NyblitDevelopers

Privacy Policy

1. Who we are

Nyblit is operated by App Goblin Ltd, registered in England and Wales under company number 16029603, with its registered office at 7, 211-213 St Margarets Road, Twickenham, Middlesex, TW1 1LU, England.

Our privacy contact is David at App Goblin Ltd. For privacy questions, personal information requests or complaints, email david@appgoblin.co.uk, or write to our registered office marked “Privacy”.

This policy covers the Nyblit apps for Apple devices (the “Native Apps”), www.nyblit.app (the “Website”), the browser application at web.nyblit.app (the “Web App”), and our support and marketing communications. It applies to both personal and business use of Nyblit Web.

We are the controller of information we use for our own account administration, purchase-entitlement administration, website operation, analytics, marketing and support correspondence.

For task content we store, synchronise or otherwise handle solely to carry out your instructions, we act as a processor. You choose what to enter and how to use it through the available features. This applies to personal and business task content; the data processing section of our Nyblit Web Terms of Service governs this processing for the Web Service. A business customer is the controller, or acts for one, and we act as its processor or sub-processor. Contact the relevant business first about information it controls; we will assist as required by law. Purely personal or household use may be exempt from the user's GDPR obligations, but this does not remove our own obligations.

2. The different kinds of information involved

Task content, technical information and correspondence are different categories of data. Native Apps can store tasks locally, sync through iCloud or use Nyblit Cloud. Web access requires Nyblit Cloud.

Depending on the features you use, the information involved includes:

You choose what to put into tasks, which may include sensitive information such as health details. Include only what you need. The access restrictions in section 3 apply to task content. If you include someone else's information, make sure you are entitled to do so.

3. Accounts, storage and migration

Nyblit accounts

You must create an account to use Nyblit Cloud and the Web App. Your Nyblit Cloud account works across iOS and the web. Supported methods include email and password, passkeys, and sign-in with Apple, Google or Discord where offered. Available options are shown on the sign-in screen. We also use emailed one-time codes for account verification and password recovery.

You supply your name and email address, or your chosen social sign-in provider supplies them. Nyblit Cloud signup, whether through iOS, Mac or the web, also asks for your age band: under 16, 16–17 or 18 or over. Users under 16 cannot create a Nyblit Cloud account or use the Web App. We use the age band to apply these age requirements and the advertising restrictions in section 5.

Your selected sign-in provider authenticates you and supplies its account identifier alongside your name and email address. We do not receive your social-provider password. Sign in with Apple may supply a relay email address if you choose to hide your email. If you link another sign-in provider, its identity becomes associated with your Nyblit account.

Our authentication provider processes sign-in credentials and session information to authenticate you and secure your account.

Using a social sign-in method does not by itself give Nyblit access to that provider's email messages, contacts or files. Optional integrations need their own authorisation.

Nyblit Cloud and the Web App

Nyblit Cloud is our cloud service. It stores and synchronises the task content and related account information needed to provide Nyblit across connected devices. When you migrate to Nyblit Cloud, that information is no longer stored solely in your private iCloud database.

We use cloud storage, authentication and hosting providers to operate Nyblit Cloud and the Web App. They process the content, account and technical information needed for those services, as described in section 9.

We do not read or browse your stored task content except for support with your explicit permission, when strictly necessary to investigate a serious security incident, or when required by law. Any access is limited to the information needed for that purpose. Our systems process task content to provide the service.

Moving from iCloud to Nyblit Cloud

Existing iCloud users must migrate their Nyblit data to Nyblit Cloud to use the Web App. Migration moves your existing Nyblit data, including archived tasks, shared tasks and their chat history, to Nyblit Cloud and associates it with your Nyblit account. The source data is deleted from iCloud. Subsequent changes sync through Nyblit Cloud only.

You can return to iCloud later and transfer your updated Nyblit Cloud data back to it. The source task data is then deleted from Nyblit Cloud. Migration in either direction deletes the data from the service you are leaving; it does not leave that source data as a separate backup. The retention provisions in section 11 also apply, including any provider-backup retention.

Before either migration, we encourage you to export a manual .nyb backup file. The underlying backup data uses JSON. You can optionally encrypt the file with a password for added protection. You control where the exported file is stored and how long it is kept. Keep the file and any password secure.

