NEVULA

LEGAL

Privacy Policy

This policy describes data processing in the NEVULA Android app during its closed-test phase.

Last updated: 1 September 2026

1. Who is responsible

Denny Alexander de Almeida
Rua das violetas 11 - 2 Dto
2870-296 Montijo, Portugal
nevula.support@proton.me

2. What stays on your device

Notes, calendar entries, the private Gallery and their encryption keys are stored locally on your Android device. They are not synchronised to the NEVULA service. Private keys remain on the device.

3. Account and delivery data

NEVULA creates a random technical account identifier through Supabase so the service can provide device keys, pairing and encrypted delivery. The service may process the random user identifier, device-key records, encrypted delivery packages, recipient identifiers, expiry times and technical request data such as IP address, user agent, timestamps and security logs.

Message text, attachments and generated voice messages are encrypted on the device before transmission. The delivery service receives ciphertext rather than readable content. Delivery packages have a mandatory expiry of no more than 28 days and may be removed sooner after retrieval.

4. Service provider and transfers

NEVULA uses Supabase for authentication, database and encrypted delivery infrastructure. Supabase may process technical service data on behalf of the operator under its applicable contractual and security safeguards.

5. Permissions

  • Camera: private captures and in-person QR pairing.
  • Microphone: recording a voice message for on-device transformation.
  • Photos and files: importing items chosen by you into the encrypted private Gallery.
  • Notifications: optional disguised reminders and message alerts.

6. No advertising or analytics

NEVULA does not include advertising and does not sell personal data. The current app does not include a third-party advertising or behavioural analytics SDK.

7. Deletion and your choices

Emergency Kill removes local NEVULA data from the current device after access-code verification and a second confirmation. It does not by itself delete the online technical account. Use the Data Deletion page for the separate online process.

8. Security and limits

Data is transmitted over TLS and private content is protected with device-side encryption. No system can guarantee absolute security. NEVULA currently provides no account recovery or multi-device recovery for deleted local content.

9. Public Community

Community nicknames, public posts, replies, reports and moderation records are separate from private Messenger activity. Community content is intentionally public. NEVULA IDs, contacts, private chats and encryption keys are not displayed in the Community.

10. Contact and changes

For privacy questions or requests, email nevula.support@proton.me. Material changes to this policy will be reflected by updating the date above.