Skip to main content
NNivorai
ProductFeaturesPricingFAQ
Log in

Privacy Policy

Last updated: 2026-05-04

1. Who we are

Nivorai (“we”, “us”, “our”) is an independent project built and operated by İlkay Bora, based in Turkey. It is not a registered company. You can find every way to reach the developer at ilkaybora.com, or write to hello@nivorai.app directly.

2. What we collect

Account data: email address, hashed password, optional 2FA secret. Product data: tasks, notes, journal entries, mood scores, finance transactions, fitness logs, focus sessions, habits — all scoped to your account. Billing data: handled by Stripe; we store only a Stripe customer ID and subscription metadata. We never see your card number. Nivorai is intended for users aged 13 and older (16 in EU jurisdictions); we do not knowingly collect data from children below that threshold.

3. Why we process it

To provide the service you signed up for (contractual basis under GDPR Art. 6(1)(b)), to send transactional notifications about your subscription, and to improve the product (legitimate interest under Art. 6(1)(f)). Mood scores, journal entries and fitness logs may qualify as health-adjacent / special-category data under GDPR Art. 9(1) and KVKK Art. 6. We process those modules only when you enable them — turning a module on in Settings → Modules counts as your explicit consent under GDPR Art. 9(2)(a) / KVKK Art. 6(3). You can withdraw at any time by turning the module off, which stops further processing immediately.

4. AI processing

When you opt in to AI features, the relevant data (your selected task, journal entry, etc.) is sent to Google’s Gemini API to generate the response. Gemini does not train on Nivorai customer data per Google’s enterprise terms. You can disable AI any time in Settings → AI.

5. Product analytics

We collect interaction events to measure how Nivorai is being used — for example which step of the onboarding wizard you finish, when you send an AI message, when you view the pricing page. Events store a short event name and a small set of structured properties (counts, flags, IDs). They never contain the contents of your tasks, notes, journal entries, AI messages, or any other free-form text. A random correlation ID is stored in your browser’s localStorage so anonymous landing-page activity can be linked to your account if you sign up; you can clear it any time. Analytics are self-hosted on the same infrastructure as the app — no Google Analytics, no Plausible, no third-party tracker. Legal basis: legitimate interest (GDPR Art. 6(1)(f)) in operating and improving the service.

6. Sharing

We share data only with: Stripe (payment processing), Resend (transactional email), Google Cloud (Gemini AI when enabled), and our hosting provider Hetzner. Each of these has a data processing agreement on file. Analytics events are not shared with anyone — they live in our own database.

7. Your rights (GDPR + KVKK)

Under GDPR Art. 15–22 and KVKK Art. 11 you may: (i) access the data we hold about you, (ii) request rectification of inaccurate data, (iii) request erasure ("right to be forgotten"), (iv) request restriction of processing, (v) receive your data in a portable machine-readable format, (vi) object to processing based on legitimate interest (e.g. analytics), and (vii) withdraw any consent you have given (e.g. for AI features, marketing, or special-category modules) without affecting the lawfulness of past processing. Most rights are self-serve from Settings → Account; for the rest email hello@nivorai.app and we will respond within 30 days. You may also lodge a complaint with the Turkish Personal Data Protection Authority (KVKK) or your local EU data protection authority.

8. Retention

We retain your data while your account is active. When you delete your account we remove all data within 30 days, including analytics events tied to your account. The exception is billing records held by Stripe, which we keep for the period required by Turkish tax law (currently 5 years for VAT invoices) and any longer period mandated by anti-money-laundering or accounting rules in your jurisdiction.

9. Data security and breach notification

We protect your data with TLS in transit, at-rest encryption, hashed passwords (Argon2id), encrypted 2FA secrets and least-privilege access controls. If a personal data breach occurs we will notify the competent supervisory authority (the Turkish KVKK and/or relevant EU DPA) within 72 hours of becoming aware of it, as required by GDPR Art. 33 and KVKK Art. 12. If the breach is likely to result in a high risk to your rights and freedoms we will also notify you directly without undue delay, with details of what happened and what you can do.

10. Cookies and local storage

Nivorai uses only essential cookies (session token, theme preference, language) plus a small amount of localStorage for the analytics correlation ID and your client-side preferences. No advertising trackers, no third-party analytics. We do not need a consent banner under EU ePrivacy because nothing we set is non-essential per the user-experience tests in WP29 Opinion 04/2012.

11. Changes

If we materially change this policy, we will email you at least 30 days before the change takes effect. The current version is always at /legal/privacy.

NNivorai

AI weekly review for solo founders. Capture in two taps. Sunday in five minutes.

Product

ProductFeaturesPricingFAQ

Company

Built by İlkay BoraContactRoadmapChangelogSign inStart free

Legal

PrivacyTermsKVKK noticeSystem status

© 2026 Nivorai. All rights reserved.