Nestbound

Privacy

How privacy works here

The short version: nothing you put into Nestbound leaves your computer, and you do not have to believe us about that.

This page explains how Nestbound is built. The binding privacy policy, who we are, what a visit to this site records, and how to exercise your rights, is at nestbound.app/privacy-policy.

Why this is built the way it is

A service that holds your plans can close, and the plans close with it. Nestbound has no service to close: no account, no server, and your file has been on your own disk the whole time. The format is published, so the file outlives us whether we are here or not.

What an entitlement is, and how to check ours

This is something you can check on your own copy, and it is worth knowing how. Every app in the Mac App Store has to ask permission before it can do certain things: open the camera, read your contacts, reach the internet. It asks by declaring those permissions in a list that is built into the app when it is compiled and sealed when Apple signs it. Apple calls them entitlements, and macOS holds the app to that list. The Mac App Store build of Nestbound declares no network entitlement at all. Not a restricted one, not a limited one. None. So there is no setting inside that build that can send your family’s information anywhere: the capability is not in its signature.

Once an app is signed it cannot add a capability to itself and it cannot use one it never declared. The system refuses. What a developer can do is declare a new capability in the next version, which is a new build with a new signature. That is exactly why the command below is worth running again after an update rather than trusting this page forever.

You can confirm it without trusting us. Open Terminal (it is in Applications ▸ Utilities), paste the command below, and press Return. The app prints its own permission list. You should see exactly three lines: com.apple.security.app-sandbox, com.apple.security.files.user-selected.read-write, and com.apple.security.print. Anything mentioning network, icloud, ubiquity, vpn, associated-domains or push would mean data could leave this Mac, and none of those are there.

codesign -d --entitlements - /Applications/Nestbound.app

If you keep Nestbound somewhere other than Applications, use that path instead. The Privacy Report inside the app prints this same command already filled in with the exact copy you are running, so you do not have to get the path right yourself. The app has been submitted to App Store review, so until Apple approves it there is nothing installed to run this against; it is here so you know what to check on the copy you end up with.

The third one is printing, and it is listed as a capability rather than assumed because macOS will not let a sandboxed app reach a printer without it. The binder is the whole point, so Nestbound asks for it. Printing hands the pages to your Mac’s own print system, and if you choose a printer on your network your Mac sends them across it. Nestbound itself still cannot open a connection to anything.

One thing that will surprise you: the first time you open the print panel, macOS may ask whether to let Nestbound find devices on your local network. That is the print panel looking for printers, every Mac app that prints triggers it, and you can safely say no. Printers already set up on your Mac keep working. Nestbound has no network access either way; the question comes from macOS, not from us.

About Nestbound, then the Privacy Report button, shows the very same list, read out of the running app’s own signature, with anything that could move data off your Mac marked in red.

One difference worth stating before you find it yourself

We may later sell Nestbound directly from this site as well as through the App Store. That build would carry the network entitlement for one reason only: a direct download has no App Store to deliver its updates, so it has to be able to ask whether one exists. It would still send none of your information anywhere, and this page will say plainly which build you are holding. The App Store build is the one you can check for yourself.

Locking the file, if you want to

A passphrase encrypts every entry and every scan in the file with AES-256, from a key derived on your own Mac. It is off unless you turn it on, and Nestbound works fully either way. There is no reset, no backup key, and no recovery of any kind: not from your family, not from us. That is the point, and the app makes you tick a box saying so before it will let you. If you do lock a file, write the passphrase down somewhere your family will find it, and keep a current printed binder on the shelf. The published spec includes a short recovery script, about twenty lines of Python using one standard cryptography library, that opens a protected file with nothing but the passphrase. It was run on 26 July 2026 against a locked file and recovered all 36 entries and all three photographs with no Nestbound code involved, and a test in our suite runs the same steps on every build.

Getting everything back out

File ▸ Export… (⇧⌘E) opens five doors: JSON (the complete copy, and the only one that can be brought back in without losing anything), Excel (one workbook, a tab for each section you have filled in), CSV (a zip of plain spreadsheets, one per section, that any tool opens), PDF (the binder), and plain text (readable in fifty years). It happens on your Mac, wherever you point the save panel, as often as you like.

Going the other way: JSON is the lossless round trip, and CSV can be brought in as well, which is the route if you already keep a list somewhere. The other three are one-way, made for reading rather than for coming back. A CSV import adds to what is already in the file rather than replacing it.

All five doors need the file open, so if you have set a passphrase you need that passphrase. There is no reset and no key on our side, by design.

The Excel workbook is written by libxlsxwriter, an open-source library whose license travels inside the app under About Nestbound ▸ Acknowledgements.

Last updated 7 September 2026. This page describes Nestbound 1.0.0.