Privacy Policy
Effective date: May 1, 2026 · Last updated: September 2, 2026
What changed on September 2, 2026: named PostHog and MetricKit as sub-processors, disclosed auto-import and file import, restated our Article 27 position, and added rights sections for Canada, India, Japan, South Korea, Australia and New Zealand.
1. Summary (Plain English)
This summary is for convenience — the sections that follow control if there is any conflict.
- Your content stays with you and Apple. Screenshots, notes, voice memos, links, PDFs, reminders, and routines are stored on your device and (if you enable iCloud sync) inside your personal Apple iCloud account using Apple's CloudKit framework. We do not host, copy, or back up your library on our servers.
- AI is on-device first, cloud only when necessary. Apple Foundation Models, Core ML, on-device OCR, and on-device speech recognition handle most AI features locally on your device. Apple’s system-wide Writing Tools are also available on text you select; those are operated by Apple, and Apple may process a longer request on its Private Cloud Compute rather than on the device. When you ask for a feature that exceeds on-device capability (advanced summarisation, multi-step reasoning, or real-time live transcription), the content of that request — which, for a question answered from your library, includes the items the assistant found relevant — may be processed by our AI partners (NVIDIA Cloud, OpenRouter, Speechmatics) under those providers’ published terms, which we describe in section 6. We never send your full library to any cloud service.
- No advertising, no profiling, no data sale. We do not sell your personal data, use it for behavioural advertising, build advertising profiles, or share it with data brokers.
- Diagnostics are aggregate and minimised. Crash reports (Sentry) and subscription events (RevenueCat) help us keep the app working. They contain device + error + purchase metadata — not your library content.
- You can delete everything. You can delete any individual item, your entire library, your subscription, and your account from inside the app at any time. Account deletion permanently removes locally stored data and queues your iCloud-synced data for deletion through Apple's CloudKit.
- You have rights. Depending on where you live, you have rights to access, correct, port, or delete your data, and to object to processing. We honour those rights regardless of where you live.
2. Who We Are (Data Controller)
This Privacy Policy is published by:
Taha Baalla
Sole proprietor, doing business as Nemos
Kingdom of Morocco
Email (privacy): [email protected]
Email (general): [email protected]
For the purposes of the EU General Data Protection Regulation (GDPR), the UK GDPR, the Swiss FADP, the California Consumer Privacy Act (CCPA/CPRA), Brazil's LGPD, and Moroccan Law n° 09-08 on the protection of natural persons with regard to the processing of personal data, Taha Baalla is the data controller (or "business" / "responsable du traitement") for Nemos.
We have not appointed a Data Protection Officer (DPO), as our processing does not meet the criteria in Article 37(1) GDPR that would require one. We are established outside the EU and the UK, and we are reviewing whether Article 27 GDPR and Article 27 UK GDPR require us to designate a representative in those territories; where a representative is required, we will designate one and publish their contact details in this section. Until then, and regardless of the outcome of that review, you can reach the controller directly using the contact details above, and we will handle any request or complaint as if it had been made to a designated representative.
3. Scope of This Policy
This Privacy Policy applies to:
- The Nemos iOS, iPadOS, macOS and watchOS application (the "App"), including its widgets, Live Activities, the Nemos keyboard, the Mac menu bar app, Share Extension, Siri Shortcuts, App Intents, and Apple Watch companion;
- The Nemos website at nemosapp.com and any subdomains, including the waitlist and account pages;
- The Nemos browser extension ("Nemos: Save Anything"), described in detail in section 25, and any desktop client or visionOS app we may release, unless it has its own published policy.
Third-party services you reach through the App or the website (for example, links you save) are governed by their own privacy practices. We are not responsible for those services.
3.1 Where Nemos is offered
Nemos is distributed through the Apple App Store in the territories shown on its App Store product page, and the Mac version is additionally available as a direct download from this website.
Mainland China. Nemos is not offered on the China mainland App Store and we do not direct the App or this website to users located in mainland China. We therefore do not process personal information under the Personal Information Protection Law of the People’s Republic of China. Hong Kong, Macao and Taiwan are separate storefronts and are not covered by that law — Nemos is available there, and in Hong Kong the Personal Data (Privacy) Ordinance applies to that use.
Sanctions. We do not make Nemos available in territories subject to comprehensive sanctions that would prohibit it. See section 33 of the Terms.
4. Information We Collect
We have organised this section to mirror Apple's App Store Privacy Nutrition Label categories so that what you read here matches what you see on the App Store listing.
4.1 Identifiers (linked to you)
- Apple ID hash: When you sign in with "Sign in with Apple", Apple gives the App a stable, opaque user identifier. We never receive your Apple ID email address unless you explicitly choose to share it. We use this identifier solely to authenticate you and synchronise your subscription state.
- Subscription identifier: RevenueCat (our subscription provider) issues an anonymous "app user ID" — which we set to your Sign in with Apple identifier, so it is pseudonymous rather than anonymous — linked to your Apple subscription so we can determine whether you have an active Pro subscription.
- Email address (waitlist only): If you join the waitlist on the website, we collect the email address you provide so we can email you when access opens. We do not require an email to use the App itself.
4.2 User content
- Screenshots, photos, links, notes, PDFs, audio recordings, transcripts, ebooks, web articles, video, and other media you save in the App.
- Folders, Smart Spaces, tags, reminders, routines, chat conversations, and the AI-generated names, summaries, and tags attached to your items.
- Knowledge-base entries you build inside the App (used by the on-device retrieval-augmented search).
Important: User content is stored locally on your device and (if you enable iCloud sync) in your personal iCloud account, not on Nemos servers. See section 7.
4.3 Usage and diagnostics
- Aggregate feature usage (e.g. how many times the capture button was tapped) collected through PostHog. This includes automatic capture of which screens you open — screen names only, never their contents, and never what you typed or tapped inside them. It runs only if you turn on “Share Usage Analytics” in Settings, which is off by default; with it off, the analytics client is never started and no events leave your device. You are identified to PostHog by a one-way hash, not by your Apple ID.
- Crash reports, ANRs (app-not-responding), and exception traces sent to Sentry. Apple MetricKit performance reports — launch time, hang rate, CPU and disk metrics that iOS itself measures — are forwarded to the same service. These describe how the app performed on your device, not what you did in it. These contain device model, OS version, app version, a stack trace, and breadcrumbs of recent in-app events. We strip personal content before sending where technically possible.
- App Store / TestFlight metrics provided to us by Apple in aggregated form.
4.4 Purchases
- Subscription start, renewal, cancellation, refund, billing-issue, and trial-conversion events forwarded by Apple via App Store Server Notifications and reconciled by RevenueCat.
