Skip to main content

Legal

Privacy policy

Which personal data Nisaba processes, why, on what legal basis, which service providers receive it and what rights you have.

Last updated:

The German version of this document is legally binding. This English text is provided for convenience. Deutsche Fassung (rechtsverbindlich)

Contents

1. Controller

The controller within the meaning of the GDPR is FluxonLab, Çağrı Bozgeyik, Arndtstraße 68, Tür 3, 1120 Wien, Austria. E-mail: contact@fluxonlab.com, phone: +43 676 563 1300.

This policy covers the website nisaba.site, the Nisaba web app and the Nisaba browser extension. Nisaba is a product of FluxonLab.

2. Overview

The table summarizes what we process and why. The sections after it explain each point.

PurposeDataLegal basis
Running the website and securityIP address (only briefly in memory, for example to limit requests), operating logs without IP addressesArt. 6(1)(f) GDPR (security and operation)
Account and sign-inE-mail address, name (optional), password hash or external account identifier, session dataArt. 6(1)(b) GDPR (contract)
Your libraryLinks, titles, notes, highlights, tags, categories, archived copies, imported files, workspaces, tab sessionsArt. 6(1)(b) GDPR (contract)
Connected accounts (only if you connect one)Identifier and name of the connected account, encrypted access key, the items saved there (link, title, text, author, date)Art. 6(1)(b) GDPR (contract, at your request); for names and content of other people in saved posts Art. 6(1)(f) GDPR
AI featuresTitles, URLs, notes, text excerpts, your questions and search queries, for pages with little text their preview imageArt. 6(1)(b) GDPR (contract)
Subscription and paymentName, e-mail, billing address, payment status, invoice dataArt. 6(1)(b) and (c) GDPR (contract, statutory retention)
System e-mailsE-mail address, message content (for example confirmation, password reset)Art. 6(1)(b) GDPR (contract)
Usage measurementPages viewed without query strings, device, browser type and approximate location; no person profilesArt. 6(1)(a) GDPR and § 165(3) TKG 2021 (consent)
Error monitoring and abuse protectionTechnical error reports (from the browser without query strings), from the server also errors and a sample of requests with technical request details, result of the bot checkArt. 6(1)(f) GDPR (stability and security)
Requests and noticesName, e-mail address, content of your message, for notices under the Digital Services Act also the reported addressArt. 6(1)(b), (c) (duties under Articles 16 and 17 DSA) and (f) GDPR

We do not sell personal data and we do not use your content for advertising.

3. Hosting and logs

Nisaba runs on a server of Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The server is located in Falkenstein, Germany. A data processing agreement under Art. 28 GDPR is in place with Hetzner.

Our reverse proxy writes no access logs with IP addresses. The application logs (operating and error messages) contain no IP addresses. They rotate by size (Docker, at most about 30 MB per service); older entries are overwritten automatically. To protect against abuse, for example at sign-in and sign-up, the application processes your IP address briefly in memory to count requests (legitimate interest, Art. 6(1)(f) GDPR). The IP address is not stored permanently.

The server is backed up every night. Hetzner keeps the last seven daily backups of the whole server. In addition, every night we back up the database and the uploaded files, keep these backups on the server for 14 days and store a copy for 30 days with Cloudflare R2 in the EU. We encrypt this copy on our server before it is transferred; Cloudflare cannot read its content. Deleted data can therefore remain in backups for up to about one month, after which the backups are deleted automatically. If the off-site copy fails, we keep the backups on the server for up to about six weeks.

4. Account and sign-in

To create an account we need your e-mail address and a password. We store passwords only as hashes, never in plain text. If the sign-in page offers sign-in with Google or GitHub and you choose it, we receive your e-mail address, your name and an identifier of your account from that provider; the provider is a separate controller for this, and its own privacy terms also apply.

Sign-in uses strictly necessary cookies (session, protection against form abuse). You can optionally set up two-factor authentication. Personal access tokens for the browser extension are stored only as hashes.

