Privacy policy
Last updated 9 September 2026
- Your nursery decides what data goes into Finnly. We only process it on the nursery's instructions.
- A parent only ever sees their own child. Nursery staff only ever see their own nursery.
- We never sell data, never show ads, and never build advertising profiles — least of all from children's data.
- You can ask for your data to be exported or deleted at any time.
1. Who we are
Finnly is nursery management software operated from Cairo, Egypt by the team behind LumiNest. This policy applies specifically to the Finnly parent app, staff app and related service. Questions about anything here go to privacy@luminesthub.com.
2. Who is responsible for the data
This distinction matters, so we want to be plain about it:
- Your nursery is the data controller. It decides which children and staff are enrolled, what is recorded about them, and who may see it.
- We are the data processor for Finnly. We store and process that information to provide the service, following the nursery's instructions. We do not decide on our own to use it for anything else.
In practice this means that if you are a parent and want a record corrected or removed, the fastest route is to ask your nursery — they control the record. We will always help them do it.
3. What we handle
| About | Information |
|---|---|
| Children | Name, date of birth, class and branch, attendance records, meals eaten, nap and mood notes, photos and videos shared by staff, development records, and any allergy, incident, medication or medical notes the nursery records. |
| Parents and guardians | Name, phone number, email address, account and nursery identifiers, which children they are linked to, invoices and payment status, and messages, voice notes and attachments exchanged with the nursery. |
| Nursery staff | Name, phone number, email address, account and nursery identifiers, role, branch and class assignments, and a securely hashed password. We never store a readable password. |
| Technical | A push-notification token, device platform and app identifier when you enable notifications, plus server logs needed to keep the service running and secure. We deliberately keep names, phone numbers and reset codes out of our logs. |
We receive this information when a nursery administrator, staff member or parent enters or uploads it, when the service creates records from actions such as attendance or messaging, and automatically through the limited server logs described above.
On children's data specifically: it exists in the service for one reason — so a nursery can care for a child and keep their parents informed. We do not use it to train advertising systems, we do not sell or share it with data brokers, and we do not profile children.
4. Consent for photos and records
Obtaining parental consent to record a child and to share their photos is the nursery's responsibility, and it is a condition of using the service. If you are a parent and you would rather your child's photo were not shared, tell your nursery — they can turn that off for your child.
5. Who can see what
- Parents see only their own child. They cannot see other children, other families, or the nursery's finances.
- Teachers see only the classes they are assigned to.
- Nursery directors and branch admins see their own nursery, and only the branches they manage.
- Our staff do not browse your data. A small number of us can access production systems when it is genuinely needed to fix a fault or to help with a support request, and that access is logged.
Each nursery's data is separated from every other nursery's at the database level, and that separation is enforced on every single request rather than being left to the interface.
6. Where your data is stored
Our servers and database are hosted in the European Union (Frankfurt, Germany), and photos and files are stored on Cloudflare's network. This means data about children in Egypt is stored outside Egypt. We use these providers because they offer stronger security and reliability than we could run ourselves. They are contractually bound to protect the data, process it only on our instructions, and provide protection consistent with this policy.
Companies that process data for us
| Provider | What for |
|---|---|
| Contabo | Servers and database hosting (Germany) |
| Cloudflare | Photo and file storage, content delivery |
| Google Firebase / Apple | Delivering push notifications to phones |
| Brevo | Sending transactional email, such as password resets |
| Paymob | Card payment processing, where a nursery has enabled it |
7. How long we keep things
- While a nursery is an active customer, its data is kept so the service works.
- If a nursery leaves, we keep its data for 90 days so it can be exported or the account reinstated, then we delete it.
- Encrypted backups roll on a 14-day cycle, so deleted data can persist in a backup for up to 14 days after deletion.
8. How we protect it
- All traffic is encrypted in transit using HTTPS.
- Sensitive fields, including medical notes, are encrypted at rest with a separate encryption key for each nursery.
- Passwords are stored only as salted hashes and cannot be read by us or recovered.
- Photos are served over expiring links rather than being left publicly reachable.
- Access to production systems is restricted and logged.
No system is perfectly secure. If a breach ever affects your data, we will tell the affected nurseries promptly and explain what happened and what we are doing about it.
9. Cookies and local storage
Our marketing site and apps do not use advertising cookies or third-party trackers. We store a language preference in your browser's local storage so the site opens in Arabic or English the next time you visit. That preference never leaves your device to be sold or profiled.
Transactional emails, such as password resets and service notices, are sent through Brevo.
10. Your rights
You can ask to see the data held about you or your child, to have it corrected, to get a copy of it, to withdraw consent where consent is the basis for processing, or to have it deleted. Because your nursery controls the record, please start with them — it is faster. If they cannot help, or if your nursery has closed, write to privacy@luminesthub.com and we will respond within 30 days.
You can turn off push notifications at any time in your phone's settings without losing access to the app.
Deleting an account: parents and staff accounts are managed by the nursery. Ask your nursery director to remove your access. If the whole nursery is leaving the service, we delete the nursery's data 90 days after cancellation (see section 7). Demo leads can be removed by emailing us.
11. The app is not for children to use
Finnly is used by adults — nursery staff and parents. It is not designed for children to sign in to or use themselves, and we do not knowingly create accounts for children.
12. Changes to this policy
If we change this policy in a way that meaningfully affects you, we will update the date at the top and notify nurseries through the dashboard. Continuing to use the service after a change means you accept the updated policy.
13. Contact
Privacy questions: privacy@luminesthub.com
Anything else: hello@luminesthub.com
This policy is governed by the laws of the Arab Republic of Egypt. Where an Arabic and an English version differ, the English version governs.