- We do not receive your payment card, banking, or address details — Apple processes the transaction.
4.5 Permission-gated device data
The App requests certain Apple system permissions only when you use the related feature, and only with the justification declared in the App's Info.plist. You can revoke any permission at any time in iOS Settings → Privacy & Security or Settings → Nemos.
- Photo Library (NSPhotoLibraryUsageDescription / WhenInUse): to import existing screenshots and photos you choose to save into the App. If you turn on Auto-import screenshots in Settings — which is off by default — the App additionally watches for newly added screenshots and imports them without asking each time, for as long as that setting is on. It imports only images iOS identifies as screenshots, it never requests photo access by itself (if you have not already granted it, nothing happens), and switching the setting off stops it immediately. Auto-imported screenshots are treated exactly like anything else you save: kept on your device and in your own iCloud, never on our servers.
- Accounts you connect: you can optionally connect Google Drive, Dropbox, Notion or GitHub to import content into Nemos. Connecting one sends you to that provider’s own sign-in page; Nemos never sees your password. We store the resulting access token in the device Keychain so the connection keeps working, and we use it only to read the items you choose to import. Disconnecting an account in Settings deletes the stored token, and you can also revoke Nemos from the provider’s own security settings at any time. Imported items become ordinary items in your library.
- An Obsidian vault you connect — if you point Nemos at a folder of notes, it reads the Markdown files in it so they can be searched and cited alongside the rest of your library. Two consequences worth stating: those notes are indexed on your device, and when you ask a question that cloud AI answers, the notes the assistant judged relevant are included in that request. That is retrieval doing its job, but it means a vault note can reach a cloud provider without you having pasted it. Disconnect the folder at any time, and see section 6.
- Instagram and TikTok sign-in — entirely optional, and only if you ask Nemos to open a video from one of those platforms that is not publicly viewable. The sign-in happens on that platform’s own page; we never see your username or password. The session it creates is stored on your device and reused for later videos from that platform, which means those requests reach Instagram or TikTok as you rather than anonymously. It is erased when you delete your account.
- Your onboarding answers — the choices you make when you first set Nemos up, and anything you type in those steps. Unlike the rest of your library, these are sent to a database we operate (see section 8.1) and stored against your Sign in with Apple identifier. Ask us and we will delete them.
- Journal suggestions — if you choose to add one, iOS offers you suggestions drawn from your recent activity (photos, workouts, places you visited, people you contacted). Nemos sees only the suggestion you actually pick, and it becomes an ordinary item in your own iCloud. Nothing is read unless you select it.
- Alarms — reminders you ask Nemos to sound at a set time are scheduled with the system alarm service on your device.
- Links you save: when you save a URL, Nemos tries to build a preview for it. It asks Apple’s on-device LinkPresentation first. If that returns nothing, the URL — and only the URL, never an account identifier — is sent to one of three preview services so a title, description and image can be fetched: Microlink for links generally, noembed for YouTube, and thum.io for LinkedIn links whose image is on a CDN that blocks direct loading. These services see that some anonymous request asked about that address; they are not told who asked. They are listed in section 8.
- Files you import: the App can import an export file you choose from another app — browser bookmarks (.html), or exports from note apps such as Evernote, Bear, Notion, mymind and Raindrop.io. The file is read on your device and its contents become items in your library. It is not uploaded to us. The App cannot read your browser’s bookmarks, history or cookies directly; iOS does not permit that, and we do not ask for it.
- Location (NSLocationWhenInUseUsageDescription / NSLocationAlwaysAndWhenInUseUsageDescription): to tag a saved place with where it is, to show your places on a map, and — only if you create a location-based reminder — to notify you when you arrive at or leave a place. That arrival/departure feature is the only thing that asks for “Always” access, and only at the moment you create such a reminder. Precise location is used to place and match your own items; it is never used for advertising or profiling, never sold, and never shared with data brokers. Coordinates stay on your device and in your own iCloud.
- Contacts (NSContactsUsageDescription): to let you import a contact card, link a birthday reminder to a person, and show a collaborator’s photo or Memoji. To build the picker you choose from, the App reads your address book on your device — that read is the whole list, because the picker has to show it. Only the person you actually select is saved into your library, and a saved card can include name, nickname, company, job title, phone numbers, email and postal addresses, websites and birthday. The private Notes field on a contact is deliberately never requested. A saved card syncs through your own iCloud like any other item; your address book itself is never uploaded anywhere. You can revoke access at any time in iOS Settings → Privacy & Security → Contacts.
- Camera (NSCameraUsageDescription): to scan documents, capture screenshots, and use the live data scanner (text / barcode / QR).
- Microphone (NSMicrophoneUsageDescription): to record voice memos and dictate notes.
- Speech Recognition (NSSpeechRecognitionUsageDescription): to transcribe voice memos. Most transcription happens on-device. Real-time / live transcription is processed by Speechmatics (see section 6).
- Notifications: to deliver reminder alerts, Live Activity updates, and routine prompts you have configured.
- Local Network: only when needed for direct device-to-device sync.
- Face ID / Touch ID (NSFaceIDUsageDescription): to lock the App. Face / fingerprint data never leaves the Secure Enclave on your device — we never see it.
- Calendar / Reminders: only if you explicitly enable two-way sync with Apple Calendar / Reminders.
- Location: the App does request precise location, with your permission, for the place and location-reminder features described above. An earlier version of this Policy said we did not, and that was incorrect. Precise location is used only to place and match your own items. Weather is served by Apple’s WeatherKit, which receives only a coarse location. If WeatherKit is unavailable, the App falls back to Open-Meteo, an independent weather service, and sends it your coordinates rounded to four decimal places (roughly 11 metres) so it can return a local forecast. No account identifier accompanies that request, but it is a third party receiving a precise position, so it is named here and in section 8 rather than folded into “weather”.
- Family Controls / Screen Time: only if you enable the optional focus-and-routines integration (currently gated, requires Apple's Family Controls entitlement).
- Nearby Interaction (UWB): only when you opt into peer-to-peer ranging features.
- Group Activities (SharePlay): only when you start a SharePlay co-edit session over FaceTime.
4.6 Web / waitlist
- Email address you submit to the waitlist form.
- IP address (necessarily processed by our hosting provider Cloudflare for routing, rate-limiting, and protection against abuse — never used to track you across sites). IP addresses are not stored in our waitlist database; they appear only in transient hosting logs.
- If, and only if, you accept the cookie / analytics consent banner: pseudonymous Google Analytics 4 measurement events (page views, durations, scroll depth) keyed to a per-browser cookie. You can withdraw consent at any time and we will stop sending events.
