Last updated: June 22, 2026 · Effective: June 22, 2026
A note on placeholders. Company name and registered address are pending SL constitution and will be filled in before App Store / Play Store publication. The rest of this policy is complete and binding.
1. Who we are
Nuvott ("we", "us", "our") is a mobile application that allows couples to set mutual trust agreements and receive calm, judgment-free notifications when something falls outside what they agreed.
Data Controller
[NOMBRE ENTIDAD — pending SL constitution]
[DIRECCIÓN — pending SL constitution]
Spain, European Union
Contact for privacy matters
2. Scope of this policy
This Privacy Policy applies to:
- The Nuvott mobile application (iOS and Android)
- The websites nuvott.com and nuvott.app
- Any related services operated by Nuvott
It does not apply to third-party services linked from our app or website.
3. Legal basis (GDPR Article 6)
We process personal data on the following legal bases:
| Purpose | Legal basis |
|---|---|
| Creating and managing your account | Performance of a contract (Art. 6.1.b) |
| Mutual agreement and boundary settings | Performance of a contract (Art. 6.1.b) |
| Sending in-app notifications | Performance of a contract (Art. 6.1.b) |
| Security and fraud prevention | Legitimate interests (Art. 6.1.f) |
| Compliance with legal obligations | Legal obligation (Art. 6.1.c) |
| Analytics (aggregated, non-identifiable) | Legitimate interests (Art. 6.1.f) |
We never process your data based on consent that you cannot freely withdraw, nor for purposes incompatible with those stated in this policy.
4. What data we collect and why
4.1 Account data
- Email address — to create and identify your account
- Username or display name — to identify you within the app
- Password (stored as a bcrypt hash — we never store plaintext passwords)
4.2 Relationship data
- The boundaries and agreements you and your partner set together
- Notification history related to those agreements
- The mutual consent records confirming both partners agreed
This data is end-to-end encrypted (AES-256-GCM). We cannot read the content of your agreements. Only you and your partner can decrypt it.
4.3 Technical data
- Device type and operating system version
- App version
- Session tokens (stored in encrypted form)
- IP address (used for security, not stored permanently)
- Crash reports and error logs (anonymized)
4.4 What we do NOT collect
- Location data (GPS or otherwise)
- Contacts from your phone
- Social media account data
- Financial data or payment information (if paid features are added in the future, payments will be processed by a third-party provider — we will never store card details)
- Any data about people who are not registered Nuvott users
5. Zero-Knowledge architecture
Nuvott is built on a zero-knowledge principle: the content of your mutual agreements is encrypted on your device before it reaches our servers. This means:
- We cannot read the content of your agreements or boundaries
- We cannot hand over the content of your agreements to third parties, because we do not have access to it
- If we receive a legal request for data, we can only provide technical metadata (account creation date, last login, device type) — not the content of your relationship agreements
6. How we use your data
We use your data exclusively to:
- Provide and maintain the Nuvott service
- Send you notifications related to your mutual agreements
- Ensure the security and integrity of the platform
- Comply with applicable legal obligations
- Improve the app based on aggregated, anonymized usage patterns
We do not use your data for:
- Advertising or marketing to third parties
- Selling or renting your data to anyone
- Profiling or automated decision-making that produces legal effects
- Any purpose incompatible with providing the Nuvott service
7. Data sharing and third parties
We share data with third parties only when strictly necessary:
| Provider | Purpose | Data shared | Location |
|---|---|---|---|
| Cloud infrastructure provider | Hosting and storage | Encrypted data only | EU (confirmed EU region) |
| Error monitoring service | Crash reporting | Anonymized error logs | EU or adequacy country |
| App Store / Google Play | App distribution | Only what stores require for review | USA (SCCs apply) |
We do not share data with advertisers, data brokers, or analytics platforms that track individual users. For any international transfers outside the EU/EEA, we ensure appropriate safeguards are in place (Standard Contractual Clauses per GDPR Art. 46).
8. Data retention
| Data type | Retention period |
|---|---|
| Account data | Until account deletion + 30 days |
| Relationship agreements (encrypted) | Until account deletion |
| Technical logs | 90 days maximum |
| Anonymized analytics | Indefinitely (non-identifiable) |
When you delete your account, all your personal data and your encrypted relationship data is permanently deleted within 30 days. Anonymized, non-identifiable aggregate data may be retained.
9. Your rights under GDPR
As a user in the European Union, you have the following rights:
- Right of access (Art. 15): Request a copy of all personal data we hold about you
- Right to rectification (Art. 16): Correct inaccurate personal data
- Right to erasure (Art. 17): Request deletion of your personal data
- Right to restriction (Art. 18): Restrict how we process your data
- Right to data portability (Art. 20): Receive your data in a machine-readable format
- Right to object (Art. 21): Object to processing based on legitimate interests
- Right not to be subject to automated decision-making (Art. 22): We do not carry out automated decision-making with legal effects
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days and may ask you to verify your identity.
You also have the right to lodge a complaint with your national data protection authority. In Spain, this is the Agencia Española de Protección de Datos (AEPD): www.aepd.es.
10. Security measures
We implement the following technical and organizational measures:
- AES-256-GCM end-to-end encryption for all relationship agreement content
- bcrypt hashing for passwords
- TLS 1.3 for all data in transit
- Access controls: only authorized personnel can access technical metadata, and no personnel can access encrypted content
- Regular security audits and penetration testing
No security system is impenetrable. In the event of a data breach that poses a risk to your rights, we will notify the relevant supervisory authority within 72 hours and affected users without undue delay, as required by GDPR Art. 33–34.
11. Children
Nuvott is not intended for users under the age of 18. We do not knowingly collect personal data from anyone under 18. If we become aware that a user is under 18, we will delete their account and all associated data immediately. If you believe a minor has registered, please contact us at [email protected].
12. Changes to this policy
We may update this Privacy Policy from time to time. When we do:
- We will update the "Last updated" date at the top of this document
- We will notify you via in-app notification for material changes
Continued use of the app after notification constitutes acceptance of the updated policy.
For significant changes affecting your rights, we will seek renewed consent where required by law.
13. Contact
Privacy questions? We're here.
- Email: [email protected]
- Response time: Within 30 days
- Data controller: [NOMBRE ENTIDAD — pending SL constitution], [DIRECCIÓN — pending SL constitution]