Privacy Policy
Last updated: 2026-07-16
1. Introduction
This Privacy Policy explains what personal data Nundinal ("Nundinal", "the Service") collects, why, how we protect it, who processes it, and the rights you have. It applies to the web application at nundinal.io.
We designed Nundinal to hold as little about you as possible. We do not run advertising, we do not use analytics or tracking, and we do not sell or rent your data to anyone.
2. Who is responsible for your data
Nundinal is operated by a private individual based in Switzerland (the "Operator", "we", "us"), who is the data controller for the personal data described here. Because Nundinal is an independent, early-stage project, we operate under the Nundinal name. You can reach the person responsible for your data at [email protected], and we will provide further identifying details on a legitimate request where required by law.
We process personal data in line with the Swiss Federal Act on Data Protection (nFADP) and, where it applies to you, the EU General Data Protection Regulation (GDPR).
3. What data we collect, why, and our legal basis
We only collect data you give us or that is strictly necessary to run the Service. We do not collect special-category data (such as health or biometric data), and we do not create advertising or behavioural profiles.
- Account email address — to create and identify your account, sign you in, send verification and account emails, and contact you about the Service. Legal basis: performance of our contract with you.
- Password — stored only as a one-way Argon2 hash; we never store or see your plaintext password. Used to authenticate you securely. Legal basis: performance of our contract; our legitimate interest in account security.
- Two-factor-authentication (2FA) secret — only if you enable 2FA; stored encrypted. Used to provide optional two-factor login. Legal basis: your consent and our legitimate interest in account security.
- Portfolios, plans, conversion strategies, and fund-accounting and lineage records — data you enter or that the Service computes. Used to provide the core Service: to store, display, compute, and trace your strategies and records. Legal basis: performance of our contract with you.
- Exchange / blockchain API credentials — only if you choose to connect an exchange or address; stored encrypted at rest. Used to fetch your balances and transaction history (read-only) so you can compare them against your records. Legal basis: your consent and performance of our contract.
- Profile image — only if you upload one. Used to personalise your account. Legal basis: your consent.
- Notifications and email records — records of the verification, reset, and strategy-trigger emails we send you. Used to operate notifications and keep a delivery record. Legal basis: performance of our contract; legitimate interest in reliable delivery.
- Security and audit records — sign-in sessions and an internal audit log of sensitive actions. Used to secure your account, detect abuse, and keep an integrity record. Legal basis: legitimate interest in security; legal obligation where applicable.
- IP address — processed transiently for rate limiting and abuse prevention. Legal basis: legitimate interest in security.
- Error and crash reports — technical diagnostics (see Section 6, Sentry). Used to detect and fix faults and keep the Service reliable and secure. Legal basis: legitimate interest in a reliable, secure Service.
We do not use your data for automated decision-making that produces legal or similarly significant effects on you.
4. Exchange access is read-only
If you connect an exchange or blockchain address, our access is strictly read-only — we fetch balances and transaction history only. Nundinal cannot and does not place orders, initiate withdrawals, or change anything on your exchange account. We strongly recommend you create read-only (view-only) API keys with no trading or withdrawal permissions, and only provide those. Any API credentials you give us are encrypted at rest.
5. How we protect your data
We use technical and organisational measures appropriate to the risk, including:
- Encryption in transit — all traffic between your browser and the Service uses TLS (HTTPS), and our database connection uses server-authenticated TLS.
- Encryption at rest for secrets — 2FA secrets and any exchange API credentials are encrypted with AES-256-GCM before they are stored.
- Strong password hashing — passwords are stored only as one-way Argon2 hashes; we never store or transmit your plaintext password.
- Access controls and isolation — your data is scoped to your account; requests are authenticated, and sensitive actions (such as deleting your account) require re-authentication.
- Optional two-factor authentication for your account.
No method of storage or transmission is perfectly secure, and we cannot guarantee absolute security.
6. Where your data is stored and who processes it
Your primary data is stored within the European Union (Frankfurt, Germany). To run the Service we rely on a small number of trusted service providers, each of which processes only the data needed for its function:
- Fly.io (Frankfurt, EU) — application hosting for the backend that handles your requests and data.
- DigitalOcean (Frankfurt, EU) — managed PostgreSQL database holding your account, portfolios, plans, records, and encrypted secrets.
- Cloudflare (Global CDN; R2 object storage location automatic — treated as potentially outside the EU, see Section 7) — frontend hosting, content delivery, and object storage for your profile image if you upload one.
- Resend (United States) — transactional email delivery; processes your email address and the content of the account/strategy emails we send you.