4.7 What we do NOT collect
- We do not read, scan, mine, or train models on the content of your library.
- We do not use location to track you. Precise location is collected only for the place and location-reminder features you choose to use (section 4.5), and never for advertising, profiling, or sale.
- We do not collect call logs, SMS, browser history, or health / fitness data. We do not read your address book as a whole — contact details reach the App only for an entry you explicitly link to a reminder or capture as an item (section 4.5).
- We do not use the Identifier for Advertisers (IDFA), fingerprinting, or any cross-site / cross-app tracking technology.
- We do not buy data about you from data brokers.
5. How We Use Your Information
We use the categories of data above only for the purposes listed:
- Provide, operate, secure, and improve the App and the website;
- Authenticate you and synchronise subscription state across your Apple devices;
- Sync your library between your devices via your personal iCloud account;
- Run on-device AI features (auto-naming, tagging, summarisation, OCR, embeddings, search, transcription) and, where you trigger features that exceed on-device capability, run cloud-assisted AI features through the partners disclosed in section 6;
- Diagnose crashes and improve reliability;
- Process subscription billing through Apple and reconcile entitlements through RevenueCat;
- Send service emails (waitlist confirmations, security alerts, material legal updates). We do not send marketing email without your prior consent;
- Comply with legal obligations and respond to lawful requests;
- Detect, prevent, and respond to fraud, abuse, security incidents, and breach of these terms.
We do not use your information for behavioural advertising, profiling for marketing purposes, or automated decision-making that produces legal or similarly significant effects on you.
6. On-Device vs. Cloud AI Processing
Nemos is designed on-device-first. The following AI features run entirely on your device, with no content leaving your device or your iCloud:
- Apple Foundation Models (iOS 26+ / iPadOS 26+ / macOS 26+ where available) for summarisation, naming, and rewriting.
- Apple Vision (VNRecognizeTextRequest) and on-device OCR for screenshot and document text extraction.
- Apple Speech (SFSpeechRecognizer, on-device mode) for voice memo transcription.
- Core ML embeddings and clustering used by the local search and "Smart Spaces" features.
- VisionKit Data Scanner for live text and barcode capture.
When you trigger features that the on-device models cannot satisfy at the required quality (for example, advanced multi-step reasoning, very large context summarisation, or real-time live transcription), the App sends the content needed for that request to one of the following processing partners. Where the assistant answers from your library, that includes the items it selected as relevant — and, if you have connected an Obsidian vault, notes from it — which you will not have picked out individually. We do not send your full library, and we do not retain the request payload on our own servers.
- NVIDIA Cloud (NIM / NeMo): for advanced inference. Operated under NVIDIA's enterprise data-processing terms. We have not enabled a per-request zero-retention mode; our proxy does not send the option that would select one.
- OpenRouter: a multi-provider AI gateway that routes specific requests to model providers. We route to providers whose published terms do not permit training on submitted content, We do not currently set per-request zero-retention routing, and we would rather say so than imply a protection we have not switched on. One exception we want to state plainly rather than bury: every request we route through OpenRouter is served by a free-tier model — our proxy rejects anything else, and OpenRouter’s published terms allow prompts sent to free endpoints to be used to improve models. OpenRouter and the underlying providers may also briefly retain inference payloads for abuse prevention.
- Speechmatics: for real-time live speech-to-text over a WebSocket connection. Audio is processed in transit and is not retained on Speechmatics' systems beyond the time needed to return the transcript.
Model training on your content. We are a one-person company using these providers on their standard commercial terms. We have not negotiated bilateral data-processing agreements with them, and we will not tell you we have. What we can tell you is what those published terms say and how we have configured our use of them: every request we send through OpenRouter uses a free-tier model, and OpenRouter’s published terms allow prompts sent to those endpoints to be used to improve models. Requests to NVIDIA run under its commercial terms, which do not. We have not switched on per-request zero-retention routing anywhere. What is entirely within our control, and is an unconditional commitment: we do not, and will not, sell or license your content to anyone for training, and we do not use your content to train anything ourselves.
If you do not want any cloud AI processing to occur, you can disable cloud-assisted AI features in Settings → Privacy. Some advanced features will be unavailable while cloud AI is disabled.
7. Where Your Data Is Stored
7.1 On your device
By default, the entire Nemos library is stored locally on your device using MMKV — an encrypted key-value store on iPhone and iPad. On Mac the same data is held in an unencrypted store, because the encrypted implementation is not reliable on that platform; it stays inside the app’s container and is covered by FileVault if you have it enabled. Alongside that we use the iOS file system inside the App's sandbox. Sensitive secrets are stored in the iOS Keychain. Live Activities, widgets, and Apple Watch read from a shared App Group container that only Nemos targets can access.
7.2 In your Apple iCloud account
If you enable iCloud sync, your library is synchronised across your Apple devices through Apple CloudKit using two databases:
- A private CloudKit database tied to your Apple ID — only you (and Apple under their privacy policy) can access this data;
- A shared CloudKit database used only when you explicitly invite another Apple user to a shared folder.
We do not receive a copy of your CloudKit data. Apple is the storage controller; their handling is governed by Apple's Privacy Policy and their iCloud terms.
7.3 On our infrastructure
We operate a thin server footprint, used only for the items listed below:
- Cloudflare Pages (United States / global edge): hosts the marketing website and waitlist form;
- Cloudflare D1 (a SQLite database at the Cloudflare edge): stores waitlist email addresses and timestamps;
- Cloudflare Workers: serve the API endpoints (waitlist subscribe, health checks) and act as the AI proxy. This is important enough to state plainly: when a feature needs cloud AI, the request does not go from your device straight to the AI provider. It passes through our Worker, which attaches our server-side API key and forwards it to NVIDIA or OpenRouter. We do this so that an API key is never shipped inside the app where it could be extracted. The Worker is a pass-through — it does not store the request or the response, and nothing about the payload is written to our database. But the content of that one request does transit our infrastructure, which is a different statement from “your data never touches our servers”, and you should know which one is true;
- Resend (United States): delivers transactional emails (waitlist confirmations, account / security emails);
- Sentry: stores crash reports, MetricKit performance reports and diagnostic events (our Sentry account is in the United States);
- RevenueCat (United States): stores subscription entitlement events;
- Supabase (United States): stores your Apple ID hash and onboarding state so your setup persists across reinstalls;
- Superwall (United States): manages paywall presentation and subscription-conversion events;
- PostHog (EU / US, routed by region): in-app product analytics — only collected if you opt in.
Two further places your library exists. If you make a backup, it is written to your own iCloud Drive as a file you can see and delete. And if you used Nemos before it was renamed, a copy of your library may remain in the iCloud container that earlier version used; we copy from it and deliberately never delete it, so that a failed migration cannot lose anything. Neither is removed by deleting your account in the app — ask us and we will talk you through removing both.
