Privacy policy
iPhone application and website
This policy explains what data Nia processes, what for, on what legal basis, for how long and what you can do about it. It covers the iPhone application and this website. The plain language version, with concrete examples, is at what happens to your data.
1. Who the controller is
The data controller is Nia, a provider established in Spain and responsible for the Nia application for iPhone.
Contact address for anything to do with this policy or with your data: hola@niapersonal.com. Requests are answered within one month of receipt, extendable by two further months where the request is complex, with notice given inside the first month.
No data protection officer has been appointed, because the processing meets none of the conditions in article 37 of the GDPR: there is no regular and systematic monitoring of people on a large scale, and no large scale processing of special categories of data.
2. The summary, before the detail
Nia does most of its work inside the iPhone. This table separates what never leaves the device from what travels to the server. The rest of the document explains each line.
| Data | Where it is processed |
|---|---|
| Your identity | Optional. Nia can be used as a guest, with no email and no name. |
| The audio of your voice | On the iPhone only, except a group radio, which sends what you say to that group. |
| Your address book | On the iPhone only. |
| Your calendar and your reminders | On the iPhone only, unless you connect Google Calendar. |
| Your photos and camera roll | On the iPhone only, except the specific image you ask to generate or edit. |
| Your Apple Health data | On the iPhone only. Never sent. |
| The audio of a meeting you record | On the iPhone only, unless you turn on telling voices apart. |
| The photo of a receipt you scan | On the iPhone only. |
| Your exact location | On the iPhone only. What reaches the server is rounded to a kilometre. |
| The text of what you ask and what Nia answers | Server and model provider. |
| What you ask it to remember | Server. |
| The documents you give it | Server and the model provider indexing service. |
| Diagnostics and usage data | Firebase Crashlytics and Firebase Analytics. |
3. What data is processed, what for and on what basis
3.1 Account data, and the guest account
You can start using Nia without giving any details at all. The guest account uses Firebase's anonymous provider: it is a real account, with an identifier your conversations, memory and usage are filed under, but it carries no email, no name and no other identity. The trade off is stated in the app itself: nobody can sign back into it from another phone, and uninstalling the application ends it. That is why a subscription cannot be bought on a guest account.
If you later identify yourself with Apple, with Google or with your email, that identity is added to the account you already had, under the same identifier, rather than creating a second one: what you did as a guest is still there. The one exception is credentials that already belong to another account, in which case you enter the existing one and the guest account is left orphaned and deleted.
To use Nia with an identity an account is needed. A user identifier and the email address tied to the method you sign in with are stored: Apple, Google, or email and password. If you use Sign in with Apple and choose to hide your email, Nia only ever receives the relay address Apple generates, never the real one. Where there is a password, it is held by Firebase Authentication under its own encryption: it is never stored in the clear and is never accessible to the controller.
Purpose: identifying you, keeping the session and tying your conversations and subscription to your account. Basis: performance of a contract.
3.2 Profile data
You may optionally add a name, a city, a preferred language and a reference photo so you can appear in the images Nia generates. All of it is voluntary and can be deleted at any time from the app itself.
Purpose: personalising answers and, for the photo, generating images you appear in. Basis: consent, which you withdraw by deleting the data.
3.3 The content of your conversations
The text of what you ask and of Nia's answers is stored against your account so you can go back to it. Dictation and wake word audio is not recorded, stored or sent: recognition happens on the device and the only thing that leaves the iPhone is the text transcription. Group radio and meeting speaker separation are exceptions explained in their own sections.
That text is sent to the model provider to generate the answer, together with what Nia remembers about you, the local time and the rounded location where the action needs it.
Purpose: answering and keeping the history. Basis: performance of a contract.
3.4 Attachments
Files you attach to a message are sent to the model provider solely to answer that turn. They are not retained: before the conversation is stored, the content is replaced by a line saying what kind of file it was. The limit is four files per message and eight megabytes each.
Purpose: answering that specific request. Basis: performance of a contract.
3.5 Memory
On plans with memory, what you expressly ask Nia to remember is stored as readable text, because search by meaning is computed over the text itself: an encrypted memory could not be found and so would serve no purpose. You can view, search, edit and delete each item, or delete all of them, from the Memory screen.
