Nuvaka › Where your data lives

Where your data lives

This page explains, in plain words, where your data is kept. It is not a legal text; the binding texts are the Terms of Use, the Privacy Policy, the KVKK notice and the Cookie Policy.

DataWhereNote
SSH, database, Redis trafficOnly between your device and the target serverNever passes through or is recorded by Nuvaka.
Passwords and key files you do not saveOn your deviceUnless you choose "save key", they never reach the server.
Server connections you choose to saveNuvaka server, tied to your account, encryptedHost, port, username and, if chosen, password/key.
Mail of the @nuvaka.com address given to youNuvaka mail serverMail received at and sent from this address is stored.
Other mail accounts you add to the appCredentials on the Nuvaka server, encryptedContent is read from your mail server and not stored, unless you save an attachment to storage.
My files, notes, file sharesNuvaka and its infrastructure providersTransferred over TLS. No end-to-end encryption on the server.
Sync folders, version history, deleted filesNuvaka serverBlock based; old versions stay until you delete them or close the account.
Clipboard pool (text and images)Nuvaka serverWith auto-send off, only what you send manually.
Friends, messages, voice room memberships, Watch Party roomsNuvaka serverVoice audio travels over UDP and is not recorded.
Game Manager project dataNuvaka serverYour game clients read it through public endpoints with the API key.
Assistant conversationsNuvaka serverDeletable at any time; see below.
Account and session recordsNuvaka serverUsername, e-mail, password hash; device name, platform, IP address, last seen, login activity.

Note: when you have the assistant run a command through your device, the command and its output pass through our server and the AI provider to be processed.

What we do not keep

Encryption, honestly

All transfer uses TLS. Saved server connections, mail credentials and the two-factor secret are stored encrypted on the server. My files, sync, clipboard and notes are not end-to-end encrypted by default: that data is readable on the server and can be accessed when the law requires it.

You can encrypt individual files on your device with a password: install File encryption from the Apps store, right-click a file in My files and choose "Encrypt". Encryption happens on your device and the password is never sent anywhere; the server only sees encrypted content, no preview is created and the assistant cannot read it. If you forget the password, the file cannot be recovered. To keep a whole section end-to-end encrypted, use Secure Space in My files: files, and optionally their names, are encrypted on your device and the keys never leave it; we cannot see this content either. Previews, public links, extensions and the assistant cannot access it. If you lose both your password and your recovery key, this data cannot be recovered.

The assistant

The assistant runs on a large language model. When you give it a task, the content needed to carry it out (for example an e-mail body, file names, a note) is sent to the model for processing. Irreversible steps such as sending mail or deleting files never happen without your approval; "Stop" works at any moment. Conversations are stored with your account; delete them one by one in the app or entirely by deleting your account. The assistant is available only to signed-in users.

Devices, freezing and 2FA

Under Profile → My devices you see every device signed into your account and can sign it out, freeze it or delete it remotely. A frozen device cannot make any request. Two-factor authentication is optional; recovery codes are shown once and stored on the server as hashes.

Crash reports

If the app crashes (or quits unexpectedly), it sends us a technical report on the next launch: app version, operating system and version, CPU architecture, the error message and stack trace, the names of the last screens opened, and a random per-install id. File names and mail, note or chat contents are never sent; remaining personal traces (tokens, e-mail addresses, home folder names) are also scrubbed on the server. Reports are kept for 90 days. You can turn this off in Profile › Privacy; pending reports are deleted when you do.

Deletion and retention