Skip to main content
nabit

Privacy Policy

Last updated April 2026. Español

This Privacy Policy describes how Nab Technologies("nab.it", "we", "us") collects, uses, and discloses information when you use nab.it and related services (the "Service"). By using the Service, you agree to this policy.

What data we collect

  • Account data: email address and display name when you register or sign in.
  • Product content: nabs, notes, attachments, tags, reminders, and other information you create or store in the app.
  • Usage data: product analytics and usage events (for example feature usage and performance) to operate and improve the Service. Where we use analytics tools, we aim to minimize personal data and use aggregated or pseudonymous information where possible.

How we store and protect data

We host application data on Supabase (PostgreSQL). Data is protected with encryption in transit (TLS) and encryption at rest as provided by our infrastructure. Access is limited to authorized personnel and systems for operations, security, and support.

Third-party services

  • Stripe — payment processing and subscription billing when you purchase a paid plan. Stripe receives billing-related information as needed to process payments.
  • Anthropic — optional AI-powered features (for example Reflect) when you choose to use them; your prompts and related content may be sent to Anthropic to generate responses.
  • Google— sign-in with Google and related OAuth flows (for example Google Drive integrations where offered); Google's privacy policy also applies to information processed by Google.
  • Supabase — authentication, database, and hosting for the Service.

Cookies and similar technologies

We use cookies and similar technologies for essential purposes, including: session and authentication security; preferences (for example theme and language); and, where enabled, analytics to understand how the Service is used. We do not use third-party advertising cookies to sell your personal data.

Your rights

Depending on your location, you may have the right to access your personal data, request deletion, and export data where the product provides export tools. You may contact us using the email below to exercise these rights. We will respond within a reasonable period as required by applicable law.

Data retention

When you delete your account, we delete or irreversibly anonymize personal data within 30 days, except where a longer retention period is required by law or for legitimate security or fraud-prevention purposes.

GDPR (EEA/UK)

If the GDPR applies, you may have rights including access, rectification, erasure ("right to be forgotten"), restriction of processing, objection, and data portability. You may lodge a complaint with your local supervisory authority. Our lawful bases may include contract, legitimate interests (for example security and product improvement), and consent where required.

Children

The Service is not intended for children under 13, and we do not knowingly collect personal information from children under 13. If you believe we have collected such information, contact us and we will take appropriate steps to delete it.

Changes

We may update this Privacy Policy from time to time. We will post the updated policy on this page and, where appropriate, notify you by email or in-product notice.

Contact

Nab Technologies — Privacy inquiries: privacy@nab.it.com