Back to home

Privacy Policy

Last updated: August 3, 2026

1. Introduction

This Privacy Policy explains how GuusLab, trading as Nemi ("we", "us", "our"), collects, uses, stores, and protects your personal data when you use our file sharing platform at nemilab.com (the "Service"). It applies to account holders as well as to people who interact with the Service without an account, such as recipients of share links, people who upload files through an upload link, and people who fill in a Nemi form.

We are committed to protecting your privacy and complying with the General Data Protection Regulation (GDPR) and other applicable data protection legislation. We process your personal data lawfully, fairly, and transparently. The Service can be used worldwide; Section 10 explains what this means for users outside the European Economic Area.

2. Data Controller

The data controller responsible for your personal data is:

GuusLab (trading as Nemi)
Utrecht, the Netherlands
KVK: 95954600
Email: support@nemilab.com

If you have questions about data processing or wish to exercise your rights, please contact us using the details above.

Where a Nemi user shares files with you, requests files from you, or sends you a form, that user decides what is collected and why; for that content we act as a processor on the user's behalf, and the user may be an independent controller of your data.

2.1 When we act as your processor

If you use Nemi for a business or organization and upload personal data about other people (client files, form responses, documents containing customer data), you are the controller of that data and we process it only on your behalf. Article 28 GDPR requires a written agreement for that relationship. Our Data Processing Agreement provides it: it is part of our Terms of Service and applies automatically, with no separate signature needed. It covers our processing instructions, confidentiality, security measures, sub-processors, assistance with data subject requests, breach notification, audits, international transfers, and deletion at the end of the contract. If your organization needs a signed copy for its records, email support@nemilab.com.

This Privacy Policy describes the data we process as a controller in our own right: your account, billing, technical, and communication data. Where the two overlap, the Data Processing Agreement governs the content you upload on behalf of others.

3. What Data We Collect

We collect and process the following categories of personal data:

3.1 Account Data

  • Name and email address. Depending on how you sign in, these come from your Google account (Google sign-in) or directly from you (email verification code).
  • Optional public username (@handle), used for sign-in, invites, and your optional public Nemi card.
  • Profile picture (from Google or a photo you upload; optional animated photo on eligible plans).
  • Passkey credentials, if you register a passkey: we store the public key and related metadata, never the private key, which stays on your device.
  • Account creation date and authentication tokens.
  • Plan status used for product features such as verified badges (blue or gold checkmarks) shown next to your name where the Service displays senders and collaborators.

3.2 Billing Data

  • Subscription status and plan type.
  • Payment information is processed directly by Stripe and is never stored on our servers. We only store your Stripe customer ID and subscription ID.

3.3 Content & Usage Data

  • Files you upload, and documents, spreadsheets, forms, and canvases you create.
  • File metadata: name, size, type, upload date, expiry date, and malware scan status.
  • Authorship information in collaborative documents: edits are attributed to the account (or connected AI assistant) that made them, so collaborators can see who wrote what.
  • Share link settings and analytics: number of downloads and opens, and timestamps.
  • Workspace information, folder structure, and contacts.
  • Contacts: email address, optional name, optional username, and (when known) a link to a Nemi account. Contacts are private to your account. We may create or update a contact when you share files, invite someone to a workspace or folder, or add a collaborator by email or @username. We do not operate a global public directory of all users.

3.3a Business organizations

On the Business plan you can create or join a company organization. For that organization we process:

  • Organization name, optional logo, seat limits, and membership roles (owner, admin, member).
  • Invites sent by email or username, and acceptance or decline of those invites.
  • Linked membership so storage and plan entitlements can be pooled for the organization while membership is active.
  • Display of the organization name and logo next to verified badges for members, on profiles and share pages where applicable.

Organization owners and admins manage seats and members. When you leave or are removed, organization-linked entitlements end for your account.

3.4 Technical Data

  • IP address (for security, rate limiting, and abuse prevention).
  • Browser type and version, and device information.
  • Cookies and similar technologies (see Section 8).

3.5 Communication Data

  • Email address for transactional and marketing emails.
  • Email interaction data (opens, clicks) for improving our communications.
  • Your email preferences and unsubscribe choices.