When Nia detects that what you were about to store looks like a password, a PIN or an access key, it stores nothing and asks you what to do, with two buttons. The decision is kept and can be changed in Settings.
Purpose: remembering what you ask to have remembered. Basis: consent, withdrawn by deleting the memory or turning the feature off.
3.6 Documents
Documents you add voluntarily are sent to the model provider indexing service so Nia can answer citing the file and the page. The limit is ten documents and twenty megabytes per account. They are deleted when you delete them or when you delete your account.
Purpose: answering questions about your own documents. Basis: consent.
3.7 Location
When an action needs it, such as finding places nearby, working out a travel time or creating a reminder that fires on arriving somewhere, location is used inside the device through the iOS services. What reaches the server is rounded to roughly one kilometre, which is enough to give context and not enough to know where you are.
The "always" location permission is only requested the first time you create a reminder or a routine that depends on a place, never during sign up.
Purpose: carrying out actions that depend on a place. Basis: consent.
3.8 Subscriptions and payments
Subscriptions are taken out through your Apple account. Payment is processed entirely by Apple: Nia does not see, receive or store your banking details, your card or your billing address. What is processed is the state of your subscription, the plan and the renewal date, which arrive through Apple and RevenueCat so the features you have paid for can be enabled.
Purpose: giving access to the plan you bought and applying its limits. Basis: performance of a contract.
3.9 Diagnostics and usage data
The application includes Firebase Crashlytics and Firebase Analytics, both from Google.
- Crashlytics collects crash reports when the app closes unexpectedly: the point in the program where it happened, the device model, the iOS version, the app version and an installation identifier generated by Crashlytics itself. It also keeps a trail of the last technical events before the crash. It does not include the text of your conversations, contact names or the content of any action.
- Analytics records four product events and only four: that a turn started and through which channel, that a tool ran and with what result, that a turn failed and with what code, and that a purchase completed and for which plan. The parameters are closed labels and counts. No text you have typed, no names and no content identifiers ever travel.
This data is not used for advertising, is not combined with data from other apps or websites, and is not sold. The system advertising identifier (IDFA) is never collected.
Purpose: finding and fixing errors, and understanding which features are used in order to decide what to improve. Basis: legitimate interest in the stability and improvement of the service, weighed against your rights: the data is minimal, does not identify you on its own and is not used to profile you.
3.10 Notifications
If you allow notifications, the token Apple assigns to that installation is stored so they can be delivered through Firebase Cloud Messaging and the Apple push notification service. It is used to tell you the result of a job, a routine or activity in a group. It is deleted when you revoke the permission or delete your account.
Purpose: delivering the notifications you asked for. Basis: consent.
3.11 Groups
If you create or join a group, the server stores the group, its members, what each one posts in it and who has responded to what, so it can be shared with the other members. Your address book plays no part: inviting somebody is a single use code that Nia writes into WhatsApp or Messages, and the contact is resolved inside your phone.
Inside a group there is no end to end encryption, and the group screen itself says so. There is none because the server has to distribute the content, moderate it when it is reported and carry out what is asked of it. Treat a group as what it is: a shared space with the people you invited.
Purpose: providing the groups feature. Basis: performance of a contract, and consent for what you post.
3.14 A group radio
When you turn a group's radio on and hold to speak, your voice does leave your iPhone: it travels encrypted in transit to our server, which passes it to the people in that group who turned their own listening on. This first version has no end to end encryption, and we say it plainly: the server holds the audio in memory in order to pass it on.
Nobody hears you unless they turned their own listening on, for a shift with an end time, and nobody can turn it on for you. Turning it on asks for your consent before the first transmission and records the date.
A voice notice lives about thirty seconds in the server's memory, just long enough to reach somebody whose phone was asleep and to be played back by somebody whose hands were full, and then it is gone. There is no history and no permanent recording. If somebody reports a notice, we then keep that recording for thirty days, so we can listen to it and act on the report within the twenty four hours the App Store rules require. That is the only exception, and deleting the reported person's account does not remove it: a record that exists because somebody complained about them cannot be erased by them.
We never identify you by your voice. We know who is speaking because they signed in, not because we analyse their voice: there is no biometric processing.
Purpose: providing the group radio, and moderating what is reported. Basis: performance of a contract and your consent; for the reported recording, the legitimate interest in acting on an abuse report and complying with store rules.
