Back to home

Terms of Service

Last updated: September 2, 2026

1. Introduction

Welcome to Nemi ("we", "us", "our"), a product of GuusLab (Dutch Chamber of Commerce / KVK: 95954600), established in Utrecht, the Netherlands. Nemi is a file sharing and document platform operated from the Netherlands within the European Union. By accessing or using our service at nemilab.com (the "Service"), you agree to be bound by these Terms of Service ("Terms"). If you do not agree to these Terms, please do not use the Service.

These Terms constitute a legally binding agreement between you and GuusLab. Please read them carefully before using the Service. The Service is available worldwide; Section 18 explains which law applies and which mandatory local protections remain unaffected.

2. Eligibility

You must be at least 16 years old to use the Service. If the law of your country sets a higher minimum age for entering into this kind of agreement or for consenting to the processing of your personal data, that higher age applies to you. By using Nemi, you represent and warrant that you meet the applicable age requirement. If you are under 18, you may only use the Service with the consent of a parent or legal guardian.

3. Account Registration

To access certain features of the Service, you must create an account. You can sign in with Google, with a one-time verification code sent to your email address, or with a passkey. You are responsible for:

  • Maintaining the security of your account, connected email address, and registered passkeys.
  • All activities that occur under your account.
  • Notifying us immediately of any unauthorized use of your account.

We reserve the right to suspend or terminate your account if we reasonably believe it is being used in violation of these Terms. Section 16 describes how suspension and termination work.

4. Description of the Service

Nemi provides a platform for file sharing and collaboration, including:

  • File upload and storage, protected with encryption in transit (TLS) and encryption at rest at our EU-based storage provider.
  • Shareable download links, with optional password protection, expiry dates, and download limits, including sharing by email or @username to people in your contacts or Business organization.
  • Upload links that let you request files from others.
  • Collaborative documents, spreadsheets, and forms (Nemi Docs, Sheets, and Forms).
  • File conversion and compression.
  • Device-to-device transfer (Beam).
  • Compressed photo storage (Nemi Gallery), described in Section 4a.
  • Video meetings with chat and screen sharing (Nemi Meet), described in Section 4b.
  • Optional integrations that let you connect third-party AI assistants to your workspace (see Section 12).
  • Workspace management and analytics on shared files.
  • Business organizations: seats, company branding, pooled storage, and linked member accounts (see Section 5a).

On the free plan a file is deleted 30 days after it was uploaded, or 30 days after a paid plan ended, whichever is later. That second half means leaving a paid plan always buys a full 30 days for everything already stored, counted from the day the plan ends, however long ago the files were uploaded. This does not apply while a free account is linked to an active Business organization, where Business entitlements apply for as long as the membership lasts. Paid plan users retain their files as long as their subscription is active. Uploaded files may be automatically scanned for malware; files identified as malicious may be blocked or removed.

We may introduce, test, or gradually roll out features to some users before others, and we may modify or discontinue individual features. If we discontinue a feature that is core to your paid plan, Section 15 (changes) and Section 6 (cancellation) apply.

4a. Nemi Gallery: compressed photo storage

Nemi Gallery stores photographs in a compressed form. You need to understand what that means before you use it, because it is different from how the rest of Nemi treats your files.

