Privacy Policy
Last updated: 8/22/2026
Privacy Policy
Last updated: 2026-08-22
This Privacy Policy explains how Nesktop collects, uses, shares, and safeguards your information when you use our website, web app, browser extension ("Extension"), mobile apps, desktop browser, and related features (collectively, the "Service"). It covers all NESKTOP surfaces and applies globally, with jurisdiction-specific detail where applicable.
1. Who We Are
NESKTOP is the public brand used for the Service. For privacy requests, data-subject requests, or complaints, contact nesktopinfo@gmail.com.
2. Information We Collect
The table below summarises the categories of information we collect, how we collect them, the purposes for which we use them, and the lawful bases we rely on under applicable law (including the GDPR, UK GDPR, KVKK, and similar state laws).
| Category | Examples | Source | Purposes | Lawful Basis (Candidates) |
|---|---|---|---|---|
| Account Information | Name, email address, account preferences, authentication credentials | You provide it during registration or profile setup | Account creation, authentication, service communication, security | Contract (performance); Legitimate interests (security) |
| Content You Save | Bookmarks, folders, layouts, notes, settings, and other items you save to your Nesktop account | You provide it by using the Service | Service provision, sync across devices, personalisation | Contract (performance); Consent (where sensitive) |
| Extension and App Data | Configuration preferences, feature toggle states, paired access tokens, local retry queue | Generated by your use of the Extension, mobile apps, or desktop browser | Feature operation, synchronisation, local caching | Contract (performance); Legitimate interests (functionality) |
| Organization Data | Membership, roles, invitations, assigned layouts, organisation name and public settings | You or your organisation administrator provide it | Organisation management, sharing, permissions | Contract (performance); Legitimate interests (administration) |
| NAPP Store Community Data | Ratings, moderated comments, abuse reports, moderation decisions, account identifier needed to enforce one rating per listing | You provide it through NAPP Store features | Community features, abuse prevention, moderation | Legitimate interests (community safety); Legal obligation (where applicable) |
| NAPP Store Activity Events | Privacy-minimised listing views, add-to-canvas actions, widget/layout add actions. These events do not store page contents or full browsing history. | Automatically collected from your interaction with NAPP | Aggregated usage insights, service improvement | Legitimate interests (product improvement) |
| Usage and Device Information | Approximate geolocation derived from IP address, browser type and version, operating system, device type, server logs | Automatically collected when you access the Service | Service operation, security, abuse prevention, diagnostics | Legitimate interests (security, operations); Legal obligation (logs where required) |
| Authentication Credentials | Secure, HttpOnly web session cookie; paired Extension access token in extension storage; mobile or desktop access token in app or OS-level secure storage | Generated automatically upon sign-in or explicit Extension pairing | Maintaining authenticated sessions, enabling account features | Contract (performance); Legitimate interests (security) |
| Website Local Storage and Session Storage | Preferences, feature toggle states, cached layout data, a non-secret signed-in compatibility marker, and basic account display data; no reusable web authentication credential | Stored locally by the webapp | Fast loading, offline capabilities, preference retention | Contract (performance); Consent (for non-essential storage) |
| Communication Data | Email address, support correspondence content, email delivery metadata | You provide it when contacting us or during service emails | Responding to enquiries, service communications, security alerts | Legitimate interests (customer support); Legal obligation (record-keeping where required) |
| Referral Program Data | Referral code, referral links clicked, referral reward eligibility status | You generate or interact with referral features | Referral tracking, reward fulfilment, abuse prevention | Legitimate interests (program operation) |
Public content: If you make content publicly available (public profile, shared layout, public organisation page, NAPP Store listing/rating/comment), that content may be viewed by anyone without authentication and may be indexed by search engines. You control what you share publicly.
3. Analytics and Usage Data
Nesktop operates self-hosted optional analytics to understand how the Service is used and to improve reliability and user experience. When you have consented to optional analytics (or where analytics are enabled by your choice), we may collect:
- Requested URL path: the page or API route you access.
- Country/locale-derived signal: approximate geographic region inferred from your IP address locale, not your precise location.
- Hashed IP address: your IP address is hashed before any storage; raw IP addresses are not stored in the PageView analytics record after hashing.
- Session ID: a randomly generated identifier for your browsing session.
- Session duration: approximate length of time you spend on the Service.
- Optional User ID: your account identifier is attached to analytics events only when you are signed in and analytics are enabled, to help us understand feature usage patterns across sessions.
Analytics data collection is optional and does not begin until you affirmatively enable it. The analytics system does not record your consent decision on the server; consent is managed on your device and communicated through the analytics opt-in mechanism. Analytics data is never used for advertising and is never sold to third parties.
