Introduction
At Nervus.io, we believe your personal data deserves the same care you put into organizing your life. This Privacy Policy explains what information we collect, how we use it, and the choices you have.
By using Nervus.io, you agree to the collection and use of information as described in this policy. We will never sell your personal data.
Nervus.io is a personal productivity platform that uses artificial intelligence to help you plan, track, and achieve your goals. We are committed to transparency about our data practices.
Data We Collect
Account Information
When you sign up, we collect your email address, display name, and authentication credentials. If you sign in via a social provider (e.g., Google), we receive your name and email from that provider.
Content You Create
Areas, objectives, goals, projects, tasks, notes, journal entries, reviews, and any other content you create within the platform. This data belongs to you.
Usage Data
We collect anonymized usage patterns such as features used, session duration, and interaction frequency to improve the product experience.
Technical Data
Browser type, operating system, device information, IP address, and general location (country/region level) collected automatically when you access the service.
Payment Information
Payment processing is handled entirely by Paddle, our merchant of record. We never store your credit card number, bank account details, or other financial information on our servers.
Connected Services (Optional)
If you choose to connect external accounts such as Google (see the Google User Data section) or LinkedIn, we store encrypted access credentials and the content needed for the features you use. For LinkedIn this means, for example, the posts you schedule and the comment notifications shown in your social inbox. Disconnecting a service deletes its credentials immediately.
How We Use Your Data
We use the data we collect for the following purposes:
- Provide the service — deliver core features like hierarchy management, focus sessions, reviews, and calendar integration.
- AI-powered features — generate personalized suggestions, weekly reviews, coaching insights, and task recommendations based on your content.
- Communications — send essential service emails (password reset, billing confirmations) and optional product updates you can unsubscribe from at any time.
- Error tracking — identify and fix bugs to keep the platform stable and reliable.
- Analytics — understand aggregate usage patterns to prioritize features and improve the user experience. We use privacy-friendly analytics (PostHog, self-hosted where possible).
We never sell, rent, or trade your personal information to third parties for marketing purposes.
Data obtained from your connected Google account (Gmail, Calendar, Contacts, Drive) is governed exclusively by the Google User Data section of this policy. The general purposes above, such as analytics and communications, do not apply to Google user data.
Data Storage & Security
We take the security of your data seriously and employ industry-standard measures:
- Database — hosted on Supabase (PostgreSQL) with encryption at rest and in transit.
- File storage — uploaded files are stored in Supabase Storage with access controls tied to your account.
- Encryption — all data transmitted between your browser and our servers is encrypted via TLS 1.3.
- Row Level Security — every database query is scoped to your user ID through PostgreSQL Row Level Security policies, ensuring you can only access your own data.
AI & Your Data
Nervus.io uses third-party AI providers (OpenAI, Anthropic, Google) to power intelligent features. Here is how we handle your data in the context of AI:
- Your content is sent to AI providers only when you actively use AI features (e.g., generating a weekly review, asking the AI coach a question).
- We send only the minimum context necessary for each AI request — not your entire account data.
- AI providers process your data according to their API data usage policies, which prohibit using API inputs for model training.
- AI-generated content (suggestions, reviews, insights) is stored in your account and treated with the same privacy protections as content you create manually.
Google User Data
Connecting a Google account to Nervus is optional. When you choose to connect one, Nervus accesses certain Google user data through Google APIs. This section explains exactly what we access and how it is used. We use Google user data solely to provide and improve user-facing features of Nervus that you can see and control. We never use it for any other purpose.
- Gmail (reading) — with your permission, we read your email messages to display your inbox inside Nervus, let you search your own mail, and give the AI assistant the context you request (for example, summarizing a conversation or preparing a reply draft for your review). Reading also powers optional features you enable that organize incoming mail, such as surfacing social notifications in your social inbox.
- Gmail (actions) — with your permission, we perform mailbox actions that you explicitly trigger in Nervus: sending a message you approved, marking a conversation as read or unread, starring, archiving, or moving to trash. Nervus never sends email or changes your mailbox on its own.
- Google Calendar (read-only) — we read your calendar events to display them alongside your Nervus tasks in a unified view. We never create, change, or delete calendar events.
