1. Scope
This Policy explains how niblo.app processes personal data of Users, public-site visitors, support contacts and people appearing in social Content. We apply lawfulness, transparency, minimisation, purpose and storage limitation, integrity and confidentiality.
2. Controller
The controller is niblo.app. Privacy requests: contact@niblo.app. Security reports: contact@niblo.app. If a data protection officer is appointed, contact details will be published here.
3. Data sources
Data comes directly from Users during registration, module use and contact; automatically from the device where needed for transmission and security; from other Users when they invite, mention or publish information; and from public metadata supplied by News publishers. Article 14 GDPR information is provided where data is obtained indirectly unless an exemption applies.
4. Data categories
Depending on the features used, we process Account data (email, identifier, name, password hash and verification); profile and preferences; files, documents, notes, events, posts, comments, reactions and saved items; contacts, blocks, reports and messages; Plan and transaction metadata; IP, browser, device, session, errors and audit logs; support submissions; and locally stored interface preferences.
We do not request special-category data. Users should avoid entering health, belief or similarly sensitive information unless genuinely necessary and lawful.
5. Purposes and legal bases
| Purpose | Data | Legal basis |
|---|---|---|
| Account and requested features | Account, profile, Content, settings | contract or pre-contract steps – Art. 6(1)(b) GDPR |
| payments and accounting | order and transaction metadata | contract and legal obligation – Art. 6(1)(b), (c) |
| security, abuse prevention and claims | logs, IP, sessions, audit, reports | legitimate interests – Art. 6(1)(f) |
| support, complaints and rights | submission and Account data | contract, legal obligation or legitimate interests |
| moderation | Content, reports and decisions | contract, legal obligation and legitimate interests |
| optional personalisation or communication | selected preference or contact | consent – Art. 6(1)(a), where required |
| reliability and diagnostics | aggregated events, errors and performance | legitimate interests; consent-requiring optional tools remain off until consent |
Legitimate interests include securing the Service, preventing fraud, accountability, legal claims and improving reliability after a balancing assessment.
6. Required data
Fields marked required are necessary for an Account, contract, payment or support request. Without them the relevant action cannot be completed. Profile details and most preferences are voluntary.
7. Visibility and messages
Users choose a post audience where supported. Public Content can be viewed by anyone, shared and displayed in the Feed. Restricted Content follows contact and audience settings. Messages are available to participants. Authorised staff access is limited to support, security, enforcement or legal obligations and should be controlled and logged.
8. Recipients
Data may be processed by vetted hosting, email, backup, monitoring, payment, accounting, support and legal providers, each receiving only what is necessary under a contract or legal duty. Authorities may receive data where law requires it, and Users receive Content according to audience settings. We do not sell personal data or disclose it to data brokers.
9. Transfers outside the EEA
We prefer EEA infrastructure. Where a provider processes data elsewhere, we rely on an adequacy decision, Standard Contractual Clauses with a transfer assessment, or another Chapter V GDPR mechanism. Details and a copy of safeguards may be requested at contact@niblo.app. Article 49 derogations are not used for routine transfers.
10. Retention periods
- Account and active Content: for the contract duration.
- Deletion requests: active copies normally erased or anonymised within 30 days, subject to law and backups.
- Backups: rotated on daily, weekly, monthly and yearly schedules. The standard configuration retains 7 daily, 5 weekly, 12 monthly and 3 yearly snapshots. Backups are not used for ordinary access and expire through subsequent rotation cycles.
- Security and session logs: generally up to 12 months, longer for a specific incident or claim.
- Accounting data: for the statutory tax/accounting period, normally five years from the relevant year end.
- Support and complaints: until closure and then up to three years or the applicable limitation period.
- Moderation and appeals: as needed for appeal, compliance and claims, generally up to three years.
- Consent data: until withdrawal or purpose completion.
Data relevant to a dispute, proceeding or incident may be preserved until final closure and expiry of claims.
11. Account deletion and backups
Deletion triggers erasure or anonymisation. Data remains only where law, claims or jointly created Content requires it, with use restricted to that purpose. Encrypted backups may temporarily retain deleted data and are overwritten in rotation; restored data is re-subjected to deletion.
12. Individual rights
Individuals have rights of access, copy, rectification, erasure, restriction, portability and objection to Art. 6(1)(f) processing. Consent may be withdrawn at any time without affecting past lawfulness. Requests go to contact@niblo.app. We may reasonably verify identity and normally respond within one month.
Complaints may be lodged with the Polish supervisory authority, President of the Personal Data Protection Office, uodo.gov.pl, or another competent EEA authority.
13. Automated decisions and recommendations
We do not make solely automated decisions producing legal or similarly significant effects. Automation may detect spam and threats, order News or recommend Content based on followed sources, topics and explicit interactions. Users can influence recommendations through controls. Material moderation and appeals receive human review.
14. Children
The Service is not intended for persons under 16. If an Account was created in breach of this restriction or without required guardian consent, we will verify and erase the data unless preservation is legally required. Guardians may contact contact@niblo.app.
15. Security
Measures proportionate to risk include TLS, password hashing, access control, environment separation, backups, monitoring, patching and administrative audit logs. Details that could facilitate an attack are not public. Where a breach is likely to create high risk, affected people are informed without undue delay as required by GDPR.
16. Browser technologies
See the Cookie Policy. Optional analytics and advertising technologies are currently disabled. Introducing them requires a register update and prior consent where required.
17. Changes and contact
Material changes are communicated in the application or by email. Version history and effective date appear with this document. Privacy rights: contact@niblo.app; security: contact@niblo.app; service complaints: contact@niblo.app.