Account and privacy
Your data and your rights
What Nemi holds about you, where it is kept, how long, and how to ask for a copy or a deletion under the GDPR.
On this page
The full and binding account is the privacy policy. This page is the short version of the parts people actually ask about, in the same facts and the same words. Where the two seem to differ, the privacy policy is right and this page is a bug.
What Nemi holds about you#
- Account data. Your name and email address, your optional username, your profile picture, the public half of any passkey you register, when the account was created, and your plan status.
- Billing data. Your subscription status and plan. Card details are handled by Stripe and never stored on our servers: we keep only your Stripe customer and subscription identifiers.
- Content. The files you upload and the documents, spreadsheets, forms and canvases you make, plus their metadata: name, size, type, dates and malware scan status. Edits in shared documents are attributed to whoever made them.
- Sharing data. Your link settings, and how often each link was opened and downloaded. If you switch on Trace for a link, considerably more, and section 3.10 of the privacy policy sets that out in full.
- Technical data. Your IP address, for security, rate limiting and abuse prevention, plus your browser and device type.
- Communication data. Your email address, your email preferences, and opens and clicks on marketing email.
Things that never reach us at all#
Two consequences follow from that and are worth stating plainly. We could not produce a recording of a meeting even if we were required to, and we cannot decrypt a vault folder in response to a legal request, however it is worded. What we can still see about a vault is that it exists, how many files are in it, how big they are and who its members are.
What Nemi does not do#
We do not use your content to create, train or improve AI or machine learning models, in raw or in derived form. We do not sell personal data and we show no advertising. Nemi itself calls no AI service: the AI connection is an assistant you bring and authorise, acting under your own account, and you can revoke it whenever you like. There are no third-party tracking or advertising cookies, which is why there is no cookie banner: the only cookies are the session and security ones, a 15 minute cookie while you connect a calendar, and a 24 hour referral cookie set only if you followed a referral link.
Where it is kept, and for how long#
| Data | Kept |
|---|---|
| Account data | While the account exists. Deleting it removes files immediately, and residual data in database backups within 30 days |
| Files on the free plan | Deleted automatically 30 days after upload |
| Files on paid plans | While the subscription is active |
| Gallery photos | Until you delete them, on every plan. The trash holds a deleted photo for 30 days |
| Download logs and share analytics | For the life of the link, and erased the moment you revoke it |
| Meeting chat and attendance | For the life of the meeting, deleted with it |
| Billing records | 7 years, as Dutch tax and accounting law requires |
| Server logs | Cleared on every deployment, and never longer than 90 days |
Files are stored in the EU, in Amsterdam, and email is sent from within the EU. Google and Stripe process some data in the United States under the EU-US Data Privacy Framework or Standard Contractual Clauses. Conversion, compression and malware scanning run on infrastructure we operate ourselves, so your files are not sent to outside conversion or scanning companies.
Your rights, and how to use them#
| Right | What to do |
|---|---|
| A copy of your data (Art. 15) | Email us. You can also download your files and export your documents yourself at any time |
| Correction (Art. 16) | Most of it you can change yourself in Settings. Email us for the rest |
| Deletion (Art. 17) | Delete the account yourself in Settings, or email us. See Closing your account |
| Portability (Art. 20) | Export documents and sheets from the app, or ask us for a machine-readable copy |
| Restriction (Art. 18) and objection (Art. 21) | Email us, saying what you object to |
The address is support@nemilab.com. We answer within one month, as the GDPR requires, and we may ask you to confirm who you are before acting on a request. If our answer does not satisfy you, you can complain to your data protection authority, which in the Netherlands is the Autoriteit Persoonsgegevens.
Related
Still stuck? Email support@nemilab.com and tell us what you were trying to do.