This legal document is available in English only.

Privacy Policy

Last updated: 29 September 2026

Controller

The controller responsible for this website and app is:

Finn Freeman

Einzelunternehmer

Regerstrasse 27, 81541 Munich, Germany

Email: info@finnfreeman.com

Phone: +49 17631135339

Study Plans and Uploaded Materials

When you request a study plan, we process the exam details, subjects, topic names, confidence ratings, estimated workload, weekly availability, session preferences, and relevant Nylo Calendar events needed to build a conflict-free schedule. Requested study inputs are sent to Google's Gemini model to produce a study blueprint. Exact session dates and times are chosen and validated by Nylo's scheduling service, not by the AI model.

If you upload a timetable or flashcard source as a PDF, image, or UTF-8 text file, it is stored temporarily in a private Cloudflare R2 bucket and sent to the Gemini Files API for the extraction you requested. Nylo does not execute, render, or make the raw file publicly available. Nylo attempts to delete both temporary copies as soon as processing finishes, fails permanently, or is cancelled. Gemini Files API uploads are automatically removed by Google after 48 hours if explicit deletion does not complete.

Extracted class blocks and generated flashcards are drafts. They are not imported into Nylo Calendar or saved as flashcard sets until you review and explicitly confirm them.

Accepted study plans, topics, preferences, proposals, and sessions are stored in Supabase under your account. Proposed schedules expire and do not change accepted sessions unless you approve them as a whole. This processing is necessary to provide the requested planning service under Art. 6(1)(b) DSGVO / GDPR.

Scope

This Privacy Policy covers the Nylo AI website, waitlist, product communications, and the Nylo AI product wherever this policy is linked.

Website and Waitlist Data

When you join the waitlist, we collect the email address you submit. The legal basis is your consent under Art. 6(1)(a) DSGVO / GDPR. We use the email address to manage the waitlist and send product updates about Nylo AI.

You can withdraw consent at any time by emailing info@finnfreeman.com. Withdrawing consent does not affect processing that happened before withdrawal.

Accounts and Google Sign-In

When you create or use a Nylo account, we process account identifiers such as your email address, user ID, authentication method, and basic Google profile information if you choose Google Sign-In. Supabase provides authentication and securely maintains the Nylo session. You may create an account with email and password instead, so Google Sign-In is optional.

Google Sign-In is used only to authenticate you and create or access your Nylo account. It does not connect Nylo to Google Calendar, request Google Calendar permissions, or allow Nylo to read or change data in Google Calendar.

During planning setup, we store the education stage, subjects, goals, planning challenges, preferred focus length, daily study capacity, time zone, onboarding progress, and the fixed weekly commitments you choose. These details are used to configure Nylo and provide study-plan defaults. No AI request is made while you complete onboarding.

Children and Young People

Nylo is a study planning tool used by students, but it is not directed at children under 16. You must be at least 16 years old to create a Nylo account. If you are under 18, you may only create an account and subscribe with the consent of a parent or legal guardian.

We do not knowingly collect personal data from children under 16. Where processing rests on consent under Art. 6(1)(a) DSGVO / GDPR and the user is below the age limit in Art. 8 DSGVO / GDPR, that consent must be given or authorised by the holder of parental responsibility.

If you believe a child under 16 has created an account or provided personal data without the required consent, contact info@finnfreeman.com. We will close the account and delete the associated personal data without undue delay.

Nylo Calendar Events

When you use the Nylo Calendar, we process an event identifier, the owning account ID, title, optional description and location, start and end dates and times, time zone, all-day setting, and creation or update timestamps. If an AI-proposed action that you approve includes attendee information, the saved event may also contain attendee email addresses supplied through that action. The current manual event form does not collect attendee information.

Calendar events are stored in Supabase and linked to your Nylo user ID so they remain separated by account. Cloudflare Workers receive authenticated Calendar requests, validate the event data, and process create, read, update, and delete operations against the appropriate account records in Supabase. Nylo does not connect to or synchronize with Google Calendar.