8. Sub-Processors
Two different kinds of third party receive data, and conflating them would misdescribe both. We separate them.
8.1 — Processors acting on our instructions. These process personal data on our behalf for a purpose we set. Where we hold a data-processing agreement with them we say so in section 6; where we are a small customer on standard published terms, those terms govern.
| Sub-processor | Purpose | Data categories | Region |
|---|---|---|---|
| Apple Inc. | Sign in with Apple, App Store, CloudKit private + shared, App Store Server Notifications, push notifications, TestFlight, WeatherKit | Apple ID identifier, subscription, library content (in your iCloud), device + app metadata | Worldwide (Apple-operated) |
| Cloudflare, Inc. | Website + API hosting, waitlist database (D1), DDoS / abuse protection | Email (waitlist), IP, user-agent, request metadata | Global edge (US-based controller) |
| Resend, Inc. | Transactional email delivery | Email, message contents | United States |
| Sentry (Functional Software, Inc.) | Crash + error monitoring | Device + OS + app metadata, stack traces, breadcrumbs | United States |
| RevenueCat, Inc. | Subscription entitlement management | Anonymous app-user ID, subscription events | United States |
| Speechmatics Ltd. | Real-time speech-to-text | Live audio stream, and for longer recordings the complete audio file, transcript | United Kingdom / EU |
| NVIDIA Corporation | Cloud AI inference | Specific request payload (transient) | United States |
| OpenRouter, Inc. | Multi-provider AI inference gateway | Specific request payload (transient) | United States |
| Open-Meteo | Current conditions and daily high/low, used only when Apple WeatherKit is unavailable. | Coordinates rounded to 4 decimal places (~11 m). No account identifier. | European Union (Germany) |
| Microlink (Microlink HQ S.L.) | Fetching the title, description and preview image for a link you save — used only when Apple’s on-device LinkPresentation returns nothing for that URL. | The URL you saved. No account identifier is sent. | European Union |
| noembed.com | Title and thumbnail for a saved YouTube link, as a fallback when the primary lookup fails. | The video URL. No account identifier is sent. | United States |
| thum.io | A preview image for a saved LinkedIn link, when LinkedIn serves its image from a CDN that blocks direct loading. | The URL you saved. No account identifier is sent. | United States |
| PostHog, Inc. | In-app product analytics — screen views and feature events. Only runs if you turn on “Share Usage Analytics” in the app, which is off by default. | Pseudonymous hashed user ID, screen names, feature events, app + OS version. Not your library content. | European Union for devices in Europe, United States otherwise (chosen on the device) |
| Expo (650 Industries, Inc.) | Delivers over-the-air updates to the App. Contacted each time the App cold-starts, to ask whether a newer version of the App’s code is available. It receives no library content. | IP address, app and runtime version, update channel, platform | United States |
| Supabase Inc. | Stores the answers you give during onboarding — what you want to use Nemos for, and anything you type in those steps — so we can understand what people need. Not used for advertising and never sold. | Your onboarding answers and the identifier from Sign in with Apple | United States |
| Vercel Inc. (Nemos media-extraction endpoint) | Resolves the playable media URL for a video or reel you save, so the App can display it. Operated by us; retains nothing. | The URL of the video or reel you saved, and your IP address | United States |
| Google LLC (Google Analytics 4) | Aggregate web analytics — only with cookie consent | Pseudonymous cookie ID, page events | United States / EU (under SCCs) |
| PostHog, Inc. | In-app product analytics — opt-in only, aggregate feature-usage events | Pseudonymous install ID, screen + event names (no library content) | EU + US (routed by region: EU / UK → EU instance) |
| Supabase, Inc. | Onboarding / account-state backend | Apple ID hash, onboarding status + timestamps | United States (under SCCs) |
| Superwall, Inc. | Paywall presentation + subscription conversion | Anonymous app-user ID, paywall + subscription events | United States |
We will keep this list current. We will give reasonable advance notice of new sub-processors that materially change how we process personal data.
8.2 — Third parties that receive data because of something you saved. These are not our processors. We have no contract with them, we do not instruct them, and each decides for itself what it does with what it receives — every one is an independent controller, and its own privacy policy applies to it. We list them because that is the accurate description, and because the alternative — presenting them as contracted sub-processors — would not be true.
Why this happens: when you save a link, Nemos tries to show you a title, a description and a picture instead of a bare address. Apple’s on-device preview handles many links without contacting anyone but the site itself. When it cannot, we ask the service that hosts the link, or a preview service — and the URL you saved is what we have to send. A saved URL can reveal what you read, so this table is the real cost of rich previews, stated in full.
| Recipient | What it receives | When | Region |
|---|---|---|---|
| Google LLC | The hostname of a saved link (not the full URL), to fetch that site’s icon | Every time a link’s icon is shown | United States |
| Google LLC (YouTube) | The video ID of a saved YouTube link, for its title and thumbnail | Saving or displaying a YouTube link | United States |
| Google LLC (Maps) | A saved Google Maps short link, expanded to identify the place | Saving a Google Maps link | United States |
| Microlink, noembed, thum.io | The full saved URL, for a title, description and preview image | Saving a link Apple’s on-device preview cannot resolve | United States |
| linkpreview.net | The full saved URL | Fallback when earlier preview attempts fail | United States |
| X Corp. and community mirrors (fxtwitter, vxtwitter, Nitter) | The author handle and post ID of a saved X post | Saving an X/Twitter link | United States and community-operated |
| Meta Platforms (Instagram, Threads) | The full saved URL, or the post shortcode If you have signed in to that platform in Nemos, these requests carry your session, so they reach the platform as you rather than anonymously. | Saving an Instagram or Threads link | United States |
| ByteDance (TikTok) | The full saved TikTok URL If you have signed in to that platform in Nemos, these requests carry your session, so they reach the platform as you rather than anonymously. | Saving a TikTok link | United States / Singapore |
| Reddit, and the vxreddit mirror | The saved post URL, including subreddit and title slug | Saving a Reddit link | United States and community-operated |
| Bluesky Social | The author handle, then the resolved post identifier | Saving a Bluesky link | United States |
| Microsoft (LinkedIn) | The full saved LinkedIn URL | Saving a LinkedIn link | United States |
| The full saved pin or board URL | Saving a Pinterest link | United States | |
| Automattic (Tumblr) | The full saved Tumblr URL | Saving a Tumblr link | United States |
| Spotify, SoundCloud, Vimeo, Dailymotion, CodePen | The full saved URL for that service | Saving a link to that service | United States / European Union |
| Wikimedia Foundation (Wikipedia, Wiktionary) | Text you highlight while reading, to look up a definition or summary | Only when you ask for a definition or summary of a selection | United States |
| Internet Archive (Open Library) | A book’s title, author or ISBN, read from a book file you import | Importing an ebook, and displaying its cover | United States |
| Hugging Face | No content — a model download request, so your IP address and device type | First use of an on-device speech model | United States |
| Dropbox, Notion, GitHub, Google Drive | Only what that connection needs: your access token for that service, and where the provider issues one, a refresh token that keeps the connection working, and the files or pages you choose to import | Only if you connect that account, and only while it stays connected | United States |
Your IP address reaches each of these, because the request comes from your device rather than from a server of ours. That is the ordinary consequence of your device fetching something, and it is the same thing that happens when you open the link in a browser.
