Privacy

The short version: there is no account, nothing is recorded, and the audio and video never pass through our servers in a form anyone could read.

What never reaches us

  • Sound and picture. They travel directly between your two devices over WebRTC, encrypted end to end. When a network blocks a direct connection the stream is forwarded by a relay, which sees encrypted packets only — it cannot decrypt them and does not store them.
  • Anything about your child. The sound level is measured on the device by the cot itself. The server is told that an alert was raised, never what was heard.
  • An account. There is no sign-up, no email, no password. There is one cookie, described below — it identifies a browser, not a person, and we never ask who you are.

What the server does hold, and for how long

  • A live session. A room identifier, the two connected devices, and the technical messages that let them find each other. It lives in memory, and a small part of it is also written to our database — the room identifier and a key that lets the device by the cot take its session back. That is what lets a session survive us restarting the server instead of ending without warning. It is deleted the moment the session ends.
  • A notification subscription, if you turn notifications on. The address your browser's push service gave us. It is stored for the length of the session and deleted with it — stored, rather than only held in memory, for one reason: if we restart the server while your phone is locked, the subscription is what lets the alert still reach you. Without it a restored session would come back with nobody to notify.
  • A record of the session, once it is over. When it started and ended, how it ended, whether it needed a relay, how much data it carried, and the address and browser of the devices involved. We keep this to understand what the service costs and why a session failed. After 90 days the address, the browser and the notification address are erased and only the anonymous part of the record remains.
  • A fingerprint of your notification address, if you turn notifications on. Stored next to the cookie, scrambled so that it cannot be used to send anything, and kept only so we can tell how often the same browser comes back under a new cookie. It tells us nothing about you and is deleted with the cookie's record.
  • Ordinary server logs. Connection errors and warnings, without anything identifying a session's contents.

On your own device

Your settings — alert channels, recently joined sessions — are stored in your browser's local storage, on your device. They are never sent anywhere. Clearing your browser's site data removes them.

Measurement

This page and the other public pages count visits with a self-hosted, cookie-free analytics tool. The monitoring pages themselves carry no analytics at all — no third-party script runs on a page pointed at a child's room. Separately, the server keeps counters and the per-session records described above (how many sessions, how long they last, how often a relay was needed) — for running the service, never for advertising or profiling, and never shared with anyone.

The cookie

Opening the application sets one cookie, nl_id. It holds a random number and nothing else — no name, no address, no history. It exists so we can tell one browser from another and bound how much of the service is free. It is set by our server and marked HttpOnly, which means no script on the page can read it, ours included.

The public pages — this one, the terms, the home page — do not set it. It is set only when you open the application itself. French and European rules exempt a cookie strictly necessary to deliver a service the user asked for from requiring consent, which is why there is no banner.

Clearing your browser's site data removes the cookie, and your next visit starts a new one with no link to the old. The earlier record does not vanish at that moment — it is erased on the same 90-day schedule as everything else.

Advertising

There is none, and there will not be. An advertising network is a data-collection business injected into the page as third-party script; that is incompatible with everything above.

Contact

Questions about any of this: contact@naplink.app.