EN / DE
← Back to homepage

Privacy Policy

Last updated: September 27, 2026

This is a convenience translation of the German original. In case of any discrepancy, the German version shall prevail.

1. Data Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) is:

Philipp Humburg
Zum Hahletal 17
37339 Leinefelde
Email: kontakt@nexmori.com

1a. Data Protection Officer

We are not required to designate a data protection officer under Art. 37 GDPR and § 38 BDSG. For data protection questions you can reach the controller personally at the email address above.

2. Processing Activities

2.1 Newsletter

Data: email address; time of sign-up and confirmation; as evidence of consent, the IP address, browser/device information and the language and version of the consent text shown at sign-up. If you sign up again before confirming, the new sign-up replaces the earlier one.

Purpose: sending the newsletter. After signing up you receive an email with a confirmation link; the subscription becomes active only once you click it (double opt-in).

Legal basis: consent, Art. 6(1)(a) GDPR. You can withdraw it at any time with effect for the future, for example via the unsubscribe link in every email.

Retention: until you unsubscribe; the record, including the consent evidence, is then deleted. Unconfirmed sign-ups are deleted within 3 days.

Recipients: Brevo (3.2), Hetzner (3.3).

2.2 User Account

The app is reserved for persons aged 16 and over. Accounts are created only by you, in the iOS app.

Data: email address; password, stored only as a hash and never in plain text; time of registration; your confirmation that you are at least 16 and, if you are a minor, have your parents' or guardians' consent; as evidence that the terms were incorporated, the accepted version, display language, time and an identifier of the wording shown. If the terms change materially and you accept the new version, we record that acceptance in the same way.

Purpose: providing the account and sign-in; evidence of the age confirmation and terms acceptance in case of dispute. The contract is concluded only when you click the link in the confirmation email (§ 312i BGB, cf. § 3 of the Terms of Service); until then the account cannot be used.

Legal basis: Art. 6(1)(b) GDPR for the account and its confirmation; Art. 6(1)(c) GDPR (§ 305(2), §§ 107, 108 BGB) in conjunction with Art. 6(1)(f) GDPR (establishing evidence) for the age and terms records.

Retention: until the account is deleted (section 4). Unconfirmed registrations are deleted within 3 days together with their age and terms records; if you mistyped your address, simply register again. A newsletter subscription for the same address is not affected.

Recipients: Brevo for the confirmation email (3.2), Hetzner (3.3).

2.2a Password Reset

Data: the account's email address; a one-time code that we send by email and store only as a hash; times of issue, expiry and use.

Purpose: resetting a forgotten password. The code is valid only briefly and can be used only once; after the reset, all existing sign-ins are ended. The response does not reveal whether an account exists for an address.

Legal basis: Art. 6(1)(b) GDPR.

Retention: used or expired codes are deleted within two days.

Recipients: Brevo (3.2), Hetzner (3.3).

2.2b Subscription and Usage Limits

Data: subscription status with the end of the trial or billing period; a pseudonymous subscriber identifier linking your account to the subscription; the history of subscription events (such as purchase, renewal, cancellation, refund) with product, price, currency, country and the App Store transaction identifiers; monthly counters of documents added and questions asked, and a daily counter of documents added.

Purpose: unlocking the subscription, keeping the subscription history traceable and enforcing usage limits against abuse. We also check the status with RevenueCat. Apple is the merchant of record; no payment card or billing address data reaches us. You manage and cancel the subscription in your Apple Account settings.

Legal basis: Art. 6(1)(b) GDPR (subscription); Art. 6(1)(f) GDPR (counter-based abuse prevention); Art. 6(1)(c) in conjunction with Art. 5(2) GDPR (event history).

Retention: status, event history and monthly counters until the account is deleted; daily counters are deleted after 31 days. Deleting documents does not reset the counters.

Recipients: RevenueCat (3.4), Hetzner (3.3); Apple as independent controller (3.5).

2.3 Document Processing and Chat

Your documents, their text and the search index stay on your iPhone. To add a document, the app sends its text to our server for indexing; to answer a question, it sends only the question, the recent history of the current conversation and a limited number of matching excerpts. The server processes this data only transiently and neither stores nor logs any of it; the chat history is not stored permanently, neither on the server nor on the device.

Data: document text; your questions and the recent conversation history; excerpts together with the AI-generated document title, document type and language placed in front of each excerpt.

Purpose: building the search index on your device and generating AI-assisted answers. AI-generated content is labelled as such in the app.

Legal basis: Art. 6(1)(b) GDPR; Art. 50(1) of Regulation (EU) 2024/1689 (AI Act) for the labelling.

Retention: none on our server; for Mistral AI see 3.1.

Recipients: Mistral AI (3.1), Hetzner (3.3).

2.3b Dictation

The optional dictation feature in the chat converts speech to text entirely on the device, using iOS speech recognition. The microphone and speech recognition are used only after you grant permission in iOS. Neither audio nor transcript is transmitted or stored by us. Only when you send the text is it processed like a typed question under 2.3.

2.4 Website Visits and API Use

Data: your IP address is processed to deliver content but is not stored in logs. Server logs contain a request identifier, the requested path, status code and duration, and for signed-in requests a pseudonymous user identifier. To prevent abuse we count requests per time window using an identifier derived from your IP or email address, or your account identifier; the addresses themselves are not stored.

Purpose: operating the website and API reliably and securely.

Legal basis: Art. 6(1)(f) GDPR.

Retention: logs are deleted after 30 days; abuse counters are held in memory only and expire within one hour.

Recipients: Hetzner (3.3).

