Privacy Policy
Last updated: 31 July 2026
Controller
The controller responsible for this website and app is:
Finn Freeman
Einzelunternehmer
Regerstrasse 27, 81541 Munich, Germany
Email: info@finnfreeman.com
Phone: +49 17631135339
Study Plans and Uploaded Materials
When you request a study plan, we process the exam details, subjects, topic names, confidence ratings, estimated workload, weekly availability, session preferences, and relevant Nylo Calendar events needed to build a conflict-free schedule. Requested study inputs are sent to Google's Gemini model to produce a study blueprint. Exact session dates and times are chosen and validated by Nylo's scheduling service, not by the AI model.
If you upload a timetable or flashcard source as a PDF, image, or UTF-8 text file, it is stored temporarily in a private Cloudflare R2 bucket and sent to the Gemini Files API for the extraction you requested. Nylo does not execute, render, or make the raw file publicly available. Nylo attempts to delete both temporary copies as soon as processing finishes, fails permanently, or is cancelled. Gemini Files API uploads are automatically removed by Google after 48 hours if explicit deletion does not complete.
Extracted class blocks and generated flashcards are drafts. They are not imported into Nylo Calendar or saved as flashcard sets until you review and explicitly confirm them.
Accepted study plans, topics, preferences, proposals, and sessions are stored in Supabase under your account. Proposed schedules expire and do not change accepted sessions unless you approve them as a whole. This processing is necessary to provide the requested planning service under Art. 6(1)(b) DSGVO / GDPR.
Scope
This Privacy Policy covers the Nylo AI website, waitlist, product communications, and the Nylo AI product wherever this policy is linked.
Website and Waitlist Data
When you join the waitlist, we collect the email address you submit. The legal basis is your consent under Art. 6(1)(a) DSGVO / GDPR. We use the email address to manage the waitlist and send product updates about Nylo AI.
You can withdraw consent at any time by emailing info@finnfreeman.com. Withdrawing consent does not affect processing that happened before withdrawal.
Accounts and Google Sign-In
When you create or use a Nylo account, we process account identifiers such as your email address, user ID, authentication method, and basic Google profile information if you choose Google Sign-In. Supabase provides authentication and securely maintains the Nylo session. You may create an account with email and password instead, so Google Sign-In is optional.
Google Sign-In is used only to authenticate you and create or access your Nylo account. It does not connect Nylo to Google Calendar, request Google Calendar permissions, or allow Nylo to read or change data in Google Calendar.
Nylo Calendar Events
When you use the Nylo Calendar, we process an event identifier, the owning account ID, title, optional description and location, start and end dates and times, time zone, all-day setting, and creation or update timestamps. If an AI-proposed action that you approve includes attendee information, the saved event may also contain attendee email addresses supplied through that action. The current manual event form does not collect attendee information.
Calendar events are stored in Supabase and linked to your Nylo user ID so they remain separated by account. Cloudflare Workers receive authenticated Calendar requests, validate the event data, and process create, read, update, and delete operations against the appropriate account records in Supabase. Nylo does not connect to or synchronize with Google Calendar.
Changes you make directly in the Calendar are applied when you submit a create or edit form or choose to delete an event. The assistant may prepare a proposed create, update, delete, import, or replacement action, but an AI-proposed action does not alter your saved events until you explicitly approve it. Rejecting or cancelling a proposal leaves the saved Calendar unchanged.
We use Calendar event data to display and manage your schedule, answer scheduling questions, and provide assistant features you request. Relevant event details or conversation context may be sent to an AI service only when needed for the requested assistant feature. The legal basis for processing account and Calendar data needed to provide Nylo is Art. 6(1)(b) DSGVO / GDPR.
Assistant Conversations
When you use Nylo's assistant, we store the messages you send, the assistant's replies, conversation titles, and unresolved calendar approval requests in a private, account-specific Cloudflare Agent database. This lets you restore conversations across signed-in devices and resume approval requests after a reload.
Relevant recent messages and a compact summary of older context may be sent to Google's Gemini model to generate the assistant response you request. The full saved conversation is not sent with every request. The legal basis for processing chat data needed to provide Nylo is Art. 6(1)(b) DSGVO / GDPR.
Conversations are retained for up to 30 days after their latest activity. You can delete one conversation or clear all conversation history earlier from the chat interface.
