1. Who is responsible for your data
Nemosine is operated by Nemosine AS (organisation number 937 091 567).
- Contact email: support@nemosine.app
- Postal address: Vestre Furmyrveg 26, 6017 Aalesund, Norway
Nemosine AS is the data controller for the personal data described in this Privacy Policy unless this page says otherwise.
2. Scope
This Privacy Policy applies to:
- the Nemosine website at
nemosine.app - the Nemosine web and app experience at
app.nemosine.app - cloud sync accounts, subscriptions, billing status, and support requests
This policy covers Nemosine's currently live production features, including optional Cloud AI models available on Nemosine Pro (section 7a). The Google Calendar integration is disabled in the current production release.
3. Data we collect
Depending on how you use Nemosine, we may process:
Account and authentication data
- email address
- a randomly generated Supabase user ID and related account identifiers; these identifiers are pseudonymous, but remain linked to your account and email address in Nemosine's systems
- authentication and session status data
User content
- note titles
- note bodies and related synced content
- synced media attachments
- synced settings and other user-created data
Nemosine is a general-purpose notes product. Because you control what you write, your content may include sensitive or special-category personal data. We do not ask for that information specifically, but if you choose to store it, we will process it only to provide the service you requested.
Sync metadata and technical data
- row IDs, table names, versions, timestamps, and deletion flags
- randomly generated device identifiers used for sync conflict resolution and ordering; these are pseudonymous identifiers linked to your Supabase account, not advertising identifiers
- storage usage, traffic usage, request counts, completed-sync status, app version, and client platform
- Supabase authentication and API logs, which may include authentication events, timestamps, user ID, request route and status, IP address, user-agent string, and other request metadata
Nemosine does not upload application-level sync error messages, error codes, or error classifications. Failed sync details remain on your device. Supabase may still record the outcome and technical metadata of the underlying network request in its own infrastructure logs.
Cloud AI data (Nemosine Pro, optional)
- the content of a cloud AI request you choose to send, while that request is being processed
- per-request usage records: token counts, model identifier, timing, status, and computed cost
Section 7a explains this in full, including what we do not store.
Subscription and transaction data
- subscription plan, status, renewal state, and entitlement status
- purchase history, product and entitlement identifiers, and transaction or subscription IDs from RevenueCat, Stripe, Apple, or Google
- billing currency, amount, taxes, fees, and subscription period dates
We do not store full payment card numbers in Nemosine systems.
Website and support data
- website request logs and technical security data handled by our hosting providers
- contact form submissions, including name, email, company, and message
- support correspondence you send to us
4. How we use personal data
We use personal data to:
- create and operate your account
- authenticate you and keep the service secure
- store and sync encrypted content across your devices when you enable cloud sync
- provide subscriptions, billing status, and entitlement checks
- provide optional Cloud AI models where you have consented to the processing, and meter your credit usage
- monitor reliability, capacity, bandwidth, storage usage, and abuse
- provide customer support and respond to legal or regulatory obligations
- maintain aggregated, non-identifiable product KPI reporting
We do not sell your notes, and we do not use synced note content for advertising or model training. We do not opt in to provider model training with content you send to Cloud AI; see section 7a.
5. Lawful bases under GDPR
If you are in the EEA, Norway, or the UK, we rely on these lawful bases:
- Contract: to create your account, authenticate you, provide cloud sync, provide subscriptions, and respond to support requests related to the service
- Legitimate interests: to secure the service, prevent abuse, troubleshoot problems, measure storage/bandwidth usage, plan capacity, and keep internal aggregated KPI reporting
- Legal obligation: to retain records required by accounting, tax, consumer, fraud, or other applicable law
- Consent (article 6(1)(a)): to process the content you choose to send to optional Cloud AI models, and anywhere else consent is specifically required by law, for example if we later add optional non-essential cookies or comparable tracking technologies
6. Encryption and what "end-to-end encrypted" means in Nemosine
Nemosine is designed to be local-first. If you do not enable cloud sync, your content stays on your device.
When you enable cloud sync:
- note content and synced media are encrypted on your device before upload
- your login password is separate from your sync encryption password
- Nemosine cannot read the encrypted synced content without the sync encryption password
However, not all metadata is end-to-end encrypted. To make authentication and cross-device sync work, the server can still process some metadata such as:
- account identifiers
- sync row and table identifiers
- timestamps
- randomly generated, pseudonymous device identifiers linked to the account and used by the sync algorithm
- row versions and deletion markers
- storage and traffic counters
- Supabase authentication and API logs, including IP addresses, user-agent strings, request details, and authentication events
Nemosine does not upload application-level sync error messages, codes, or classifications. This does not prevent Supabase from retaining infrastructure logs for the underlying authentication, API, storage, or function request.
