Niv Privacy Policy

Effective date: October 7, 2026

The short version

  • Your notes are Markdown files on your Mac. If you never sign in, they never leave it.
  • If you connect a folder to a Space, Niv stores and syncs that folder’s notes on our servers so your devices and the people you invite can work on them.
  • If you publish a note, it is public on the web, and search engines can find it.
  • We don’t sell your data. We don’t share it for advertising. We don’t use your notes to train AI models.
  • The AI chat in the desktop app runs the AI tool you installed (Claude Code, Codex, and others) on your Mac, under your own account. Niv doesn’t see those conversations.
  • Niv also processes your synced notes on its servers for search: it creates search “fingerprints” (embeddings) of them using OpenAI’s API, for semantic search used by Niv’s integrations such as the MCP server. More in section 3.
  • Niv may offer paid AI features of its own later, under separate terms. We’ll update this policy before they launch.
  • The app sends us usage counts (which features get used, how long things take). Never your note titles, file names or text.
  • You can ask us for a copy of your data, to fix it, or to delete it at any time: hey@niv.md.

The rest of this page says the same thing in full.

1. Who we are

Niv is run by GABRIEL ARAUJO RUDY CONSULTORIA EM TECNOLOGIA DA INFORMACAO, an individual entrepreneur business (Empresário Individual, ME) registered in Brazil under CNPJ 48.868.347/0001-87, with its registered office at Avenida Prefeito Osmar Cunha, 416, Sala 1108, Centro, Florianópolis/SC, CEP 88015-100, Brazil (“Niv”, “we”, “us”).

We decide why and how your personal data is used, so we are the controller (under Brazil’s LGPD and the EU/UK GDPR) and the business (under US state privacy laws).

Contact for anything in this policy: hey@niv.md.
Data protection officer (Encarregado, LGPD art. 41): Gabriel Araujo, at hey@niv.md.

This policy covers the Niv desktop app, the website at niv.md (including published notes at niv.md/p/…) and Niv’s sync and collaboration service (together, “the Service”).

2. What we collect, and why

2.1 Your account

When you sign in, we collect:

  • Your email address. You sign in with a one-time code or a link we email you, or with Google or GitHub.
  • From Google or GitHub, if you use them: your name, email address, profile picture link and your account ID with that provider. We also keep the sign-in tokens the provider gives us. We don’t get your password.
  • Sign-in sessions: a session token, when it expires, the IP address and the device/browser description (user agent) of the sign-in.
  • One-time codes and links, which expire after a few minutes.

Why: to create your account, sign you in, keep it secure and contact you about it.
Legal basis: performing our contract with you (LGPD art. 7, V; GDPR art. 6(1)(b)). Keeping session IP and device data for security relies on our legitimate interest in protecting accounts (LGPD art. 7, IX; GDPR art. 6(1)(f)).

On your Mac, the desktop app keeps your session token in the macOS Keychain, not in a plain file.

2.2 Your notes, when you sync

Niv works on a folder of Markdown files on your Mac. Nothing in that folder is sent to us until you sign in and connect the folder to a Space. After that, we store on our servers:

  • The content of your notes, as the live document that keeps every device in step, plus a readable copy.
  • Structure: note titles, folders, file names, emoji, links between notes, tags and properties you write, and when things were created, moved, renamed, trashed or restored (a structural log that lets you undo changes).
  • Version history: the edits that make up each note’s history, and who made each change, so you can see and restore earlier versions.
  • Images you add to notes, stored in our file storage. Anyone who has the link to an uploaded image can open it, so treat image links like the note itself.
  • Space details: the Space’s name, its address (slug), its members and their roles, and settings for daily notes, templates and recurring notes.
  • Which days you wrote (used for the streak and calendar on Home).

Files you mark as local-only (and AGENTS.md and CLAUDE.md, which are local-only by default) are never uploaded.

Why: to sync your notes between your devices, let the people in your Space work with you, show history and recover mistakes.
Legal basis: performing our contract with you (LGPD art. 7, V; GDPR art. 6(1)(b)).

What other people in a Space see. Everyone who is a member of a Space can read and edit its notes, see who else is a member (name, email, picture), see who is working in a note right now, and see who changed what in the history. Only invite people you trust with that Space’s content.

Notes about other people. If your notes contain personal data about others, you decide what goes in them. We store and sync it on your behalf; you are responsible for having the right to keep it.