  • The photo you upload is converted, and the original is not kept. Every photo is re-encoded to AVIF and, on most plans, scaled down to the maximum resolution your plan allows. The file you get back from Gallery is that converted photo, not the file you put in. We never store the original, so we cannot return it to you later.
  • The conversion is lossy and cannot be undone. Detail is discarded to make the photo smaller. It is intended to be indistinguishable at normal viewing sizes, and it is not suitable if you need the master file: for printing, editing, licensing, evidence, or any other purpose that depends on the original data.
  • Your plan sets the stored resolution and the number of photos. The current values are listed on our pricing page. Photos already stored are not re-processed if you change plans: upgrading does not restore detail that was discarded when the photo was uploaded, and downgrading does not shrink or delete photos you already have.
  • A library belongs to a workspace, not to you. Everyone in the workspace sees the same photos, albums and trash, and can add to them. If you want a library nobody else can see, keep it in a workspace with no other members.
  • Gallery photos count toward your storage, but the photo limit is the workspace owner's. The compressed bytes are charged to whoever uploaded them, against their own storage. How MANY photos a library may hold, and at what resolution they are stored, come from the plan of the person who owns the workspace, and that allowance is shared across every library they own. Uploading into somebody else's workspace therefore spends their photo allowance and your storage. Joining a workspace on a bigger plan does not raise your own limits anywhere else.
  • Deleted photos are held for 30 days. A photo you delete goes to the Gallery trash, still counts toward your storage while it is there, and is permanently removed after 30 days. Unlike free-plan files, Gallery photos do not expire on their own.
  • A library can be shown on a screen with no account on it. On the plans that allow it, you can put a library on a television or a monitor as a slideshow. You add the screen by entering the code it displays, so a screen is always something somebody signed in chose to start. Everyone who can see that screen can see the photographs on it, and that is your decision and your responsibility: choose where a screen goes, tell the people in the room, and press End in Gallery when the screen leaves your control. How many screens may run at once comes from the plan of the person who owns the workspace, counted across every workspace they own. What the screen may see and what we record about it are set out in Section 3.8b of our Privacy Policy.

Because the original is discarded on purpose, Gallery is not a backup service and must not be your only copy of a photograph. Section 13 applies to Gallery in full.

4b. Nemi Meet: video meetings

Nemi Meet connects the people in a meeting directly to each other rather than through our servers. That shapes what the Service can and cannot do for you, so the consequences are set out here.

  • We do not record meetings, but a participant can. The audio, video and screens in a meeting never reach us in a form we could store, so we cannot produce a recording and cannot recover one for you. What we do offer is recording on a participant's own device: their browser composites the call as they are receiving it and saves the result to their Nemi files. That file belongs to them, counts against their storage, and is not deleted when the meeting is. Everyone is shown that recording is running, and you should assume that anyone in a meeting is able to keep a copy of it.
  • Your plan sets how many people fit in a meeting and how long it can run. The current values are on our pricing page. A meeting that reaches its time limit ends for everyone, with a warning beforehand. These limits exist for technical reasons as well as commercial ones and there is no plan on which they are unlimited in size.
  • Anyone with the link can join. A meeting link works until you delete the meeting, and by default it does not require a Nemi account. You can add a password, make people wait for you to let them in, lock a meeting once everyone has arrived, or restrict it to signed-in accounts. Choosing not to is your decision.
  • The host runs the meeting. Whoever created a meeting can mute participants, remove them, and end the meeting for everyone. If you join someone else's meeting, they hold those controls.
  • Connections can fail for reasons outside our control. Because the connection is direct, some networks, particularly restrictive corporate ones, will not allow it. Meet is not a telephone service and must not be relied on for emergency communication.

You are responsible for what you show and say in a meeting you host or attend, including for having the right to share what appears on a screen you share. If you record a meeting, whether with Meet's own device-side recording or with your own tools, you are responsible for complying with any law that requires you to tell the other participants, and for what you then do with the file. Section 8 (acceptable use) and Section 13 apply to Meet in full.

Correction, August 10, 2026. This section previously said there was no recording feature and that nothing about a meeting survives it except the chat and the attendance list. That was wrong, and it is corrected above.

4c. Nemi Beam: direct transfers

A direct Beam sends a file from one browser to another without it passing through our servers. That removes the limits that exist because storage costs money, and it introduces one that cannot be removed.

