Legal

Privacy Policy

How we handle your data — clearly and by consent.

Last updated: June 22, 2026 · Effective: June 22, 2026

A note on placeholders. Company name and registered address are pending SL constitution and will be filled in before App Store / Play Store publication. The rest of this policy is complete and binding.

1. Who we are

Nuvott ("we", "us", "our") is a mobile application that allows couples to set mutual trust agreements and receive calm, judgment-free notifications when something falls outside what they agreed.

Data Controller

[NOMBRE ENTIDAD — pending SL constitution]
[DIRECCIÓN — pending SL constitution]
Spain, European Union

Contact for privacy matters

[email protected]

2. Scope of this policy

This Privacy Policy applies to:

  • The Nuvott mobile application (iOS and Android)
  • The websites nuvott.com and nuvott.app
  • Any related services operated by Nuvott

It does not apply to third-party services linked from our app or website.

3. Legal basis (GDPR Article 6)

We process personal data on the following legal bases:

PurposeLegal basis
Creating and managing your accountPerformance of a contract (Art. 6.1.b)
Mutual agreement and boundary settingsPerformance of a contract (Art. 6.1.b)
Sending in-app notificationsPerformance of a contract (Art. 6.1.b)
Security and fraud preventionLegitimate interests (Art. 6.1.f)
Compliance with legal obligationsLegal obligation (Art. 6.1.c)
Analytics (aggregated, non-identifiable)Legitimate interests (Art. 6.1.f)

We never process your data based on consent that you cannot freely withdraw, nor for purposes incompatible with those stated in this policy.

4. What data we collect and why

4.1 Account data

  • Email address — to create and identify your account
  • Username or display name — to identify you within the app
  • Password (stored as a bcrypt hash — we never store plaintext passwords)

4.2 Relationship data

  • The boundaries and agreements you and your partner set together
  • Notification history related to those agreements
  • The mutual consent records confirming both partners agreed

This data is end-to-end encrypted (AES-256-GCM). We cannot read the content of your agreements. Only you and your partner can decrypt it.

4.3 Technical data

  • Device type and operating system version
  • App version
  • Session tokens (stored in encrypted form)
  • IP address (used for security, not stored permanently)
  • Crash reports and error logs (anonymized)

4.4 What we do NOT collect

  • Location data (GPS or otherwise)
  • Contacts from your phone
  • Social media account data
  • Financial data or payment information (if paid features are added in the future, payments will be processed by a third-party provider — we will never store card details)
  • Any data about people who are not registered Nuvott users

5. Zero-Knowledge architecture

Nuvott is built on a zero-knowledge principle: the content of your mutual agreements is encrypted on your device before it reaches our servers. This means:

  • We cannot read the content of your agreements or boundaries
  • We cannot hand over the content of your agreements to third parties, because we do not have access to it
  • If we receive a legal request for data, we can only provide technical metadata (account creation date, last login, device type) — not the content of your relationship agreements

6. How we use your data

We use your data exclusively to:

  • Provide and maintain the Nuvott service
  • Send you notifications related to your mutual agreements
  • Ensure the security and integrity of the platform
  • Comply with applicable legal obligations
  • Improve the app based on aggregated, anonymized usage patterns

We do not use your data for:

  • Advertising or marketing to third parties
  • Selling or renting your data to anyone
  • Profiling or automated decision-making that produces legal effects
  • Any purpose incompatible with providing the Nuvott service

7. Data sharing and third parties

We share data with third parties only when strictly necessary:

ProviderPurposeData sharedLocation
Cloud infrastructure providerHosting and storageEncrypted data onlyEU (confirmed EU region)
Error monitoring serviceCrash reportingAnonymized error logsEU or adequacy country
App Store / Google PlayApp distributionOnly what stores require for reviewUSA (SCCs apply)

We do not share data with advertisers, data brokers, or analytics platforms that track individual users. For any international transfers outside the EU/EEA, we ensure appropriate safeguards are in place (Standard Contractual Clauses per GDPR Art. 46).

8. Data retention

Data typeRetention period
Account dataUntil account deletion + 30 days
Relationship agreements (encrypted)Until account deletion
Technical logs90 days maximum
Anonymized analyticsIndefinitely (non-identifiable)

When you delete your account, all your personal data and your encrypted relationship data is permanently deleted within 30 days. Anonymized, non-identifiable aggregate data may be retained.

9. Your rights under GDPR

As a user in the European Union, you have the following rights:

  • Right of access (Art. 15): Request a copy of all personal data we hold about you
  • Right to rectification (Art. 16): Correct inaccurate personal data
  • Right to erasure (Art. 17): Request deletion of your personal data
  • Right to restriction (Art. 18): Restrict how we process your data
  • Right to data portability (Art. 20): Receive your data in a machine-readable format
  • Right to object (Art. 21): Object to processing based on legitimate interests
  • Right not to be subject to automated decision-making (Art. 22): We do not carry out automated decision-making with legal effects

To exercise any of these rights, contact us at [email protected]. We will respond within 30 days and may ask you to verify your identity.

You also have the right to lodge a complaint with your national data protection authority. In Spain, this is the Agencia Española de Protección de Datos (AEPD): www.aepd.es.

10. Security measures

We implement the following technical and organizational measures:

  • AES-256-GCM end-to-end encryption for all relationship agreement content
  • bcrypt hashing for passwords
  • TLS 1.3 for all data in transit
  • Access controls: only authorized personnel can access technical metadata, and no personnel can access encrypted content
  • Regular security audits and penetration testing

No security system is impenetrable. In the event of a data breach that poses a risk to your rights, we will notify the relevant supervisory authority within 72 hours and affected users without undue delay, as required by GDPR Art. 33–34.

11. Children

Nuvott is not intended for users under the age of 18. We do not knowingly collect personal data from anyone under 18. If we become aware that a user is under 18, we will delete their account and all associated data immediately. If you believe a minor has registered, please contact us at [email protected].

12. Changes to this policy

We may update this Privacy Policy from time to time. When we do:

  • We will update the "Last updated" date at the top of this document
  • We will notify you via in-app notification for material changes

Continued use of the app after notification constitutes acceptance of the updated policy.

For significant changes affecting your rights, we will seek renewed consent where required by law.

13. Contact

Privacy questions? We're here.

  • Email: [email protected]
  • Response time: Within 30 days
  • Data controller: [NOMBRE ENTIDAD — pending SL constitution], [DIRECCIÓN — pending SL constitution]