3.6 Data About Recipients & Visitors (No Account Needed)

If you interact with the Service without an account, we process a limited amount of data about you:

  • When you download a shared file: the download timestamp. The sender sees download counts and timestamps as analytics. We do not store your IP address or browser details with downloads.
  • When you open or preview a shared file: an open event with a salted, truncated hash of your IP address (we do not store your raw IP address for open analytics) and the timestamp.
  • When you upload files through an upload link or Beam: the files themselves and technical data about the upload. These files belong to the workspace of the Nemi user who requested them.
  • When you fill in a Nemi form: the answers you submit, which are delivered to the Nemi user who created the form.

3.7 Connected Calendar Accounts (Optional)

Nemi Calendar can connect to an external calendar so your events appear alongside the ones you create in Nemi. Connecting an account is always your choice, it never happens automatically, and you can disconnect at any time in your calendar settings. We support:

  • Google Calendar. We request only two permissions: the read-only list of your calendars, and read and write access to the events in the calendars you enable. We do not request access to Gmail, Google Drive, Google Photos, your contacts, or any other Google service, and we cannot read them.
  • Microsoft Outlook Calendar. Your profile name and email, and read and write access to your calendar events.
  • ICS feeds. The events published by a calendar URL you give us. These are read-only.
  • Spotify (optional). Read-only listening history, shown as entries on your timeline. Nothing is written back to Spotify.

For a connected account we store the calendar list, the event data needed to display and sync your calendar (title, description, location, times, recurrence, attendees, and the provider's event identifiers), and the access and refresh tokens for the connection. Tokens are encrypted with AES-GCM before they are written to our database, so a database dump alone cannot read your calendar.

Calendars are bound to your personal account rather than to a workspace, so connecting a calendar does not expose it to the other members of a workspace you belong to. Sync is two-way: changes you make in Nemi are sent back to the connected provider, and changes made in the provider are pulled into Nemi. When you disconnect an account or delete your Nemi account, the stored tokens, calendars, and events for that connection are deleted.

3.8 Photos in Nemi Gallery

Photographs can carry more about you than the picture itself. Nemi Gallery is built around that fact, so this section sets out exactly what happens to a photo you add.

  • Compression happens on your device. In most browsers your photo is converted to AVIF locally and only the converted, smaller file is uploaded. The original never leaves your device. If your browser cannot do the conversion (some browsers cannot, and most cannot read iPhone HEIC photos), the original is sent to our server, converted there, and the uploaded original is discarded immediately afterwards. It is never stored.
  • The original is not kept. We store the converted photo and a small thumbnail. This is deliberate and irreversible; see Section 4a of our Terms.
  • Camera metadata is read out of the photo and stored separately. Converting a photo discards what the camera wrote into it, so before that happens we read: the capture date and time, the camera make and model, the lens, the exposure settings (shutter, aperture, ISO, focal length), the orientation, and the location coordinates if your camera recorded them. These are stored as data in your library so the app can sort your photos by when they were taken and show you their details.
  • You can drop the location before it is uploaded. Gallery has a setting that removes GPS coordinates on your device, before anything is sent to us. When it is on, we never receive the location of new photos at all. It applies to photos added afterwards; it does not change photos already in your library.
  • Your library is private and bound to your account. Gallery is not shared with a workspace: other members of a workspace you belong to cannot see your photos. We do not run facial recognition, we do not scan photos to identify people, places, or objects, and we do not use your photos to train models (Section 5).
  • Deletion. A deleted photo sits in the Gallery trash for 30 days and is then permanently removed, along with its metadata. Deleting your account deletes your library and everything in it.

Photographs of identifiable people are personal data about those people, and a photograph can also reveal things that count as a special category of personal data under Article 9 GDPR. You decide what you upload, so Section 5a applies to Gallery as it does to the rest of the Service: we do not analyze, index, or profile what your photos contain, and Gallery is not the place for photographs that carry medical or comparably sensitive information.

4. Legal Basis for Processing

Under the GDPR, we process your personal data on the following legal bases:

PurposeLegal Basis
Providing the ServicePerformance of contract (Art. 6(1)(b) GDPR)
Processing paymentsPerformance of contract (Art. 6(1)(b) GDPR)
Sending transactional emailsPerformance of contract (Art. 6(1)(b) GDPR)
Sending marketing emails to existing customersLegitimate interest (Art. 6(1)(f) GDPR), with opt-out at any time
Security, malware scanning & abuse preventionLegitimate interest (Art. 6(1)(f) GDPR)
Download & open analytics for sendersLegitimate interest (Art. 6(1)(f) GDPR)
Referral programLegitimate interest (Art. 6(1)(f) GDPR)
Analytics & service improvementLegitimate interest (Art. 6(1)(f) GDPR)
Legal obligations (tax, accounting, lawful requests)Legal obligation (Art. 6(1)(c) GDPR)

Where we rely on legitimate interest, we have conducted a balancing test to ensure your rights and freedoms are not overridden. You can request details of these assessments, or object to any legitimate-interest processing, by contacting us.