A fixed weekly commitment is stored as an account-owned recurring series with its selected weekdays, local times, time zone, and term range. Nylo creates the individual Calendar occurrences for that term. Series changes preserve occurrences that have already started and replace the remaining occurrences; individual exceptions are not supported in the current version.

Changes you make directly in the Calendar are applied when you submit a create or edit form or choose to delete an event. The assistant may prepare a proposed create, update, delete, import, or replacement action, but an AI-proposed action does not alter your saved events until you explicitly approve it. Rejecting or cancelling a proposal leaves the saved Calendar unchanged.

We use Calendar event data to display and manage your schedule, answer scheduling questions, and provide assistant features you request. Relevant event details or conversation context may be sent to an AI service only when needed for the requested assistant feature. The legal basis for processing account and Calendar data needed to provide Nylo is Art. 6(1)(b) DSGVO / GDPR.

Assistant Conversations

When you use Nylo's assistant, we store the messages you send, the assistant's replies, conversation titles, and unresolved calendar approval requests in a private, account-specific Cloudflare Agent database. This lets you restore conversations across signed-in devices and resume approval requests after a reload.

Relevant recent messages and a compact summary of older context may be sent to Google's Gemini model to generate the assistant response you request. The full saved conversation is not sent with every request. The legal basis for processing chat data needed to provide Nylo is Art. 6(1)(b) DSGVO / GDPR.

For signed-in assistant chats, Nylo may also send your education stage, subjects, selected goals and challenges, preferred focus length, and daily study capacity to Gemini so a response can reflect your saved planning preferences. Nylo does not include your display name, email address, or fixed weekly schedule in this profile context. These fields are treated as user-provided data, not as instructions to the model.

Conversations are retained for up to 30 days after their latest activity. You can delete one conversation or clear all conversation history earlier from the chat interface.

Stripe Billing and Trial Protection

Stripe hosts the card setup, subscription Checkout, payment-method management, and invoice pages. Stripe processes card details, billing address, tax information, payment attempts, invoices, and receipts. Nylo does not receive or store full card numbers or card security codes. Nylo stores the Stripe customer, subscription, Checkout, and schedule identifiers needed to manage your account, together with your plan, subscription status, renewal or trial dates, cancellation state, and subscription history.

To enforce the one-trial-per-account-and-card rule, Nylo receives the card fingerprint of every subscription from Stripe and immediately converts it into an HMAC-SHA256 digest using a private server-side key. Nylo never stores the raw Stripe fingerprint. The digest is used only for trial fraud prevention, reservation of an in-progress checkout, and enforcement of prior trial or subscription use. Fingerprint digests expire after 24 months. Tokenized wallet cards may produce a different fingerprint, so wallet matching is best-effort.

If you start the free 3-day Lite access, Nylo stores its start and end time with your account. To offer it only once per person, Nylo also stores a keyed one-way digest (HMAC-SHA256 with a private server-side key) of your normalized email address, meaning lowercased, without any +tag and, for Gmail addresses, without dots. This email digest is kept for 24 months, even after your account is deleted, so the same mailbox cannot claim the offer again. A keyed one-way digest of your network address is stored with the claim for 48 hours to limit how many free claims come from one network. The browser check uses the cookie described under Cookies: the proxy sends our backend a one-way digest of an internal account ID, which can appear in the backend's technical request logs for up to 7 days. These digests are used only to prevent fraud on the free offer, never for advertising or profiling. The legal basis is our legitimate interest in preventing abuse of a free offer under Art. 6(1)(f) DSGVO / GDPR, subject to your applicable rights.

This processing is necessary to perform the subscription contract and provide paid access under Art. 6(1)(b) DSGVO / GDPR. Trial-abuse prevention and service security are based on our legitimate interests under Art. 6(1)(f), subject to your applicable rights. Stripe may calculate tax and process related location and transaction information where required.

