Boring, in the
best way.

No badges, no certification logos we did not earn. Just a plain description of where your files live, who can reach them, and how long we keep them.

How your files are protected.

Encrypted in transit
Every request runs over TLS/HTTPS, from the upload in your browser to the download on the other side.
Encrypted at rest
Every object is encrypted with AES-256 by our storage provider in Amsterdam. Nothing sits on an open disk.
Stored in the EU
File storage runs in Amsterdam, email delivery in Frankfurt. Our own servers run in the Netherlands.
Processed on our own machines
Conversion, compression and malware scanning run on infrastructure we operate. Your files are not shipped to an external conversion or scanning company.
Malware scanning
Uploads are scanned automatically. Files identified as malicious are blocked before a recipient can reach them, and a human reviews it if you think we got it wrong.
Controls on every link
Password protection, expiry dates and download limits on share links, plus optional password encryption of exported .nemi documents.
Least privilege access
Administrative access is limited to what is needed to run and support the Service, and everyone with access is bound by confidentiality.
Analytics without the tracking
Download logs hold no IP address or browser details. Share opens store only a salted, truncated hash of the viewer IP.

Your files are yours.

  • We do not train AI models on your files, documents or form responses.
  • We do not sell your data, and we do not show advertising.
  • We do not read, index or profile the contents of your files.
  • We do not load third-party analytics or advertising scripts, and web fonts come from our own servers.
  • We do not send your files to an AI provider unless you connect an assistant yourself, which you can revoke at any time.

A short list, published.

These are every provider that touches data on our behalf. If we ever add one, we announce it here 30 days in advance and you can object.

ProviderWhat it doesWhere
WasabiFile and document storage, AES-256 at restEU, Amsterdam
AWS SESEmail deliveryEU, Frankfurt
StripeSubscription paymentsEU/US, Data Privacy Framework and SCCs
GoogleSign-in with GoogleEU/US, Data Privacy Framework and SCCs
GuusLabApplication servers, conversion, compression, malware scanning, database backupsNetherlands, our own hardware

Wasabi, where your files live, is ISO 27001 certified and its data centers are SOC 2 audited, and it encrypts every object at rest with AES-256. Those are their certifications, not ours: the compliance section further down says exactly what we do and do not hold.

The formal version, with the notice period and your right to object, is Annex 3 of our Data Processing Agreement.

Deleted means deleted.

We back up the database, so your account, workspaces and documents survive a failure. We do not back up uploaded files: storage holds one copy. Nobody can quietly restore a file after you remove it, not even us. The other side of that deal is that Nemi is not your backup either, so keep your own copy of anything you cannot lose. Documents and spreadsheets do have version history inside the app, which is a different thing.

Free plan files
Removed automatically 30 days after upload.
Paid plan files
Kept while your subscription is active. After a downgrade, files above the free limits fall back to the 30 day expiry.
Your account
Delete it yourself in settings. Files go immediately and permanently; residual account data in database backups is gone within 30 days.
Share analytics
Live as long as the share does, and are deleted together with it.
Server logs
Cleared on every deploy, usually at least once a day, and never longer than 90 days.
Billing records
Seven years, because Dutch tax law says so.

What we have, and what we do not.

Nemi is built and run in the Netherlands under the GDPR. You get a Data Processing Agreement under Article 28 that applies automatically to business use, with a published sub-processor list, breach notification within 48 hours, audit rights and deletion when you leave. Our Privacy Policy covers your own rights of access, correction, export and erasure, and support@nemilab.com is also our point of contact under the EU Digital Services Act.

We are not SOC 2 audited, not ISO 27001 certified, and not built for HIPAA, the Dutch Wgbo or NEN 7510. We do not sign business associate agreements. Because of that, Nemi may not be used for special categories of personal data under Article 9 GDPR, such as health data or biometrics, or for patient records. That rule is in Section 7 of our Terms of Service, and it applies to the questions you ask in a Nemi form too.

If a data breach puts your rights at risk, we notify the Dutch supervisory authority within 72 hours and affected users without undue delay. For data we process on your behalf as a processor, you hear from us within 48 hours.

Tell us, we will answer.

Report a vulnerability to support@nemilab.com with "security" in the subject. Include the steps to reproduce it and what you think the impact is. You get a reply within two business days, we keep you posted while we fix it, and we credit you if you want.

Please test only against your own account, do not access other people's data, and give us a reasonable window to fix things before publishing. We will not pursue researchers who follow that. We do not run a paid bug bounty.

Illegal content or abuse goes to the same address and is handled under Section 8 of our Terms of Service.

Free to start, no credit card.

Files, safely done.

15 GB free, stored in the EU, never trained on.