  • Both devices have to be open at the same time. A direct Beam is a live handoff, not a delivery. If either tab closes, the transfer stops, and there is nothing waiting to be picked up later.
  • Nothing is stored, so nothing can be recovered. We never receive the file. A transfer that fails halfway cannot be resumed by us, restored by us, or produced by us afterwards, for you or for anyone else. If you need the file to be waiting for someone, use a share link or a Beam drop box, both of which do go through our servers.
  • There is no size limit and no storage cost, on any plan. That is a direct consequence of the above rather than a promotion, and it is why direct Beam is not a paid feature.
  • The two devices see each other's network addresses. That is how a direct connection is made. It is described in Section 3.11 of our Privacy Policy, and if it is not acceptable for a given transfer, use a share link instead.
  • The code is the key. Anyone holding the Beam code can connect while the beam is live. Treat it like a share link and do not post it anywhere public.

A direct Beam is not a backup, not a delivery service, and not a record of anything. Section 13 applies to it in full.

4d. Vault folders: encryption you hold the key to

A vault is a folder encrypted on your own device with a key we never receive. It is the strongest privacy guarantee in the Service and it is the one place where we cannot help you if something goes wrong. Both halves of that are binding.

  • If you lose your key, the files are gone. Losing your passkey or forgetting your passphrase, without the recovery code you were shown when you set the vault up, means the contents cannot be recovered by you, by us, or by anyone. There is no reset, no support process and no exception, because a way for us to let you back in would be a way for us to let ourselves in. You are responsible for keeping your recovery code somewhere safe.
  • Features that read your files do not work in a vault. Previews we generate, thumbnails, conversion, compression, malware scanning, zipping and sharing by link are unavailable for vault files, because every one of them requires reading the file. This is not a limitation we intend to remove.
  • Sharing a vault means adding a member. Access is granted inside an existing member's browser, so the person you add needs a Nemi account and needs to have set up their own key first.
  • Removing a member stops future access only. It does not undo what they have already seen or already copied, and no software can.
  • A vault is not a backup. Section 13 applies to it in full, and applies harder: for ordinary files we hold data we cannot restore, and for a vault we hold data we cannot even read.

4e. Trace: analytics about the people you send links to

Trace is an optional setting on a share link that reports how the people who open it engaged with it: how long they spent, which pages held them, roughly where they were and on what device. Section 3.10 of our Privacy Policy sets out exactly what is recorded.

  • Switching it on makes it your decision about someone else. Trace collects personal data about the recipients of your link. In most jurisdictions that makes you responsible for having a lawful basis for it and for telling those people, and under the GDPR it will usually make you the controller of that data with us acting as your processor. Our Data Processing Agreement covers that relationship.
  • You must not use it to do something you could not do openly. Do not use Trace to monitor employees covertly where the law requires you to tell them, to profile individuals, or in any way that would be unlawful if the recipient knew about it. We may disable the feature on an account we believe is using it this way.
  • Reading time is an estimate. It is measured by the recipient's own browser and can be incomplete or wrong. Do not treat it as proof that a document was read, and do not rely on it as evidence for anything with consequences for the person it describes.
  • Only you see it. The trace of your link is visible to you and to nobody else, and we do not use it for our own purposes.

4f. Sending links from your own domain

On Creator and higher, a workspace can connect a domain it owns so that its public links (shares, upload links, published documents, forms, embeds and rooms) are served from that hostname instead of nemilab.com. Section 3.14 of our Privacy Policy sets out what is stored and who issues the certificate.

  • You must control the domain. By connecting one you confirm that you are entitled to use it, and you prove it by publishing a record we give you. Do not connect a domain that belongs to someone else, that you have stopped using, or that you have sold: we obtain a public TLS certificate for whatever you connect, and the hostname appears in public Certificate Transparency logs.
  • It changes the address, not the responsibility. The pages are still the Service and these Terms still apply to everything you publish through them, including Section 7. A branded address does not make the content yours to publish if it was not already.
  • Only public links are served there. The application, signing in and everything tied to your account stay on nemilab.com. A page on your domain is never a Nemi sign-in prompt, which is deliberate and not something you can switch on.
  • We may disconnect a domain. If the required records disappear, if the plan no longer includes the feature, or if we believe the domain is not yours, we stop serving links on it. Nothing breaks when that happens: every link keeps working on nemilab.com, which is why we treat disconnecting as a safe step rather than a last resort.

