Privacy Policy

Last updated: September 27, 2026

Your conversations are yours. You control whether they help improve nen.

Saved material in your space is not used for training. Conversations with nenspace's own models may be used for quality review and model improvement, with an opt-out in Settings. The details are below.

This policy explains what data nenspace collects, how we use it, and how you can control it.


What data we collect

When you use nenspace, we store the following data in your account:

  • Account information — your email address, used for authentication, account recovery, service notices and, if chosen, occasional product updates (unsubscribe in every such email and in Settings).
  • Conversations — messages between you and nenspace, including logbook dialogues.
  • Memory — facts, observations, and patterns that nenspace extracts from your conversations to provide continuity. You can disable this in Settings.
  • Habits — habits you create and their daily completion records.
  • Notes — notes and note entries you write, organized in folders.
  • Tasks — tasks, projects, areas, and checklists you create.
  • Preferences — your app settings (display preferences, memory toggle, notification preferences).
  • Subscription and usage — your subscription status and message usage counts for tier management.
  • Product analytics — page views and limited interaction events such as sign-up, feature use, feedback category, and checkout progress.

How we use your data

We use your data to provide the service and, for eligible conversations, for the model-improvement work described below:

  • Conversations are sent to our AI provider to generate responses during your sessions.
  • Memory and profile data are used to give nenspace context about you so it can be a more useful companion.
  • Habits, notes, and tasks are stored and displayed back to you as part of your personal space.
  • Usage data is tracked to manage free and paid tier limits.

Improving nen

nenspace trains its own models. That is the product: models that answer plainly, in nenspace's own register, served under names like nen. To keep making them better, conversations with nenspace's own models may be scored for quality by automated checks, and a filtered subset may be used as training examples for nenspace's own models.

Plain rules that always hold:

  • Identifying details are removed before any conversation is used as a training example.
  • Notes, logbook entries, habits, tasks, memories, files, and anything else in your space are never used for training. Only conversations with nenspace's own models.
  • Conversations from before August 24, 2026 (the original policy date) are never used.
  • Training happens on nenspace's own infrastructure account with Overmind (see Third-party services); no third party trains on your data.
  • The switch: Settings → Privacy → "help improve nen's models". Turn it off and your conversations are not used for training and not sent for quality scoring. The service works identically either way.
  • Deleting your account deletes your conversations from nenspace, and nenspace requests deletion of the corresponding data held with our infrastructure provider. Models already trained on the filtered, de-identified corpus are not retrained retroactively.

What we don't do

  • We do not sell your data to anyone.
  • We do not train third-party AI models on your data, and no third party is permitted to train on your data. Conversations with nenspace's own models may help improve those models: see "Improving nen" above, including the switch that turns this off.
  • We do not share your data with other users.
  • We do not read your conversations, notes, or logbook entries in the ordinary course of operating the service. Automated quality checks score conversations with nenspace's own models, and a human may review a small sample of those conversations solely for model-quality work, under the same confidentiality as everything else here.
  • We do not sell or share your data for advertising.

Data security

Your data is stored in a secure, hosted PostgreSQL database with Row-Level Security (RLS) enabled on every table. These policies restrict access to the records associated with an authenticated account. We also use application-level access checks; no security measure can guarantee that a service will never have a vulnerability.

All connections are encrypted in transit via TLS. Authentication is handled through Supabase Auth with support for email/password and Google OAuth.

Analytics

We use PostHog for basic, privacy-first product analytics. Autocapture, session recording, and automatic exception capture are disabled. We collect page views, public landing-page paths, referring domains, campaign labels, subscription status, and limited product interaction events, including completed exchanges and return visits. We remove URL query strings from page views and do not collect private page identifiers. Events are linked with an internal account ID; we do not send your email, name, feedback message, or the contents of your conversations, memory, notes, logbook, habits, tasks, or files to PostHog.

We use Ahrefs Web Analytics to understand how people find and browse the public site (page views, referrers, and coarse location). It does not use cookies and does not collect personal information or workspace content.