Sensitive information. We don’t ask for sensitive data (health, religion, political views and similar). If you write it in a note that you sync, we store it only to provide the Service, like any other note.

2.3 Published notes

When you publish a note, its title, emoji, cover image, content and publish date become public at niv.md/p//. The address includes your Space’s name. Published notes are listed in our public sitemap so search engines can find and index them, and they come with a preview image for links shared on social media. Your name and email are not shown on the page.

You can unpublish at any time. The page then stops being served, but copies already made by search engines, archives or other people are outside our control.

Legal basis: performing our contract with you, at your request (LGPD art. 7, V; GDPR art. 6(1)(b)).

2.4 The AI chat in the desktop app

The desktop app’s AI chat and inline edits run an AI tool you installed on your Mac — today Claude Code, Codex, Cursor, Grok, OpenCode or Antigravity — signed in with your own account with that provider. What you type, and any notes the tool reads, go from your Mac to that provider under its terms and privacy policy, not ours. Niv does not receive those prompts or answers.

This is separate from what Niv itself does with your synced notes on its servers (section 3). Niv may also offer its own AI features later, including paid ones, under separate terms; we will update this policy before they launch.

To let that tool read a Space you choose, the app can give it a short-lived (5-minute) read-only access key to that Space.

We do count, without content, that a chat message was sent, which provider and model were picked, and whether an install worked (see 2.6).

2.5 The waitlist

If you join the waitlist for a platform Niv doesn’t support yet, we keep your email, the platform (Windows, Linux, iOS, iPadOS or Android), the site language you used and the date. We use it only to tell you when Niv arrives on that platform.
Legal basis: your consent (LGPD art. 7, I; GDPR art. 6(1)(a)). You can leave the list at any time by emailing hey@niv.md.

2.6 Usage data from the desktop app

The desktop app sends us two kinds of technical data:

  • Product events: a short, fixed list of things that happened, such as “AI chat opened”, “Space opened” or “install finished”, with counts, durations, on/off values and choices from a fixed list (for example, which AI provider). Each event carries a random ID for your device, and your Niv account ID once you sign in, the app version, macOS, and your Space’s ID.
  • Error and performance logs: what went wrong and how long things took.

These are built so that nothing you wrote can be included: no note titles, file names, folder names, note text or prompts. Values that aren’t on an approved list are dropped before anything is sent.

As with any internet request, our analytics provider receives your IP address when the app sends data.

Why: to find bugs, see which features are used and make the app faster.
Legal basis: our legitimate interest in keeping the app working and improving it (LGPD art. 7, IX; GDPR art. 6(1)(f)). You can object at any time by writing to hey@niv.md.

2.7 The website

  • Cookies we always use (necessary): a language cookie (niv-locale, one year) that remembers English or Portuguese, and, when you sign in on niv.md, a sign-in session cookie. The site also keeps your chosen look in your browser’s local storage and the sign-in step in session storage. These never leave your browser except to make the page work.
  • Analytics:
    • Before you choose, or if you choose “Reject”: we only count page views without cookies and without identifying you.
    • If you choose “Accept”: our analytics provider (PostHog) sets cookies and records how you use the site — pages, clicks and sessions — including heatmaps and session recordings. Recordings mask everything you type, and the sign-in page is never recorded. Recordings are kept for 30 days.
    • Every visitor is asked, whatever the browser sends. If your browser sends Global Privacy Control or Do Not Track, analytics stays at “Reject” until you choose “Accept”.
    • You can change your choice at any time with the Cookies link at the bottom of every page. Legal basis: your consent (LGPD art. 7, I; GDPR art. 6(1)(a)) for analytics cookies and recordings; legitimate interest for cookieless page counts.
  • Server logs: our hosting and network providers record requests (IP address, time, page, browser) to run and protect the site.

2.8 Email

We email you to sign you in and, when needed, about your account, security or changes to this policy. We don’t send marketing email without your consent.

2.9 Security and abuse prevention

To stop abuse (for example, someone trying thousands of sign-in codes), we briefly keep your IP address or account ID in a counter that resets within an hour. Our servers also keep technical logs, which can include your account ID, email address (when an account is created) and IP address.
Legal basis: legitimate interest in security (LGPD art. 7, IX; GDPR art. 6(1)(f)), and complying with law where required (LGPD art. 7, II; GDPR art. 6(1)(c)). Brazilian law (Marco Civil da Internet, Law 12,965/2014, art. 15) requires us to keep application access logs — IP address, date and time — for at least 6 months.

