Privacy Policy
Nitya is designed around your privacy. We do not sell your data, share it with advertisers, or use it to build profiles for third parties. Your information exists to make your assistant experience work — nothing else.
1. Who we are
Nitya (“we,” “our,” or “us”) is a personal AI assistant application. You can contact us at hello@heynitya.com. The service is available at heynitya.com.
2. Information we collect
Information you provide directly
- Account information: email address and password (if using email sign-in), or your Google account name and email (if using Google sign-in).
- Content you create: reminders, tasks, notes, and voice recordings you provide to the assistant. These form the working memory that makes Nitya useful.
- Conversation history: messages you send to Nitya and responses returned. Stored to provide context for follow-up interactions.
- Preferences and settings: notification preferences, work-hour windows, and other configuration you set in the app.
Information collected automatically
- Push notification tokens: device tokens issued by Google Firebase Cloud Messaging (FCM) to deliver reminder notifications to your device.
- Basic usage signals: feature interactions used to improve the product (e.g., which reminder types you use most). Not linked to third-party advertising systems.
- Crash and error logs: technical error reports used to diagnose and fix bugs. Not linked to your content.
Information from Google services (optional)
If you choose to connect your Google Calendar, Nitya requests the calendar.readonly scope. This allows Nitya to:
- Read your calendar events to detect scheduling conflicts when you set a reminder.
- Defer a reminder notification if you are in a meeting when it is due to fire.
Nitya uses Google Calendar data only for the purposes described above. We do not:
- Create, edit, or delete calendar events.
- Share your calendar data with third parties.
- Use calendar data for advertising or marketing.
- Store your calendar event content permanently — event data is fetched in real time, used for the single check, and not retained.
Nitya’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
You can disconnect Google Calendar at any time from the Settings screen in the app. Disconnecting removes all stored OAuth tokens immediately.
3. How we use your information
- To provide the assistant experience: understanding your messages, creating and managing reminders, tasks, and notes, sending timely notifications.
- To send your proactive daily briefing and check-in follow-ups.
- To authenticate your account and keep your session secure.
- To improve the product based on aggregate, anonymised usage patterns.
- To respond to support requests you send us.
We do not use your data for advertising, we do not sell it to data brokers, and we do not share it with third parties for their independent marketing purposes.
4. How we store and protect your data
Your data is stored in a secure cloud database (Railway Postgres, hosted in the United States). We apply the following protections:
- Encryption in transit: all communication between the app and our servers uses TLS 1.2 or higher.
- Encryption at rest: the database is encrypted at rest by the hosting provider.
- Field-level encryption: sensitive fields such as OAuth tokens are encrypted using AES-256-GCM before being written to the database. The decryption key is never stored in the database.
- Password hashing: passwords are hashed using bcrypt; we never store plaintext passwords.
- Refresh token security: JWT refresh tokens are SHA-256 hashed before database storage.
5. Data sharing
We share your data with the following categories of service providers who help us operate the service:
- AI inference providers: your message content is sent to large language model APIs (including Groq, Google Gemini, OpenRouter, OpenAI, and Anthropic) to generate assistant responses. Each provider’s data-use policies govern their handling of inference requests. We use these APIs through standard API calls; we do not opt you into any AI training programmes.
- Cloud infrastructure: Railway (database and API hosting), Vercel or similar (web hosting).
- Push notifications: Google Firebase Cloud Messaging (FCM) to deliver notifications to Android devices.
- Email delivery: an SMTP provider to send transactional email (email verification, reminders by email).
Beyond the above, we do not sell, rent, or otherwise share your data with third parties.
6. Your rights and controls
You have the following rights with respect to your personal data:
- Access: you can view your reminders, tasks, notes, and conversations directly in the app at any time.
- Delete: you can delete individual items from within the app. To request deletion of your entire account and all associated data, email us at hello@heynitya.com with the subject line “Account Deletion Request.” We will process the request within 30 days and confirm by email.
- Disconnect connected services: you can disconnect Google Calendar (or any other connected service) from Settings at any time. This removes all stored OAuth tokens.
- Notification preferences: you can disable push notifications from the app Settings screen or your device notification settings at any time.
- Portability: you may request a copy of your data in machine-readable format by emailing hello@heynitya.com.
You may also submit a data deletion request via our Data Deletion page.
7. Data retention
We retain your data for as long as your account is active. If you delete your account, we will delete or anonymise your personal data within 30 days, except where we are required to retain it for legal or regulatory reasons.
Push notification tokens are automatically removed when Firebase reports them as stale or unregistered.
8. Children
Nitya is not directed at children under the age of 13 (or the applicable minimum age in your jurisdiction). We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us at hello@heynitya.com.
9. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last updated” date at the top of this page and, where the changes are significant, notify you via email or an in-app notice. Continued use of Nitya after a policy update constitutes acceptance of the updated policy.
10. Contact us
If you have questions about this Privacy Policy or your data, please contact us:
- Email: hello@heynitya.com
- Subject line: Privacy Inquiry