Connected services that require your permission, such as Gmail, must be authorised again before you use them on the web. Migration of Nyblit data does not automatically grant the Web App access to those connected accounts.

Returning to iCloud leaves your Nyblit Cloud account open. You can delete that account separately using the account-deletion option in the Nyblit app. Section 11 explains retention and deletion.

We explain the data movement before you start migration. Signing in with Apple does not change your selected storage arrangement.

Native Apps using iCloud or Local Only

In iCloud mode, the Native Apps store tasks on your devices and sync through your own Apple iCloud account. We do not have developer access to the content of that private iCloud task database. This limited statement does not apply to data you migrate into Nyblit Cloud or deliberately send to support.

Local Only mode stores the task database on your device without synchronising it to iCloud or Nyblit Cloud.

Browser storage and sharing

Your browser processes task content to display and edit it. Its working copy is held in page memory, while limited information, including task titles for wake alerts, is saved in browser storage. Section 6 explains what is stored and what remains after sign-out. Signing out does not delete your Nyblit Cloud account or data.

Task sharing and chat are not available in the Web App at launch. Where Native App sharing is available, selected recipients receive access according to the permissions granted and may retain their own copies. We will explain the privacy implications before introducing web sharing; this policy does not grant advance permission for it.

Exports and integration tools

You can export your data as a .nyb backup using JSON, with optional password encryption. Where your plan includes API Access, you can also retrieve supported data through Nyblit's API and compatible tools. Moving exported information into another app may require conversion to match its import requirements.

You authorise an API tool by providing a personal access token with permissions and an expiry you choose. A valid token can reveal your account identifier and, where available, your name and email address. Your chosen permissions determine which task, project and workflow data the tool can read or change, including deletion where permitted. You can revoke tokens in My account → API Access to stop further access using them.

Review the privacy arrangements of any tool or service you choose to receive your information. Token expiry or revocation does not undo earlier changes or erase copies already obtained. Deleting information from Nyblit Cloud does not itself delete independent copies you have saved or supplied elsewhere. Google-derived information remains subject to the restrictions in section 4.

4. Gmail and native Apple Intelligence

Optional Gmail connection

When you connect Gmail in a supported version of Nyblit, you authorise us to link and display conversations and prepare or send replies using the permissions you grant. We do not receive your Gmail password and send messages only when you instruct us. A Gmail connection made in a Native App must be authorised separately on the web.

For each linked thread, Nyblit saves identifiers, the subject, participants, the latest message preview, message dates and counts, unread/reply/draft status and the link date. The preview contains a short extract of email content. These records follow your task storage: your device in Local Only mode, your private iCloud database in iCloud mode, or Nyblit Cloud. Web task storage uses Nyblit Cloud.

In the Native Apps, message bodies, attachments and full message headers are fetched from Google when you open a conversation and used temporarily in memory. They are not saved as part of the linked-thread record. Task backups include the saved thread information, including previews, rather than the full messages fetched from Gmail. Drafts saved to Gmail are held by Google.

On the web, message bodies pass through Nyblit's servers to provide the Gmail feature. We process them temporarily and do not retain full message bodies. The saved thread information, including previews, follows the storage arrangements above.

The Native Apps keep Gmail connection credentials in the device keychain, outside Nyblit's task sync. Web connection credentials use the browser storage described in section 6.

You can disconnect in Nyblit or revoke permission through your Google Account connections. Revocation prevents further authorised retrieval; it does not delete messages or drafts already in Gmail. Remove retained task references separately where necessary.

Nyblit's handling of data received through Google APIs complies with the Google API Services User Data Policy, including its Limited Use requirements. Google data is used only for the permitted, visible features you authorise. We do not sell it, use it for advertising or credit decisions, or use it to train or improve general-purpose AI or machine-learning models.

Any transfer must fall within Google's permitted purposes: providing or improving an authorised user-facing feature with your consent, security, compliance with law, or a business transfer with your explicit prior consent. Human access must also meet the restrictions in section 3 and Google's Limited Use requirements. These restrictions apply to derived data, anyone acting for us and any permitted Nyblit Cloud storage.