- Sentry (United States) — error and crash monitoring; processes technical error diagnostics, which may include limited technical context such as the page and browser involved.
- CoinGecko (United States) — market price data; we request public market prices only, and no personal data about you is shared.
The charting library used to draw charts in the app is served directly from Nundinal's own hosting, so viewing charts does not cause your browser to contact any additional third-party content network.
We do not sell, rent, or trade your personal data, and we do not share it with anyone other than the processors above, except where required by law or to protect our rights.
7. International data transfers
Your primary data (application and database) is stored in the EU. Some of our processors — Cloudflare, Resend, Sentry, and CoinGecko — are based in the United States and may process data outside Switzerland/the EU. Where personal data is transferred outside Switzerland or the EU, we rely on appropriate safeguards recognised under nFADP and GDPR, such as Standard Contractual Clauses and, where applicable, adequacy decisions or data-transfer frameworks. You may request more information about these safeguards at [email protected].
8. How long we keep your data
- Account and Service data is kept for as long as your account exists. When you delete your account, we erase it as described in Section 11.
- Backups — our database provider keeps automatic backups for a short rolling window (up to 7 days) for disaster recovery. Deleted data is removed from active systems immediately and ages out of backups automatically as they rotate.
- Error/diagnostic reports are retained by our monitoring provider for its standard retention period (up to 90 days) and then deleted.
- IP addresses used for rate limiting are processed transiently and are not retained as a persistent per-user log.
9. Cookies and local storage
Nundinal does not use tracking or advertising cookies. To keep you signed in, the app stores your authentication token in your browser's LocalStorage (a local storage mechanism, not a cookie). This data stays in your browser, is used only to authenticate your session, and is cleared when you sign out. Because we use no tracking technologies, there is no consent banner to click through.
The public landing page at nundinal.io (the page you see before signing in) uses Cloudflare Web Analytics, a cookieless analytics service. It does not use cookies, does not fingerprint your device, and does not track you across other sites. It has no access to your account data.
10. Your rights
Depending on where you live, you have rights over your personal data. Under the GDPR and Swiss nFADP these include the right to:
- access the personal data we hold about you;
- rectify inaccurate or incomplete data;
- erase your data ("right to be forgotten");
- restrict or object to certain processing (including processing based on our legitimate interests);
- data portability — receive your data in a structured, commonly used, machine-readable format; and
- withdraw consent at any time, where processing is based on your consent (this does not affect processing already carried out).
You can exercise many of these directly in the app — for example, you can view and edit your data, and delete your account. For any request, or to reach a human, email [email protected]. We will respond within the time required by law (generally within one month). Exercising your rights is free unless a request is manifestly unfounded or excessive.
If you believe we have mishandled your data, you have the right to lodge a complaint with a supervisory authority — in Switzerland, the Federal Data Protection and Information Commissioner (FDPIC); in the EU, your local data-protection authority.
11. Deleting your account (right to erasure)
You can permanently delete your account at any time from your account settings. Deletion requires you to re-authenticate (your password, plus a 2FA code if you have 2FA enabled) and to confirm — this is intentional, so an account cannot be deleted by accident or by someone who briefly has access to your session.
When you delete your account, we permanently and irreversibly erase your account and all associated records from our database in a single operation, including your:
- account (email and password hash), sign-in sessions, and refresh tokens;
- two-factor-authentication secret and any exchange API credentials;
- portfolios, portfolio assets, storage locations, and balance snapshots;
- conversion plans, sub-plans, steps, executions, and outputs;
- fund-accounting records, fund lineage, distributions, and orphaned-fund records;
- external observations and transaction matches;
- notifications, email-delivery records, audit records, feedback, and onboarding progress; and
- any profile image you uploaded.
This deletion cannot be undone. Copies may persist briefly in encrypted backups until those backups rotate out automatically (Section 8). We may retain the minimum information required to comply with a legal obligation or to resolve a dispute, where the law allows.
12. Children
Nundinal is not intended for anyone under 18, and we do not knowingly collect data from children. If you believe a child has provided us with personal data, contact [email protected] and we will delete it.
13. Data breaches
If a personal-data breach occurs that is likely to result in a risk to your rights, we will notify the competent supervisory authority and, where required by law, affected users, within the timeframes the law requires.
14. Changes to this Policy
We may update this Privacy Policy from time to time. When we make material changes we will update the "Last updated" date above and take reasonable steps to notify you, for example by email or an in-app notice. Please review this page periodically.
15. Contact
For any privacy question or to exercise your rights, email [email protected]. For general questions, email [email protected]. To report a security vulnerability, email [email protected].