You can delete your account and its data in the settings.

5. Your library

We process everything you save in Nisaba to provide the service: saved links with title, description and page text, notes, highlights, tags, categories, archived copies, workspaces, tab sessions and files you import (browser bookmarks, exports from Raindrop, Pocket, Instapaper, CSV, JSON exports from X, Instagram, LinkedIn or Facebook).

For X, Instagram, LinkedIn and Facebook you upload the export file yourself. We do not ask for credentials for social networks, do not use their session cookies and do not read their web pages automatically.

Connected accounts. At your explicit request you can connect an account on GitHub, Mastodon, Bluesky or YouTube (Google) through that platform's official consent page (OAuth). We never receive a password, only an access key with read permissions, which we store encrypted and never log. Our server calls the platform's official interface only when you connect an account or choose “Import new items” (for YouTube also in the weekly check, see below); the platform sees our server's IP address. The items read are shown to you as a preview first; they enter your library only when you confirm the import. The platforms are separate controllers; their own privacy terms also apply.

PlatformWhat we readPermission requested
GitHubYour starred repositories (name, description, link, date) and the identifier and name of your profileNo additional permission, public information only
Mastodon (the server you name)Your bookmarks and favourites (text, author, link, date) and the identifier and name of your accountread:bookmarks, read:favourites and profile (read:accounts on older servers)
BlueskyYour bookmarks and likes (text, author, link, date) and your DID and handleatproto and read access to app.bsky.bookmark.getBookmarks and app.bsky.feed.getActorLikes only
YouTube (Google)Your liked videos and your own playlists (video title, channel name, link, date) and the identifier and name of your YouTube channelRead access only: https://www.googleapis.com/auth/youtube.readonly

Saved posts and pages can contain other people's names and content, for example the author of a post. We process them only to provide them to you in your private library; the legal basis is our legitimate interest and that of our users in keeping their own collection of bookmarks (Art. 6(1)(f) GDPR). Such items become publicly visible only if an account deliberately shares them in a workspace (section 13). Informing each person concerned individually would be impossible or disproportionate (Art. 14(5)(b) GDPR); they can contact us at any time to exercise their rights, in particular the right to object. The AI features in section 7 apply to imported items like to any other item.

YouTube. For the YouTube connection Nisaba uses YouTube API Services. By connecting you agree to be bound by the YouTube Terms of Service; for the data Google processes, the Google Privacy Policy applies. Approval runs through Google's sign-in page with read-only access; until Google has reviewed our app, Google first shows an “unverified app” warning. We read your liked videos and your own playlists (video title, channel name, link, date added) and the identifier and name of your YouTube channel, and use them only to provide them to you in your library. We do not use them for advertising. Nisaba's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

We keep the stored YouTube data current: once a week we check with Google that your approval still stands, update the name of your YouTube channel and bring the video title and channel name of the imported items in line with YouTube (your own changes to those two fields are overwritten, your notes never); videos that no longer exist are deleted (your own notes stay). The data is therefore at most 30 days old, or it is deleted. When you disconnect in Nisaba, we revoke our access at Google right away and delete all items imported from YouTube immediately. Deleting in Nisaba does not change your data at YouTube; to delete data there, use a YouTube application. In addition to this normal deletion procedure, you can withdraw Nisaba's access at any time on Google's security page at https://security.google.com/settings/security/permissions; we notice it at the next weekly check and then delete the items, within 30 days at the latest. Send questions or complaints about how we handle this data to contact@fluxonlab.com. The AI features in section 7 apply to items imported from YouTube like to any other item.

You can disconnect a connected account in Nisaba at any time (Import, or Settings → Data). We then revoke our access at the platform and delete the access key. You choose whether the items imported from that account stay in your library or are deleted as well (for YouTube they are always deleted). You can also withdraw access directly at the platform, for example on GitHub under Settings → Applications → Authorized OAuth Apps, on Mastodon in your server's account settings under “Authorized apps” or for YouTube at https://security.google.com/settings/security/permissions. When you delete your Nisaba account, we revoke all connections.