Partner Referrals

Nylo runs a referral programme in which partners share a link containing a referral code. If you arrive through such a link, the code is stored in a first-party cookie for 30 days and, if you then create an account, that account is recorded as having been referred by that partner. The cookie holds only the code and the time it was set, it cannot be read by scripts on the page, and it is deleted once your account is created or the code is found not to apply. Existing accounts are never attributed to a partner.

Partners can see, for the accounts they referred, a partly hidden email address (first character and domain only, for example f•••@example.com), the date the account was created, and whether the subscription is active, in a trial, cancelled, or not started. Partners are never shown your name, your full email address, your plan, what you pay, any payment or card information, or any failed payment. This is the minimum needed for a partner to check the commission they are owed.

Some partners run a team and give each team member a referral link of their own. If you arrive through such a link, your account is recorded as referred by that partner, together with the team link it came through. Partners who run a team see less than described above: only how many accounts each of their links brought in and how many of those are currently subscribed, never anything about an individual account. Team members see nothing through Nylo.

Operating the referral programme and paying partners correctly is based on our legitimate interests under Art. 6(1)(f) DSGVO / GDPR, subject to your applicable rights. You can object to your account being attributed to a partner by contacting us, and the attribution will be removed.

Processors and Service Providers

We use the following service providers for the website and Nylo product:

  • Supabase - provides authentication and database infrastructure, including storage for waitlist records, account-linked Nylo Calendar events, persistent study-plan data, private subscription state, checkout reservations, payment-fingerprint digests, and free-offer digests.
  • Cloudflare - hosts and delivers this website and runs Nylo's backend service. Cloudflare's network receives every request to the website, including your IP address, browser type and the page requested, in order to deliver it and to protect the site against attacks, bots and abuse. Cloudflare also stores account-specific assistant conversations for up to 30 days, processes authenticated Calendar, assistant, billing, entitlement, Stripe webhook, and trial-eligibility requests, and temporarily holds uploaded PDFs, images, and text files in private R2 storage while an asynchronous document job is processed. Cloudflare, Inc. is based in the United States.
  • Google - provides optional Google Sign-In and the Gemini model used for requested chat and assistant features, including study-blueprint, timetable-extraction, and flashcard-draft requests. Depending on your request, relevant recent conversation context, study inputs, Calendar event details, or an uploaded document may be sent to Gemini. Google Sign-In itself does not request Google Calendar access.
  • Stripe - provides hosted card setup and Checkout, recurring subscription billing, payment-method management, invoices, receipts, fraud signals, and tax calculation.
  • IONOS - IONOS SE, Montabaur, Germany, sends the confirmation email for a cancellation or withdrawal declaration submitted through the cancellation page and receives any reply to it.

Data may be processed in the European Union / European Economic Area and, where providers process data outside the EU/EEA, under applicable transfer safeguards such as data processing agreements, standard contractual clauses, or equivalent safeguards provided by the service provider. Transfers to Cloudflare in the United States rely on its certification under the EU-U.S. Data Privacy Framework, with the European Commission's Standard Contractual Clauses in Cloudflare's Data Processing Addendum as a fallback.

Hosting, Security and Server Logs

When you open any page, your browser necessarily sends your IP address, the requested address, the time, and technical details such as your browser type to our hosting provider, Cloudflare. Cloudflare uses this information to deliver the page and to protect the website against attacks, bots and abuse.

We use your IP address for a few minutes, in memory only, to limit how often forms, referral claims, study-material generation requests and page-visit measurements can be submitted; it is not written to our database. For study-material generation, our backend receives only a keyed one-way hash of the address, which can appear in its technical request logs for up to 7 days. When you start the free Lite days, a keyed one-way digest of the address is stored for 48 hours, as described under Stripe Billing and Trial Protection. The only other exception concerns the site operator's own admin area: for a failed admin sign-in attempt we store a hashed form of the IP address in the admin audit log, so repeated guessing can be blocked.

Cloudflare's security systems may record the IP address of a request that triggers a security rule for up to 24 hours, and its network processes connection logs for a limited period in data centres in the European Union and the United States. The legal basis is our legitimate interest in the secure and reliable operation of the website under Art. 6(1)(f) DSGVO / GDPR.