4g. Folio: a page you publish about yourself

A folio is a public page belonging to your account: your name, a description, the work you choose to show, links, and an address people can write to. Section 3.15 of our Privacy Policy sets out what is stored and what is recorded about the people who open it, which is almost nothing.

  • Publishing is the moment it becomes public. Until you press Publish, nobody but you can open the page or the files on it. After that, anyone with the address can, including anyone it is forwarded to. Being listed by a search engine is a second switch that stays off until you turn it on.
  • You are publishing, so Section 7 applies to all of it. Everything on a folio is content you made public through the Service: the pictures, the video, the words and the links. Publish only work you are entitled to publish, and only material you would be willing to stand behind under your own name, because it is under your own name.
  • We may take a folio down. Under Sections 7 and 8 we can unpublish a page that breaks these Terms, and a suspended account's folio stops answering with the rest of the account. Unpublishing does not delete your work: it stops us serving it.
  • The address follows your username. A folio lives at an address built from your username, so changing the username changes the address and the old one stops working. Section 5a governs usernames, including the ones we do not allow.
  • On your own domain. Where a workspace has connected a domain (Section 4f), its home page can be the folio of the person who owns that workspace, and only that person's. Everything in Section 4f still applies.

4h. The page behind your links

The page a recipient lands on can be laid out by you: which blocks are on it, what they say, and how it looks. There is one such page per workspace and every link that workspace sends opens it, including links sent before it was designed, so anybody who can edit the workspace can change what all of its recipients see. Section 3.16 of our Privacy Policy sets out what that means for the person opening it.

  • It is content you publish. The words, pictures and links you put on such a page reach whoever has the link, so Section 7 applies to all of it, and so does your responsibility for anything you link out to.
  • An agreement block is between you and your recipient. Where you add a box asking somebody to accept terms before downloading, it releases the buttons on that page. It does not restrict the files, we are not a party to it, and we do not record who ticked it. Use the link's password, expiry and download limit for anything that has to be enforced.
  • The Nemi block. On the free plan every share page carries a small block naming Nemi. You decide where it sits; it is restored if it is removed. Plans that include custom branding may reword or remove it, which is the same entitlement described in Section 5.
  • We may reset a page. Under Sections 7 and 8 we can remove a page design that breaks these Terms, which returns that workspace's links to the default page. The files themselves are unaffected.

4i. Nemi AI: the assistant inside Nemi

On the Max and Business plans you can ask an assistant inside Nemi to do things for you. It runs on a language model we do not host ourselves, so using it sends part of your content to the providers named in Section 6.1 of our Privacy Policy, which also sets out exactly what is sent and what we keep. Section 3.18 of that policy is the full description; the terms below are the ones that affect what you can expect from it.

  • It acts as you. Anything the assistant does is done with your account and your permissions, on your instruction, and counts as your own action for the purposes of these Terms. It can create, change, delete and share things, so read what it tells you it did. It cannot do what you cannot do: an action you have no right to take in a workspace is refused.
  • It can be wrong. A language model can misunderstand a request, miss something, or state something untrue with confidence. Nothing it says is advice, and it is not a substitute for checking. We provide it as it is, and Section 14 applies to it in full.
  • There is a weekly limit. Every request costs us money at a third party, so each account has an allowance per week, shown in the assistant. When it is used up the assistant stops answering until the allowance comes back. We may change the allowance, and we will say so in the product when we do.
  • Fair use. The assistant is for working in your own account. Automating it to generate volume, to resell access, or to use it as a general purpose model outside Nemi is not what it is for, and we may switch it off for an account that does so.
  • It may change or stop. Which model runs behind it can change, and answers will change with it. We may withdraw the feature, in which case Section 5 applies to the plan you are on.

