank requests the https://www.googleapis.com/auth/calendar.readonly scope. This allows the app to read your calendar events and display them in the Schedule tab.
We do not:
- Store your calendar events in our database
- Share your calendar data with any third party
- Use your calendar data for any purpose other than displaying it to you in the app
You can revoke Google Calendar access at any time by visiting myaccount.google.com/permissions and removing NannyTank.
NannyTank's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We never use or transfer Google user data for serving advertisements, selling to data brokers or information resellers, determining credit-worthiness, lending, training generalised AI or machine-learning models, or any purpose other than providing and improving the calendar feature you see in the app.
5. Payments and purchases
Access to NannyTank is a one-time purchase after a 14-day free trial — R699 in South Africa, and a local price elsewhere. No card is needed to start the trial, anywhere. If you buy NannyTank outright, nothing recurs and we do not bill you again. If you choose the monthly subscription instead, your payment provider keeps a payment method on file so that it can charge you each month, and it stops doing so when you cancel. NannyTank itself never stores your card number under either option. Purchases by South African customers are handled by Paystack, a PCI-DSS compliant payment processor, and purchases from outside South Africa by Paddle, which acts as merchant of record. With either provider your card details are entered into and stored by them, not by NannyTank. We only store whether you have purchased or subscribed, when a subscription next renews, the number of photo scans you have left, and the provider references needed to confirm the payment and to cancel a subscription. Paystack's handling of your payment information is governed by their privacy policy.
One-off purchases from the resources shop. Buying a document does not need an account. Payment is handled by Paystack for South African buyers and by Paddle for buyers elsewhere — Paddle acts as merchant of record for those sales, meaning it is the seller for tax purposes and handles the payment and any VAT. In both cases your card details are entered into and stored by the payment provider, not by NannyTank. We receive and keep the email address you gave, what you bought and the provider's transaction reference, which is what lets us deliver your files and re-send them if you lose them. Paddle's handling of your information is governed by its privacy policy.
6. Data storage and security
Your data is stored in Supabase (PostgreSQL), hosted on AWS infrastructure. All data is encrypted in transit (HTTPS/TLS) and encrypted at rest. Access requires authentication, and each user's data is isolated using Row Level Security — you can only access your own records, except for the information you choose to make public (a profile or job listing you publish), to share with someone else (the details you send when you contact an au pair, apply to a job, or connect an employer), or to share with an agency team you belong to (that team's job listings and the applications to them). Those are described in section 3.
Aside from what you choose to publish or share, your data is not accessible to other NannyTank users. If you connect Google Calendar, your events are read live and shown in the app only — they are never written to our database.
Your uploaded documents. We give the certificates and personal documents you upload extra protection, because they can include sensitive identity documents such as a driver's licence, ID or passport. They are kept in a private storage area: there is no public link to them, and they cannot be found by browsing our storage or by guessing a web address. Access is restricted by the same Row Level Security rules as the rest of your data, so the only people who can open a document are you and an employer you have personally connected — no other NannyTank user, and no member of the public, can reach them. When you or your connected employer view a document, it opens through a temporary link that expires after a short time and cannot be reused by anyone else. Deleting a document removes both the file and its record. Like all data in NannyTank, your files are encrypted in transit and at rest; as with any online service, our operator and hosting provider have the technical access needed to run, secure and back up the service, and we do not look at your documents except where genuinely necessary to operate or support NannyTank, or where the law requires it.
7. Data retention and deletion
Your data is retained for as long as you have an account.
Deleting your account yourself. You can delete your account from your account page, under Settings. It happens immediately and it cannot be undone. It removes your logged hours and kilometres, your settings, your marketplace profile, your job listings and the applications to them (unless they belong to an agency team — see below), the contact requests you sent or received, your uploaded documents and your shared schedule entries. You can also still email support@nannytank.co.za and we will do it for you within 7 days.