5. How We Use Your Data

We use your personal data to:

  • Provide, maintain, and improve the Service.
  • Process your file uploads, conversions, and compressions.
  • Scan uploaded files for malware to protect recipients and the Service.
  • Manage your account and subscriptions.
  • Process payments through Stripe.
  • Send transactional emails (account confirmations, download notifications, billing receipts).
  • Send marketing communications about new features and offers (with easy opt-out, see Section 11).
  • Monitor for abuse, fraud, and security threats.
  • Enforce our Terms of Service.
  • Comply with legal obligations.

We do not use your content to create, train, or improve AI or machine learning models, we do not sell your personal data, and we do not show advertising. This covers your files, documents, spreadsheets, forms, canvases, and the data from any calendar account you connect, in raw form as well as aggregated, anonymized, or derived form. Section 6.4 sets out the specific commitment that applies to data received from Google Workspace APIs.

5a. Special Categories of Personal Data

We do not knowingly or intentionally process special categories of personal data within the meaning of Article 9 GDPR: data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and genetic data, biometric data used to identify a person, data concerning health, or data concerning a person's sex life or sexual orientation. We also do not process data on criminal convictions and offences under Article 10 GDPR.

None of our own processing requires this kind of data. We never ask you for it, no feature depends on it, and we do not derive it from your content: we do not analyze, index, or profile the contents of your files, documents, or form responses.

Your responsibility as a user. Because you decide what you upload, our Terms of Service (Section 7) prohibit using Nemi for special category data and for data subject to sector-specific rules such as HIPAA, the Dutch Wgbo, or NEN 7510. This applies to files you share, to documents and spreadsheets you create, and to the questions you ask in a Nemi form or upload link. If you need to handle medical records, patient data, or comparable sensitive data, use a platform that is built and certified for it.

If special category data reaches our servers anyway, we still protect it with the measures in Section 14, we do not use it for any purpose of our own, and we will delete it on request. We may also remove it and inform the account holder, as described in our Terms of Service.

6. Data Sharing & Third Parties

We share your personal data only with the following categories of third parties, and only to the extent necessary:

6.1 Service Providers (Data Processors)

ProviderPurposeData Location
Google (OAuth, Calendar API)Sign-in, and calendar sync if you connect it (Section 3.7)EU/US (EU-US Data Privacy Framework, SCCs)
StripePayment processingEU/US (EU-US Data Privacy Framework, SCCs)
WasabiFile storage (AES-256 at rest)EU (Amsterdam)
AWS SESEmail deliveryEU (Frankfurt)

File conversion, compression, and malware scanning run on infrastructure we operate ourselves; your files are not sent to external conversion or scanning companies. Web fonts are served through our own servers, so your IP address is not sent to font providers.

These providers are also our sub-processors when we process personal data on your behalf. The current list, including what each provider does and where it stores data, is Annex 3 of our Data Processing Agreement, together with the notice period that applies before we add a new one.

6.2 People You Share With

When you share a file or document, the recipients you choose can see the shared content and your name as the sender. Where applicable they may also see your username, verified badge, and (for Business-linked accounts) your organization name or logo. When someone downloads your shared file, you can see download analytics about that download (see Section 3.6).

Exact username lookup for sharing is only available to signed-in users and only returns a match when the handle exists. It is not a browseable public user list.

6.3 AI Assistants You Connect (Optional)

Nemi contains no built-in AI features. We do not run, host, or call any AI or machine learning model as part of the Service, and we have no contract with any AI provider, aggregator, or model gateway. Nothing you store in Nemi is sent to such a service by us.

On eligible plans you can connect your own third-party AI assistant (for example through our MCP integration) to your workspace. This never happens automatically: it requires your explicit authorization, the assistant acts under your account and your credentials, and the content you let it access is processed by that assistant's provider under the agreement between you and that provider. We record which changes were made through the integration so collaborators can see them. We never send your data to AI providers on our own initiative, and you can revoke a connection at any time in your account settings.