Apple Intelligence in the Native Apps

The iOS and Mac apps offer features using Apple Intelligence. When you ask Nyby to help draft an email, it uses the thread's message bodies temporarily with Apple's Foundation Models, on your device or through Apple's Private Cloud Compute, depending on your AI setting. Nyblit does not retain those bodies as a separate AI conversation history. Other AI features use the content you ask them to work with. Any result you save into a task becomes part of that task and follows your chosen Local Only, iCloud or Nyblit Cloud storage arrangement.

The Web App has no AI features at launch. We do not use Nyblit Cloud task content to train general-purpose AI models. We will explain any new AI processing and obtain any required consent before it begins.

5. Analytics, diagnostics and advertising measurement

Native-app analytics

The Native Apps use Google Firebase Analytics to understand which features are used and improve Nyblit. Analytics includes usage events, device information and pseudonymous device or installation identifiers. We do not send your name, email address or the content of your tasks, notes, projects or emails to Firebase Analytics. IDFA collection and advertising personalisation are disabled.

Native-app analytics is enabled by default. You can turn it off at any time in Nyblit's General Settings using Share Anonymous Analytics. Turning it off stops further analytics collection. Although we use summary statistics, the underlying technical identifiers mean the collected records are not necessarily anonymous.

Website and Web App analytics

The Website uses Google Analytics 4 after you choose Allow analytics. It measures visits and interactions using device/browser details and approximate location. Analytics is optional; the Cookie settings control in the footer lets you change your choice. Advertising personalisation is disabled.

The Web App uses Google Analytics and our hosting provider's visitor analytics to understand how people use Nyblit. Statistical usage and performance analytics are enabled by default to help us improve Nyblit. You can turn them off at any time in the Web App's General Settings. This stops further statistical analytics collection; essential server and security logging continues. The hosting provider also supplies performance measurements and server/error logs to help us maintain the service and investigate faults. These tools process usage and technical information such as pages requested, browser/device details, loading times and errors.

These analytics and diagnostic records exclude task titles and content, Gmail message content and sign-in credentials.

Advertising tracking and associated sharing with Google Ads are off by default in the Web App and available only to users who have declared that they are 18 or over. They remain disabled for users aged 16–17 and users whose age band is unknown. If you are eligible and opt in, we share analytics information with Google Ads to measure the effectiveness of Nyblit's advertising. This choice is separate from accepting our Terms of Service. You can create and use an account without opting in, and withdraw your consent at any time to stop future advertising tracking and sharing.

With that consent, we may also send Google a hashed version of an email address you provide directly to us, together with conversion information such as account signup. Google uses this “enhanced conversions” feature to match the hash against Google accounts and measure which ads led to those actions. Hashing changes the form of the address; it does not make this information anonymous. We do not use task content or information obtained through Gmail for advertising measurement.

You can change your Web statistical-analytics and advertising choices at any time using Privacy choices, available on the sign-in page and in the Web App's General Settings. Advertising measurement remains unavailable to users under 18 or whose age band is unknown.

Advertising attribution and diagnostics

On supported iOS devices, we use Apple's SKAdNetwork, with Firebase support, to measure the results of advertising for Nyblit. Google Ads can receive SKAdNetwork attribution reports, which do not include your name, email address or user- or device-specific identifiers.

In the Native Apps, Google Ads purchase-conversion measurement is limited to devices configured for regions outside the EEA, UK and Switzerland when analytics is enabled. Advertising personalisation remains disabled.

Apple may share app usage statistics and diagnostic reports with us according to the analytics-sharing choices you make in your iOS or macOS privacy settings.

6. Cookies and browser storage

The Web App loads tasks from Nyblit Cloud and holds its working copy while the page is open. It does not keep a full offline task database. Your browser also stores:

Signing out clears the working task copy but leaves some browser information listed above. On a shared device, also close the Web App tabs and clear Nyblit's site data. Closing or reloading the page can discard changes that have not synchronised.

We explain optional storage and obtain consent where required. You can turn off statistical analytics or refuse advertising measurement and still use Nyblit. Use Privacy choices on the Web sign-in page or in General Settings to revisit these choices after dismissing the notice. Dismissing the notice does not give consent to advertising measurement or any other processing that requires consent. Changing a choice stops the relevant future collection and sharing; contact us about deleting earlier records.

