1. Who is responsible
clusterhack operates Nibvine at nibvine.com and is the controller of the personal data described here. For privacy questions, data access requests or complaints, write to privacy@nibvine.com.
Where you use Nibvine to store personal data about other people, you are the controller of that data and we act as your processor. The Data Processing terms cover that relationship.
2. What we collect
- Account data
- Your username, email address and the identifier issued by our sign-in provider. If you sign in with a social or enterprise identity, we receive the profile fields that provider releases.
- Workspace content
- Projects, notes and their tree structure, tasks, ideas, comments, quick notes, tags, attachments and change history — everything you or your connected agents put into the product.
- AI records
- Prompts and responses for the AI features you run, the provider and model used, token counts and computed cost, plus cached analyses so the same request does not have to be paid for twice.
- Credentials you supply
- Model provider API keys you add for BYOK use. These are encrypted at rest, never shown back to you in full, and every access is written to an audit log.
- Access tokens
- API and MCP tokens are stored only as a hash, together with their scopes, optional project restriction, expiry and last-used time.
- Integration data
- The link between your account and a messaging bot, the destinations of any webhooks or chat notifications you configure, and delivery results.
- Technical data
- Server logs containing IP address, user agent, requested path, status code and timing. These exist to keep the Service running and secure.
- Preferences
- Interface settings such as your theme and pinned projects.
We do not run advertising or third-party analytics trackers, and we do not buy personal data about you from anyone.
3. Why we use it, and on what legal basis
| Purpose | Data used | Legal basis |
|---|---|---|
| Provide the product: store and display your projects, notes and tasks | Account data, workspace content, preferences | Performance of a contract |
| Run the AI features you trigger and meter their cost | Workspace content, AI records, credentials you supply | Performance of a contract |
| Authenticate people and agents, and enforce scopes | Account data, access tokens, technical data | Performance of a contract; legitimate interest in security |
| Keep the Service secure, prevent abuse, debug faults | Technical data, audit logs | Legitimate interest in a secure, working service |
| Deliver the integrations you configure | Integration data, workspace content you route | Performance of a contract |
| Answer support requests | Account data, the content of your message | Performance of a contract; legitimate interest |
| Meet legal and accounting obligations | Account data, billing records | Legal obligation |
4. What is sent to model providers
AI features work by sending project context to a model provider. That context can include note titles and bodies, task and idea text, comments, and project metadata drawn from the project you are working in.
- Nothing is sent unless you, an agent using your token, or a linked bot command starts an AI operation.
- The provider used is the one configured for the operation — OpenAI, OpenRouter or Google Gemini. The subprocessor list is kept current.
- When the configured key is a placeholder, the product runs in mock mode and no request leaves the server at all.
- With your own provider key, requests go to that provider under your own account and terms.
5. Who else sees your data
We do not sell personal data and we do not share it for advertising. Data reaches other parties only in these situations:
- Subprocessors that run part of the Service — hosting, sign-in, model providers, messaging — each listed on the subprocessors page with its purpose.
- Destinations you choose yourself: an AI client you connect, a webhook you configure, a chat channel you point us at, or a public share link you publish.
- Legal requests we are obliged to answer, where we will give the minimum required and tell you unless we are prohibited from doing so.
- A successor entity if the Service is sold or merged, under the same commitments as this policy.
6. How long we keep it
| Data | Retention |
|---|---|
| Workspace content | Until you delete it or close your account |
| Account record | Until you close the account |
| AI records and token usage | Kept for usage history and cost accounting; removed with the account |
| Access tokens | Until revoked, expired, or the account closes |
| Server logs | Up to 90 days, then deleted or aggregated |
| Key access audit log | Up to 12 months |
| Backups | Rolling window, normally not longer than 30 days |
| Billing records | As long as tax and accounting law requires |
7. Your rights
Depending on where you live you have some or all of the following rights. We honour them for everyone, wherever you are.
- Access — get a copy of the personal data we hold about you.
- Portability — export your projects and notes as JSON at any time, from the product itself.
- Rectification — correct anything inaccurate.
- Erasure — delete projects, notes or the whole account.
- Restriction and objection — ask us to stop a particular processing activity based on legitimate interest.
- Withdraw consent — where processing relies on consent, withdraw it without affecting what happened before.
- Complain — to your local data protection authority.
Write to privacy@nibvine.com. We answer within 30 days and will not charge you for a reasonable request.
8. International transfers
Our subprocessors operate in several countries, including outside the European Economic Area. Where personal data moves across borders we rely on the transfer mechanisms those providers offer — normally the European Commission’s Standard Contractual Clauses or an adequacy decision.
9. Security
Traffic is encrypted in transit. Provider keys are encrypted at rest, access tokens are stored only as hashes, and scopes are enforced on every API and MCP call. The security overview describes the controls in more detail and explains how to report a vulnerability.
10. Children
Nibvine is not intended for children under 16. If you believe a child has given us personal data, write to privacy@nibvine.com and we will delete it.
11. Changes to this policy
We update this policy as the product changes. The effective date at the top always reflects the current version, and material changes are announced before they take effect.
Questions about this document? Write to legal@nibvine.com.