Do Not Track (DNT) and Global Privacy Control (GPC): Nesktop respects DNT and GPC signals. When a valid DNT or GPC signal is detected, optional analytics collection is disabled for that session and data collection is limited to what is strictly necessary to provide the Service.
4. How We Use Information
We use your information for the following purposes:
- Provide and operate the Service: account features, synchronisation across devices, personalisation of your canvas and layouts, organisation management, and troubleshooting.
- Maintain security and prevent abuse: detect and respond to unauthorised access, fraud, spam, policy violations, and other harmful activity.
- Communicate with you: send verification emails, password reset links, security alerts, service notices, and respond to your enquiries. Marketing communications require your separate affirmative opt-in.
- Improve the Service: understand aggregate usage patterns, fix bugs, and prioritise feature development using anonymised or hashed analytics data.
- Comply with legal obligations: retain records where required by applicable law, respond to lawful requests from competent authorities, and enforce our Terms of Service.
5. How We Share Information
We share your information only as described below. We do not sell your personal data, and we do not use it for cross-context behavioural advertising.
Service Providers (Processors)
We engage verified third-party service providers to help us operate the Service. These providers process your information subject to applicable provider terms and, where required, data-processing terms/agreements:
| Provider | Service | Jurisdiction | Notes |
|---|---|---|---|
| OVH | Hosting and infrastructure (server, storage, network) | Germany (OVH data centre) | Owner-confirmed hosting location. All primary service data is stored here. |
| OAuth authentication / identity provider | Global (Google infrastructure) | Used for optional Google-sign-in. Google's privacy policy applies to its processing. | |
| Cloudflare | Anti-abuse and security (Turnstile) | Global (Cloudflare edge network) | Used for bot detection and abuse prevention. Cloudflare may process IP address and user-agent data. |
| Transactional email provider | Email delivery (verification, security alerts, service notices) | Provider and location depend on the active email configuration | Used only to deliver service-related messages; the applicable provider privacy notice and processing terms apply. |
Each provider may process your information under its own privacy policy and terms when you interact with its services directly (for example, when you use Google OAuth to sign in, Google's privacy policy applies to that specific interaction). We recommend reviewing their respective privacy notices.
Other Disclosures
We may disclose your information if required by law, to enforce our Terms of Service, or to protect the rights, safety, or property of Nesktop, our users, or the public.
6. International Transfers
Your information is primarily stored and processed on servers located in Germany (OVH data centre). As a global service, your information may be transferred to and processed in countries other than your country of residence, including Türkiye (where Nesktop is operated) and the United States (where some service providers operate).
When we transfer your information from the European Economic Area (EEA), the United Kingdom, Switzerland, or Türkiye to a country without an adequacy decision, we use a lawful transfer mechanism and supplementary measures where required by the applicable data-protection law. The applicable provider safeguards and transfer terms are available on request.
Where our service providers process your information, their processing may involve transfers covered by their own privacy frameworks and safeguards.
7. Data Retention
We retain your information only as long as necessary to fulfil the purposes described in this Policy, unless a longer retention period is required or permitted by law.
| Data Category | Retention Period | Basis / Qualification |
|---|---|---|
| Account information and saved content | Lifetime of your account plus a limited period after deletion for legal and backup purposes | Default configurable period; the exact retention after account deletion depends on backup rotation schedules and applicable legal requirements |
| Server logs | Operational/legal retention period pending exact server configuration | Specific retention period is server-configuration dependent and may vary by log type, operational need, and applicable legal requirement |
| Analytics event records | Self-hosted PageView, PlanClickEvent, and product activity event records are automatically pruned daily using the configured ANALYTICS_RETENTION_DAYS value (default 90 days) | The configured retention window applies to event records; hashed IP data and aggregate event data are retained only within that window unless a lawful exception applies |
| NAPP Store ratings and approved comments | Until you remove them, delete your account, or moderation requires removal | Reports and moderation audit records may be retained longer for safety, dispute handling, and abuse prevention |
| Backups | Retained according to configured backup schedule and legal needs; exact rotation pending verification | No automatic purge is claimed; retention duration depends on the operator's backup schedule and applicable legal requirements. Copies are retained only as long as needed for operational continuity and compliance |
If you delete your account, your data is removed from active systems within a reasonable period. Backup copies are retained subject to the applicable backup schedule and legal hold requirements. Some information may be retained where required by applicable law (for example, tax records or legal hold obligations).
8. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal information. These rights derive from applicable laws including the Turkish KVKK, the EU/EEA GDPR, the UK GDPR, and similar state privacy laws (such as the California Consumer Privacy Act / CCPA, where applicable). Where a right is not guaranteed under the law applicable to you, we do not make a blanket commitment to provide it.
- Right of access: request confirmation of whether we process your data and a copy of the data we hold.