Clearing site data does not delete your Cloud account or synchronised tasks, revoke permissions granted to connected services, or cancel an Apple subscription.

7. Purchases, support and email updates

All plans include Nyblit Cloud and Web access. Paid plans are purchased through Nyblit's Apple app. Apple processes payments; the Web App has no checkout and does not collect card details. Nyblit manages purchase records directly and stores them in Nyblit Cloud when you use it, to recognise your plan and access rights. The Nyblit Web Terms of Service explain plan limits, purchases, subscriptions and continuing Lifetime and Founder entitlements. Section 11 below explains retention of purchase records and the separate rules for inactivity and version retirement.

We use support messages and attachments to respond and investigate. Please send only what is needed for the issue. Contacting support does not subscribe you to marketing.

At signup, you can opt in to Nyblit news and updates or choose essential communications only. You can unsubscribe through an email link or by contacting us, without affecting your access. Essential account, security, service and billing messages may continue. We do not track opens or link clicks in marketing emails.

Where UK GDPR or EU GDPR applies and we act as controller, we use these bases for the specified purposes:

Where we rely on legitimate interests, we consider the impact on your rights and use information proportionately.

Task content handled solely on your instructions is covered by the processor arrangements in section 1. If data protection law applies to your use of that content, you must establish the appropriate legal basis and any additional conditions for sensitive information. A business customer's agreement with us does not itself provide a legal basis for processing everyone mentioned in its tasks. These responsibilities do not remove our own legal duties.

Providing essential sign-in or purchase information is necessary to supply the relevant service. Without it, we may be unable to provide that feature or process the purchase. Optional analytics and marketing are not required. We do not require you by law to enter personal information into tasks.

9. Who receives information

We do not sell or rent your personal information, or share it with other companies for their own marketing. We use service providers to operate Nyblit, as described below:

Providers acting on our instructions process information under applicable data processing arrangements. Some providers separately control their own account administration, security or legal-compliance processing. Their corporate privacy notices do not replace this notice for Nyblit customer content processed on our behalf.

We may also disclose relevant information to recipients you deliberately choose through supported sharing, email or API features; professional advisers or authorities where necessary for advice, legal obligations or claims; and a successor business in a genuine sale or restructuring, subject to safeguards and notice. Google data remains subject to the stricter transfer restrictions in section 4, including explicit prior consent for a business transfer.

10. International processing

Nyblit Cloud uses the United Kingdom as the primary location for storing and processing account and task data. Supporting services, including platform logs, administration, web hosting and technical support, may involve processing personal information outside the UK.

For restricted transfers for which we are responsible, we use an applicable adequacy decision or approved contractual safeguards, together with the required assessment and supplementary measures where needed. UK safeguards may include the International Data Transfer Agreement or the UK Addendum; EU transfers may use the European Commission's Standard Contractual Clauses. You can ask us for details or a copy of the relevant safeguards, with confidential information appropriately redacted.

11. Retention and deletion

We keep information only for the stated purpose and any applicable legal retention requirement. Different categories have different deletion arrangements:

Nyblit 2 end of support. Cloud synchronisation and existing web features for Nyblit 2 are supported for three years after Nyblit 3's public release. Before that period ends, users relying solely on the new “Purchase Nyblit 2” option must upgrade to Nyblit 3 to continue using the supported Cloud/web service, or export their information and move to another app.

We will announce the exact support end date when Nyblit 3 is publicly released. We will email affected users at the address linked to their Nyblit account at least 90 days before deletion, with reminders 30 and 7 days before deletion, and display a prominent in-app warning. These notices will explain the deadline, the upgrade and export options, and the consequences of taking no action.

At the deadline, remaining Nyblit 2 task content held in Nyblit Cloud that has not been transferred to Nyblit 3 will be deleted from the live service. This deletion leaves your Nyblit Cloud login account open. You can delete the account separately using the account-deletion option in the Nyblit app; the separate inactivity policy below also continues to apply. Recent activity does not extend the Nyblit 2 support deadline.

We do not delete your Nyblit Cloud account or task content solely for inactivity while you have an active paid subscription, an existing Lifetime purchase or a Founder entitlement.