What is deliberately kept, and why. If you bought a document from us, the record of that sale — the email address you bought with, what you bought, the amount and the date — is kept after your account is gone. It is a record of a completed sale and we are required to keep it for tax and accounting purposes (POPIA section 14 allows retention where the law requires it, and where it is the record of a contract we performed). It holds no login and nothing you logged. Similarly, if an employer bought you a licence, the record of their purchase stays with them — your identity is removed from it, but we do not delete something somebody else paid for.
We will not delete an account that is still being billed. If you have a subscription that can still take a payment, deletion is refused until you cancel it. This is not an obstacle we put in your way — your card is charged by Paystack or Paddle, not by us, and deleting your account here would remove the only screen you have to stop it while the payments carried on. Cancel first, on the Plan tab, and then delete.
If you are on an agency team. Deleting your account removes you from the team. The job posts you created pass to another member of it, along with the applications to them, because they are the agency’s listings rather than your personal ones — the agency keeps answering the people who applied, and your name comes off them. If you would rather they came down as well, unpublish or delete them before you delete your account. If you are the last person on the team there is nobody to pass them to, and they are removed along with everything else.
If a licence bought for you ends. Nothing is deleted. Your account stays, everything you logged stays, and you can sign in, read it and export the full spreadsheet for as long as the account exists. What stops is adding new entries — the record is yours, not the job's. See section 3.
If your free trial ends and you don't buy. What you logged during the trial stays yours. You can sign in and export it as a spreadsheet for at least 3 months after your trial ends — the option is on the screen you see when the trial is over. You just cannot add new entries until you buy. After that we may delete it, and we will email you before we do. We keep it that long so that nobody loses a month of hours they might still need to claim for; we do not keep it indefinitely, because POPIA asks us not to hold personal information for longer than the purpose requires.
8. Your rights (POPIA)
NannyTank is operated from South Africa and handles your personal information in line with the Protection of Personal Information Act (POPIA). You have the right to access the personal information we hold about you, to have it corrected, to object to its processing, and to request its deletion. Most of your information you can view and change directly in the app or on your account page at any time. Two of those rights are now self-service: you can download everything your account holds as a file from Settings on your account page, and you can delete your account from the same screen (see section 7 for exactly what that does and does not remove). You can still email support@nannytank.co.za for any access, correction, objection or deletion request, and for anything the self-service options do not cover.
9. Third-party services
- Supabase — database and authentication. Privacy policy
- Vercel — hosting, and privacy-friendly website analytics (see section 10). Privacy policy
- Paystack — payment processing (South Africa). Privacy policy
- Paddle — app and resource-shop payment processing outside South Africa, as merchant of record. Privacy policy
- Anthropic — AI reading of the schedule photos you choose to scan, to turn them into draft calendar entries (see section 2). Photos are sent only when you use that feature. Privacy policy
- Resend — transactional email (claim submissions, review notifications, and marketplace messages such as when someone contacts you or applies to your job). Privacy policy
- Google — authentication and calendar access (optional). Privacy policy
10. Cookies and local storage
NannyTank does not use advertising or tracking cookies.
We use your browser's local storage to remember small preferences on your device — such as your chosen theme (light or dark), whether you've seen the welcome walkthrough, and your employer's WhatsApp number for Quick Status. On our website we also briefly remember, for the length of your visit, which page you arrived on and which site sent you, so that if you buy something we know how you found us. If you followed a link from one of our creators, we remember their code so they get credit. This information stays on your device and is only sent to us if you make a purchase.
We use Vercel Web Analytics to count visits to our website. It sets no cookies and does not follow you to other websites. It records the page visited, the site you came from, your rough location (country, region and city), and your device and browser type. Visitors are identified only by a temporary value derived from the request, which is discarded after 24 hours, so we cannot tell who you are or link your visits together over time. We see totals, not people. How Vercel Web Analytics handles data
11. Contact
You can download your data or delete your account yourself from your account page (see sections 7 and 8). For any other privacy question or request, contact:
support@nannytank.co.za