Connected calendars are outside this integration. The MCP integration reaches only files, folders, documents, spreadsheets, forms, and canvases. It has no ability to read, write, or search calendar accounts, calendars, or events, so data obtained from Google Calendar or any other connected calendar provider cannot be passed to an AI assistant through Nemi. This is a property of the integration itself, not a setting: no such capability exists in it.

6.4 Google Workspace APIs and Limited Use

Nemi's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. The use of raw or derived user data received from Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.

In practice this means that data we receive from Google Workspace APIs, which for Nemi is Google Calendar data only:

  • Is used solely to provide and improve the calendar features you asked for, and is shown only to you.
  • Is never transferred to any third party, except as needed to provide those features, to comply with applicable law, or as part of a merger or acquisition, and never for advertising.
  • Is never sold, and is never used for advertising, retargeting, or credit assessment.
  • Is never used, in raw, aggregated, anonymized, or derived form, to create, train, fine-tune, evaluate, or improve any foundational, generalized, or other machine learning or artificial intelligence model, whether ours or a third party's.
  • Is never transferred to a third-party AI or machine learning service. Nemi integrates with no such service, and the optional AI assistant integration described in Section 6.3 cannot reach calendar data at all.
  • Is not read by humans, except with your explicit consent for a specific support request, where it is necessary for security purposes such as investigating abuse, or to comply with applicable law.

6.5 International Transfers

We store files and send email within the EU. Where personal data is transferred outside the European Economic Area (EEA), for example to Google or Stripe in the US, we ensure adequate safeguards are in place: an adequacy decision such as the EU-US Data Privacy Framework, or Standard Contractual Clauses (SCCs) approved by the European Commission.

6.6 Legal Disclosure

We may disclose your data if required by law, regulation, legal process, or governmental request, or to protect the rights, property, or safety of Nemi, our users, or the public. Where the law allows, we will inform you of such requests.

7. Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected:

  • Account data: Retained for the duration of your account. When you delete your account in your settings, your account, files, and associated data are deleted immediately. Uploaded files are gone permanently at that moment, because file storage holds only one copy; residual account data in our database backups is removed within 30 days.
  • Files (free plan): Automatically deleted 30 days after upload.
  • Files (paid plans): Retained while your subscription is active. After cancellation and downgrade, files exceeding free-tier limits become subject to the free plan's 30-day expiry.
  • Gallery photos: Retained until you delete them, on every plan, including the free plan. A deleted photo stays in the Gallery trash for 30 days and is then permanently removed together with its metadata. Originals are never retained at all (Section 3.8).
  • Download logs & share analytics: Retained for the lifetime of the related share and deleted together with it.
  • Billing data: Retained for as long as required by tax and accounting regulations (in the Netherlands, 7 years).
  • Email send log & preferences: Retained for the duration of your account, so we can honor your unsubscribe choices.
  • Server logs: Cleared on every deployment of the Service, which is usually at least once a day, and never kept longer than 90 days.

8. Cookies & Similar Technologies

We use the following cookies and similar technologies:

CookieTypeDurationPurpose
Session cookieStrictly necessarySessionAuthentication and session management
CSRF tokenStrictly necessarySessionSecurity: prevents cross-site request forgery
Referral cookieFunctional24 hoursRemembers a referral code you followed, only set when you open a referral link

We also use your browser's local storage to remember interface preferences (such as view settings) on your own device; this data is not sent to us. We do not use third-party tracking cookies, advertising cookies, or third-party analytics scripts. Because we only use strictly necessary and low-impact functional cookies, no cookie consent banner is required under the Dutch Telecommunications Act and the ePrivacy rules.

9. Your Rights Under GDPR

As a data subject under the GDPR, you have the following rights:

  • Right of access (Art. 15): You can request a copy of all personal data we hold about you.
  • Right to rectification (Art. 16): You can request correction of inaccurate or incomplete personal data.
  • Right to erasure (Art. 17): You can request deletion of your personal data ("right to be forgotten"). You can also delete your account yourself at any time in your account settings.
  • Right to restrict processing (Art. 18): You can request that we limit how we process your data.
  • Right to data portability (Art. 20): You can request your data in a structured, commonly used, machine-readable format. You can also download your files and export your documents directly from the Service.
  • Right to object (Art. 21): You can object to processing based on legitimate interest, including marketing.
  • Right to withdraw consent: Where processing is based on consent, you can withdraw it at any time.

