Browse legal documents

Privacy Policy

Last updated: 8/3/2026

Privacy Policy

Last updated: 2026-07-14

This Privacy Policy explains how Nesktop collects, uses, shares, and safeguards your information when you use our website, web app, browser extension ("Extension"), mobile apps, desktop browser, and related features (collectively, the "Service"). It covers all NESKTOP surfaces and applies globally, with jurisdiction-specific detail where applicable.

1. Who We Are

Nesktop is an independent software service operated under the Nesktop brand from Türkiye. Nesktop is not yet a registered company entity; formal company establishment is pending. As a result, Nesktop does not have a registered legal identity, business address, or tax identification number at this time. For all privacy-related matters, contact nesktopinfo@gmail.com.

2. Information We Collect

The table below summarises the categories of information we collect, how we collect them, the purposes for which we use them, and the lawful bases we rely on under applicable law (including the GDPR, UK GDPR, KVKK, and similar state laws).

CategoryExamplesSourcePurposesLawful Basis (Candidates)
Account InformationName, email address, account preferences, authentication credentialsYou provide it during registration or profile setupAccount creation, authentication, service communication, securityContract (performance); Legitimate interests (security)
Content You SaveBookmarks, folders, layouts, notes, settings, and other items you save to your Nesktop accountYou provide it by using the ServiceService provision, sync across devices, personalisationContract (performance); Consent (where sensitive)
Extension and App DataConfiguration preferences, feature toggle states, paired access tokens, local retry queueGenerated by your use of the Extension, mobile apps, or desktop browserFeature operation, synchronisation, local cachingContract (performance); Legitimate interests (functionality)
Organization DataMembership, roles, invitations, assigned layouts, organisation name and public settingsYou or your organisation administrator provide itOrganisation management, sharing, permissionsContract (performance); Legitimate interests (administration)
NAPP Store Community DataRatings, moderated comments, abuse reports, moderation decisions, account identifier needed to enforce one rating per listingYou provide it through NAPP Store featuresCommunity features, abuse prevention, moderationLegitimate interests (community safety); Legal obligation (where applicable)
NAPP Store Activity EventsPrivacy-minimised listing views, add-to-canvas actions, widget/layout add actions. These events do not store page contents or full browsing history.Automatically collected from your interaction with NAPPAggregated usage insights, service improvementLegitimate interests (product improvement)
Usage and Device InformationApproximate geolocation derived from IP address, browser type and version, operating system, device type, server logsAutomatically collected when you access the ServiceService operation, security, abuse prevention, diagnosticsLegitimate interests (security, operations); Legal obligation (logs where required)
Authentication TokensSession tokens, access tokens stored locally in browser storage, session storage, or OS-level secure storageGenerated automatically upon sign-inMaintaining authenticated sessions, enabling account featuresContract (performance); Legitimate interests (security)
Local Storage and Session StoragePreferences, feature toggle states, cached layout data, authentication tokens stored on your deviceStored locally by the webapp and ExtensionFast loading, offline capabilities, preference retentionContract (performance); Consent (for non-essential storage)
Communication DataEmail address, support correspondence content, email delivery metadataYou provide it when contacting us or during service emailsResponding to enquiries, service communications, security alertsLegitimate interests (customer support); Legal obligation (record-keeping where required)
Referral Program DataReferral code, referral links clicked, referral reward eligibility statusYou generate or interact with referral featuresReferral tracking, reward fulfilment, abuse preventionLegitimate interests (program operation)

Public content: If you make content publicly available (public profile, shared layout, public organisation page, NAPP Store listing/rating/comment), that content may be viewed by anyone without authentication and may be indexed by search engines. You control what you share publicly.

3. Analytics and Usage Data

Nesktop operates self-hosted optional analytics to understand how the Service is used and to improve reliability and user experience. When you have consented to optional analytics (or where analytics are enabled by your choice), we may collect:

  • Requested URL path: the page or API route you access.
  • Country/locale-derived signal: approximate geographic region inferred from your IP address locale, not your precise location.
  • Hashed IP address: your IP address is hashed before any storage; raw IP addresses are not stored in the PageView analytics record after hashing.
  • Session ID: a randomly generated identifier for your browsing session.
  • Session duration: approximate length of time you spend on the Service.
  • Optional User ID: your account identifier is attached to analytics events only when you are signed in and analytics are enabled, to help us understand feature usage patterns across sessions.

Analytics data collection is optional and follows your consent choice. It does not begin until you affirmatively enable it or, in jurisdictions where consent is not required, until you have been informed and not opted out. The analytics system does not record your consent decision on the server; consent is managed on your device and communicated through the analytics opt-in mechanism. Analytics data is never used for advertising and is never sold to third parties.