5. Plans, Payments & Price Changes

Nemi offers both free and paid subscription plans. Paid plans are billed monthly or yearly through Stripe, our payment processor. By subscribing to a paid plan, you agree to:

  • Provide accurate and complete billing information.
  • Authorize recurring charges for your chosen billing cycle.
  • Pay all fees associated with your subscription.

Prices are displayed in euros (EUR). Where you buy as a consumer, prices shown to you include VAT where applicable; any applicable taxes are shown at checkout before you confirm your purchase.

Which plan applies inside a workspace, as of 31 August 2026.A workspace runs on the plan of the account that owns it, and every limit inside it is that account's: storage, upload volume, file sizes, link expiry, conversions and compressions per day, branding and custom domains, the photo cap and resolution, how many documents, spreadsheets, canvases and forms it holds, how many forms may accept responses and how many responses they may receive, how long version history is kept, and how many members it may have. This applies to everybody working in that workspace, whatever they pay for themselves: being invited into a workspace on a larger plan gives you those limits while you work there and nowhere else, and your own paid plan does not raise a workspace somebody else owns. Some things are not part of a workspace and follow your own account instead, wherever you are: Calendar, Contacts, Beam, Folio, Rooms, the size and length of a meeting you host, and the assistant's usage budget. This has always been how storage, conversion and compression worked; until this version the limits on documents, spreadsheets, canvases and forms were counted against the person who created them instead, and they are now counted against the workspace like everything else. If you hold a Business seat, your plan is the better of your own plan and Business, and that better plan is what applies.

Auto-extend, and how extra storage is actually charged. Storing more than your plan allows is not automatic: it happens only if you switch auto-extend on, and only while you have an active paid subscription. Extra storage is then charged at €0.01 per GB as stated on our pricing page. The free plan does not include additional storage, and neither does an account whose subscription has lapsed: in both cases uploads that would go past the limit are refused instead.

A correction, and a change, as of 10 August 2026.The charge is based on the HIGHEST amount of extra storage you held at any point during the billing period, not on what you are holding when the invoice is written. Deleting files later in the period does not reduce that period's charge. That has always been how the charge was calculated, and earlier versions of these Terms did not say so; this is the correction. Separately, auto-extend now always carries a spend limit: the most extra storage may cost you in one billing period, which you set yourself between €1.00 and €500.00. Uploads that would go past it, or past a storage cap set on the workspace, are refused. Accounts that previously had no limit are treated as being on the €500.00 maximum. If you need more, contact support@nemilab.com.

On a Business organization, storage is pooled and the pool belongs to the organization owner, so auto-extend for the pool is the owner's setting and any extra storage is invoiced to the owner's subscription.

We may change our prices. If we increase the price of your subscription, we will notify you by email at least 30 days before the change takes effect, and the new price will apply from your next billing cycle after that period. If you do not agree with the new price, you can cancel your subscription before it takes effect.

5a. Business organizations, usernames, and verified badges

Business organizations. The Business plan lets the billing account create a company organization with seats for linked members. The organization owner is responsible for seats, invites, and the conduct of members while they use organization-linked features. Linked members may receive Business plan entitlements (such as storage and conversion limits) only while membership is active. Leaving or being removed ends those entitlements for that account.

Extra seats may be billed as described on our pricing page when a seat price is configured. Storage pooling and stacked personal plans for members work as described in the product; the organization owner remains the primary billing party for the Business subscription.

Usernames. You may claim a unique @username. Usernames must not impersonate others, mislead people, or violate these Terms or applicable law. We may reclaim or require changes to usernames that violate these rules.

Verified badges. Blue or gold checkmarks and optional company logos indicate Nemi plan or organization status (for example Creator/Pro/Max, Business billing, or membership in a Business organization). They are not government ID verification, professional certification, or an endorsement of your content. We may adjust badge rules as the product evolves.