3.12 Third party accounts you connect
If you connect your Google account, Nia receives an access token carrying the specific permissions you granted and uses it to read or write only what the requested action needs: reading and sending mail in Gmail, reading and writing in Google Calendar, searching Google Drive. The token is stored encrypted on the server, is shared with nobody, and is destroyed when you disconnect the account or delete yours. Each permission is granted separately, and you can also revoke them from the security settings of your Google account.
Purpose: carrying out the actions you ask for on those services. Basis: consent.
3.13 What never leaves the iPhone
The following data is processed exclusively on the device, through the iOS frameworks, and Nia's server has no access to it at any time:
- Your address book. It is read on the phone to work out who you are calling or writing to. It is never uploaded to any server, not even turned into codes or summaries.
- The contents of your calendar and reminders, except the specific event you ask to create or look up, and unless you connect Google Calendar, in which case that service is the one answering.
- Your photos. Nia reads the most recent photo, or the one you pick, only when you ask for an edit, and saves what it generates into the "Nia" album.
- Your Apple Health data.
- The audio of your meetings. Transcription happens on the device. The one exception is telling voices apart, which does send audio to the server, is asked for separately and can be refused.
- The photos of receipts you scan. Merchant, date, total and line items are extracted on the device with Vision.
- The audio of dictation and of the wake word. A group radio is the exception and has its own section, 3.14.
- Nia Studio masks, that is the cutout separating a person or an object from the background.
- Your exact location.
4. The system permissions, one by one
Nia asks for no permissions during sign up. Each one is requested the first time an action needs it, with the explanation in front of you, and all of them can be revoked at any time from iOS Settings. If you revoke one, the app carries on with the rest and tells you which specific action it can no longer perform.
| Permission | What it is used for |
|---|---|
| Microphone | Hearing what you say when you talk to Nia. Dictation and the wake word stay on the iPhone. Group radio and meeting speaker separation require a specific action and consent before audio is sent. |
| Speech recognition | Turning what you say into text, on the device itself. |
| Calendar | Reading your diary, creating events and moving them. |
| Reminders | Creating, listing, changing and completing reminders. |
| Contacts | Working out who you are calling or writing to. It does not leave the phone. |
| Photos, add only | Saving the images and videos you generate into the "Nia" album. |
| Photos, read and write | Editing a photo of yours and saving the new version without touching the original. |
| Camera | Scanning a document or a receipt. |
| Location while using | Finding places nearby and working out travel times. |
| Location always | Reminders and routines that fire on arriving at or leaving a place. |
| Notifications | Telling you the result of a job, a routine or a group. |
| Health, read | Answering what you ask about sleep, steps or workouts. |
| Health, write | Logging water, weight or a workout when you ask. |
| Home (HomeKit) | Turning your home accessories on, off and adjusting them. |
| Media and Apple Music | Playing music inside the app. |
| Bluetooth | Noticing the car stereo disconnecting so it can save where you parked. |
| Alarms | Creating alarms and timers that ring on silent. |
5. Health data
Health data is a special category of personal data (article 9 of the GDPR) and is treated apart:
- It is read and written exclusively on the device, through HealthKit and with your explicit consent, granted permission by permission from the Health app.
- It is never sent to Nia's server or to any third party. The only thing that can appear in an answer is the specific number you asked to hear.
- It is never used for advertising, marketing, profiling or data mining, and is neither sold nor disclosed to data brokers.
- It is not stored in iCloud or in any cloud storage service.
- Nia is not a medical device and does not replace the judgement of a professional.
6. Legal bases for processing
- Performance of a contract (article 6.1.b GDPR): handling your requests, keeping your conversations, applying your plan's limits and providing the service you signed up for.
- Consent (article 6.1.a): the system permissions, connecting third party accounts, memory, documents and profile. They are asked for one at a time, at the moment they are needed, and can be withdrawn at any time without affecting the lawfulness of processing before withdrawal.
- Explicit consent (article 9.2.a) for health data.
- Legitimate interest (article 6.1.f): the security of the service, preventing abuse and fraud, fixing errors and understanding usage in aggregate. In each case it has been weighed against your rights and the minimum data has been chosen.
- Legal obligation (article 6.1.c): keeping the billing records required by applicable law.