Contact form: we forward your name, email address and message to ourselves by email to answer your enquiry (Art. 6(1)(f) GDPR). We delete them no later than 6 months after the enquiry is closed. Recipient: Brevo (3.2).

2.5 Document Classification

When a document is added, an AI language model suggests a document type based on its text, such as invoice or contract (Art. 13(2)(f) GDPR, Art. 50(1) AI Act). It also suggests key facts such as date, period and sender. The suggestions have no legal effect and you can change them at any time. No automated decision within the meaning of Art. 22 GDPR takes place. The legal basis is Art. 6(1)(b) GDPR; the recipient is Mistral AI (3.1).

2.6 Cookies and Storage on Your Device

Website: if you open the home page directly, we redirect you once to the German version based on your browser's language setting; this setting is not stored. If you choose the English version via a link, we set a language cookie so that the redirect does not happen again. It contains no identifier and is deleted after 12 months. The cookie is strictly necessary for the language version you chose (§ 25(2) no. 2 TDDDG); the legal basis is Art. 6(1)(f) GDPR. We use no other cookies, no tracking and no analytics, and all content is served from our own server.

iOS app: your archive is stored encrypted on your iPhone and excluded from iCloud and computer backups; we have no access to it. If you share a document through the iOS share sheet, that is your own data flow: the target app you choose is responsible for it, and we do not learn where you share.

3. Processors and Recipients

We use the following processors. A data processing agreement under Art. 28 GDPR is in place with each of them.

3.1 Mistral AI, Paris

  • Service: AI language models for indexing, answers and classification (2.3, 2.5).
  • Location: primarily in the EU.
  • Third-country transfer: where one exceptionally occurs, based on Standard Contractual Clauses (Art. 46(2)(c) GDPR).
  • Agreement: A data processing agreement under Art. 28 GDPR is in place.
  • No training: Mistral AI does not use the data to train its models; it retains the data for up to 30 days for abuse monitoring.
  • Not sent: no account identifiers, email addresses or IP addresses.

3.2 Brevo, Paris

  • Service: email delivery: newsletter, account confirmation, password reset codes, account deletion confirmation, notices of changes to the terms, and forwarding of contact enquiries.
  • Location: primarily in the EU.
  • Third-country transfer: where one exceptionally occurs, based on Standard Contractual Clauses (Art. 46(2)(c) GDPR).
  • Agreement: A data processing agreement under Art. 28 GDPR is in place.
  • No tracking: open and click tracking is switched off for all emails.
  • Not sent: no document content, no subscription or usage data.

3.3 Hetzner Online GmbH, Gunzenhausen

  • Service: hosting of the website, API and account database, including server backups.
  • Location: data centre in Germany.
  • Third-country transfer: none.
  • Agreement: A data processing agreement under Art. 28 GDPR is in place.
  • Not stored: no document content; texts for indexing and chat pass through the server only transiently.

3.4 RevenueCat, Inc., San Francisco

  • Service: subscription management: forwarding Apple's subscription events and checking subscription status (2.2b). Sent are the pseudonymous subscriber identifier, subscription status and events, app version, country and the device data transmitted by the app (vendor device identifier, IP address, device model, language setting).
  • Location: USA.
  • Third-country transfer: based on Standard Contractual Clauses (Art. 46(2)(c) GDPR).
  • Agreement: A data processing agreement under Art. 28 GDPR is in place.
  • Not sent: no payment data, no email address, no document or chat content.

3.5 Apple

You buy the subscription from Apple. Apple acts as an independent controller, not as our processor: it sells in its own name, handles payment and processes your payment and Apple Account data under its own privacy policy. We send no personal data to Apple and receive, via RevenueCat, only the subscription events listed in 2.2b.

4. Deletion

The iOS app offers two ways to delete:

  • Data deletion: the app deletes the archive, index and key on your device. As our server holds no documents, nothing is removed there. Your account, usage counters and any newsletter subscription remain.
  • Account deletion: we delete all data of your account (2.2 to 2.2b), including any newsletter subscription under the same email address, and send a one-time confirmation to that address via Brevo. If sending fails, the deletion still stands.

Deleted data may persist in server backups for up to 7 days.

5. Your Rights

You have the right to:

  • Access (Art. 15 GDPR). You can retrieve the access report yourself in the iOS app; we record the time and status of each request until the account is deleted.
  • Rectification (Art. 16 GDPR).
  • Erasure (Art. 17 GDPR), in the app via the options in section 4.
  • Restriction of processing (Art. 18 GDPR).
  • Data portability (Art. 20 GDPR). Your account data is included in machine-readable form in the access report; you can share your documents individually as PDFs from the app.
  • Objection (Art. 21 GDPR) to processing based on Art. 6(1)(f) GDPR.
  • Withdrawal of consent with effect for the future (Art. 7(3) GDPR).

To exercise these rights, write to kontakt@nexmori.com. We respond without undue delay and within one month at the latest (Art. 12(3) GDPR); for complex or numerous requests this period may be extended by two further months, in which case we will inform you within the first month.

You may also lodge a complaint with any data protection supervisory authority (Art. 77 GDPR), in particular in the Member State of your habitual residence, place of work or place of the alleged infringement. The authority responsible for us is:

Thüringer Landesbeauftragter für den Datenschutz und die Informationsfreiheit (TLfDI)
Häßlerstraße 8, 99096 Erfurt, Germany
Phone: +49 361 57-3112900
Email: poststelle@datenschutz.thueringen.de
Web: www.tlfdi.de

© 2026 Nexmori · Hosted in Germany

Imprint · Privacy Policy · Terms of Service · Subscription Terms · Accessibility