Contacts. When you share or invite by email or @username, we may save that recipient in your private contacts for autocomplete later. Contacts are not a public directory of Nemi users.

6. Cancellation, Refunds & Right of Withdrawal

You may cancel your subscription at any time through your account settings or Stripe's customer portal. Upon cancellation:

  • Your paid features remain active until the end of the current billing period.
  • After the billing period ends, your account reverts to the free plan.
  • Your files become subject to the free plan's expiry rule, counted from the day the plan ends: nothing is deleted for at least 30 days after that day, whenever it was uploaded, and we email you at the start of that period, seven days before the deletion date and again the day before it.
  • While your account holds more than the free plan allows, you cannot upload anything new. You can still open, download, share, export and delete everything you have, and you can subscribe again at any time.
  • A correction. Until 2 September 2026 this section promised a reasonable opportunity to download your files before deletion, and the Service did not honour it: on the day an account returned to the free plan, everything uploaded more than 30 days earlier was deleted within the hour, because the 30 days were counted from the upload date alone. The rule above is what the Service now does, and the change applies to every account.

EU/EEA consumers: right of withdrawal. If you are a consumer in the EU or EEA, you have the right to withdraw from your subscription within 14 days of purchase without giving a reason. Because the Service is provided to you immediately, you agree at checkout that we start performance right away. If you withdraw within the 14-day period, you pay only a proportionate amount for the period in which you used the paid Service, and we refund the rest. To exercise this right, contact us at support@nemilab.com within the withdrawal period.

Outside the EU/EEA, mandatory refund rights under your local consumer law remain unaffected.

7. Acceptable Use

You agree not to use the Service to:

  • Upload, share, or distribute any content that is illegal under applicable law, or that is harmful, threatening, abusive, or defamatory.
  • Distribute malware, viruses, or other malicious software.
  • Infringe on any third party's intellectual property rights.
  • Share child sexual abuse material (CSAM). This is strictly prohibited and will be reported to the relevant authorities.
  • Engage in any activity that interferes with or disrupts the Service.
  • Attempt to gain unauthorized access to any part of the Service.
  • Use the Service for spam, phishing, or fraudulent purposes. An embed link can serve a web page from a nemilab.com address, and publishing a page there that imitates another company, another service, or a sign-in screen is phishing whatever you call it.
  • Circumvent any security measures, access controls, or plan limits.
  • Upload, store, request, or collect special categories of personal data within the meaning of Article 9 GDPR: data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and genetic data, biometric data used to identify a person, data concerning health, or data concerning a person's sex life or sexual orientation. This includes building a Nemi form, upload link, document, or spreadsheet that asks other people for such data.
  • Upload or process patient records, medical files, or other data that is subject to sector-specific rules such as HIPAA, the Dutch Wgbo, NEN 7510, PCI DSS, or comparable healthcare, financial, or government security frameworks. Nemi is not built or certified for those regimes, we do not sign business associate agreements, and we make no representation that the Service meets those requirements.
  • Upload or process personal data relating to criminal convictions and offences within the meaning of Article 10 GDPR, or classified government information.

A page you host is content you published. Where an embed link serves HTML, the page runs in the browser of whoever opens it, and everything in this section applies to it exactly as it applies to a file you upload. You are responsible for what the page does, including anything its scripts send anywhere. We serve it in a sandbox that stops it reaching Nemi itself, which protects the person visiting it and is not an endorsement of what is in it.

Why this matters. Nemi is a general purpose file sharing and collaboration platform. It is designed for ordinary business and personal content, not for data that requires additional safeguards under Article 9 GDPR or sector-specific law. If you use the Service in breach of this rule, you do so at your own risk and you are responsible for the consequences, including toward the people whose data you uploaded. Section 15 (indemnification) applies.

We may remove content and suspend or terminate accounts that violate these Terms, following the process in Section 8 and Section 16.

