1. Controller and contact
For GDPR purposes, the controller is:
Nemosine AS
Org. no. 937 091 567
Vestre Furmyrveg 26, 6017 Aalesund, Norway
support@nemosine.app
Nemosine has not currently appointed a separate data protection officer. Privacy questions should be sent to the contact above.
2. What processing this page covers
This page summarises GDPR-relevant processing for Nemosine's currently live service, including:
- account creation and authentication
- optional encrypted cloud sync
- subscriptions and billing status
- support and website contact requests
- operational metrics for reliability, capacity, storage, and bandwidth planning
The optional read-only Google Calendar integration and optional Cloud AI models on Nemosine Pro are part of the current processing scope. Cloud AI content processing is based on explicit, revocable consent. Luna (Cloud) uses OpenAI, Grok (Cloud) uses xAI, and GLM 5.3 Flash (NEAR AI) uses NEAR AI; a request goes only to the provider of the model selected for that conversation. See section 7a of the Privacy Policy and Cloud AI data processing.
3. Main categories of personal data
Nemosine may process:
- identifiers such as email address and user ID
- user-generated content you choose to store or sync
- sync metadata such as timestamps, row IDs, versions, and randomly generated device IDs used by the sync algorithm
- usage counters such as storage, ingress, egress, read/write requests, and session totals
- technical error data only if you choose to submit an error report, without note contents or synced note bodies
- subscription and transaction metadata
- support and contact-form information
- content you choose to include in a Cloud AI request, while it is being relayed and processed
- Cloud AI usage records containing token counts, model, timing, status, and cost, without prompt or reply content
- for Grok, an opaque pseudonymous per-conversation cache-routing value derived with a keyed one-way function; xAI does not receive the underlying Nemosine account or conversation identifiers
4. Lawful bases
For EEA, Norwegian, and UK users, Nemosine generally relies on:
- Article 6(1)(b) contract for account creation, authentication, cloud sync, subscriptions, and support connected to the service
- Article 6(1)(f) legitimate interests for service security, abuse prevention, troubleshooting, operational metrics, capacity planning, and internal aggregated KPI reporting
- Article 6(1)(c) legal obligation where records must be retained under accounting, tax, consumer, or other applicable law
- Article 6(1)(a) consent for content you choose to send to Cloud AI, and where consent is otherwise specifically required, such as any future optional non-essential cookies or comparable tracking
5. Encrypted sync and metadata
If you enable cloud sync, synced note content and synced media are encrypted on your device before upload.
However, not all metadata is encrypted end-to-end. To provide authentication and sync, Nemosine still processes technical metadata such as:
- account identifiers
- timestamps
- sync row and table identifiers
- row versions and deletion markers
- randomly generated device identifiers used by the sync algorithm as anonymous technical metrics
- usage and quota counters
Technical error data is only sent if you choose to submit an error report, and those reports do not include note contents or synced note bodies.
Nemosine therefore provides end-to-end encryption for synced content, but not for all sync metadata.
6. Recipients and international transfers
Nemosine uses service providers including Supabase, Vercel, Formspree, Stripe, Apple, and Google, depending on the feature you use. If you use Cloud AI, OpenAI Ireland Limited receives Luna requests, xAI receives Grok requests, and NEAR AI (Jasnah, Inc.) receives GLM 5.3 Flash requests. Nemosine does not put your account identifier, email address, or client IP address in a provider request. Grok's opaque cache-routing value and free-form request content remain pseudonymous personal data where they can be linked to a person; they are not treated as anonymous data.
Where personal data is transferred outside the EEA or Norway, Nemosine relies on applicable legal transfer mechanisms such as adequacy decisions, Standard Contractual Clauses, and supplementary safeguards where appropriate. For Cloud AI, Nemosine's data processing agreement for Luna is with OpenAI Ireland Limited in Ireland; OpenAI carries any onward transfer outside the EEA — including to OpenAI OpCo, LLC in the United States — under its own agreements containing Standard Contractual Clauses or an adequacy decision. Grok requests are sent to xAI in the United States, and GLM 5.3 Flash requests to NEAR AI (Jasnah, Inc.) in the United States.
7. Retention
In general:
- account and cloud data are retained while the account remains active
- cloud data may be deleted after 2 years of inactivity
- paid accounts normally retain cloud data while the subscription or account remains active
- local copies on your devices are not automatically deleted when cloud data is deleted
- Nemosine does not retain or log Cloud AI prompt or reply content on its servers
- xAI processes Grok requests under Zero Data Retention; request inputs and model outputs are not persisted to disk, although temporary in-memory processing, prompt caching, and operational-metadata processing may occur
- NEAR AI processes GLM 5.3 Flash requests on its own GPUs inside a Trusted Execution Environment, and its terms exclude using customer data to train generative AI models; a TEE reduces but does not eliminate the risk of access to data in use, and Nemosine's relay handles the request in readable form before forwarding it
- OpenAI may retain Luna request and response content in abuse-monitoring logs for up to 30 days unless Nemosine's OpenAI organisation is separately approved and configured for Zero Data Retention;
store: falseprevents provider-hosted application-state storage but does not by itself remove that abuse-monitoring period - Cloud AI token-usage and billing records are retained for 24 months and are then aggregated into statistics that do not identify you
- legal and accounting records may be retained longer where required
- de-identified or aggregated statistics may be retained after account deletion
8. Your GDPR rights
Subject to GDPR and applicable exceptions, you may have the right to:
- access
- rectification
- erasure
- restriction
- objection
- portability
- withdraw consent where processing is based on consent
You also have the right to complain to a supervisory authority. In Norway, that authority is Datatilsynet.
Requests may be sent to support@nemosine.app. We may request information needed to confirm your identity before acting on a request.