- Right to rectification: request correction of inaccurate or incomplete data.
- Right to erasure ("right to be forgotten"): request deletion of your data, subject to legal retention obligations.
- Right to data portability: request a copy of your data in a structured, commonly used, machine-readable format.
- Right to object: object to processing based on legitimate interests, including analytics.
- Right to restriction: request that we restrict processing of your data in certain circumstances.
- Right to withdraw consent: where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of processing based on consent before its withdrawal.
- Right to complain: lodge a complaint with your local data protection authority (for EEA/UK: your national Data Protection Authority; for Türkiye: the Kişisel Verileri Koruma Kurulu — KVKK).
To exercise any of these rights, contact us at nesktopinfo@gmail.com. We will respond within the timeframe required by applicable law. We may need to verify your identity before processing your request.
California residents (CCPA where applicable): You have the right to know what personal information we collect, use, share, and sell, where the CCPA or other applicable state law applies. We do not sell your personal information. You may request deletion and opt out of any future sale (though none currently occurs). To exercise your rights, contact us at nesktopinfo@gmail.com.
9. Children
The Service is intended for adults aged 18 or older (or the higher age of majority in the user's country). It is not directed to children, and we do not knowingly collect children's personal information. If we learn that a child has created an account or submitted personal information, contact nesktopinfo@gmail.com so we can investigate and delete it where required.
Public profiles, shared layouts, organisation pages, and NAPP Store content may be indexed by search engines. Do not include another person's personal information in public content without a lawful basis.
10. Browser Extension, Mobile Apps, and Desktop Browser
Browser Extension
If you install the Nesktop Browser Extension, you control what it accesses through its settings and optional permissions. The Extension may access certain browser data (bookmarks, popular sites via topSites) only when you enable the relevant feature, grant the optional permission, and explicitly request an action (e.g., by clicking "Pull browser" or "Add to NESKTOP"). The Extension does not automatically upload or store your full browser bookmarks tree on our servers. Only items you explicitly choose to save or import into your Nesktop account are sent to our servers.
Open-tab titles and URLs are read only after you take action: you grant the optional "tabs" permission and click Save open tabs. When you save open tabs, you choose whether to save the tabs in your current window or in all windows. A destination folder is required, or you must explicitly choose Unorganized, before any tabs are read or saved. The Extension filters out internal browser pages (such as chrome:// or about: pages) and duplicate tabs, saves eligible tabs in batches, and reports the outcome after saving — including how many tabs were saved, skipped, duplicated, or failed. The optional "tabs", "bookmarks", and "topSites" permissions remain disabled until you take an action to enable them, and the Extension's permission dashboard shows each as Granted or Not granted. Before anything is saved or uploaded, a summary of the eligible tabs is shown with counts for your current window and all windows (plus any skipped items), and you confirm the destination folder (or explicitly choose Unorganized) and the window scope. The tabs permission can persist until you revoke it in the Extension settings or your browser's extension management page. Tabs are never continuously monitored, closed, moved, or reloaded by the Extension.
When you use "Add to NESKTOP," the Extension sends only the active page URL and title plus your selected canvas/page destination. If delivery is temporarily unavailable, the Extension may keep a bounded local retry queue on your device.
The Extension does not collect your full browsing history (no History API permission), does not track your browsing across websites for advertising, and does not inject ads or affiliate links.
Mobile Apps (Android)
The Android app connects to the Nesktop service for login, sync, and personalised layouts. It transmits data over HTTPS and may process standard device and network data (IP address, diagnostics, crash logs) to operate and secure the service. Session tokens are stored locally. The app does not request location, camera, microphone, contacts, SMS, phone, or advertising ID permissions.
Parental Control Mode is a guardian-operated safety feature for limiting browsing to approved domains. It is not a child-directed feature.
Desktop Browser
The NESKTOP desktop browser stores account profiles, per-profile website sessions, browser history, settings, and the last synchronised personal or assigned organisation workspace locally. Account tokens use operating-system secure storage when available. The offline workspace cache provides read-only access when the network is unavailable. You are responsible for removing stored profiles before sharing or transferring a device.
11. Data Security
We implement reasonable technical and organisational measures to protect your information, including:
- Encryption in transit using HTTPS/TLS for all communications with our servers
- Access controls and authentication on internal systems
- Use of operating-system secure storage for account tokens where available (desktop browser)
No method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security. We do not claim compliance with specific security certifications (such as ISO 27001, SOC 2, or equivalent) as we have not obtained independent certification of such standards.
12. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date at the top of this Policy and provide notice through the Service or by other means (such as email). Your continued use of the Service after the updated Policy takes effect constitutes acceptance of the changes, to the extent permitted by applicable law.