How to reduce it. Turning off link previews in Settings stops the largest and most frequent part of this: Nemos will keep your links without fetching a title, a description, a preview image or a site icon.
Being precise about what that switch does not cover, because a control described too broadly is its own kind of false claim. It does not affect: looking up a word or phrase you select (Wikimedia), reading a book file you import (Open Library), expanding a map link you save (Google Maps), downloading an on-device speech model (Hugging Face), or any account you have connected yourself. Those happen because you asked for that specific thing, and each is listed above. Items you saved before switching previews off keep the preview image and icon already stored on them, so those addresses are still loaded when the item is shown; deleting the item removes them.
9. Sharing and Disclosure
We do not sell, rent, or trade your personal data. We do not share it for cross-context behavioural advertising as defined under California law. We share data only as follows:
- With the sub-processors listed above, strictly to provide the App and the website;
- With Apple, for billing, subscription, and platform integration;
- With other Nemos users you choose to invite to a shared folder — they will see the contents of that folder until you revoke their access;
- With government, courts, or law enforcement, only when compelled by legally valid process, after meaningful review, and to the minimum extent required. We will challenge requests we believe are overbroad or unlawful;
- In the event of a corporate change (sale of the business, merger, succession of the sole proprietorship). We will give reasonable notice and your data will continue to be governed by a privacy policy at least as protective as this one;
- To protect rights and safety, where strictly necessary to investigate fraud, abuse, threats to physical safety, or violations of our Terms of Service.
10. Shared Folders
When you share a folder, the people you invite gain access to the items inside that folder for as long as the share is active. Sharing operates over Apple's CloudKit Shared Database — Nemos does not relay or copy the contents.
You can change a participant's permissions or revoke access at any time from inside the App. Once you revoke access, future updates are no longer visible to the former participant; copies they have already exported are outside our control.
A share link is a key, not an invitation. A folder you share is opened by anyone holding its link — iCloud does not ask us, or you, to approve each person, and the link does not check who they are. Someone you invited can forward it. Treat it the way you would treat a door key: send it to people you mean to let in, and stop sharing the folder if it goes further than you intended, which revokes it for everyone.
11. iOS Surfaces (Live Activities, Widgets, App Intents, Spotlight, Apple Watch)
To make Nemos useful on the lock screen and your wrist, we use a shared App Group container so the main App, the widget extension, the Live Activity extension, the Share Extension, and the Apple Watch companion can read and write the same data.
- Only Nemos targets that you have installed can read this container.
- Spotlight indexing donates an item's title and its text — for a screenshot, the text read out of the image; for a note, its body. That is what makes your library findable from the home screen, and it also means anyone who can unlock your device can find it there. iOS keeps that index on the device: it is not sent to us or to Apple. You can disable Spotlight indexing for Nemos at any time in iOS Settings → Siri & Search.
- App Intents (used by Siri, Shortcuts, and the new App Intents framework) run on-device and only invoke the operations you explicitly allow.
- The Apple Watch companion sends voice recordings to the iPhone (over Watch Connectivity) for transcription; the audio is not relayed off-device unless you have enabled cloud transcription.
What this puts on a locked screen. Widgets and Live Activities are designed to be readable without unlocking, so a reminder’s title, a note’s first lines, and an amount attached to a reminder can be visible to anyone holding your device. That is what makes them useful, and it is worth knowing before you put something private in a reminder. iOS controls this: Settings › Face ID & Passcode › Allow Access When Locked.
One thing the watch sends onward. The watch itself never transcribes and never talks to anyone but your iPhone. If you ask for a recording to be tidied into a particular format, the resulting text — never the audio — goes through the AI path described in section 6.
11A. The Nemos Keyboard, Clipboard History, and the Mac Menu Bar App
Three parts of Nemos read things you copy. They are the most sensitive surfaces in the product, so this section is unusually specific.
The Nemos keyboard (iPhone and iPad). If you add it in Settings and grant it Full Access, then each time you bring the keyboard up, it reads what is currently on your clipboard so it can offer it to you to paste. Text, images and files are all captured this way and become items in your clipboard history.
- The keyboard has no network access at all. It contains no networking code. It writes into the shared storage area Nemos and its extensions use on your device, and the main app is what later syncs that to your own iCloud.
- It skips anything a password manager marks as secret. Clipboard entries flagged as concealed, transient or auto-generated — the markers 1Password and others set — are ignored before their contents are read at all.
- It is entirely optional. Nemos works fully without it. Remove it in Settings › General › Keyboard, or leave Full Access off, and none of the above happens.
The Mac menu bar app. If you use Nemos on a Mac and enable the menu bar app, it watches two things: the macOS clipboard, so copies reach your library the way they do on iPhone; and the folders where macOS saves screenshots (your Desktop and Pictures/Screenshots), so a screenshot you take can be captured. It honours the same password-manager markers as the keyboard, and skips very large clipboard payloads rather than syncing them inline.
Where clipboard history goes. A saved clip also records which app it was copied from and which device copied it, so you can recognise it later. Clipboard items are otherwise ordinary Nemos items. They live on your device and in your own iCloud, in the same private database as the rest of your library. We do not receive them — we operate no server that stores library content. You can delete any clipboard item, and turn clipboard capture off, in Nemos.
A clipboard can hold passwords, verification codes, and text from every other app on your device. We would rather over-explain this than have you discover it. If any of the above is more than you want, the keyboard and the menu bar app are both separate, optional components and Nemos is complete without either.
12. Cookies and Online Tracking (Website Only)
The Nemos iOS / iPadOS / watchOS App uses no cookies for tracking or analytics. There is one exception, and it is not tracking: if you sign in to Instagram or TikTok to let Nemos open a video you saved, that sign-in leaves a session cookie on your device, described in section 4.5.