Your library is visible only to your account unless you deliberately share a workspace publicly (see section 13). You can export all your data as HTML, JSON or CSV at any time.

6. Fetching web pages when you save

When you save a link, our server fetches the page to read its title, description and text and to keep a readable copy for you. The website sees the IP address of our server, not yours. When you save with the browser extension, the extension can send the page content from your browser to your Nisaba account so that pages our server cannot fetch can still be saved. If a page has little text, our server also downloads its preview image for AI categorization (section 7); the server that hosts the image also sees only our server's IP address. Preview images in your library and images in the reader view, by contrast, are loaded by your browser directly from the server that hosts them, which sees your IP address.

If you choose “Send to Wayback” in the reader view and confirm, our server sends the address of the page to the Internet Archive (USA), which creates a publicly accessible copy of it. We do not send your name or account. The Internet Archive is a separate controller for this; its own terms apply.

7. AI features

Nisaba offers AI features, for example “Ask your library” with source references, summaries, translations and suggested categories and tags. For an AI request we send the provider only the content the task needs: titles, URLs, notes, excerpts of the saved page text and your question or search query. When we categorize a page with little text, we also send its preview image to OpenAI in reduced size; we do not store it for this (details in the AI policy).

  • OpenAI (answers, summaries, translations, category and tag suggestions, and embeddings for search by meaning; ranking search results when TypeSafe returns no usable result)
  • TypeSafe AI, Inc. (model “Jev”: ranking search results; receives your search query and the title, address without query string, tags and short summary of the candidate entries)

Under OpenAI's API terms, submitted inputs are not used to train its models. OpenAI may retain API inputs, including images, for up to 30 days for abuse monitoring, and longer only where the law requires it or it is reasonably necessary to protect OpenAI's services or third parties from harm. OpenAI automatically scans submitted images for child sexual abuse material; an image flagged by this scan is kept by OpenAI for manual review. Because EU data residency is not set up for our OpenAI project, OpenAI may process the data outside the EU through its affiliates and sub-processors, including in the USA. OpenAI bases such transfers on standard contractual clauses or an adequacy decision; the safeguards in section 16 also apply. TypeSafe processes the data in the USA and, under its contract terms, does not use it to train models. Zero data retention is agreed with TypeSafe for Nisaba: TypeSafe does not store the data sent, but processes it only to answer the request in question. The transfer to TypeSafe is based on the EU standard contractual clauses in its data processing agreement (section 16).

The legal basis is performance of the contract (Art. 6(1)(b) GDPR). AI is switched on for new accounts. Some transfers then happen without a separate AI request: when you open an entry in the reader view, we send the text of the readable copy in sections to OpenAI to create embeddings for search by meaning. After an import we categorize the entries with AI unless you untick that option for the import. When you search your library, we send the search query and the candidate entries to TypeSafe for ranking. You can switch AI off for your account in the settings. No content, including preview images, is then sent to AI providers; keyword search keeps working. You can also switch off just the sending of preview images there; it is on by default. We store embeddings in our database.

What we send for AI features, such as text excerpts, notes, your questions and search queries or preview images, can name or show people and incidentally contain sensitive information, for example indications of health. We use this content only for the feature in question and do not specifically analyse it for such information; we do not use preview images to recognize people or to draw conclusions about them. For third parties named or shown in it, section 5 applies accordingly.

We do not take decisions with legal effect solely by automated means. Categories and tags are suggestions you can change. AI output can be incomplete or wrong. More in the AI policy.

8. Payments and subscription

Stripe processes payments for Pro. This is Stripe Payments Europe, Ltd., Ireland, together with Stripe, Inc., USA where needed. You enter your card details only with Stripe; we do not receive them. We process name, e-mail address, billing country, billing address, subscription status and invoice data, and whether and when you asked in the order step for Pro to start during the withdrawal period (to calculate a refund). With a billing country in the EU you buy from us; Stripe processes the payment for us. Stripe also processes some payment data as a separate controller, for example to prevent fraud and to meet legal obligations; the Stripe privacy policy applies to that.