The following inactivity policy applies to free-plan accounts and holders of the new “Purchase Nyblit 2” option, unless they also have an active paid subscription, an existing Lifetime purchase or a Founder entitlement. After 12 consecutive months of inactivity, we will email the address linked to your Nyblit account with a warning that the account and its Cloud task content may be deleted. You will have at least one further calendar month from that warning to return or export your information before deletion. Signing in to your Nyblit Cloud account or using Nyblit Cloud through any Native App or the Web App counts as activity, cancels any pending inactivity deletion and starts a new inactivity period. The warning will explain how to keep your account active and export a manual .nyb backup.

If you purchased Nyblit 2, inactivity closure of your Cloud account does not cancel your perpetual Nyblit 2 licence. You remain entitled to restore that purchase without buying Nyblit 2 again. Restoring the purchase does not recover task content deleted under this policy.

If a legal obligation or active dispute requires longer retention, we restrict further use to that purpose and delete the information when the reason ends.

Disconnecting an integration, stopping renewal, signing out and deleting content are separate actions. Ask us if you need help identifying the right deletion route. You can delete your Nyblit Cloud account using the account-deletion option in the Nyblit app, or contact us for help with a deletion request. Before deleting the account, you can export a manual .nyb backup of information you wish to keep, with optional password encryption. Deletion may affect all connected Nyblit devices; it does not cancel an Apple subscription. For information held only on your device or in your private iCloud database, you may need to use device or Apple controls. We will explain which route applies.

12. Security

Nyblit Cloud data is encrypted in transit and at rest. It is not end-to-end encrypted. We use measures appropriate to the information and risks involved, including limiting authorised access.

No online service can guarantee absolute security. Keep devices and browsers updated, protect your Nyblit and connected-provider accounts, and sign out on shared computers. Contact us promptly if you suspect a security problem involving Nyblit.

13. Your rights and choices

Depending on the applicable law and circumstances, you can ask to access your personal information, correct it, erase it, restrict its use, or receive certain information in a portable format. Rights can be subject to lawful exceptions.

Your right to object: you may object to processing based on legitimate interests on grounds relating to your situation. You can object to direct marketing at any time; we will stop using your information for that purpose.

Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of earlier processing. Use the relevant analytics control, unsubscribe link or connected-account controls, or contact us. Withdrawing a permission needed for an optional feature may prevent that feature from working.

Send requests to david@appgoblin.co.uk. We may need proportionate information to verify your identity. We normally respond within one month, subject to any lawful extension or adjustment, and will explain if one applies. Requests are normally free; we will explain any lawful exception.

Decisions to suspend or close an account for suspected misuse receive human review. You can contact us to challenge a decision. The separate inactivity and end-of-support rules are explained in section 11.

14. Children

The minimum age for the Native Apps, including the iOS app, is 12. Creating or using a Nyblit Cloud account requires a minimum age of 16, including when the account is created through a Native App. The Web App also requires users to be 16 or older. Users aged 12–15 may use Local Only or iCloud mode in the Native Apps.

Users under 18 require permission from a parent or legal guardian. If you select 16–17 when creating a Nyblit Cloud account through iOS, Mac or the web, we ask you to confirm that your parent or guardian has reviewed the applicable terms and authorised your use, and record that declaration with your account. Any higher local minimum age or additional legally required parental authorisation also applies.

We use your declared age band to apply these age limits. Web advertising measurement is restricted to adults who separately opt in, as described in section 5.

If you believe a child has provided information to us in circumstances that require action, contact us. We will investigate and take appropriate steps, which may include deletion or other measures required to protect the child.

15. Complaints

You can raise a data protection complaint by emailing david@appgoblin.co.uk or writing to our registered office. Please explain the concern and how we can contact you. We will acknowledge your complaint within 30 days, investigate without undue delay, keep you appropriately informed and communicate the outcome.

You also have the right to complain to the UK Information Commissioner's Office (ICO) through its complaints service. Where EU GDPR applies, you may complain to the supervisory authority in the country where you live, work or consider an infringement occurred. Other local privacy rights may also apply.

16. Changes to this policy

We will update this policy when our services or handling of information changes. The date at the top identifies the current version. For a material change, we will provide a prominent notice and any further notification required by law before the changed processing begins. We will seek fresh consent where required. Continued use alone is not treated as consent to a new optional processing purpose.