Your screen recordings never leave your computer. The two-week study runs on your device; raw captures are processed locally and deleted after your map is built. What reaches our servers is limited to redacted, structured text about your workflows, the content your Nibbins handle for the specific tasks you give them, and ordinary account information. We don't sell your data, we never train models on your content, you can opt out anytime of the anonymized signals we use to improve Nibbin, and a connection never sends or changes anything until you approve that specific action.
1. Who we are
Nibbin, Inc. ("Nibbin," "we," "us") provides software that helps people who work for themselves understand their workflows and delegate routine tasks to AI agents ("Nibbins"). This policy covers nibbin.com, the Nibbin web application, the Nibbin desktop application (the "Observer"), and related services.
2. Information we collect
| Category | Examples | Where it lives |
|---|---|---|
| Account | Name, email, sign-in identifiers (Google/Apple/magic link), plan, billing status | Our servers |
| Connected services | OAuth tokens for services you connect (e.g., Gmail, calendars, invoicing tools), and the content those connections return when a scan or a Nibbin you've adopted does its work | Tokens in an encrypted vault on our servers; content processed to perform the task |
| Field Study data (Observer) | Screen captures, accessibility-tree events, app and window activity during a study you start | Your device only. Raw captures and recordings are never uploaded — by architecture, the capture component has no network capability |
| Synthesis packet | Redacted, structured text descriptions of workflows (with personal details replaced by placeholders like {PERSON} and {EMAIL}), uploaded only when you explicitly choose to generate your diagnosis | Our servers, to produce your diagnosis |
| Usage & device | Product interactions in the web app, approximate region, browser type; payment handled by Stripe (we never see full card numbers) | Our servers / Stripe |
We do not collect audio or camera data. The Observer ships with no telemetry; optional desktop crash reports are off by default.
3. The two-week Field Study, specifically
- Studies are opt-in, show a visible countdown, and hard-stop after 14 days.
- Secure input fields (passwords) cannot be captured; banking, health, and other sensitive categories are excluded by default; you can exclude any app or site and pause everything with one hotkey.
- Raw study data is encrypted on your device, reviewable and deletable by you daily, and automatically deleted after your diagnosis is built — with the deletion shown to you.
- Only the redacted synthesis packet ever leaves your device, and only on your explicit action. Pixels never do.
4. Connected accounts & the Google API disclosure
When you connect a service, we request the narrowest scopes that let your Nibbins do the work you'll ask of them — for Gmail and Calendar that includes the permission to draft and send or to create events. Holding that permission is not the same as using it: nothing is ever sent or changed beyond what you have granted. You set each Nibbin's action level (Observe, Draft, or Act) — Agent School grades how accurately it has been working so you always know when to trust it with more. Some platforms offer no read-only permission at all (Instagram DMs and QuickBooks are examples); there we request the narrowest scope the platform has and enforce read-only in our own connector and database layers instead. If you opt in when you connect Gmail, Nibbin runs a one-time onboarding read of about your last 12 months of sent and inbox mail (capped) to learn how you write and the questions you answer most. Your sent messages are processed by the model; your inbox is reduced to subjects and short previews. Only the short derived notes — including a few of your voice phrases — are kept in your grove memory; we don't retain the raw mail beyond that processing. It's off unless you choose it, and you can turn it off in Data & Privacy. You can disconnect any service at any time; disconnection revokes our access and pauses dependent Nibbins.
Nibbin's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is used only to provide and improve user-facing features of Nibbin (your scans, your Nibbins' work, your Field Notes), is never used for advertising, and is never sold. Human access is limited to narrow cases: with your explicit consent for support, for security and abuse investigation, or as required by law.
5. How we use information
- To provide the service: run scans, draft and perform the tasks you've delegated, build your diagnosis, show Field Notes.
- To operate the business: billing, support, abuse and fraud prevention, security.
- To improve Nibbin: aggregate, de-identified product analytics, and — unless you opt out — anonymized, aggregate signals about how Nibbin's capabilities and models perform. We never train our models on your content. You can manage this anytime in Settings → Data & Privacy.
- We do not sell or rent your personal information, and we do not share it for cross-context behavioral advertising.
6. AI processing
Nibbin uses large language model providers as processors to perform the work you ask for (for example, drafting a reply). Content sent to these providers is limited to the task at hand, sent under agreements that prohibit them from training on it, and never includes your raw study data, which stays on your device.
7. Sharing
We share information only with: service providers acting on our instructions (hosting, database, email delivery, payments, model providers — a current subprocessor list is available at nibbin.com/subprocessors); parties you direct us to share with (the recipient of an email your Nibbin sends for you); and authorities when legally required, in which case our data-minimization design means there is little to produce. If Nibbin is involved in a merger or acquisition, this policy continues to govern transferred data.
8. Retention & deletion
This schedule is the same one published on our Data & AI page, and the product enforces it exactly.
| Data | Kept | Your control |
|---|---|---|
| Raw Field Study data (on device) | Until your diagnosis is built, max 14 days | Review daily, delete blocks, or abort the study — deletion is shown to you |
| Synthesis packet | Processed into your diagnosis, then stored as part of it | Delete the diagnosis anytime |
| Agent run logs | 90 days by default | Shorten the window or wipe logs anytime |
| Nibbin journals (derived from your draft decisions — what changed and how much, never the draft text) | Follows the run-log clock | Wiping run logs clears them |
| Scan results | While the connection is active | Disconnect to remove; re-scan anytime |
| Connection tokens | While connected, in an encrypted vault | One-click revoke; dependent Nibbins pause politely |
| Account data | Life of the account + 30 days after verified deletion | Export and delete from settings, web or desktop |
| Encrypted backups | Roll off within 35 days of deletion | Automatic |
| Unsubscribe & bounce record (email address only) | Kept indefinitely | Kept to honor your request — that address is never mailed again |
9. Security
Connection tokens are stored in an encrypted vault, never in our application database in plaintext. Study data on your device is encrypted with keys held in your device's secure hardware. Access within Nibbin is role-restricted, multi-factor protected, and logged; staff cannot view your study data (it never reaches us) and cannot read your message content without an explicit, time-boxed consent grant from you.
10. Your rights
Depending on where you live (including the EEA/UK under GDPR and California under CCPA/CPRA), you may have rights to access, correct, export, delete, and restrict processing of your personal information, and to non-discrimination for exercising them. Use in-product controls or email hello@nibbin.com; we respond within 30 days. We do not "sell" or "share" personal information as those terms are defined in the CCPA. Where Global Privacy Control signals apply, we honor them.
11. Children
Nibbin is for people running their own work and is not directed to anyone under 18. We do not knowingly collect information from children; if you believe a minor has provided us data, contact us and we will delete it.
12. Changes & contact
We'll post changes here and, for material changes, notify you in-product or by email before they take effect. Questions: hello@nibbin.com · Nibbin, Inc.