With a billing country outside the EU you buy through Stripe Managed Payments; the seller (merchant of record) is then Link, a Stripe service. Link processes the purchase, payment and tax data of that purchase as an independent controller, for example for checkout, invoices, taxes, refunds and purchase support; the Link privacy policy applies to that. We receive from Stripe the data we need for your subscription (e-mail address, billing country, subscription status and payment amounts).

If you cancel on the page Cancel contracts here, we process what you enter there (e-mail address, name, requested end date and, for an extraordinary termination, the reason) to carry out and confirm the cancellation.

The legal bases are performance of the contract (Art. 6(1)(b) GDPR) and our statutory retention duties (Art. 6(1)(c) GDPR). We keep accounting records for seven years (§ 132 BAO).

The 14-day Pro trial does not require payment details.

9. E-mail delivery

We send system e-mails (confirmation, password reset, notices about your subscription such as a renewal reminder and confirmation of cancellation or withdrawal) through Resend (Resend, Inc., USA), processed in the EU region Ireland. Resend processes your e-mail address and the message content on our behalf. We send marketing e-mails only with your explicit consent.

10. Usage measurement (only with consent)

If you agree, we measure how the website and app are used with PostHog (EU cloud). We record only pages viewed without query strings and figures about device, browser and approximate location, which PostHog derives from the IP address. For this PostHog stores a random identifier of your browser. We build no person profiles, record no sessions and capture no input. Nothing is recorded on sign-in and password pages.

Before you decide, PostHog is neither loaded nor sent any data. You can change or withdraw your choice at any time with “Cookie settings” in the website footer or, when signed in, in the app under Settings → Account; withdrawal applies to the future. The legal basis is your consent (Art. 6(1)(a) GDPR, § 165(3) TKG 2021).

11. Error monitoring and abuse protection

To detect technical errors we use the error monitoring service Sentry. Error reports from the browser are sent without the address query string and without cookies, and no default personal data is attached. Performance tracing and session recording in the browser are off. On the server, Sentry records errors and, for performance monitoring, a sample of requests, each with technical details of the request such as the address called including its query string and the request headers, but without your IP address. The provider is Functional Software, Inc. (Sentry), USA; error data is stored in Sentry's EU data region in Frankfurt, Germany. The legal basis is our legitimate interest in a stable and secure service (Art. 6(1)(f) GDPR).

To protect against automated abuse we use Cloudflare Turnstile on the sign-up form. Cloudflare then processes technical characteristics of your browser and your IP address to check whether a person is filling in the form. The legal basis is our legitimate interest in stability and security (Art. 6(1)(f) GDPR). Turnstile sets no cookies on nisaba.site for this.

12. Browser extension

The Nisaba extension for Chrome sends the address, title and text of a page to your Nisaba account when you save, and the list of your open tabs when you use the tab feature. The extension stores settings and your access token locally in the browser. It requests extra website permissions only when a feature needs them.

We use this data only to provide the extension's visible features. We do not sell it, use it for advertising or use it to assess creditworthiness. Our use of information the extension receives through Chrome APIs complies with the Chrome Web Store User Data Policy, including the Limited Use requirements.

13. Public workspaces and RSS

If you share a workspace publicly, its name, description, the selected entries and optionally an RSS feed are available to anyone with the link. Public pages are excluded from search engines by default. You can end sharing at any time. Everything else stays private.

14. Cookies and local storage

We use strictly necessary cookies and local storage for sign-in, security and settings (language, appearance, layout of the interface such as sidebar, library, reader view and mind map, your cookie choice). They are allowed without consent (§ 165(3) TKG 2021). See the cookie notice for details.

We serve fonts ourselves; visiting our public pages loads no fonts from third-party servers.