Stripe Billing and Trial Protection
Stripe hosts the card setup, subscription Checkout, payment-method management, and invoice pages. Stripe processes card details, billing address, tax information, payment attempts, invoices, and receipts. Nylo does not receive or store full card numbers or card security codes. Nylo stores the Stripe customer, subscription, Checkout, and schedule identifiers needed to manage your account, together with your plan, subscription status, renewal or trial dates, cancellation state, and subscription history.
To enforce the one-trial-per-account-and-card rule, Nylo receives a card fingerprint from Stripe and immediately converts it into an HMAC-SHA256 digest using a private server-side key. Nylo never stores the raw Stripe fingerprint. The digest is used only for trial fraud prevention, reservation of an in-progress checkout, and enforcement of prior trial use. Fingerprint digests expire after 24 months. Tokenized wallet cards may produce a different fingerprint, so wallet matching is best-effort.
This processing is necessary to perform the subscription contract and provide paid access under Art. 6(1)(b) DSGVO / GDPR. Trial-abuse prevention and service security are based on our legitimate interests under Art. 6(1)(f), subject to your applicable rights. Stripe may calculate tax and process related location and transaction information where required.
Processors and Service Providers
We use the following service providers for the website and Nylo product:
- Supabase - provides authentication and database infrastructure, including storage for waitlist records, account-linked Nylo Calendar events, persistent study-plan data, private subscription state, checkout reservations, and payment-fingerprint digests.
- Vercel - hosts the website and provides Vercel Analytics for aggregated website statistics.
- Cloudflare- runs Nylo's backend service, stores account-specific assistant conversations for up to 30 days, and processes authenticated Calendar, assistant, billing, entitlement, Stripe webhook, and trial-eligibility requests. Private R2 storage temporarily holds uploaded PDFs, images, and text files while an asynchronous document job is processed.
- Google - provides optional Google Sign-In and the Gemini model used for requested chat and assistant features, including study-blueprint, timetable-extraction, and flashcard-draft requests. Depending on your request, relevant recent conversation context, study inputs, Calendar event details, or an uploaded document may be sent to Gemini. Google Sign-In itself does not request Google Calendar access.
- Stripe - provides hosted card setup and Checkout, recurring subscription billing, payment-method management, invoices, receipts, fraud signals, and tax calculation.
Data may be processed in the European Union / European Economic Area and, where providers process data outside the EU/EEA, under applicable transfer safeguards such as data processing agreements, standard contractual clauses, or equivalent safeguards provided by the service provider.
Analytics
This website uses Vercel Analytics to understand aggregated page views and basic usage patterns. Vercel Analytics is designed to work without third-party cookies and without giving Nylo AI information that identifies individual visitors. We do not use advertising trackers or cross-site tracking pixels on this website.
Retention and Deletion
Waitlist email addresses are kept until you request deletion, withdraw consent, or the waitlist is no longer needed. Account data is kept while your account remains active and as required for security or legal obligations. Calendar events are kept while they remain saved in your Nylo account. Study plans and accepted study sessions are kept until you archive or delete the plan; archiving does not delete them. Raw document uploads are deleted from Cloudflare R2 after success, permanent failure, or cancellation; abandoned uploads are swept within 24 hours. Gemini file copies are explicitly deleted on the same job transitions and are automatically removed by Google after 48 hours if explicit cleanup fails. Assistant conversations are removed 30 days after their latest activity unless you delete an individual conversation or clear all history sooner. Deleting an event removes it from the active Calendar database when the deletion request completes, and the remaining Calendar events are removed when your account is deleted. Residual copies may remain temporarily in routine service-provider backups until those backups are overwritten. Subscription, support, security, and accounting records are kept only as long as needed for the purpose collected, legal obligations, claims, fraud prevention, and accounting requirements. Trial-fingerprint digests are deleted after 24 months; short-lived Checkout reservations expire automatically.
Your Rights
Under the DSGVO / GDPR, you may have the following rights:
- Access to personal data concerning you (Art. 15 DSGVO)
- Rectification of inaccurate personal data (Art. 16 DSGVO)
- Erasure of personal data (Art. 17 DSGVO)
- Restriction of processing (Art. 18 DSGVO)
- Data portability (Art. 20 DSGVO)
- Objection to processing based on legitimate interests (Art. 21 DSGVO)
- Withdrawal of consent at any time for consent-based processing
To exercise these rights, email info@finnfreeman.com.
Contact
For questions about this Privacy Policy or data processing, contact info@finnfreeman.com.