The website at nemosapp.com uses:
- Strictly necessary cookies for the waitlist form and abuse prevention. These cannot be disabled, are session-only or short-lived, and contain no personal identifiers beyond what is needed for the request.
- Analytics cookies (Google Analytics 4) — only after you accept the cookie banner. We load no analytics or advertising script that can identify you before you consent. One exception, stated because the sentence would otherwise be untrue: our host inserts a cookieless page-view counter on every visit, which sets nothing on your device and cannot identify you. You can withdraw consent at any time by clicking "Cookie preferences" in the website footer.
We do not load advertising cookies, social-media tracking pixels, or fingerprinting libraries on the website.
13. Apple App Tracking Transparency (ATT)
Nemos does not "track" you in the sense defined by Apple's App Tracking Transparency framework. We do not link information collected from the App with information from third-party apps or websites for advertising or advertising-measurement purposes, and we do not share device identifiers with data brokers. The App therefore does not display the ATT prompt — there is no tracking we could ask permission for.
14. Data Retention
We retain personal data only as long as is necessary for the purpose for which it was collected, or as required by law:
- Your library content: retained on your device and in your iCloud until you delete it. Items moved to "Recently Deleted" are erased automatically after 30 days.
- Waitlist email: retained until you unsubscribe (every email contains a one-click unsubscribe link) or you ask us to delete it.
- Subscription events (RevenueCat): retained for the life of your subscription plus 7 years for tax / accounting purposes (or longer if a longer period is required by law).
- Crash reports (Sentry): retained for up to 90 days, then permanently deleted.
- Aggregate / pseudonymous analytics: retained in non-identifiable form indefinitely for trend analysis.
- Server logs (Cloudflare, Resend): retained for up to 30 days for security and abuse-prevention purposes.
- Records related to a legal claim: retained for the duration of the limitation period applicable to the claim.
15. International Data Transfers
The data controller is established in the Kingdom of Morocco. Some of our sub-processors are located in the United States, the United Kingdom, and the European Economic Area. When personal data leaves your country, we rely on lawful transfer mechanisms:
- For transfers from the EEA, the UK, or Switzerland to a third country: the European Commission's Standard Contractual Clauses (with the UK Addendum / Swiss recognition where applicable), supplemented by technical safeguards (encryption in transit and at rest, access controls);
- For transfers from Morocco to a third country: compliance with Moroccan Law n° 09-08 and any prior authorisations or transfer mechanisms required by the Commission Nationale de contrôle de la protection des Données à caractère Personnel (CNDP).
You can request a copy of the safeguards in place by emailing [email protected].
16. Account Deletion
You can delete your Nemos account and the data associated with it from inside the App at any time:
- Open the App;
- Go to Settings → Danger Zone → Delete Account;
- Confirm the deletion.
Account deletion immediately, from inside the app and without contacting us:
- Signs out of Sign in with Apple and deletes the stored credential on this device. We cannot revoke the connection for you — only Apple can, and only from your device: Settings › your name › Sign in with Apple › Nemos › Stop Using Apple ID. We would rather point you there than imply we did it;
- Erases what is stored locally on that device: the app’s databases, its Keychain entries, the screenshots, recordings and thumbnails on disk, and the session left behind if you signed in to Instagram or TikTok. Two things it does not reach, because they are outside the app: a backup you saved to your own iCloud Drive, and a copy of your library left in the iCloud container an older version of Nemos used. Ask us and we will walk you through removing both;
- Deletes your CloudKit records — the private zone is deleted and recreated, and shared folders you own are unshared. The App then reads the zone back and reports a failure to you if anything remains, rather than reporting success it has not verified.
Three further deletions cannot be performed from your device, because each requires a secret key that would be extractable if it shipped inside the app. We do them on request, and we do not make you justify the request:
- Deleting your subscriber record at RevenueCat;
- Removing your address from the website waitlist database, if you ever joined it;
- Deleting diagnostic events already sent to Sentry (Sentry's own deletion timelines apply, and can take up to 90 days).
Email [email protected] from the address you used, or from any address quoting your email address you used, and we will complete these and confirm in writing within 30 days — the GDPR deadline — and usually far sooner. An earlier version of this Policy listed all three as automatic parts of in-app deletion. They were not, and we would rather correct that than leave it standing.
If your subscription is still active, deleting your account does not automatically cancel the subscription — you must cancel through Apple (Settings → Apple ID → Subscriptions). See section 8 of the Terms of Service.
You can also request deletion by emailing [email protected]. We will verify your identity and complete the deletion within 30 days (or sooner if required by applicable law).
17. Your Rights
17.1 Rights available to all users
- Access — view what we hold and how we use it;
- Correction — fix inaccurate data;
- Deletion — delete your account and personal data (see section 16);
- Export — export your library at any time from the App;
- Withdraw consent — for any processing based on your consent.
17.2 EEA, UK, and Switzerland (GDPR / UK GDPR / FADP)
You have the rights of access, rectification, erasure ("right to be forgotten"), restriction of processing, data portability (for data you provided based on contract or consent and processed by automated means), objection (including a general right to object to processing based on legitimate interests), and not to be subject to a decision based solely on automated processing producing legal or similarly significant effects.
Our legal bases for processing are:
- Performance of a contract (GDPR Art. 6(1)(b)) — to provide the App and the subscription you have purchased;
- Legitimate interests (Art. 6(1)(f)) — to keep the App secure, prevent fraud, and improve reliability, balanced against your rights and freedoms;
- Consent (Art. 6(1)(a)) — for cookies / analytics on the website and any optional opt-in features clearly labelled as such;
- Legal obligation (Art. 6(1)(c)) — to comply with tax, accounting, and law-enforcement obligations.
You have the right to lodge a complaint with your supervisory authority (in the EEA, that is the data-protection authority of your member state of residence; in the UK, the Information Commissioner's Office; in Switzerland, the FDPIC).
17.3 California (CCPA / CPRA)
California residents have the right to know what personal information we collect, use, disclose, and (if applicable) sell or share; the right to delete personal information; the right to correct inaccurate personal information; the right to opt out of the sale or sharing of personal information for cross-context behavioural advertising — we do not sell or share personal information as defined by California law; the right to limit the use of sensitive personal information — we do not use sensitive personal information for purposes that trigger this right; and the right to non-discrimination for exercising these rights.
To exercise these rights, email [email protected]. You may also designate an authorised agent. We will verify your identity by matching the email or Apple ID identifier on file.
17.4 Other US states (Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Iowa, Indiana, Tennessee, Delaware, New Hampshire, New Jersey, Minnesota, Maryland, Rhode Island, and others)
If you reside in a US state with a comprehensive privacy law, you generally have rights to access, correct, delete, and obtain a portable copy of your personal data, and to opt out of targeted advertising, sale, and certain forms of profiling. We do not engage in targeted advertising, sale, or profiling that produces legal effects. To exercise any state-law right, email [email protected].