To exercise any of these rights, contact us at support@nemilab.com. We will respond within one month, as required by the GDPR. We may ask you to verify your identity before acting on a request. If you are not satisfied with our response, you have the right to lodge a complaint with your local data protection authority. In the Netherlands, this is the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl).

10. Users Outside the EEA

The Service can be used from anywhere in the world, and we apply the protections described in this policy to everyone, regardless of where you live. Your data is processed in the EU (and by the providers listed in Section 6) no matter where you use the Service from.

  • United Kingdom: If you are in the UK, the rights in Section 9 apply to you under the UK GDPR, and you can complain to the Information Commissioner's Office (ico.org.uk).
  • United States (including California): We do not sell or share your personal information for advertising purposes, and we honor requests to access, correct, and delete your data as described in Section 9, regardless of your state of residence.
  • Other countries: Where your local data protection law grants you rights similar to those in Section 9, you can exercise them through the same contact details, and you keep any additional mandatory protections of your local law.

11. Email Communications

We send the following types of emails:

  • Transactional emails: Account confirmations, sign-in codes, download notifications, billing receipts, and security alerts. These are necessary for the Service and cannot be opted out of.
  • Marketing emails: Product updates, new features, and promotional offers about Nemi, sent to you as an existing customer. You can unsubscribe at any time using the link in every email or through your email preferences page, and we honor all unsubscribe requests promptly.

Marketing emails may contain measurement of opens and clicks so we can improve our communications; unsubscribing stops both the emails and this measurement. Every marketing email includes our name, a working unsubscribe link, and our location, in line with the GDPR, the Dutch Telecommunications Act, and comparable rules elsewhere (such as CAN-SPAM).

12. AI Assistant Integrations

If you choose to connect an AI assistant to your workspace (see Section 6.3), the following applies:

  • Connections are opt-in and authorized by you through an explicit consent screen.
  • The assistant can only access what its authorization allows, and only in your workspace.
  • The integration covers files, folders, documents, spreadsheets, forms, and canvases only. It cannot read, write, or search connected calendar accounts, so data received from Google Calendar or any other calendar provider is never available to it.
  • Nemi itself calls no AI or machine learning service. The assistant is one you bring and authorize, and we add no model provider of our own behind it.
  • Content the assistant reads or edits is processed by the assistant's provider under that provider's privacy policy. Review it before connecting.
  • Edits made by an assistant are marked as AI edits in document authorship history, so collaborators can see what was written by a person and what was not.
  • You can revoke the connection at any time in your account settings, which immediately stops further access.

13. Automated Decision-Making

We do not make decisions based solely on automated processing that produce legal effects for you or similarly significantly affect you. Uploaded files may be automatically scanned for malware, and files identified as malicious may be automatically blocked; if you believe a file was wrongly blocked, contact us at support@nemilab.com and a human will review the decision.

14. Data Security

We implement appropriate technical and organizational measures to protect your personal data, including:

  • Encrypted data transmission using TLS/HTTPS.
  • AES-256 encryption at rest at our storage provider, with keys managed by that provider.
  • Optional password protection on share links, and optional password encryption of exported .nemi documents.
  • Automated malware scanning of uploaded files.
  • Hashing of viewer IP addresses for share open analytics.
  • Access controls and the principle of least privilege for administrative access.
  • Backups of the database, so accounts and documents survive a failure. Uploaded files are not backed up: file storage holds one copy and deletion is permanent.
  • Regular security reviews and updates.

In the event of a data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and inform affected users without undue delay, as required by GDPR Articles 33 and 34.

15. Children's Privacy

The Service is not directed at children under the age of 16. We do not knowingly collect personal data from children under 16. If we become aware that we have collected personal data from a child under 16 without parental consent, we will take steps to delete that data promptly.

16. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. If we make material changes, we will notify you by a prominent notice in the Service (which you can acknowledge) and, where appropriate, by email. The "Last updated" date at the top of this page indicates when this policy was last revised.

17. Contact Us

For any questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us:

GuusLab (trading as Nemi)
Utrecht, the Netherlands
KVK: 95954600
Email: support@nemilab.com

You also have the right to lodge a complaint with a supervisory authority, in particular in the EU Member State of your habitual residence, place of work, or place of the alleged infringement.