Privacy policy

Last updated: July 5, 2026

Nullo is built so you can share sensitive text without handing us the content. Our default is to collect as little as possible, keep nothing we do not need, and never log what you encrypt. This policy explains what we do process and why. It complements our Terms of service.

What we never see

  • The plaintext of messages you encrypt.
  • Decryption keys (they stay in the URL fragment on the client).
  • Your name, email address, or password. We do not ask for them.
  • Recipient identity when someone opens a share link.

What we process and why

Encrypted secrets

When you create a link, we store an opaque ciphertext blob, an expiry time, and an optional view limit. This is necessary to relay the encrypted payload to recipients. Secrets are deleted when they expire, after burn-after-read consumption, or when purged by our background sweeper.

Accounts

When you register, we store a one-way hash of your 16-digit account number (not the number itself), the account creation time, and how long your prepaid access lasts. This lets you sign in and create links from the app. Unpaid accounts that never receive a payment may be removed after a short grace period.

Payments

For card payments, your card details are processed by Stripe. We store the amount, currency, payment status, and Stripe's reference ID in our database for the 7-day refund period, then delete it. We use these records only to handle refunds and resolve billing issues during that window.

For cryptocurrency payments, we use BTCPay Server on infrastructure we host and operate. We store invoice status and amount in our database until your payment is confirmed, then delete it. The payment itself is recorded on the blockchain, which is public by design.

Neither payment method asks for your name, email, or other personal information. Payment records are also removed from our database when you delete your account.

When you sign in on the website, we set a signed, HTTP-only session cookie that contains your account hash and an issue time. It lasts up to 24 hours and is used only to keep you signed in. We do not use advertising or analytics cookies.

Anonymous statistics

We count coarse events, such as a page view on the landing page, a secret created, or a download, without attaching user identifiers, account numbers, secret IDs, or IP addresses to those rows.

Rate limiting and server logs

We keep track of client IP addresses in server memory to enforce rate limits. Each address is removed within at most one hour of your last request and is never stored in our database or logs.

Our application logs are limited to operational metadata and do not include information that identifies you, your account, or the content you share.

We process personal data only where we have a lawful basis under the GDPR:

  • Encrypted relay, accounts, and sessions: necessary to provide the service you signed up for (performance of contract).
  • Payments and refunds: necessary to handle your payment and honor refunds (performance of contract), and where applicable to meet accounting obligations (legal obligation).
  • Rate limiting and anonymous statistics: necessary to keep the service secure and running (legitimate interest).
  • Support email: necessary to answer your questions and resolve issues (legitimate interest).

Retention

  • Secrets: until expiry, burn-after-read deletion, or automated purge.
  • Accounts: until you delete them from your account page, or until an unpaid account is swept.
  • Payments: we keep completed payment records on our servers only for the refund period, then delete them. Stripe may retain card and transaction data under its own policies. Cryptocurrency invoice records on our side are removed once your payment is confirmed; the transaction itself remains on the public blockchain.
  • Statistics: anonymous event records are kept for as long as we need them for operational reporting.
  • Support email: if you contact us by email, we keep correspondence only as long as needed to resolve the issue or answer your question.

Third parties

We rely on third parties for parts of the service. Hosting is provided by DigitalOcean; our application and database run on servers in the EU. Card payments are processed by Stripe. Cryptocurrency checkout runs on BTCPay Server that we host and operate ourselves. We do not sell personal data. We share it with service providers only as described above, and only to operate the service.

International transfers

We store and process data on DigitalOcean servers in the EU. Stripe and other payment providers may process data outside the EU under their own policies.

Automated decisions

We do not use profiling or automated decision-making that produces legal or similarly significant effects.

Your rights

Depending on where you live, you may have rights to access, correct, delete, or restrict processing of personal data, or to object to certain processing. Because we intentionally avoid collecting identifying information, we often cannot link a request to a specific person. During the refund period, we may be able to match a card payment if you provide the payment date, amount, and last four digits of the card. Do not send your account number by email.

To exercise your rights or ask questions, email [email protected]. You may also lodge a complaint with your local data protection authority.

This policy and any disputes relating to it are governed by the laws of the Czech Republic. Courts in the Czech Republic have exclusive jurisdiction.

Children

Nullo is not directed at children under 16, and we do not knowingly collect personal data from them.

Changes

We may update this policy. When we do, we will revise the date at the top of this page. Material changes will be announced on nullo.app at least 30 days before they take effect.

Contact

Nullo is owned and run by Rainbow Unicorn s.r.o. (IČO: 11893427), a company registered in the Czech Republic.

Rainbow Unicorn s.r.o.
Vítězná 71, 360 01 Karlovy Vary,
Czech Republic

Privacy inquiries: [email protected]