15. Recipients and processors

We share personal data only with service providers that act on our behalf and are bound by a data processing agreement, or where necessary to perform the contract or you ask us to.

ProviderPurposeWhere processed
Hetzner Online GmbHHosting, server, backups; mailbox for contact@fluxonlab.comGermany (server in Falkenstein)
Namecheap, Inc.Forwarding e-mails sent to nisaba.site addresses (for example support@nisaba.site)USA
Resend, Inc.Sending system e-mailsEU region Ireland (provider based in the USA)
Stripe Payments Europe, Ltd. / Stripe, Inc.Payment processingIreland / USA
OpenAI Ireland Ltd (contracting party) / OpenAI OpCo, LLCAI features, embeddingsAlso outside the EU, including the USA
TypeSafe AI, Inc.AI ranking of search resultsUSA
PostHog Inc.Usage measurement, only with consentEU cloud (Germany)
Cloudflare, Inc.Bot protection (Turnstile) at sign-up; encrypted off-site backup copies (R2)Turnstile: global network (provider based in the USA); R2: EU
Functional Software, Inc. (Sentry)Error monitoringEU data region Frankfurt, Germany (provider based in the USA)
Google Ireland Limited / GitHub, Inc.Sign-in with an external account, only if the sign-in page offers it and you choose it (separate controllers)EU / USA
Internet ArchiveOnly if you send a page to the Wayback Machine: the address of the page (separate controller)USA

16. Transfers to third countries

Some providers are based in the USA or process data there. For such transfers we rely on the standard contractual clauses approved by the European Commission (Art. 46(2)(c) GDPR) and, where a provider is certified, on the adequacy decision for the EU-US Data Privacy Framework (Art. 45 GDPR). With TypeSafe AI, Inc. the standard contractual clauses (Module 2, controller to processor) that form part of its data processing agreement apply. You can request a copy of the safeguards using the contact address.

17. Retention

  • Account and library: until you delete content or your account
  • Access keys of connected accounts: until you disconnect or delete your account
  • Items imported from YouTube: until you disconnect, at most 30 days without a refresh from YouTube; at most 30 days after access is revoked at Google
  • Billing and accounting records: seven years (§ 132 BAO)
  • Operating logs: rotate by size (at most about 30 MB per service), older entries are overwritten automatically
  • Cookie choice: in your browser until you clear or change it
  • Requests and notices: until they are dealt with, then only as long as we need them to establish or defend legal claims, as a rule at most three years
  • Backups: up to about one month, up to about six weeks if the off-site copy fails (see section 3)

Beyond these periods we keep data only where the law requires it or we need it to establish, exercise or defend legal claims.

18. Your rights

You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object to processing based on legitimate interests (Art. 21 GDPR). You can withdraw consent at any time with effect for the future.

Right to object: Where we process data on the basis of our legitimate interest (Art. 6(1)(f) GDPR, for example operating logs, request limiting, error monitoring and bot protection), you can object at any time on grounds relating to your particular situation (Art. 21(1) GDPR). We then stop processing the data unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing serves to establish, exercise or defend legal claims.

To exercise your rights, write to contact@fluxonlab.com or support@nisaba.site. You can also export and delete your data yourself.

You have the right to lodge a complaint with a supervisory authority. In Austria this is the Datenschutzbehörde, Barichgasse 40–42, 1030 Vienna, dsb@dsb.gv.at, www.dsb.gv.at. You can also contact the authority where you usually live.

Providing the data for account and payment is necessary for the contract; without it we cannot provide the service.

19. Security

Transmission between your browser and Nisaba is encrypted with TLS. We store passwords and access tokens only as hashes, and access keys of connected accounts encrypted (AES-256-GCM). Access to servers and data is limited to what is necessary. No system is perfectly secure; if personal data is breached we report it where the law requires.

20. Changes

We update this policy when Nisaba, our providers or the law change. The date above shows the current version. We announce material changes in the app or by e-mail.