So the accurate description is: Nemosine provides end-to-end encryption for synced content, but not for all sync metadata.
If you lose your sync encryption password, some synced cloud content may become unrecoverable.
7. Service providers and disclosures
We share data only where needed to run the service or comply with law. Current providers include:
- Supabase for authentication, database, encrypted sync storage, and infrastructure logging. Supabase authentication and API logs can contain the linked Supabase user ID, authentication events, IP address, user-agent string, request route and status, timestamps, and other request metadata.
- RevenueCat for subscription entitlement management, receipt validation, purchase history, and analytics. Nemosine supplies RevenueCat with the pseudonymous Supabase user ID as its app user ID, so RevenueCat's purchase and entitlement records are linked to the Nemosine account.
- Vercel for website hosting and website request handling
- Formspree for website contact form handling
- Stripe for web subscription payments
- Apple and Google for in-app subscription payments and billing events
- OpenAI Ireland Limited for Luna (Cloud) and xAI (SpaceXAI LLC) for Grok (Cloud), as model providers for optional Cloud AI on Nemosine Pro (section 7a). Our data processing agreement for Luna is with OpenAI Ireland Limited; OpenAI's affiliates and its own sub-processors may process the request on its behalf
- NEAR AI (Jasnah, Inc.) for GLM 5.3 Flash (NEAR AI), as model provider for optional Cloud AI on Nemosine Pro (section 7a). GLM is an open-weights model that NEAR AI runs on its own hardware; its originator, Z.ai, does not receive the request
RevenueCat, Apple, Google, and Stripe also apply their own privacy terms to data they process on their own behalf.
We may also disclose personal data:
- if required by law, court order, or valid government request
- to establish, exercise, or defend legal claims
- in connection with a merger, acquisition, financing, or asset transfer, subject to applicable confidentiality and legal requirements
7a. Optional Cloud AI
Nemosine Pro may offer Luna (Cloud) and Grok (Cloud). These optional AI models run on servers instead of on your device. Cloud AI is off until you turn it on, and it only sends anything when you use it.
On-device AI is a separate thing and is not covered by this section: supported local models run on your own hardware, are available on every plan, and send nothing to us or to anyone else.
What leaves your device
Cloud processing happens only after you have explicitly accepted the Cloud AI Data Processing document in the app. When you then send a cloud request, the content of that request — your prompt, the chat history, and any note content the request includes — is sent over TLS to our server function and on to the model provider.
Nothing else in your library is uploaded, and your end-to-end encrypted sync is unaffected. Requests are assembled on your device rather than on our servers, so the provider only ever receives what your device included.
Provider routing and pseudonymisation
Requests to each model provider are sent from our infrastructure through one organisational API credential for that provider. We do not put your Nemosine user ID, email address, account details, or client IP address in the provider request.
For Grok, we may include an opaque cache-routing value derived on our server from your account and local conversation identifiers using a keyed one-way function. xAI does not receive those underlying identifiers. The value is different for different accounts and conversations, but lets xAI recognise requests from the same Nemosine conversation so it can route them to the same prompt cache. We send no comparable explicit conversation cache key to OpenAI or NEAR AI, although each may apply its own automatic prompt caching.
These safeguards make the processing pseudonymous, not anonymous. The selected provider processes the request content and may recognise repeated Grok requests carrying the same opaque value. If the words, images, or other content you send identify you or someone else, the provider processes that identifying content.
Providers, retention, and training
The provider depends on the model you select: Luna (Cloud) uses OpenAI, Grok (Cloud) uses xAI, and GLM 5.3 Flash (NEAR AI) uses NEAR AI. A request is sent only to the provider of the selected model. Nemosine does not opt in to provider model training with your Cloud AI content.
- xAI: we enable Grok only through an xAI team with Zero Data Retention (ZDR). Under ZDR, request inputs and model outputs are not persisted to disk by xAI. Our server verifies xAI's ZDR response header. Temporary in-memory processing and prompt caching may still occur while serving a request, and xAI may process operational metadata under its terms.
- NEAR AI: GLM 5.3 Flash runs on NEAR AI's own GPUs inside a hardware Trusted Execution Environment (TEE). NEAR AI states that prompts and outputs processed inside that enclave cannot be read by the host operating system, the GPU operator, or NEAR AI itself, and its Terms of Service state that it will not use customer data to train any generative AI model. A TEE reduces the risk of access to data while it is in use but does not eliminate it, and NEAR AI does not represent that TEE processing satisfies any particular regulatory requirement. Our relay still handles the request in readable form in order to forward it, so selecting this model does not give you encryption running unbroken from your device into the enclave.