No automated decisions are taken that produce legal effects concerning you or similarly significantly affect you, within the meaning of article 22 of the GDPR.
7. Who the data is shared with
Nia relies on the following processors, each under a contract requiring them to process the data only on our instructions:
| Who | What they process | What for |
|---|---|---|
| Google, Gemini model | The text of your requests and answers, your documents and the images or videos you ask for | Generating the answer and the requested content |
| Google Cloud, including Cloud Run and Firestore | Everything stored on the server | Hosting and database |
| Firebase Authentication | User identifier and email | Identifying you and keeping the session |
| Firebase App Check | A device integrity attestation | Checking the request comes from the genuine app |
| Firebase Cloud Messaging | The notification token | Delivering notifications |
| Firebase Crashlytics | Crash reports and technical device data | Finding and fixing errors |
| Firebase Analytics | Four product events with labels and counts | Understanding which features are used |
| Google Sign In | The details of the account you sign in with | Letting you sign in with Google |
| RevenueCat | The state of your subscription | Enabling the plan you bought |
| Apple | Payment and subscription state | Charging and validating the purchase |
| Google Search | The text of the query when an answer needs current information | Answering with up to date facts |
| Google Workspace (Gmail, Drive, Calendar) | Only what the permission you granted allows | Carrying out what you ask on your account |
| Telegram | The message you ask to be sent to you and your chat identifier | Delivering that message, if you link the feature |
Each of the providers above has been verified to give your data a level of protection equal to the one described in this policy and required by the App Store Review Guidelines. None of them is permitted to use your data for their own purposes, for advertising or to train general models.
Nia does not sell your data, does not disclose it for advertising, does not share it with data brokers and does not use it to train artificial intelligence models. Beyond the processors listed, your data would only be disclosed to a third party at the request of a competent authority, on the terms the law requires.
8. International transfers
The providers above may process data outside the European Economic Area, mainly in the United States. In those cases the transfer relies on the Standard Contractual Clauses approved by the European Commission and, where the provider is certified, on the Data Privacy Framework between the European Union and the United States, alongside the supplementary technical measures described in the security section. You can ask for a copy of these safeguards by writing to hola@niapersonal.com.
9. How long data is kept
| Data | Period |
|---|---|
| Conversations, free plan | One year from creation. |
| Conversations, Plus and Pro plans | Until you delete them. |
| Memory, Plus plan | Thirty days. |
| Memory, Pro plan | Until you delete it. |
| Documents | Until you delete them. |
| Account and profile data | For as long as the account exists. |
| A guest account left unused | Removed by the Firebase anonymous account cleanup, along with whatever was inside it. |
| Tokens for connected accounts | Until you disconnect that account. |
| Group content | While the group exists or until you leave it. |
| Voice notices on a group radio | About thirty seconds, in memory only. |
| A voice notice somebody reported | Thirty days, so the report can be acted on. |
| Server technical logs | Ninety days at most. |
| Crash reports | The Firebase Crashlytics retention periods, up to ninety days. |
| Usage events | The Firebase Analytics retention periods, set to the shortest available. |
| Billing records | The period required by applicable tax and commercial law. |
Deleting the account erases all of the above from the server, except what a legal obligation requires to be kept, crash reports that are not tied to your identity, and a reported radio recording during its thirty day retention period. That exception lets us handle the report and is not available to group members.
10. Your rights
You may exercise at any time the rights of access, rectification, erasure, restriction of processing, objection and portability, and withdraw any consent you have given. Two of them are inside the application and need no email and no waiting:
- Portability and access: in Settings, under Account, "Export my data" produces a file with your conversations, memories, routines and skills, in a machine readable format.
- Erasure: in Settings, under Account, "Delete account" erases your data from the server and signs you out. Deletion is final and requires no prior approval.
For the remaining rights, or if you prefer to exercise them in writing, write to hola@niapersonal.com saying which one you are exercising. Proof of identity may be requested where there is reasonable doubt about who is making the request.
If you consider that the processing does not comply with the law, you can lodge a complaint with the Spanish Data Protection Agency (aepd.es), calle Jorge Juan 6, 28001 Madrid, or with the supervisory authority of your country of residence.