Analytics

This website does not use third-party analytics services, advertising trackers or cross-site tracking pixels.

We also measure page visits ourselves, so we can see which pages people find useful and where the signup process is confusing. For each visit we record the page address, how long it was open, the site you arrived from, your country, and whether you are on a phone, tablet or computer. If you followed a link we tagged ourselves — for example from a newsletter — we also record the campaign labels in that link, so we can tell which of our own links people used. These are labels we wrote, not anything about you, and no other part of the web address is read or kept. Visits are grouped using a random identifier held in your browser for the current tab only; it is not a cookie, it is not shared with anyone, and it is discarded when you close the tab. Your IP address is not stored in these visit records; your country is derived from it by our hosting provider when the request arrives. If you are signed in, these visits are linked to your account so that support can see what you saw.

Cookies

The current website does not set analytics cookies. A first-party referral cookie is set for 30 days only if you arrive through a partner referral link, as described under Partner Referrals. When you are signed in, Nylo sets a first-party cookie named nylo-first-account that holds a one-way digest of an internal ID of the first Nylo account used in this browser. It cannot be read by page scripts, is sent only to Nylo's own API proxy on this website, lasts up to 2 years, and is used only to limit the free Lite days to one account per browser, never for tracking. Stripe-hosted Checkout and Billing Portal pages may use cookies or similar storage that are necessary to secure and complete billing on Stripe's domain. More detail is available in the Cookie Policy.

Retention and Deletion

Waitlist email addresses are kept until you request deletion, withdraw consent, or the waitlist is no longer needed. Account data is kept while your account remains active and as required for security or legal obligations. Planning profiles and weekly commitment series are kept while your account remains active and are removed with the account. Calendar events are kept while they remain saved in your Nylo account. Study plans and accepted study sessions are kept until you archive or delete the plan; archiving does not delete them. Raw document uploads are deleted from Cloudflare R2 after success, permanent failure, or cancellation; abandoned uploads are swept within 24 hours. Gemini file copies are explicitly deleted on the same job transitions and are automatically removed by Google after 48 hours if explicit cleanup fails. Assistant conversations are removed 30 days after their latest activity unless you delete an individual conversation or clear all history sooner. Deleting an event removes it from the active Calendar database when the deletion request completes, and the remaining Calendar events are removed when your account is deleted. Residual copies may remain temporarily in routine service-provider backups until those backups are overwritten. Subscription, support, security, and accounting records are kept only as long as needed for the purpose collected, legal obligations, claims, fraud prevention, and accounting requirements. Hashed IP addresses of failed admin sign-in attempts are currently kept in the admin audit log without a fixed deletion date, as a record of attempts to access the admin area. Card-fingerprint digests are deleted after 24 months; short-lived Checkout reservations expire automatically. Free-offer email digests are deleted after 24 months, including when the account was deleted earlier, network digests after 48 hours, and the nylo-first-account cookie expires after at most 2 years.

Your Rights

Under the DSGVO / GDPR, you may have the following rights:

  • Access to personal data concerning you (Art. 15 DSGVO)
  • Rectification of inaccurate personal data (Art. 16 DSGVO)
  • Erasure of personal data (Art. 17 DSGVO)
  • Restriction of processing (Art. 18 DSGVO)
  • Data portability (Art. 20 DSGVO)
  • Objection to processing based on legitimate interests (Art. 21 DSGVO)
  • Withdrawal of consent at any time for consent-based processing

To exercise these rights, email info@finnfreeman.com.

Supervisory Authority

You have the right to lodge a complaint with a data protection supervisory authority. For a private-sector operator in Bavaria, the competent authority is generally the Bayerisches Landesamt fuer Datenschutzaufsicht (BayLDA), Promenade 18, 91522 Ansbach, Germany.

Contact

For questions about this Privacy Policy or data processing, contact info@finnfreeman.com.