With your permission, we also use Google Analytics to measure visits to the public website. It uses cookies to distinguish browsers and visits. We send public page paths, referring domains, and approved campaign labels. Google also receives browser and device information and derives approximate location from your IP address. We do not send nenspace account IDs, private app pages, URL query strings, or workspace content. Advertising features and automatic collection of user-provided data are disabled. Your choice is saved in this browser for six months; declining or withdrawing permission stops Google Analytics collection and removes its cookies from this browser.

Google Analytics cookies: off.

How to delete your data

You can delete your entire account and all associated data at any time from Settings → Account → Delete Account within the app. This permanently removes:

  • All conversations and messages
  • All memories and your profile
  • All habits, notes, tasks, and projects
  • All preferences and subscription data
  • Your user account itself

This action is irreversible. Once deleted, your data cannot be recovered.

How to export your data

You can export all of your data at any time from Settings → Account → Export Data. This downloads a JSON file containing everything associated with your account — conversations, memories, habits, notes, tasks, preferences, and more.

Third-party services

nenspace relies on the following third-party services to operate:

  • Supabase — database hosting and authentication.
  • OpenAI / Anthropic — AI model providers for generating conversation responses. Messages are sent for processing but are not used for model training under our API agreements.
  • Together AI — AI model provider hosting nen's own fine-tuned models. Messages are sent for processing but are not used for model training under our API agreements.
  • Overmind — AI infrastructure for nenspace's own models: hosting, quality evaluation, and training. Conversations with nenspace's own models are processed on Overmind's infrastructure to generate responses and score quality, and, where "Improving nen" allows it, to train nenspace's own models. Overmind acts as nenspace's data processor; data is hosted on AWS in the EU (Ireland) and encrypted in transit and at rest, and Overmind does not use your data for anything except nenspace.
  • TypeSafe: a decision model for working memory. When a thought is captured, its text is sent to TypeSafe's Jev model to read where it might belong (task, note, logbook). Opening working memory or the space page can also send existing thoughts that have not yet been read. Recurrence checks include recent earlier thoughts from your working memory, including thoughts already moved elsewhere or set down, to tell whether a thought repeats any of them. Longer captures may also be sent to suggest splitting them into pieces of your original text. The reading is a suggestion on screen; nothing moves or splits without you. Turning off automatic memory suggestions hides those suggestions while reading continues to prepare your review. Text is sent for processing only and is not used for model training under TypeSafe's Data Processing Agreement.
  • Firecrawl — retrieval of research paper abstracts. The search query is sent, which on the first message of a conversation can be that message's own words; the conversation itself is not.
  • Brave Search — web search. The search query is sent, which on the first message of a conversation can be that message's own words; the conversation itself is not.
  • Exa — web search and page reading. The search query is sent, which on the first message of a conversation can be that message's own words, together with the addresses of pages to read; the conversation itself is not.
  • Jina — page reading. Page addresses are sent, both links a person supplies and pages a search found.
  • Apple App Store / StoreKit — payment processing for iOS in-app subscriptions. We do not store your Apple payment details.
  • Stripe — payment processing for web subscriptions. We do not store your payment details; Stripe handles this directly.
  • PostHog — limited product analytics; no personal workspace content is shared.
  • Ahrefs — cookieless web analytics for the public site; no personal workspace content is shared.
  • Google Analytics — public website analytics with your permission; advertising features are disabled.

Working memory in chat: when suggestions are enabled, TypeSafe also reads your latest user message to offer a thought to keep. After a pause in typing, your draft and up to sixty active working-memory thoughts can be sent to suggest relevant context. Keeping a thought and including one in a draft each require your tap. Included text stays visible and editable. A conversation that includes working-memory text, and its later replies, is excluded from our model-training and quality-dataset collection, even if you edit or remove that text later.


Contact

If you have questions about this privacy policy or want to request data deletion without logging in, contact us at hello@nenspace.com.