NIMU

Nimu Privacy Policy

Version 2.4. Effective October 8, 2026.

Data controller: IBRSTUDIO LLC, Colorado, United States. Email: soporte@nimuapp.app.

In one sentence: we keep the minimum needed for Nimu to work, your business card is public because that is what it is for, we do not sell your data, and we show no third party advertising. What you keep in your Vault, not even we can read.

Scope. This Privacy Policy (the "Policy") describes how IBRSTUDIO LLC ("Nimu," "we") collects, uses, retains, discloses, and protects the personal data of those who use the Nimu mobile application for iOS and Android, the nimuapp.app website, and the public pages Nimu generates at its users' request (business cards, coupons, documents, job postings, NIMU Events invitations and albums, among others), as well as of people who, without an account, interact with those pages. It forms an integral part of the Nimu Terms and Conditions. Capitalized terms not defined here have the meaning given to them in the Terms. In this Policy, "personal data" means any information that identifies a natural person or makes that person reasonably identifiable; "processing" means any operation performed on that data, such as collecting, storing, consulting, transmitting, or erasing it; and "provider" or "processor" means a company that processes data on behalf of and at the instruction of Nimu.

Our role. With respect to the data of your account, your card, and your use of the service, Nimu acts as data controller. With respect to third party data that you upload for your own activity (the recipients of your scheduled emails, the clients on your documents, the guests at your events, or the people who apply to your job postings), you decide what data is processed and for what purpose, and Nimu processes it on your behalf, as processor, for the sole purpose of providing the service you request. This does not reduce the obligations this Policy assumes toward those people.

1. What we collect

We collect only the categories of data described below, to the extent you use the corresponding feature. Where a category is optional, we say so; where a feature is not used, its data is not collected.

  1. Your account: email address, username, the name you choose to display, profile photo if you upload one, and password. The password is never stored in plain text: our authentication provider keeps it in encrypted form using an irreversible hash function. If you sign in with Google or Apple, we receive from that provider your email and, when it shares them, your name and photo; if you choose to hide your email, Apple gives us a relay address. We also record the date you accepted the Terms and the version accepted.
  2. Your business card, if you create one: business name, category or trade, description, logo, cover, photos and catalog, links (website, social networks, WhatsApp, contact email and phone), address and location of the business and its branches, country, city, time zone, languages, business hours, email signature and, if you link it, the business's Google listing (its public identifier and the result of the verification). This information is public by design.
  3. Your approximate location: used while you use the app to show you nearby businesses and coupons. The permission is "while using the app" only: Nimu does not request or use your location in the background. To notify you of nearby coupons, we store on our servers a single reference point, which is the city you choose or your last known location, rounded to about 1.1 km before it is stored, so that it never records your exact home address. Your list of recent cities lives only on your device.
  4. Content you create: coupons, quote requests you send, to dos, and emails you schedule, including the contact details of recipients you enter, personal notes with their reminders, appointment requests and their notes, and NIMU Celebrate announcements.
  5. Usage events without identity: we count views, taps, and redemptions on each card to give businesses statistics, without recording who did them. The business sees numbers, never people. When the card is opened by someone who is not signed in, so as not to count the same visit twice we compute an irreversible fingerprint from the IP address, the day, and a secret value; that fingerprint changes every day, does not allow anyone to be followed from one day to the next, and is deleted after two days.
  6. Technical data: notification token, device language, and error reports. The token and language are used to deliver notices to you in your language and are deleted when you sign out. Error reports contain the type of failure, the screen and app version, the operating system, and your account's internal identifier, without your name, your email, or your IP address; default sending of personal data is turned off. We do not incorporate advertising analytics or cross app tracking tools.
  7. Redemption records: when you redeem a coupon we store which account redeemed it for the sole purpose of preventing double redemption. The business sees the number of redemptions, never the identity of who redeemed. If a business invites you to its team to scan coupons, we store your membership in that team for as long as it lasts.
  8. Microphone (NIMU Beam), only if you allow it: NIMU uses the microphone only while the app is on screen, to receive cards by sound: when you tap Receive or, if you turn it on, while NIMU is open. No audio is recorded or saved: everything is processed on the phone, which only looks for a card code in the sound and discards it. What travels through the air is an 8-character code that expires in 10 minutes; the business ID never travels. A business counter mode only plays that sound and does not use the microphone.
  9. Invitation on shared cards: whoever opens a business card in the browser may see an invitation to create their own digital card with NIMU: full screen the first time on each device and, on later visits, as a bar at the bottom. To know you already saw it, the browser keeps in its local storage (localStorage) only the date it was shown; that data does not leave your device. We count how many times it is shown and tapped, without personal data: we do not store your IP address or who you are, and so as not to count the same tap twice we use an irreversible fingerprint that expires after 24 hours.
  10. NIMU Events and the Vault: what they store is explained in sections 11 and 12.
  11. Camera, photos, and files: the camera is used to scan coupon codes and to digitize documents; the photo library, to choose the images you publish; and the permission to save to Photos, only to save to your device what you download (your coupons, your QR code, or the photos in your album). Only the images and files you choose to publish or send are uploaded to our servers. Document scanning and reading text in images take place on your device with the operating system's tools.
  12. Contacts, only if you allow it: the contacts permission is requested only when you tap Import in the NIMU Invitations guest list. Only the name and phone number of the contacts you choose one by one are uploaded; the rest of your address book does not leave your phone and Nimu never writes to it.
  13. Payment data: in-app purchases (the NIMU Pro subscription and NIMU Events one-time purchases) are charged by the Apple or Google store. Through our subscription management provider, we receive from the store the status of your subscription, the product, the store, the transaction ID, the price, the currency, and the dates, linked to your account's internal identifier; never your card details. Purchases Nimu offers on its website and businesses' online payments are described in section 13.
  14. Invitation program and NFC card: if you sign up with another user's invitation code or link, we permanently store who invited you, when, and whether your account was activated, in order to credit any applicable benefit and so that the record of who invited whom is preserved. If you claim a physical NFC card, we store the shipping name and address you enter and the shipping status; that data, together with your email, your businesses, and your invitations, is communicated to the internal Nimu team that prepares and ships the card.
  15. Support and security: when you write to us we keep your message, your contact details, and the images you attach. To protect accounts we record failed sign in attempts and, if they repeat, we send you a security notice; to curb abuse we apply usage limits by irreversible fingerprint of the IP address, which are deleted in cycles of one or two days.
  16. Data of people without an account: whoever requests a quote from a business through its card gives us their name, phone number, and message; whoever sends it a file with "Send a file" gives us the file, the name they sign with, and an optional note; and whoever opens a document a business sent them leaves the open record described in section 13. Those people may exercise the rights in section 9 just like a registered user.

