Privacy Policy
Last updated: 28 August 2026
This policy explains which personal data Nobio Cloud processes, on what legal basis, and how you stay in control of it.
Who is responsible
The controller for this service is the operator of Nobio Cloud (see Imprint). Data protection questions: privacy@mail.nobio-cloud.app.
What we process
- Account data — email address, password hash, sign-in provider, account creation date. Needed to provide the service (Art. 6(1)(b) GDPR).
- Files and folders — the content you upload, file names, sizes, types, versions and share links. Stored to perform the contract.
- Mail data — your mail.nobio-cloud.app address and the messages in that mailbox, plus delivery logs for troubleshooting.
- Billing data — plan, subscription status and payment references. Card details are handled by Stripe; we never see them.
- Technical logs — IP address, timestamp, user agent for security and abuse prevention (Art. 6(1)(f) GDPR).
What we do not do
We do not sell personal data, we do not use advertising trackers, and we do not use your files or emails to train AI models. When you use the built-in assistant, only the file metadata you explicitly allow is sent to the AI provider for that request.
Processors
We use a small set of providers under data processing agreements: our cloud database, storage and hosting provider, Stripe (payments), and our transactional email sender. Data is processed in the EU where the provider offers it; transfers outside the EU rely on the EU standard contractual clauses.
Retention
Files stay until you delete them; trashed items are removed after 30 days. Account data is deleted within 30 days of account deletion. Invoices are kept for the statutory 10 years. Technical logs are kept up to 90 days.
Your rights
You can request access, correction, deletion, restriction, data portability and object to processing based on legitimate interest. Write to privacy@mail.nobio-cloud.app; we answer within 30 days. You may also complain to your local data protection authority.
Security
Traffic is encrypted with TLS, files are stored in a private bucket with per-user access rules, and every access path (web, API keys, SSH keys) is bound to your account. You can revoke keys and share links at any moment.