2.10 Content loaded from other services

Some things in the app load directly from other companies, which then see your IP address:

  • Cover images from Unsplash, if you choose one.
  • Videos you embed (for example, YouTube), when you play them.
  • App updates, checked and downloaded from releases.niv.md (served by Cloudflare).

3. Search fingerprints (embeddings)

When a note in a Space changes, our servers create embeddings — lists of numbers that represent what the text is about — of the note’s title and text, and store them with the note. Their purpose is semantic search across your synced notes, used by Niv’s integrations such as the MCP server (which lets an AI tool you authorize search the Spaces you choose). A background job run by Trigger.dev (US) picks up recently changed notes and sends the full title and text to OpenAI’s API (US), which creates the embeddings. Both act as our service providers. Under OpenAI’s API terms, this data is not used to train OpenAI’s models and is kept by OpenAI for a limited time for abuse monitoring.

Embeddings are replaced when the note changes and deleted when the note is permanently deleted.

Legal basis: performing our contract with you (LGPD art. 7, V; GDPR art. 6(1)(b)).

4. What we don’t do

  • We don’t sell your personal data, and we don’t share it for cross-context behavioral advertising (as those words are defined in California law).
  • We don’t use your notes to train AI models, and we don’t let our providers do so.
  • We don’t make decisions about you based only on automated processing that have legal or similarly significant effects.
  • Niv doesn’t process payments today.

5. Who we share data with

We share data only with:

  • Service providers that run parts of Niv for us, under contracts that limit them to our instructions:
Provider What they do Data Where
Railway Hosts our servers, database and cache Everything in section 2.1–2.3, 2.5, 2.9 United States (US East)
Cloudflare Website hosting, DNS, file storage for images and app downloads Website requests, uploaded images, download requests Global network; storage in the US
Resend Sends sign-in emails Email address, sign-in code or link United States
PostHog Product analytics, logs, website analytics and recordings Data in 2.6, 2.7, 2.9 United States
Trigger.dev Runs background jobs (history clean-up, search indexing) Note content and metadata while a job runs United States
OpenAI Creates embeddings (section 3) Note titles and text United States
Google, GitHub Sign-in, if you choose them What’s described in 2.1 United States
  • Other members of your Space, as described in 2.2, and everyone, for notes you publish.
  • Authorities, when the law requires it, or to protect the rights, property or safety of our users, the public or Niv.
  • A buyer or successor, if Niv’s business is transferred. We’d tell you first, and this policy would keep applying to your data.

6. International transfers

Niv is run from Brazil, and our servers and providers are mostly in the United States. So your data is transferred to the US, wherever you live.

  • From Brazil, we rely on transfers necessary to perform our contract with you at your request (LGPD art. 33, V) and on contracts with our providers, including the ANPD standard contractual clauses where our providers offer them (LGPD art. 33, II, b).
  • From the EU, EEA, UK or Switzerland, we rely on the European Commission’s (or UK) standard contractual clauses, or on a provider’s certification under the EU-US Data Privacy Framework where it has one, plus the safeguards in our providers’ contracts.

Ask us at hey@niv.md for more about these safeguards.

7. How long we keep data

Data How long
Account and profile While your account exists. Deleted within 30 days after you ask us to delete it.
Notes, structure, images and Space data While the note or Space exists. Trashed notes stay in the trash until purged; everything goes when your account or the Space is deleted.
Detailed version history 90 days in full detail; older history is merged into a single starting version of the note.
Embeddings Until the note is changed or deleted.
Published pages Until you unpublish or delete the note.
Sign-in sessions Until they expire (about 7 days unless renewed by use) or you sign out.
Sign-in codes and links Minutes.
Abuse counters Up to 1 hour.
Server and app logs [6 months]
Product events (desktop) [24 months]
Website session recordings 30 days.
Waitlist Until the platform launches and we’ve told you, or until you ask to leave; at most [24 months].
Messages you send us [3 years] after the conversation ends, to handle follow-up and legal claims.

Backups can keep deleted data for up to [30 days] before they roll over.