8. Reporting Illegal Content & Moderation

Anyone can report content hosted on Nemi that they believe is illegal or violates these Terms by emailing support@nemilab.com. Please include the link to the content, an explanation of why you believe it is illegal or infringing, your name and email address, and a statement that your report is accurate and made in good faith. This mailbox also serves as our single point of contact under the EU Digital Services Act for authorities and users alike; you can contact us in English or Dutch.

We review reports without undue delay. If we remove or block content or restrict an account, we will inform the affected user of the decision and the reasons for it, unless we are legally prevented from doing so (for example in cases involving CSAM or an ongoing investigation). If you disagree with a moderation decision, you can object by replying to our decision email or by contacting support@nemilab.com, and we will review the decision again.

We do not use automated tools to make final moderation decisions about the meaning of your content. Automated malware scanning may block files identified as malicious; if you believe a file was wrongly blocked, contact us and a human will review it.

9. Intellectual Property

You retain all ownership rights to the content you upload to Nemi. By uploading content, you grant us a limited, non-exclusive license to store, process, and transmit your content solely for the purpose of providing the Service to you, including making it available to the people you choose to share it with. This license ends when you delete the content or your account, except where retention is required by law.

We do not use your content to train AI models, and we do not sell your content.

The Nemi name, logo, and all related branding, software, and design are the intellectual property of GuusLab. You may not use, copy, or distribute any of our intellectual property without prior written consent.

10. Privacy & Data Protection

Your use of the Service is also governed by our Privacy Policy, which describes how we collect, use, and protect your personal data in compliance with the General Data Protection Regulation (GDPR) and other applicable data protection laws.

Data Processing Agreement. If you use the Service in the course of a business or organization and, in doing so, upload personal data about other people (for example client files, form responses, or documents containing customer data), you act as the controller of that data and we act as your processor. Our Data Processing Agreement sets out the terms required by Article 28 GDPR, including our processing instructions, security measures, sub-processors, breach notification, audit rights, and deletion at the end of the contract. It forms part of these Terms and applies automatically to every business use of the Service. You do not need to sign a separate document; if your organization requires a signed copy, email support@nemilab.com.

The Data Processing Agreement does not extend the Service to categories of data that Section 7 excludes. Special categories of personal data under Article 9 GDPR and sector-regulated data remain out of scope, whether you are a controller, a processor for your own customers, or a private user.

11. Security

We take reasonable technical and organizational measures to protect your files and data:

  • All data is encrypted in transit using TLS/HTTPS.
  • Files are stored with AES-256 encryption at rest at our EU-based storage provider.
  • You can add password protection, expiry dates, and download limits to share links.
  • Documents exported in the .nemi format can optionally be encrypted with a password of your choice; we cannot open or recover a password-protected .nemi export if you lose the password.
  • Uploaded files may be automatically scanned for malware, except inside a vault folder, where we cannot read the file (Section 4d).
  • A vault folder is encrypted on your device with a key we never hold, so its contents are not readable by us. The trade for that is Section 4d: if you lose the key, we cannot get the files back.

No method of electronic storage or transmission is 100% secure. You are responsible for keeping your share link URLs, link passwords, and account credentials confidential; anyone with a valid link (and its password, if set) can access the shared content.

12. Third-Party Services & AI Assistants

The Service integrates with third-party services such as Google (sign-in), Stripe (payments), our storage and email providers, and the providers that run the language model behind the assistant in Section 4i. Your use of those services may be subject to their own terms.

Separately from the assistant built into Nemi, on eligible plans you can connect third-party AI assistants of your own to your workspace through our MCP integration. This is entirely optional and only happens when you explicitly authorize a connection. When you connect an AI assistant, the content you give it access to is processed by that assistant's provider under that provider's own terms and privacy policy, and instructions you give the assistant are carried out in your workspace on your behalf. You are responsible for the assistants you connect and for the changes they make; edits made through the integration are marked as AI edits in document history where supported. You can revoke a connection at any time in your account settings.

