Account and privacy
Your data and your rights
What Nemi holds about you, where it is kept, how long, and how to ask for a copy or a deletion under the GDPR.
On this page
The full and binding account is the privacy policy. This page is the short version of the parts people actually ask about, in the same facts and the same words. Where the two seem to differ, the privacy policy is right and this page is a bug.
What Nemi holds about you#
- Account data. Your name and email address, your optional username, your profile picture, the public half of any passkey you register, when the account was created, and your plan status.
- Billing data. Your subscription status and plan. Card details are handled by Stripe and never stored on our servers: we keep only your Stripe customer and subscription identifiers.
- Content. The files you upload and the documents, spreadsheets, forms and canvases you make, plus their metadata: name, size, type, dates and malware scan status. Edits in shared documents are attributed to whoever made them.
- Sharing data. Your link settings, and how often each link was opened and downloaded. If you switch on Trace for a link, considerably more, and section 3.10 of the privacy policy sets that out in full.
- Technical data. Your IP address, for security, rate limiting and abuse prevention, plus your browser and device type.
- Communication data. Your email address, your email preferences, and opens and clicks on marketing email.
- Nemi AI conversations. If you use Nemi AI, what you asked it, what it did and what came back, stored on your own account and readable by nobody else. See Your conversations and what is sent.
- Presence. One word for what you are doing right now and when your browser last said so, overwritten every time and never kept as a history. Your contacts and workspace members see it as the ring around your photo, and one switch turns that off. See The ring around your profile photo.
Things we can never see#
Two consequences follow from that and are worth stating plainly. We could not produce a recording of a meeting even if we were required to, and we cannot decrypt a vault folder in response to a legal request, however it is worded. What we can still see about a vault is that it exists, how many files are in it, how big they are and who its members are.
What Nemi does not do#
We do not use your content to create, train or improve AI or machine learning models, in raw or in derived form, and that includes what you say to Nemi AI. We do not sell personal data and we show no advertising. There are no third-party tracking or advertising cookies, which is why there is no cookie banner. The cookies Nemi does set are the ones it needs to work: signing you in, keeping a protected link or a shared document open for a working session, listing your signed-in devices so you can sign one out, and remembering preferences such as your theme, your accessibility settings and which workspace you last used. Section 8 of the privacy policy names every one of them with how long it lasts and what it is for.
Where it is kept, and for how long#
| Data | Kept |
|---|---|
| Account data | While the account exists. Deleting it removes files immediately, and residual data in database backups within 30 days |
| Files on the free plan | Deleted 30 days after upload, or 30 days after a paid plan ended, whichever is later |
| Files on paid plans | While the subscription is active |
| Gallery photos | Until you delete them, on every plan. The trash holds a deleted photo for 30 days |
| Download logs and share analytics | For the life of the link, and erased the moment you revoke it |
| Meeting chat and attendance | For the life of the meeting, deleted with it |
| Billing records | 7 years, as Dutch tax and accounting law requires |
| Nemi AI conversations | Until you delete them, and deleted with the account |
| Files attached to Nemi AI | 24 hours, and deleted at once with the account. A copy you asked it to save to a workspace is an ordinary file |
| Server logs | Cleared on every deployment, and never longer than 90 days |
Files are stored in the EU, in Amsterdam, and email is sent from within the EU. Google and Stripe process some data in the United States under the EU-US Data Privacy Framework or Standard Contractual Clauses. Conversion, compression and malware scanning run on infrastructure we operate ourselves, so your files are not sent to outside conversion or scanning companies. Nemi AI is the one feature that sends content to a company outside the EU, and only while you are using it. The model itself runs in the EU; the company that routes the request to it is in the United States. Both are named in section 6.1 of the privacy policy.
Your rights, and how to use them#
| Right | What to do |
|---|---|
| A copy of your data (Art. 15) | Take it yourself: Settings, Account, Export your data. See Export your data. Email us if you would rather we did it |
| Correction (Art. 16) | Most of it you can change yourself in Settings. Email us for the rest |
| Deletion (Art. 17) | Delete the account yourself in Settings, or email us. See Closing your account |
| Portability (Art. 20) | The same export is the machine-readable copy: JSON throughout, with your documents as Markdown. Individual documents and sheets also export from the app |
| Restriction (Art. 18) and objection (Art. 21) | Email us, saying what you object to |
The address is support@nemilab.com. We answer within one month, as the GDPR requires, and we may ask you to confirm who you are before acting on a request. If our answer does not satisfy you, you can complain to your data protection authority, which in the Netherlands is the Autoriteit Persoonsgegevens.
Related
Still stuck? Email support@nemilab.com and tell us what you were trying to do.