13. Contact
For privacy questions, requests, or complaints, contact us at:
We aim to respond within a reasonable timeframe. If you are unsatisfied with our response, you may lodge a complaint with your local data protection authority as described in Section 8 (Your Rights).
NESKTOP BROWSER EXTENSION — Privacy Policy (Extension-Specific)
This section is extension-specific and explains what the Nesktop Browser Extension can access only when you enable a feature.
Effective date: 2026-08-22
Support email: nesktopinfo@gmail.com
This section explains how the Nesktop Browser Extension ("Extension") handles data. The main Privacy Policy above also applies to your use of the Extension.
A) What the Extension accesses (only when enabled by you)
1) Extension settings and local cache (always)
The Extension stores locally (in browser extension storage) things like:
- Your toggle settings (master enable/disable and feature toggles)
- Cached UI or layout data for fast New Tab loading
- An extension access token after you explicitly pair the Extension with your account (not your password)
2) Save current page to Nesktop (only when you click save + feature enabled)
When you actively choose to save a page, the Extension may access and send to Nesktop:
- Page URL
- Page title
- (Optional) favicon or thumbnail (if available)
3) Open tabs (only when you grant optional tab access and click Save open tabs)
If you grant the optional "tabs" permission and click Save open tabs, the Extension reads eligible tab titles and URLs from your browser. You then choose whether to save the tabs in your current window or in all windows. A destination folder is required, or you must explicitly choose Unorganized, before any tabs are read or saved. The Extension filters out internal browser pages (such as chrome:// or about: pages) and duplicate tabs, saves eligible tabs in batches, and reports the outcome after saving — including how many tabs were saved, skipped, duplicated, or failed. Before anything is saved or uploaded, a summary of the eligible tabs is shown with counts for your current window and all windows (plus any skipped items), and you confirm the destination folder (or explicitly choose Unorganized) and the window scope. The tabs permission can persist until you revoke it in the Extension settings or your browser's extension management page. Tabs are never continuously monitored, closed, moved, or reloaded by the Extension.
4) Browser bookmarks (only if you enable "Share Browser Bookmarks")
If enabled, the Extension can read your browser bookmarks to display them in the web app's "Browser Folders" UI for organising and copying. Bookmarks are read locally in your browser. The Extension does not automatically upload or store your full bookmarks tree on Nesktop servers. Only the specific folders or bookmarks you explicitly choose to save or import into Nesktop are sent to our servers and stored in your account.
5) Popular sites (only if you enable "Share Popular Sites")
If enabled and supported by your browser, the Extension reads the browser topSites list to show "Popular Sites" in the Nesktop UI. We do not use the Chrome History API.
6) Account pairing and sign-in state
The signed-in Nesktop web app creates a short-lived, one-time pairing code. The Extension exchanges that code directly with Nesktop for its own access token. The web page does not send its JWT to the Extension, and the Extension does not inject its token into page JavaScript or web storage. The Extension stores its access token only in local extension storage and may call Nesktop endpoints (such as GET /api/auth/me) to show its signed-in state. The Extension does not read or store your password.
The Extension's permission dashboard shows the current state of each optional permission — bookmarks, Top Sites, and open tabs — as Granted or Not granted, and lets you enable or revoke them. These optional permissions remain disabled until you take an action to enable them.
B) What the Extension does NOT collect
The Extension does not:
- Collect your full browsing history (no History API permission)
- Track your browsing across websites for advertising
- Record keystrokes, form inputs, or page content you view
- Sell your data to third parties
- Inject ads or affiliate links
C) What is sent to our servers (and when)
The Extension communicates with Nesktop servers only for:
- Authentication status checks (to show logged-in or logged-out state)
- User-requested actions, such as saving the current page, saving open tabs to a confirmed destination, or saving items you explicitly choose to import into your Nesktop account
Browser bookmarks, topSites, and open tab data are not automatically uploaded to our database. They are displayed in the UI locally, and are saved to your Nesktop account only if you explicitly choose to save or import them after confirming a destination.
D) Where data is stored
- On your device: settings, caches, and the paired extension access token stored locally by the Extension
- On Nesktop servers: only data you explicitly save to your Nesktop account
E) Data retention and deletion
If you turn OFF a feature toggle, related cached data is cleared from local extension storage. If you turn OFF the master "Extension enabled" toggle, all extension features stop and caches are cleared. Uninstalling the Extension removes all local extension storage. Items you explicitly saved into your Nesktop account remain in your account until you delete them in the web app or delete your account.
F) Security
We use modern security practices including HTTPS for network communication. You should keep your browser and device up to date.
G) Children
The Extension is not intended for children under the age required to consent to data processing in your jurisdiction.
H) Changes to this policy
We may update this policy. We will update the effective date and publish the new version.
I) Contact
Privacy questions: nesktopinfo@gmail.com.