Privacy Policy
1. Who we are
Nivorai (“we”, “us”, “our”) is an independent project built and operated by İlkay Bora, based in Turkey. It is not a registered company. You can find every way to reach the developer at ilkaybora.com, or write to hello@nivorai.app directly.
2. What we collect
Account data: email address, hashed password, optional 2FA secret. Product data: tasks, notes, journal entries, mood scores, finance transactions, fitness logs, focus sessions, habits — all scoped to your account. Billing data: handled by Stripe; we store only a Stripe customer ID and subscription metadata. We never see your card number. Nivorai is intended for users aged 13 and older (16 in EU jurisdictions); we do not knowingly collect data from children below that threshold.
3. Why we process it
To provide the service you signed up for (contractual basis under GDPR Art. 6(1)(b)), to send transactional notifications about your subscription, and to improve the product (legitimate interest under Art. 6(1)(f)). Mood scores, journal entries and fitness logs may qualify as health-adjacent / special-category data under GDPR Art. 9(1) and KVKK Art. 6. We process those modules only when you enable them — turning a module on in Settings → Modules counts as your explicit consent under GDPR Art. 9(2)(a) / KVKK Art. 6(3). You can withdraw at any time by turning the module off, which stops further processing immediately.
4. AI processing
When you opt in to AI features, the relevant data (your selected task, journal entry, etc.) is sent to Google’s Gemini API to generate the response. Gemini does not train on Nivorai customer data per Google’s enterprise terms. You can disable AI any time in Settings → AI.
5. Product analytics
We collect interaction events to measure how Nivorai is being used — for example which step of the onboarding wizard you finish, when you send an AI message, when you view the pricing page. Events store a short event name and a small set of structured properties (counts, flags, IDs). They never contain the contents of your tasks, notes, journal entries, AI messages, or any other free-form text. A random correlation ID is stored in your browser’s localStorage so anonymous landing-page activity can be linked to your account if you sign up; you can clear it any time. Analytics are self-hosted on the same infrastructure as the app — no Google Analytics, no Plausible, no third-party tracker. Legal basis: legitimate interest (GDPR Art. 6(1)(f)) in operating and improving the service.
6. Sharing
We share data only with: Stripe (payment processing), Resend (transactional email), Google Cloud (Gemini AI when enabled), and our hosting provider Hetzner. Each of these has a data processing agreement on file. Analytics events are not shared with anyone — they live in our own database.
7. Your rights (GDPR + KVKK)
Under GDPR Art. 15–22 and KVKK Art. 11 you may: (i) access the data we hold about you, (ii) request rectification of inaccurate data, (iii) request erasure ("right to be forgotten"), (iv) request restriction of processing, (v) receive your data in a portable machine-readable format, (vi) object to processing based on legitimate interest (e.g. analytics), and (vii) withdraw any consent you have given (e.g. for AI features, marketing, or special-category modules) without affecting the lawfulness of past processing. Most rights are self-serve from Settings → Account; for the rest email hello@nivorai.app and we will respond within 30 days. You may also lodge a complaint with the Turkish Personal Data Protection Authority (KVKK) or your local EU data protection authority.
8. Retention
We retain your data while your account is active. When you delete your account we remove all data within 30 days, including analytics events tied to your account. The exception is billing records held by Stripe, which we keep for the period required by Turkish tax law (currently 5 years for VAT invoices) and any longer period mandated by anti-money-laundering or accounting rules in your jurisdiction.
9. Data security and breach notification
We protect your data with TLS in transit, at-rest encryption, hashed passwords (Argon2id), encrypted 2FA secrets and least-privilege access controls. If a personal data breach occurs we will notify the competent supervisory authority (the Turkish KVKK and/or relevant EU DPA) within 72 hours of becoming aware of it, as required by GDPR Art. 33 and KVKK Art. 12. If the breach is likely to result in a high risk to your rights and freedoms we will also notify you directly without undue delay, with details of what happened and what you can do.
10. Cookies and local storage
Nivorai uses only essential cookies (session token, theme preference, language) plus a small amount of localStorage for the analytics correlation ID and your client-side preferences. No advertising trackers, no third-party analytics. We do not need a consent banner under EU ePrivacy because nothing we set is non-essential per the user-experience tests in WP29 Opinion 04/2012.
11. Changes
If we materially change this policy, we will email you at least 30 days before the change takes effect. The current version is always at /legal/privacy.