13. Service Availability

We strive to maintain high availability of the Service, but we do not guarantee uninterrupted access. The Service may be temporarily unavailable due to maintenance, updates, or circumstances beyond our control. Where reasonably possible we announce planned maintenance in advance.

We do not keep backups of your files. If you or someone in your workspace deletes a file, or a file expires under the free plan, it is gone and we cannot restore it. Documents and spreadsheets have version history inside the Service, which is not the same as a backup. Photos in Nemi Gallery are stored only in the compressed form described in Section 4a, and the originals are never kept. Keep your own copies of anything critical; the Service is not intended as your only copy.

14. Limitation of Liability

To the maximum extent permitted by applicable law:

  • The Service is provided "as is" and "as available" without warranties of any kind, whether express or implied.
  • We are not liable for any indirect, incidental, special, consequential, or punitive damages arising from your use of the Service.
  • Our total liability to you for any claim arising from or related to the Service shall not exceed the amount you have paid us in the 12 months preceding the claim, or €50 if you have paid us nothing.

Nothing in these Terms excludes or limits our liability for death or personal injury caused by our negligence, for fraud or willful misconduct, or for any other liability that cannot be excluded or limited under applicable law. If you are a consumer, nothing in these Terms limits your mandatory statutory rights, including your rights under EU and Dutch consumer law regarding digital content and services that do not conform to the contract.

15. Indemnification

If you use the Service in the course of a business, you agree to indemnify and hold GuusLab harmless from any third-party claims, damages, losses, or expenses (including reasonable legal fees) arising from your use of the Service, your violation of these Terms, or your infringement of any third party's rights. If you are a consumer, this section applies only to the extent permitted by the mandatory law of your country of residence, and only where the claim results from your own unlawful conduct or breach of these Terms.

16. Termination

By you: you can stop using the Service and delete your account at any time in your account settings. Deleting your account permanently removes your files and personal data as described in our Privacy Policy.

By us: we may suspend or terminate your access to the Service if you materially breach these Terms, if we are required to do so by law, or if we discontinue the Service. Except where a violation is serious (such as illegal content, CSAM, malware, or fraud) or where the law requires immediate action, we will give you prior notice, the reasons for the decision, and a reasonable opportunity to export your data. Upon termination:

  • Your right to use the Service ceases.
  • We may delete your account data and uploaded files after a reasonable period.
  • If we terminate a paid subscription without cause, we refund the unused portion of any prepaid period.
  • Provisions that by their nature should survive termination (such as limitation of liability) remain in effect.

17. Changes to These Terms

We may update these Terms from time to time, for example to reflect changes in the Service or in applicable law. If we make material changes, we will notify you with a prominent notice in the Service (which you can acknowledge) and, where appropriate, by email, at least 30 days before they take effect when required. If you do not agree with the changes, you can cancel your subscription and stop using the Service before the changes take effect. Your continued use of the Service after the effective date constitutes acceptance of the revised Terms.

18. Governing Law & Disputes

These Terms are governed by the laws of the Netherlands. If you are a consumer, you additionally enjoy the protection of any mandatory provisions of the law of the country in which you reside; nothing in these Terms deprives you of that protection.

Any disputes arising from or relating to these Terms or the Service shall be submitted to the competent courts in the Netherlands. If you are a consumer in the EU/EEA, you may also bring proceedings before the courts of your country of residence.

If you have a complaint, please contact us first at support@nemilab.com; most issues can be resolved quickly. EU consumers can also turn to a recognized alternative dispute resolution body in their country.

19. Severability

If any provision of these Terms is found to be unenforceable or invalid, that provision shall be limited or eliminated to the minimum extent necessary so that these Terms shall otherwise remain in full force and effect.

20. Contact

If you have any questions about these Terms, please contact us at:

GuusLab (trading as Nemi)
Utrecht, the Netherlands
KVK: 95954600
Email: support@nemilab.com