17.5 Morocco (Law n° 09-08)
If you are in Morocco, you have the rights of information, access, rectification, and opposition under Law n° 09-08. You may also lodge a complaint with the CNDP (Commission Nationale de contrôle de la protection des Données à caractère Personnel).
17.6 Brazil (LGPD)
Data subjects in Brazil have the rights established under Articles 17–22 of the LGPD, including confirmation, access, correction, anonymisation, blocking, deletion, portability, information about sharing, and revocation of consent.
We respond to verifiable rights requests within 30 days, or sooner where the law where you live requires it — Brazil's LGPD gives us 15 days for an access request, and we treat the shortest applicable deadline as the one that governs, not the longest. We do not charge a fee for a rights request. If a request is manifestly unfounded or repetitive we may charge a reasonable administrative fee or decline it, in which case we will tell you which, and why, in writing — and you may appeal (see 17.10). We may need to ask for additional information to verify your identity. Where you exercise your rights through an authorised agent, the agent must demonstrate that you have authorised them to act.
17.7 Canada (PIPEDA and Quebec Law 25)
If you are in Canada, the Personal Information Protection and Electronic Documents Act (PIPEDA) applies, and if you are in Quebec, so does the Act respecting the protection of personal information in the private sector as amended by Law 25. You may access the personal information we hold about you, ask us to correct it, withdraw a consent you previously gave, and complain to the Office of the Privacy Commissioner of Canada or, in Quebec, to the Commission d’accès à l’information.
Quebec’s Law 25 additionally requires that the person accountable for personal information be identified by name. That person is Taha Baalla, reachable at [email protected]. Law 25 also grants a right to data portability: on request we will provide the personal information you gave us in a structured, commonly used technological format. In practice the App already does this for your library — Settings → Storage & Backup exports it without going through us at all.
We do not use your personal information for automated decision-making that produces a legal or similarly significant effect, so the Law 25 right to be informed of such a decision does not arise. If that ever changes, we will say so here before it does.
17.8 India (Digital Personal Data Protection Act, 2023)
If you are in India, you may ask us for a summary of the personal data we process and the processing activities involved, ask for correction, completion, updating or erasure, and nominate another person to exercise your rights in the event of your death or incapacity.
Grievance redressal. The DPDP Act requires an accessible grievance mechanism and that you use it before approaching the Data Protection Board. Send grievances to [email protected] with “DPDP grievance” in the subject line. We will acknowledge within 7 days and respond substantively within 30. The grievance officer is Taha Baalla.
Age. The DPDP Act treats anyone under 18 as a child and requires verifiable parental consent before processing their data. Our minimum age is 13 (16 in the EEA), which is lower than that threshold. We therefore do not knowingly offer Nemos to users under 18 who are in India without verifiable parental consent, and a parent or guardian who believes their child is using Nemos should contact us at the address above and we will delete the account and its data.
17.9 Japan, South Korea, Australia and New Zealand
- Japan (Act on the Protection of Personal Information): you may request disclosure, correction, suspension of use, or deletion. We do not provide personal data to third parties for their own purposes, so the opt-out and record-keeping duties attaching to third-party provision do not arise.
- South Korea (PIPA): you may request access, correction, suspension of processing, and deletion, and you may withdraw consent at any time. Where PIPA requires separate consent for distinct purposes, the App asks separately — cloud AI, analytics and cloud transcription each have their own switch, and each is off or on independently of the others.
- Australia (Privacy Act 1988 and the Australian Privacy Principles) and New Zealand (Privacy Act 2020): you may request access to and correction of your personal information, and complain to the OAIC or the New Zealand Privacy Commissioner respectively. We do not rely on the Australian small-business exemption; we apply the APPs to Australian users regardless of our size.
17.10 How to exercise a right — and how to appeal if we say no
Making a request. Email [email protected] and tell us what you want. You do not need to use a particular form of words or cite a statute; “please delete my data” is a valid request everywhere this policy applies. Most of what you might ask for you can also do yourself inside the App, immediately and without contacting us: export from Settings → Storage & Backup, and delete from Settings → Danger Zone.
Verifying who you are. We ask for enough to be reasonably sure the request comes from you, and no more — for most requests, that you write from the email address associated with your account, or quote the email address you signed up with. We will not ask you to create an account, send identity documents, or provide any information we do not already hold, purely to make a request. Information you send us for verification is used only for that purpose and deleted afterwards. If we genuinely cannot verify you, we will say so and explain what would satisfy us rather than simply refusing.
Authorised agents. Someone may make a request on your behalf. We will ask for written authorisation signed by you, and may contact you to confirm it.
Appeals. If we refuse a request, in whole or in part, we will tell you the reason in writing and you may appeal by replying with “Appeal” in the subject line. A refusal is not the end of the matter: we will reconsider and give you a written decision within 45 days, and if we still refuse we will explain why and tell you how to complain to your regulator. Virginia, Colorado, Connecticut, Montana, Texas, Oregon, Delaware, New Jersey, Minnesota, Maryland and other US state privacy laws each require this appeal path, and we extend it to everyone rather than only to residents of those states.
Complaining to a regulator. You may complain to your supervisory authority at any time, and you do not have to come to us first — though we would rather you did, because we can usually fix it faster. In the EEA that is your national data protection authority; in the UK the Information Commissioner’s Office; in Switzerland the FDPIC; in Morocco the CNDP; in Canada the OPC or the CAI in Quebec; in Brazil the ANPD; in India the Data Protection Board; in Australia the OAIC. Under the CCPA you may also complain to the California Privacy Protection Agency or the California Attorney General.
No retaliation. We will not degrade the App, change your price, or refuse you service because you exercised a privacy right.
18. Children's Privacy
Nemos is rated 4+ on the App Store but is not directed at children. The App is intended for users aged 13 and older (16 or older in the EEA, where the digital-consent age in your country is 16). We do not knowingly collect personal data from children below the applicable digital-consent age without verifiable parental or guardian consent.
If you are a parent or guardian and you believe your child has provided personal data to us without your consent, please contact [email protected] and we will delete that data. We comply with the US Children's Online Privacy Protection Act (COPPA) and Article 8 GDPR.
19. Security
We protect personal data with safeguards proportionate to the risk. We describe them precisely, and we deliberately do not list controls we have not implemented — a security claim you cannot verify is worse than no claim, because it is the one a regulator can test:
- Transport security. TLS 1.2 or higher is required for every connection the App makes. This is enforced at the operating-system level through App Transport Security, which also requires forward secrecy and Certificate Transparency for the domains we contact. We do not implement certificate pinning, and we do not claim to.
