Nibbin, Inc.

How Nibbin uses AI & your data

Plain language, kept current · effective June 10, 2026 · the legal version lives in the Privacy Policy
The five promises

1. Screen captures from the study never leave your device — by architecture, not policy.
2. Your data is never sold and never used for advertising.
3. We never train our models on your content. The anonymized signals we use to improve Nibbin are yours to opt out of, anytime.
4. Everything is retained on a clock you can see, and most clocks you can shorten.
5. A connection can hold the keys to act, but nothing is ever sent or changed beyond what you've granted. You set each Nibbin's action level — Observe, Draft, or Act — and its Agent School grade tells you how accurately it's working so you know when to grant more. Where a platform offers no read-only permission (Instagram DMs, QuickBooks), we request the narrowest scope it has and enforce read-only in our own connector and database layers until you choose to grant Act.

Where AI runs, and on what

Nibbin uses large language models to do three jobs: hold the Grovekeeper conversation, turn scan findings into plain language, and do the work you delegate (drafting a reply, chasing an invoice). For ongoing work, the model sees only what that task needs — the email thread being answered, not your inbox; the invoice being chased, not your books. Light routine steps run on small fast models; only genuinely hard steps use frontier models. Models act as processors: they perform the task and are contractually barred from retaining or training on your content.

The one exception is a one-time onboarding read when you first connect Gmail — and only if you opt in. To learn your voice and the questions you answer most, Nibbin reads about your last 12 months of sent and inbox mail (capped). Your sent messages are processed by the model to learn your voice; your inbox is reduced to subjects and short previews. Only the short derived notes — a summary of your FAQs and a few of your voice phrases — are kept in your grove memory; the raw mail is not retained beyond that processing. It's off unless you choose it, and you can turn it off anytime in Data & Privacy.

What leaves your device, and what never does

DataLeaves your device?Why
Screen captures & recordings (Field Study)Never.Captured, redacted, analyzed, and deleted locally. The capture component has no network capability.
Synthesis packet (Field Study)Only when you click "build my diagnosis"Redacted, structured text — names, emails, and numbers replaced with placeholders before upload.
Connected-service contentPer taskFetched when a scan or a Nibbin needs it, processed, and not retained beyond the run log.
Account & usage dataYesNormal SaaS operation: login, plan, meters, product analytics (aggregate).

Retention — the actual clocks

DataKeptYour control
Raw Field Study data (on device)Until your diagnosis is built, max 14 daysReview daily, delete blocks, or abort the study — deletion is shown to you
Synthesis packetProcessed into your diagnosis, then stored as part of itDelete the diagnosis anytime
Agent run logs90 days by defaultShorten the window or wipe logs anytime
Nibbin journals (derived from your draft decisions — what changed and how much, never the draft text)Follows the run-log clockWiping run logs clears them
Scan resultsWhile the connection is activeDisconnect to remove; re-scan anytime
Connection tokensWhile connected, in an encrypted vaultOne-click revoke; dependent Nibbins pause politely
Account dataLife of the account + 30 days after verified deletionExport and delete from settings, web or desktop
Encrypted backupsRoll off within 35 days of deletionAutomatic
Unsubscribe & bounce record (email address only)Kept indefinitelyKept to honor your request — that address is never mailed again

Who touches your data

A small set of subprocessors run Nibbin: cloud hosting and database, the encrypted token vault, LLM providers (processing only), email delivery for Field Notes, and Stripe for payments. We publish the named list with regions at nibbin.com/subprocessors and update it before adding anyone new. Nibbin staff cannot read your study data (it never reaches us), cannot see vault tokens, and cannot open your message content without a time-boxed consent grant you initiate — and every staff action is logged where you can see it.

Your controls, in one place

Settings → Data & Privacy gives you: per-connection scopes and revoke; run-log retention; journal deletion; model-improvement contribution opt-out — anonymized signals only, on unless you turn it off; data export; account deletion. During a study, the desktop app adds: pause hotkey, exclusion list, daily review, and abort-with-deletion.

Questions, or something here that doesn't match what you see in the product? That's a bug — tell us: hello@nibbin.com