Do Not Track (DNT) and Global Privacy Control (GPC): Nesktop respects DNT and GPC signals. When a valid DNT or GPC signal is detected, optional analytics collection is disabled for that session and data collection is limited to what is strictly necessary to provide the Service.

4. How We Use Information

We use your information for the following purposes:

  • Provide and operate the Service: account features, synchronisation across devices, personalisation of your canvas and layouts, organisation management, and troubleshooting.
  • Maintain security and prevent abuse: detect and respond to unauthorised access, fraud, spam, policy violations, and other harmful activity.
  • Communicate with you: send verification emails, password reset links, security alerts, service notices, and respond to your enquiries. Marketing communications require your separate affirmative opt-in.
  • Improve the Service: understand aggregate usage patterns, fix bugs, and prioritise feature development using anonymised or hashed analytics data.
  • Comply with legal obligations: retain records where required by applicable law, respond to lawful requests from competent authorities, and enforce our Terms of Service.

5. How We Share Information

We share your information only as described below. We do not sell your personal data, and we do not use it for cross-context behavioural advertising.

Service Providers (Processors)

We engage verified third-party service providers to help us operate the Service. These providers process your information subject to applicable provider terms and, where required, data-processing terms/agreements:

ProviderServiceJurisdictionNotes
OVHHosting and infrastructure (server, storage, network)Germany (OVH data centre)Owner-confirmed hosting location. All primary service data is stored here.
GoogleOAuth authentication / identity providerGlobal (Google infrastructure)Used for optional Google-sign-in. Google's privacy policy applies to its processing.
CloudflareAnti-abuse and security (Turnstile)Global (Cloudflare edge network)Used for bot detection and abuse prevention. Cloudflare may process IP address and user-agent data.
Email/SMTP providerEmail delivery (verification, security alerts, service notices)Configurable; currently using generic SMTPWe use a generic SMTP service for transactional email. The specific provider may change.
GoDaddyDomain name registrarGlobalGoDaddy processes domain registration data only; no user content is shared.
Lemon SqueezyMerchant of Record (future — not yet live)GlobalCheckout is not live. Lemon Squeezy is our intended payment processor for future subscription payments.
StripePayment processing (configured; not yet active)GlobalStripe payment integration is configured in the codebase but is not actively processing payments. When activated, Stripe will handle payment data under its own privacy policy.

Each provider may process your information under its own privacy policy and terms when you interact with its services directly (for example, when you use Google OAuth to sign in, Google's privacy policy applies to that specific interaction). We recommend reviewing their respective privacy notices.

Other Disclosures

We may disclose your information if required by law, to enforce our Terms of Service, or to protect the rights, safety, or property of Nesktop, our users, or the public.

6. International Transfers

Your information is primarily stored and processed on servers located in Germany (OVH data centre). As a global service, your information may be transferred to and processed in countries other than your country of residence, including Türkiye (where Nesktop is operated) and the United States (where some service providers operate).

When we transfer your information from the European Economic Area (EEA), the United Kingdom, or Switzerland to a country that has not been deemed adequate by the European Commission or the UK Government, appropriate safeguards such as Standard Contractual Clauses (SCCs) or equivalent transfer mechanisms will be identified and implemented where legally required. The exact transfer mechanisms remain subject to operator/counsel review.

For transfers from Türkiye under the KVKK, required safeguards will be identified and implemented in accordance with applicable requirements; exact mechanisms remain subject to operator/counsel review.

Where our service providers process your information, their processing may involve transfers covered by their own privacy frameworks and safeguards.

7. Data Retention

We retain your information only as long as necessary to fulfil the purposes described in this Policy, unless a longer retention period is required or permitted by law.

Data CategoryRetention PeriodBasis / Qualification
Account information and saved contentLifetime of your account plus a limited period after deletion for legal and backup purposesDefault configurable period; the exact retention after account deletion depends on backup rotation schedules and applicable legal requirements
Server logsOperational/legal retention period pending exact server configurationSpecific retention period is server-configuration dependent and may vary by log type, operational need, and applicable legal requirement
Analytics event recordsSelf-hosted PageView and PlanClickEvent records are automatically pruned daily using the configured ANALYTICS_RETENTION_DAYS value (default 365 days)Configurable by the operator; may be set to any positive number or disabled entirely. Hashed IP data and aggregated event data are retained within the configured retention window for trend analysis
NAPP Store ratings and approved commentsUntil you remove them, delete your account, or moderation requires removalReports and moderation audit records may be retained longer for safety, dispute handling, and abuse prevention
BackupsRetained according to configured backup schedule and legal needs; exact rotation pending verificationNo automatic purge is claimed; retention duration depends on the operator's backup schedule and applicable legal requirements. Copies are retained only as long as needed for operational continuity and compliance

If you delete your account, your data is removed from active systems within a reasonable period. Backup copies are retained subject to the applicable backup schedule and legal hold requirements. Some information may be retained where required by applicable law (for example, tax records or legal hold obligations).

8. Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal information. These rights derive from applicable laws including the Turkish KVKK, the EU/EEA GDPR, the UK GDPR, and similar state privacy laws (such as the California Consumer Privacy Act / CCPA, where applicable). Where a right is not guaranteed under the law applicable to you, we do not make a blanket commitment to provide it.

  • Right of access: request confirmation of whether we process your data and a copy of the data we hold.
  • Right to rectification: request correction of inaccurate or incomplete data.
  • Right to erasure ("right to be forgotten"): request deletion of your data, subject to legal retention obligations.
  • Right to data portability: request a copy of your data in a structured, commonly used, machine-readable format.
  • Right to object: object to processing based on legitimate interests, including analytics.
  • Right to restriction: request that we restrict processing of your data in certain circumstances.
  • Right to withdraw consent: where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of processing based on consent before its withdrawal.
  • Right to complain: lodge a complaint with your local data protection authority (for EEA/UK: your national Data Protection Authority; for Türkiye: the Kişisel Verileri Koruma Kurulu — KVKK).

To exercise any of these rights, contact us at nesktopinfo@gmail.com. We will respond within the timeframe required by applicable law. We may need to verify your identity before processing your request.

California residents (CCPA where applicable): You have the right to know what personal information we collect, use, share, and sell, where the CCPA or other applicable state law applies. We do not sell your personal information. You may request deletion and opt out of any future sale (though none currently occurs). To exercise your rights, contact us at nesktopinfo@gmail.com.

9. Children

The Service is intended for users who are at least 13 years of age (or the minimum age required in your country). We do not knowingly collect personal information from children under 13 (or the applicable minimum age). If we learn that we have collected personal information from a child below the applicable age, we will take steps to delete that information promptly.

The Service is not directed to children. Parental Control Mode is a guardian-operated safety feature for limiting browsing to approved domains; it is not a child-directed feature and does not change our data practices with respect to children.

Public profiles, shared layouts, organisation pages, and NAPP Store content may be indexed by search engines. Users under the applicable age should not include personal information in public content.

10. Browser Extension, Mobile Apps, and Desktop Browser

Browser Extension

If you install the Nesktop Browser Extension, you control what it accesses through its settings and optional permissions. The Extension may access certain browser data (bookmarks, popular sites via topSites) only when you enable the relevant feature, grant the optional permission, and explicitly request an action (e.g., by clicking "Pull browser" or "Add to NESKTOP"). The Extension does not automatically upload or store your full browser bookmarks tree on our servers. Only items you explicitly choose to save or import into your Nesktop account are sent to our servers.

Open-tab titles and URLs are read only after you grant the optional "tabs" permission and click Save open tabs. Eligible tabs are previewed and you confirm a destination before anything is saved or uploaded. The tabs permission can persist until you revoke it in the Extension settings or your browser's extension management page. Tabs are never continuously monitored, closed, moved, or reloaded by the Extension.

When you use "Add to NESKTOP," the Extension sends only the active page URL and title plus your selected canvas/page destination. If delivery is temporarily unavailable, the Extension may keep a bounded local retry queue on your device.

The Extension does not collect your full browsing history (no History API permission), does not track your browsing across websites for advertising, and does not inject ads or affiliate links.

Mobile Apps (Android)

The Android app connects to the Nesktop service for login, sync, and personalised layouts. It transmits data over HTTPS and may process standard device and network data (IP address, diagnostics, crash logs) to operate and secure the service. Session tokens are stored locally. The app does not request location, camera, microphone, contacts, SMS, phone, or advertising ID permissions.

Parental Control Mode is a guardian-operated safety feature for limiting browsing to approved domains. It is not a child-directed feature.

Desktop Browser

The NESKTOP desktop browser stores account profiles, per-profile website sessions, browser history, settings, and the last synchronised personal or assigned organisation workspace locally. Account tokens use operating-system secure storage when available. The offline workspace cache provides read-only access when the network is unavailable. You are responsible for removing stored profiles before sharing or transferring a device.

11. Data Security

We implement reasonable technical and organisational measures to protect your information, including:

  • Encryption in transit using HTTPS/TLS for all communications with our servers
  • Access controls and authentication on internal systems
  • Use of operating-system secure storage for account tokens where available (desktop browser)

No method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security. We do not claim compliance with specific security certifications (such as ISO 27001, SOC 2, or equivalent) as we have not obtained independent certification of such standards.

12. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date at the top of this Policy and provide notice through the Service or by other means (such as email). Your continued use of the Service after the updated Policy takes effect constitutes acceptance of the changes, to the extent permitted by applicable law.

13. Contact

For privacy questions, requests, or complaints, contact us at:

nesktopinfo@gmail.com

We aim to respond within a reasonable timeframe. If you are unsatisfied with our response, you may lodge a complaint with your local data protection authority as described in Section 8 (Your Rights).


NESKTOP BROWSER EXTENSION — Privacy Policy (Extension-Specific)

This section is extension-specific and explains what the Nesktop Browser Extension can access only when you enable a feature.

Effective date: 2026-07-14

Support email: nesktopinfo@gmail.com

This section explains how the Nesktop Browser Extension ("Extension") handles data. The main Privacy Policy above also applies to your use of the Extension.

A) What the Extension accesses (only when enabled by you)

1) Extension settings and local cache (always)

The Extension stores locally (in browser extension storage) things like:

  • Your toggle settings (master enable/disable and feature toggles)
  • Cached UI or layout data for fast New Tab loading
  • An extension access token after you explicitly pair the Extension with your account (not your password)

2) Save current page to Nesktop (only when you click save + feature enabled)

When you actively choose to save a page, the Extension may access and send to Nesktop:

  • Page URL
  • Page title
  • (Optional) favicon or thumbnail (if available)

3) Open tabs (only when you grant optional tab access and click Save open tabs)

If you grant the optional "tabs" permission and click Save open tabs, the Extension reads eligible tab titles and URLs from your browser. Eligible tabs are previewed with you and you confirm a destination folder (or choose Unorganized) before anything is saved or uploaded. The tabs permission can persist until you revoke it in the Extension settings or your browser's extension management page. Tabs are never continuously monitored, closed, moved, or reloaded by the Extension.

4) Browser bookmarks (only if you enable "Share Browser Bookmarks")

If enabled, the Extension can read your browser bookmarks to display them in the web app's "Browser Folders" UI for organising and copying. Bookmarks are read locally in your browser. The Extension does not automatically upload or store your full bookmarks tree on Nesktop servers. Only the specific folders or bookmarks you explicitly choose to save or import into Nesktop are sent to our servers and stored in your account.

5) Popular sites (only if you enable "Share Popular Sites")

If enabled and supported by your browser, the Extension reads the browser topSites list to show "Popular Sites" in the Nesktop UI. We do not use the Chrome History API.

6) Account pairing and sign-in state

The signed-in Nesktop web app creates a short-lived, one-time pairing code. The Extension exchanges that code directly with Nesktop for its own access token. The web page does not send its JWT to the Extension, and the Extension does not inject its token into page JavaScript or web storage. The Extension stores its access token only in local extension storage and may call Nesktop endpoints (such as GET /api/auth/me) to show its signed-in state. The Extension does not read or store your password.

B) What the Extension does NOT collect

The Extension does not:

  • Collect your full browsing history (no History API permission)
  • Track your browsing across websites for advertising
  • Record keystrokes, form inputs, or page content you view
  • Sell your data to third parties
  • Inject ads or affiliate links

C) What is sent to our servers (and when)

The Extension communicates with Nesktop servers only for:

  • Authentication status checks (to show logged-in or logged-out state)
  • User-requested actions, such as saving the current page, saving open tabs to a confirmed destination, or saving items you explicitly choose to import into your Nesktop account

Browser bookmarks, topSites, and open tab data are not automatically uploaded to our database. They are displayed in the UI locally, and are saved to your Nesktop account only if you explicitly choose to save or import them after confirming a destination.

D) Where data is stored

  • On your device: settings, caches, and the paired extension access token stored locally by the Extension
  • On Nesktop servers: only data you explicitly save to your Nesktop account

E) Data retention and deletion

If you turn OFF a feature toggle, related cached data is cleared from local extension storage. If you turn OFF the master "Extension enabled" toggle, all extension features stop and caches are cleared. Uninstalling the Extension removes all local extension storage. Items you explicitly saved into your Nesktop account remain in your account until you delete them in the web app or delete your account.

F) Security

We use modern security practices including HTTPS for network communication. You should keep your browser and device up to date.

G) Children

The Extension is not intended for children under the age required to consent to data processing in your jurisdiction.

H) Changes to this policy

We may update this policy. We will update the effective date and publish the new version.

I) Contact

Privacy questions: nesktopinfo@gmail.com.