8. Your rights

Wherever you live, you can ask us to:

  • confirm whether we process your data, and access it;
  • correct it;
  • delete it (including your whole account), or anonymize or block data that is unnecessary;
  • give you a copy in a portable format;
  • tell you who we shared it with;
  • withdraw consent, where we rely on it, without affecting what we did before;
  • object to processing based on legitimate interest, such as product analytics;
  • have a person review decisions made only by automated processing (we make none).

Your notes are already yours in an open format: the Markdown files on your Mac are the copy you keep, whatever happens to your account.

How: email hey@niv.md from the address on your account. We may ask you to confirm it’s you. We’ll answer within 15 days, and sooner where the law requires. We don’t charge for requests. If you are unhappy with our answer, you can complain to your data protection authority (see section 9).

You can also delete a Space’s notes from inside the app.

9. Where you live

Brazil (LGPD)

You have all the rights in LGPD art. 18, including information about the consequences of refusing consent and about the public and private entities we share data with. You may complain to the Autoridade Nacional de Proteção de Dados (ANPD) at gov.br/anpd, after contacting us first. Our encarregado is Gabriel Araujo, at hey@niv.md. As a consumer you can also turn to consumer protection bodies (Procon, consumidor.gov.br).

United States — California and other states

This section is the notice required by the California Consumer Privacy Act as amended (CCPA) and similar laws in other US states (such as Colorado, Connecticut, Virginia, Texas and Oregon), to the extent they apply to Niv.

Categories collected in the last 12 months (and where from, why, and who receives them, as described above):

Category (CCPA) Examples Source Disclosed for a business purpose to
Identifiers Name, email, account ID, IP address, device ID You, your device, Google/GitHub Service providers in section 5
Customer records Email, name You Service providers
Internet or network activity App usage events, logs, website interactions and recordings (with consent) Your device, your browser Service providers
Approximate location Inferred from IP address Your device Service providers
Content of your notes and files Notes, images, history You Service providers; Space members; the public, if you publish
Inferences None — —
Sensitive personal information Account sign-in credentials (sign-in session). We do not use sensitive personal information to infer characteristics about you. You Service providers
  • Selling and sharing: we have not sold or shared personal information in the last 12 months, and we don’t knowingly sell or share data of anyone under 16.
  • Global Privacy Control: we honor GPC as a request to opt out: the website keeps analytics at “Reject” unless you choose “Accept”.
  • Your rights: to know, delete, correct, opt out of sale or sharing, and limit use of sensitive personal information (which we only use as permitted). We won’t treat you differently for using them.
  • Authorized agents: someone you authorize can make a request for you; we may ask for proof of the authorization and to verify your identity directly.
  • Appeals: if we refuse a request, you can appeal by replying to our answer. If you’re still unhappy, you can contact your state attorney general.
  • Retention: see section 7.

European Economic Area, United Kingdom and Switzerland

Our legal bases are listed in section 2. You have the rights in section 8, including the right to restrict processing, and to complain to your local data protection authority. Niv does not have a representative in the EU or UK.

10. Security

We use encryption in transit (HTTPS/TLS) everywhere, keep your desktop sign-in in the macOS Keychain, limit who can access production systems, and keep the data our app sends about usage free of your content by design. No system is perfectly secure; if a breach affects you, we’ll tell you and the authorities as the law requires (including LGPD art. 48).

11. Children

Niv is not for children under 13. You must be at least 13 to use Niv, and at least 16 in the EEA or UK where local law sets that age for consent. If you are under 18, you need permission from a parent or guardian.

We don’t knowingly collect personal data from children under 13. If we learn that we have, we’ll delete it. If you believe a child under 13 has given us data, write to hey@niv.md.

12. Changes to this policy

When we change this policy, we’ll update the date at the top. If a change matters — new uses of your data or new kinds of data — we’ll tell you in the app or by email before it takes effect, and ask for your consent where the law requires it.

13. Contact

GABRIEL ARAUJO RUDY CONSULTORIA EM TECNOLOGIA DA INFORMACAO (Niv)
CNPJ 48.868.347/0001-87
Avenida Prefeito Osmar Cunha, 416, Sala 1108, Centro, Florianópolis/SC, CEP 88015-100, Brazil
hey@niv.md

  • Privacy
  • Terms
  • English
  • Português (Brasil)

Cookies

Niv counts visits without cookies. With your OK, it also uses them to see how the site gets used, including recordings with every field hidden. Privacy