1. Screen captures from the study never leave your device — by architecture, not policy.
2. Your data is never sold and never used for advertising.
3. We never train our models on your content. The anonymized signals we use to improve Nibbin are yours to opt out of, anytime.
4. Everything is retained on a clock you can see, and most clocks you can shorten.
5. A connection can hold the keys to act, but nothing is ever sent or changed beyond what you've granted. You set each Nibbin's action level — Observe, Draft, or Act — and its Agent School grade tells you how accurately it's working so you know when to grant more. Where a platform offers no read-only permission (Instagram DMs, QuickBooks), we request the narrowest scope it has and enforce read-only in our own connector and database layers until you choose to grant Act.
Where AI runs, and on what
Nibbin uses large language models to do three jobs: hold the Grovekeeper conversation, turn scan findings into plain language, and do the work you delegate (drafting a reply, chasing an invoice). For ongoing work, the model sees only what that task needs — the email thread being answered, not your inbox; the invoice being chased, not your books. Light routine steps run on small fast models; only genuinely hard steps use frontier models. Models act as processors: they perform the task and are contractually barred from retaining or training on your content.
The one exception is a one-time onboarding read when you first connect Gmail — and only if you opt in. To learn your voice and the questions you answer most, Nibbin reads about your last 12 months of sent and inbox mail (capped). Your sent messages are processed by the model to learn your voice; your inbox is reduced to subjects and short previews. Only the short derived notes — a summary of your FAQs and a few of your voice phrases — are kept in your grove memory; the raw mail is not retained beyond that processing. It's off unless you choose it, and you can turn it off anytime in Data & Privacy.
What leaves your device, and what never does
| Data | Leaves your device? | Why |
|---|---|---|
| Screen captures & recordings (Field Study) | Never. | Captured, redacted, analyzed, and deleted locally. The capture component has no network capability. |
| Synthesis packet (Field Study) | Only when you click "build my diagnosis" | Redacted, structured text — names, emails, and numbers replaced with placeholders before upload. |
| Connected-service content | Per task | Fetched when a scan or a Nibbin needs it, processed, and not retained beyond the run log. |
| Account & usage data | Yes | Normal SaaS operation: login, plan, meters, product analytics (aggregate). |
Retention — the actual clocks
| Data | Kept | Your control |
|---|---|---|
| Raw Field Study data (on device) | Until your diagnosis is built, max 14 days | Review daily, delete blocks, or abort the study — deletion is shown to you |
| Synthesis packet | Processed into your diagnosis, then stored as part of it | Delete the diagnosis anytime |
| Agent run logs | 90 days by default | Shorten the window or wipe logs anytime |
| Nibbin journals (derived from your draft decisions — what changed and how much, never the draft text) | Follows the run-log clock | Wiping run logs clears them |
| Scan results | While the connection is active | Disconnect to remove; re-scan anytime |
| Connection tokens | While connected, in an encrypted vault | One-click revoke; dependent Nibbins pause politely |
| Account data | Life of the account + 30 days after verified deletion | Export and delete from settings, web or desktop |
| Encrypted backups | Roll off within 35 days of deletion | Automatic |
| Unsubscribe & bounce record (email address only) | Kept indefinitely | Kept to honor your request — that address is never mailed again |
Who touches your data
A small set of subprocessors run Nibbin: cloud hosting and database, the encrypted token vault, LLM providers (processing only), email delivery for Field Notes, and Stripe for payments. We publish the named list with regions at nibbin.com/subprocessors and update it before adding anyone new. Nibbin staff cannot read your study data (it never reaches us), cannot see vault tokens, and cannot open your message content without a time-boxed consent grant you initiate — and every staff action is logged where you can see it.
Your controls, in one place
Settings → Data & Privacy gives you: per-connection scopes and revoke; run-log retention; journal deletion; model-improvement contribution opt-out — anonymized signals only, on unless you turn it off; data export; account deletion. During a study, the desktop app adds: pause hotkey, exclusion list, daily review, and abort-with-deletion.
Questions, or something here that doesn't match what you see in the product? That's a bug — tell us: hello@nibbin.com