- OpenAI: we explicitly ask OpenAI not to store the API response as hosted application state. OpenAI may still retain request and response content in abuse-monitoring logs for up to 30 days unless our OpenAI organisation is separately approved and configured for ZDR. OpenAI may also temporarily retain encrypted prompt-cache state on its GPU infrastructure.
We do not use provider-hosted conversation history, files, collections, or batch processing for Cloud AI. More detail is available in Cloud AI data processing.
What Nemosine stores
For each cloud request we store a billing record: token counts, the model identifier, timing, status, and computed cost. We do not store or log your prompts, included note content, or model replies on our servers.
Consent and withdrawal
This processing is based on your explicit consent. That consent is versioned, recorded, and revocable in Nemosine's settings at any time. Withdrawing consent stops future cloud processing. Billing records for usage that already happened are kept under section 9.
8. International transfers
Our providers may process personal data outside Norway or the EEA, including in countries that may not have the same level of legal protection.
When that happens, we rely on applicable transfer mechanisms such as:
- adequacy decisions
- the European Commission's Standard Contractual Clauses
- additional contractual, technical, and organisational safeguards where appropriate
For Cloud AI specifically, our data processing agreement for Luna is entered into with OpenAI Ireland Limited in Ireland. Where OpenAI moves that content outside the EEA — including to OpenAI OpCo, LLC in the United States — it does so under its own agreements containing Standard Contractual Clauses, or under a European Commission adequacy decision. Grok requests are sent to xAI in the United States, and GLM 5.3 Flash requests to NEAR AI (Jasnah, Inc.) in the United States.
9. Retention
We keep personal data for as long as needed for the purposes described above.
In general:
- active account and cloud-sync data are retained while your account remains active
- we may delete cloud account data if the account has been inactive for 2 years
- for paid subscriptions, we normally keep cloud data while the subscription or account remains active
- free accounts that stay inactive for more than 2 years may have cloud data removed
- deleting cloud data does not automatically delete local copies stored on your own devices
- Cloud AI usage and billing records are kept for 24 months, after which they are aggregated into statistics that do not identify you
- Supabase authentication and API logs are retained for the period made available by Nemosine's configured Supabase project plan and log settings; the available period can change if that plan or configuration changes
- billing and accounting records may be kept longer where required by law
- de-identified or aggregated statistics that do not reasonably identify you may be kept after account deletion
10. Your rights
If GDPR or similar privacy laws apply to you, you may have the right to:
- access your personal data
- correct inaccurate data
- request deletion of your data
- restrict or object to certain processing
- receive a portable copy of data you provided to us
- withdraw consent where processing is based on consent
- complain to your local supervisory authority
If you are in Norway, you can complain to Datatilsynet.
If you are in certain US states, you may also have rights to know, access, correct, delete, and appeal certain decisions about personal data processing. Nemosine does not currently sell personal information or share it for cross-context behavioural advertising.
To exercise rights, contact support@nemosine.app. We may ask for information needed to verify your identity before acting on a request.
11. Children's privacy
Nemosine is a general-audience product and is not directed to children. You must be at least 16 to create a cloud account or use Cloud AI, in every country, including where local law sets a lower age. We do not knowingly collect personal data from anyone under 16 for cloud-sync accounts, subscriptions, or Cloud AI. If you believe someone under 16 has provided personal data to us, contact support@nemosine.app and we will investigate.
If you are under the age required to enter into a binding contract where you live, do not buy a subscription unless your parent or legal guardian is involved.
12. Cookies, local storage, and website technologies
Nemosine does not currently use advertising cookies or third-party behavioural tracking on the public website.
We may still use:
- necessary website request logs and security tooling through our hosting providers
- essential browser storage or app-side local storage to make the website or app work
- secure device storage inside the app for account and sync-related settings
If we later add optional analytics, marketing cookies, or similar technologies that require consent, we will update this Privacy Policy and request consent where required.
13. Security
We use technical and organisational measures designed to protect personal data, including encryption in transit, on-device encryption for synced content, access controls, and least-privilege service design. No system is perfectly secure, so we cannot guarantee absolute security.
14. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. If we make a material change, we will tell you in the app, summarise what changed on our legal updates page, and ask you to acknowledge the updated policy before cloud sync continues. We may also notify you through the website or the account email address on file. Other changes, such as corrections and clarifications, take effect when we publish them.
15. Contact
For privacy questions, support requests, or legal notices related to privacy, contact:
Nemosine AS
Org. no. 937 091 567
Vestre Furmyrveg 26, 6017 Aalesund, Norway
support@nemosine.app