- Encryption at rest, on the device. On iPhone and iPad, the App’s local key-value store is encrypted with a key held in the device Keychain. On a new installation that key is generated on the device and is unique to it; installations upgraded from an earlier version continue to use the key that version shipped with, because changing it would make their existing data unreadable. Files in the App sandbox are protected by iOS Data Protection at the level iOS applies by default, which unlocks after the first unlock following a restart rather than remaining locked whenever the device is locked. On Mac, the local store falls back to an unencrypted store because the encrypted implementation is not yet reliable on that platform; the file remains inside the App’s sandbox container and is covered by macOS FileVault where you have it enabled.
- Encryption in iCloud. Your library is stored in your own iCloud account and encrypted by Apple, in transit and at rest. Apple holds the keys for standard iCloud protection, which means it is not end-to-end encrypted unless you have Advanced Data Protection enabled on your Apple Account. We do not describe Nemos as end-to-end encrypted, because for most accounts it is not.
- Credentials. Sign-in credentials and third-party access tokens are held in the Apple Keychain, not in ordinary App storage. One kind is not: if you sign in to Instagram or TikTok, the resulting session is a cookie held by the system web view, because that is the only place a web sign-in can live. Deleting your account erases it.
- App Lock. Face ID, Touch ID or your device passcode can gate access to the App.
- Our own infrastructure. We operate two servers, neither of which stores your library. A request proxy holds our AI provider keys so they are not shipped inside the App and forwards AI requests upstream. A small extraction endpoint resolves the media URL for a video or reel you save, so the App can show it. Both see the request as it passes and neither retains its contents.
- Maintenance. Dependencies and code are reviewed on an ongoing basis, and automated checks run before each release.
We have not commissioned a SOC 2 audit, an ISO 27001 certification, or an external penetration test, and we do not claim any. If that changes we will say so here with the date and scope.
No system can be guaranteed 100% secure. If we become aware of a personal-data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours where required by law, and notify affected users without undue delay where the breach is likely to result in a high risk.
20. Beta and TestFlight
Until the App is available on the App Store, it is distributed through Apple's TestFlight programme as a pre-release beta. Beta versions may contain bugs, may collect additional diagnostic data, and may be discontinued at any time. Apple's TestFlight terms apply in addition to this Privacy Policy.
21. Third-Party Services and Links
The App allows you to save content from third-party websites, services, and apps. Those services have their own privacy practices. We are not responsible for them and recommend you review their policies before saving sensitive content.
22. Automated Decision-Making and Profiling
We do not subject you to decisions based solely on automated processing — including profiling — that produce legal or similarly significant effects on you. AI features in the App help you organise your library; they do not make decisions about your rights, eligibility, or access to services.
23. Do-Not-Track and Global Privacy Control
We honour the Global Privacy Control (GPC) browser signal as a valid request to opt out of any sale or sharing of personal information. Because the App and the website do not sell or share personal information, GPC has no incremental effect, but the signal is treated as authoritative for any future processing that could be regarded as sale or sharing.
24. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes, we will:
- Update the "Last updated" and "Effective date" lines at the top of this page;
- Notify you in-App or by email at least 30 days before the changes take effect, where the change is material and where we have your contact information;
- Where required by law, obtain your renewed consent before the new processing begins.
If you do not agree to the updated policy, you must stop using the App and may exercise your rights under section 17.
25. Browser Extension (Nemos: Save Anything)
This section describes the Nemos: Save Anything browser extension for Chrome, Edge, Firefox, Safari, Brave, Opera, and other compatible browsers. The extension is a web clipper: it saves the pages you explicitly choose into your own private iCloud library. It is covered by this Policy under the scope in section 3.
25.1 What it saves, and where
- When you click save, the extension captures the page's title, URL, preview image, and — for "Save as Article" — a clean copy of the article text, and writes it directly from your browser to your own private iCloud database through Apple's CloudKit Web Services. We never receive, store, or proxy a copy.
- The extension reads page content only on a page you actively choose to save. It does not read, log, monitor, or transmit the pages you merely visit.
25.2 Sign-in
You sign in with your Apple ID on Apple's own sign-in page; the extension never sees your Apple password. After sign-in, Apple returns a CloudKit web-authentication token to a small callback page on nemosapp.com that we operate — so the token appears in one request to our website before it reaches your browser. We do not record it. The extension then stores it locally in browser storage and uses to read and write your iCloud library. The token is removed when you sign out or uninstall the extension.
25.3 Permissions
- activeTab / scripting — read the current page and run the article extractor, only when you click save.
- storage — keep your iCloud token, theme preference, and folder cache on your device.
- tabs — complete sign-in (detect and close the Apple sign-in callback tab) and open the library page.
- contextMenus — add a "Save to Nemos" right-click item.
- alarms — a timer, roughly every four hours, that refreshes your iCloud sign-in so saving does not fail with an expired token. It contacts Apple and nobody else.
- sidebar / side panel — show your saved library beside the page you are reading.
- Host access — the extension requests access to all HTTPS sites, because a browser cannot express "only the page the user is saving, at the moment they save it". What limits it is behaviour, not the grant: it is present on every page and does nothing until you press save to save, and reach Apple CloudKit (
api.apple-cloudkit.com), which is the storage backend.
25.4 No third parties, no tracking
- The extension sends your saved content only to your own iCloud (Apple CloudKit). It uses no analytics, no tracking, no advertising, no fingerprinting, no profiling, and no crash or telemetry reporting in the builds we publish — the code contains an error reporter that ships switched off, and if we ever turn it on we will say so here before we do, and it never shares your data with the developer, an advertiser, or a data broker. The developer operates no server that receives your saved content and collects nothing from the extension.
- To render a link preview, the extension may request the page you saved in order to read its public preview image and title — that is a request to the website you chose to save, not to us.
- We — the developer — operate no server that receives your saved content, and we collect nothing from the extension.
In the data categories used by browser stores, the extension handles website content (the pages you save) and authentication information (your iCloud sign-in) — both strictly required for its core function and both transmitted only to your own iCloud. Uninstalling the extension removes all of its local data; your saved items remain in your iCloud until you delete them in the Nemos app or from your iCloud.
26. Contact
For privacy questions, rights requests, or to report a concern:
Taha Baalla — Nemos
Privacy: [email protected]
General: [email protected]
Postal correspondence: available on request to the email above.
If you are in the EEA, the UK, or Switzerland and you are not satisfied with our response, you have the right to lodge a complaint with your local data-protection authority. If you are in Morocco, you may lodge a complaint with the CNDP at cndp.ma.
