Privacy policy

Last updated:

Draft: this page is not final yet.

Who is responsible

Maximilian Groh, Kirchenfeldstrasse 26, 5630 Muri, Switzerland, is responsible for the personal data processing described in this policy where we determine its purposes and means. Contact: [email protected]. In this policy, “we” and “us” refer to Maximilian Groh, publishing nubbio.

This policy covers nubbio.app and the nubbio app. The app is not yet publicly available; the app sections describe its intended release configuration.

Overview

nubbio stores your app content locally in an encrypted database. We do not operate a backend that receives that content. This does not mean that no personal data is processed: our website hosting, support correspondence, Apple’s services and any AI provider you choose involve separate processing, described below.

Content on your device

  • App content: tasks, notes, lists, reminders, decisions, projects, Commitment Radar findings and Weekly Review history are stored in an encrypted database using SQLCipher and AES-256. Its key is kept in Apple’s Keychain on your device.
  • Calendars: nubbio reads the calendars you select through Apple’s calendar permissions. Access is read-only, and locally stored calendar data is encrypted.
  • Commitment Radar: nubbio reads documents and notes only from locations you authorise. Saved evidence text is stored encrypted on your device.
  • App Lock: its settings are stored in your device’s Keychain.
  • Local summaries: counts such as tasks completed this week are calculated on your device and are not sent to us.

These operations provide the features you choose to use. You control access through the app and your device’s permissions. Withdrawing access may prevent the corresponding feature from working; it does not necessarily erase information already imported.

We do not use advertising or tracking SDKs in the app, sell personal data or use your app content to build advertising profiles. Sync between devices is not currently available.

Optional AI services

AI features are off by default. If you connect a provider under your own account, content you select or authorise for analysis is sent to that provider. This is an exception to local-only processing. Do not include confidential information or another person’s personal data unless you are entitled to disclose it.

The provider processes requests under its own terms and privacy information. Its retention, use of inputs for model improvement and processing locations depend on the provider, service and account settings; local encryption does not protect content after it is sent to the provider.

You control use through nubbio’s approvals and Emergency Stop. Stopping AI activity does not recall data already transmitted or delete copies held by the provider. Requests about those copies must be addressed to the provider.

Apple purchases and diagnostics

Purchases, subscription billing and refunds take place through Apple. Apple processes account and payment information under its own terms. We receive sales reports from Apple; nubbio does not collect your payment-card details.

Depending on your Apple privacy settings and the distribution channel, Apple may make usage statistics and crash diagnostics available to us. We use these to understand technical problems and improve reliability. Crash diagnostics can include individual technical reports; they should not be described as invariably aggregated or anonymous. Apple explains this in its developer documentation on crash reports.

Website hosting and analytics

The website is hosted through Cloudflare. Delivering and protecting it requires processing connection and request information, including IP addresses, requested pages and browser information. This is distinct from the content stored inside the nubbio app.

We use Cloudflare Web Analytics to understand visits and website performance. Cloudflare states that this service does not use cookies or local storage to collect usage metrics and does not fingerprint individuals. See Cloudflare Web Analytics. Those statements concern analytics; they do not mean that hosting and security involve no processing of personal data.

The website has no account registration or forms. Its own code does not set cookies, and fonts are served from the website. Cloudflare’s analytics script is loaded when enabled for the deployment.

Support and other correspondence

If you email us, we process your email address, your name if supplied, the message, attachments and related correspondence to respond, investigate the issue and keep an appropriate record. Our email service is Google Workspace. Google processes message data to provide that service.

Please send only information needed for your enquiry. We do not have remote access to your local app database, but we can read content you choose to include in an email, screenshot or diagnostic attachment.

Providing information by email is voluntary. Without sufficient information, we may be unable to answer your request. We do not use support correspondence for unsolicited marketing.

Recipients and international processing

The recipients described above include our hosting and email service providers, Apple and an AI provider you choose. Information may also be disclosed where required by law or necessary to establish, exercise or defend legal claims, subject to applicable data protection requirements.

Cloudflare and Google provide international services. Their published data processing terms address transfers outside Switzerland, the European Economic Area and the United Kingdom: Cloudflare’s terms and Google’s Cloud Data Processing Addendum.

This section is not final: the countries relevant to our Cloudflare and Google Workspace configurations and the applicable transfer safeguards still need to be confirmed and listed here before this policy is published as final. A link to a provider’s terms is not a substitute for that information.

Retention and deletion

You can export or delete app content through the app’s settings. We cannot retrieve, restore or erase your local database remotely. Deleting data in nubbio does not necessarily remove separate exports, backups, original calendar entries, source documents or copies already sent to another service; manage those separately.

For data we receive, the proposed retention rule is to keep it only for the purpose described, then delete or anonymise it, unless a legal retention duty or a specific legal claim requires longer storage. Support correspondence is needed while an enquiry is being handled; any further retention must have a defined reason. Technical reports are needed only while relevant to investigating or resolving the issue.

This section is not final: operational retention and deletion arrangements for support email, diagnostics and hosting logs still need confirmation. Cloudflare currently states that Web Analytics reports are accessible for the previous six months; this is a reporting window, not proof that all underlying data is deleted at that point. See its analytics FAQ.

Applicable law and your rights

We handle personal data under the Swiss Federal Act on Data Protection. Where the EU General Data Protection Regulation (GDPR) applies to particular processing, its requirements also apply.

For processing subject to the GDPR, the intended legal bases are performance of a contract or steps you request before entering one for related support; legitimate interests in operating and securing the website, responding to other enquiries and diagnosing faults; and compliance with applicable legal obligations where retention or disclosure is required. Processing that requires consent will take place only with that consent. This policy is information about processing, not a request for blanket consent.

Subject to the conditions and exceptions in applicable law, you can request access to personal data concerning you, correction of inaccurate data, deletion or restriction of processing, and delivery or transfer of data in a portable format. Where the GDPR applies, you may object to processing based on legitimate interests on grounds relating to your particular situation. Where processing relies on consent, you can withdraw it for the future without affecting the lawfulness of earlier processing.

Contact [email protected] to exercise these rights. We may request information reasonably necessary to verify your identity. Local app controls let you manage content we do not hold; they do not replace your rights concerning data we do process.

You may raise a concern with the Swiss Federal Data Protection and Information Commissioner. Where the GDPR applies, you may also complain to the competent supervisory authority, including in the EU country of your habitual residence, workplace or the alleged infringement.

Changes to this policy

We will update the date on this page when this policy changes. Material changes affecting app users will also be communicated in the app where appropriate. If new processing requires consent, we will obtain it before starting that processing.