11. Children
Nia is not aimed at children under fourteen and does not knowingly collect data from children of that age, fourteen being the age from which a minor's consent is valid on its own in Spain under Organic Law 3/2018. If we find an account belonging to a child under fourteen, it is deleted along with its data. If you are a parent or guardian and believe a child in your care has created an account, write to hola@niapersonal.com and it will be resolved without further formality.
12. Security
The technical and organisational measures applied, in the terms of article 32 of the GDPR, are the following:
- Encryption in transit: all communication between the app, the server and the providers travels over HTTPS with TLS. The app accepts no unencrypted connections.
- Encryption at rest: the cloud provider storage encrypts data on disk.
- No credentials inside the binary: the application contains no key for any artificial intelligence provider. The server is the only point in the system holding them, which means extracting the binary gives access to nothing.
- Integrity checking: every request to the server carries an App Check attestation, so a request that does not come from the genuine application is rejected.
- Access control: every request requires a valid session token, and the database rules prevent one account from reading or writing another account's data.
- Minimisation: location is rounded before it leaves the device, attachments are not persisted and usage events carry no content.
- Device isolation: whatever can be resolved inside the iPhone is resolved inside the iPhone, which is the most effective security measure of all.
No system is invulnerable. Should a security breach occur that poses a risk to your rights and freedoms, it will be notified to the Spanish Data Protection Agency within the seventy two hour period set out in article 33 of the GDPR, and communicated to you without undue delay where the risk is high, under article 34.
13. Artificial intelligence
Nia runs on a large language model hosted by Google. Three things worth saying plainly:
- You are talking to an automated system, not to a person. The application makes that clear in its own interface.
- The model can get things wrong. Check what it does before taking it as final, especially for decisions with consequences: emails sent, events involving other people, health data or spending. What iOS does not allow an application to complete is documented in what iOS will not allow, and Nia says so rather than pretending the action completed.
- Your data is not used to train models. Neither ours nor the provider's. The content you send is processed to answer that request and nothing more.
The images and videos Nia generates are synthetic content, created by an artificial intelligence system. If you publish or share them, it is for you to say so where the law requires it.
14. Advertising and tracking
Nia shows no advertising, performs no tracking within the meaning of Apple's transparency framework, and includes no advertising network and no third party measurement kit for advertising purposes.
- The device advertising identifier (IDFA) is not collected, and therefore the application never shows the system tracking prompt.
- Your data is not combined with data from other companies' apps or websites.
- Your data is not sold, not rented and not disclosed to data brokers.
- The privacy manifest shipped with the application declares
NSPrivacyTrackingas false and declares no tracking domains.
15. This website
This website is static and served as files: it uses no cookies, includes no analytics, loads no third party fonts or resources and does not profile its visitors. The only thing it stores in your browser is a local preference with the light or dark mode you chose, which is sent nowhere and disappears when you clear the site data. The hosting provider records requests in its own technical logs, for the purpose of operating and protecting the service.
16. The App Store privacy label
Apple publishes a summary of the data an application handles alongside it. This table maps what that label declares onto what this policy explains, so you can check that the two say the same thing.
| Apple category | Collected | Linked to you | What for |
|---|---|---|---|
| Contact info, email address | Yes | Yes | App functionality |
| Identifiers, user ID | Yes | Yes | App functionality |
| User content, other content | Yes | Yes | App functionality |
| Purchases, purchase history | Yes | Yes | App functionality |
| Diagnostics, crash data | Yes | No | App functionality |
| Usage data, product interaction | Yes | No | Analytics |
| Location, coarse location | Yes | Yes | App functionality |
| Audio data, group radio notice | Yes, only while you transmit or when a notice is reported | Yes | App functionality and safety moderation |
| Health and fitness | Does not leave the device | Not applicable | Not applicable |
| Contacts | Does not leave the device | Not applicable | Not applicable |
| Data used to track you | None | Not applicable | Not applicable |
| Advertising, IDFA | No | Not applicable | Not applicable |
17. How this fits with the other documents
This policy sits alongside two more documents: the terms of use, which describe the service, the plans and the subscription conditions, and the licence agreement, which governs your right to use the application. Where they conflict on the processing of personal data, this policy prevails.
18. Changes to this policy
If anything material changes, the date in the header is updated and notice is given inside the application before the change takes effect. Where the change affects processing based on your consent, it will be asked for again. Previous versions are provided on request by writing to hola@niapersonal.com.