- Google Contacts (read-only) — we read your contacts only when you use the contact import feature, so you can choose which contacts to bring into Nervus. We never change your Google contacts.
- Google Drive — we list and read files and their metadata to build the file view you see inside Nervus, and we manage files in folders created by Nervus. We never delete your Drive files or share them with anyone.
- Account identification — we store the email address of each connected Google account so you can tell your connected accounts apart in the interface.
Nervus's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. The use of raw or derived user data received from Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.
In addition, we commit to the following for all Google user data:
- We use it only to provide and improve the Nervus features described above. We never use it for advertising, marketing, market research, or profiling.
- We never sell it. We transfer it to third parties only when necessary to provide a feature you requested, for security investigations, or to comply with applicable law.
- We never use it, in raw, aggregated, or derived form, to create, train, or improve foundational or generalized artificial intelligence or machine learning models. When you actively use an AI feature, the minimum necessary content is processed by our AI providers under agreements that prohibit them from training models on your data.
- No person at Nervus reads your Google user data unless you explicitly ask us to for support, it is necessary for security purposes, or we are required to by law.
- Access credentials (OAuth tokens) are stored encrypted at rest (AES-256-GCM). When you disconnect a Google account, we delete its credentials immediately and all access stops.
- Content that entered your Nervus account through your own actions (for example, a note you created from an email, or synced copies that power your inbox view and search inside Nervus) remains part of your account data and is permanently deleted when you delete it or delete your account.
Third-Party Services
We use the following third-party services to operate Nervus.io:
| Service | Purpose | Region |
|---|---|---|
| Supabase | Database, Auth, Storage | EU / US |
| Cloudflare | CDN, DDoS Protection | Global |
| Vercel | Hosting, Edge Functions | US |
| Paddle | Payments (Merchant of Record) | UK |
| Sentry | Error Tracking | US |
| PostHog | Product Analytics | EU |
| Resend | Transactional Email | US |
| OpenAI / Anthropic / Google | AI Processing | US |
Your Rights
You have the following rights regarding your personal data:
- Access — request a copy of all personal data we hold about you.
- Correction — update or correct inaccurate personal information.
- Deletion — request permanent deletion of your account and all associated data.
- Portability — export your data in a standard, machine-readable format.
- Withdraw consent — opt out of optional data processing (e.g., analytics) at any time.
GDPR Compliance
If you are located in the European Union or the European Economic Area, we process your personal data under the legal bases of contract performance, consent, and legitimate interest. You can exercise all of the rights listed above and you also have the right to lodge a complaint with your local supervisory authority. International transfers are protected by standard contractual clauses.
LGPD Compliance
If you are located in Brazil, you have additional rights under the Lei Geral de Proteção de Dados (LGPD), including the right to know about data sharing with third parties, to request anonymization of unnecessary data, and to revoke consent. We process your data under the legal bases of consent and legitimate interest.
To exercise any of these rights, contact us at privacy@nervus.io.
Nervus.io uses a minimal number of cookies to operate:
- Essential cookies — authentication session tokens required for the service to function. These cannot be disabled.
- Analytics cookies — anonymous usage tracking via PostHog. You can opt out at any time by emailing privacy@nervus.io.
We do not use advertising cookies or cross-site tracking pixels. We do not participate in ad networks.
Data Retention
- Active accounts — your data is retained for as long as your account is active.
- Deleted accounts — all personal data is permanently deleted within 30 days of account deletion.
- Backups — encrypted database backups are retained for up to 7 days and then automatically purged.
- Legal obligations — certain records (e.g., billing history) may be retained longer as required by applicable law.
Children's Privacy
Nervus.io is not intended for children under 16 years of age. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us at privacy@nervus.io.
International Transfers
Your data may be processed in countries other than your country of residence, including the United States and the European Union. We ensure appropriate safeguards are in place, including standard contractual clauses where applicable, to protect your data in accordance with this policy.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will notify you via email or a prominent notice within the service.
The "Effective date" at the top of this page indicates when the policy was last revised. Your continued use of the service after changes are posted constitutes acceptance of the updated policy.
Contact
If you have questions about this Privacy Policy or our data practices, please reach out:
Nervus.io
Cayman Islands
privacy@nervus.io