2. On what basis and why we use your information

We process your data to perform our service contract with you, with your consent where applicable, and for our legitimate interest in operating and protecting Nimu. The purposes are: operate the directory and cards, show nearby coupons, deliver quote requests, send the emails you schedule, send you useful notifications, give statistics to businesses, moderate prohibited content, prevent fraud, and improve the app.

In greater detail, each purpose rests on the basis indicated:

  1. Performance of the contract: creating and managing your account; publishing your card, your coupons, your job postings, and your announcements; delivering to each business the quote requests, appointments, files, and applications addressed to it; sending the emails, documents, and reminders you schedule; operating NIMU Events, the Vault, NIMU Office, and NIMU Beam; verifying your purchases and activating what you paid for; providing you with support.
  2. Consent: access to the microphone, camera, photos, contacts, and location, which you grant in the operating system and may withdraw at any time in its settings; notifications; turning on the Vault; connecting your Google Drive, Dropbox, Facebook, Instagram, or TikTok accounts; and the optional data a guest enters when responding to an invitation. Withdrawing consent does not affect the lawfulness of prior processing.
  3. Legitimate interest: the security of accounts and of the service; preventing fraud, promotion abuse, and unsolicited messaging; moderating published content; the aggregate statistics offered to businesses; diagnosing errors; and improving the product. We weigh that interest against your rights and, for that reason, whenever the purpose allows it, we work with irreversible fingerprints, aggregate data, or rounded data instead of data that identifies you.
  4. Compliance with legal obligations: retaining transaction records as required by tax and accounting rules; responding to valid requests from authorities; and handling copyright notices and privacy requests.

We do not use your data for purposes incompatible with those described here. If in the future we wished to use it for a new purpose, we will inform you and, where the law requires it, ask for your prior consent.

3. What we do not do

We do not sell or rent your data, and we do not share it for third party advertising. We show no third party advertising. We do not record the identity of who visits or taps a card. We do not read your personal to dos for any purpose other than showing and executing them. We do not use facial recognition. We cannot read the contents of your Vault.

Nor do we build profiles for advertising purposes, track your activity across other companies' apps or websites, share your data with data brokers, use your location in the background, record audio, or use the private content of your documents, notes, events, or Vault to train artificial intelligence models. Within the meaning of California privacy law, Nimu does not "sell" or "share" personal data for cross context behavioral advertising.

4. Public content

Your business card, your coupons, and your business information are public: anyone can view and share them, and they can appear in search engines and artificial intelligence assistants. Do not publish on your card information you do not want to make public. An account that Nimu authorizes for social publishing may post the poster of public cards from its country's directory, with their link and QR code, on its own Facebook, Instagram, or TikTok pages; it never posts hidden cards.

Your job postings and your NIMU Celebrate announcements are likewise public while they are active. The Google reviews shown on a card are public at their source, belong to their authors, and include the name under which each author published them on Google. Nimu also offers read only access for artificial intelligence agents, which queries exclusively the public information in the directory, subject to the same country and visibility limits as the app. A card's link and QR code are permanent: if the NIMU Pro subscription ends, the card leaves the directory and its page shows only the name, the logo, and the notice that the business is renewing its NIMU, without phone, links, coupons, or documents. Once another person has copied, shared, or saved public content, Nimu cannot remove it from third parties' devices or services.

Prefilled listings. Nimu shows listings of independent businesses built from public data in open sources (INEGI's DENUE and Overture Maps) and checked on the business's own website: name, category, address, phone, hours, the source, and the verification date. This is business data, not personal data, and anyone can remove the listing free of charge with "Remove my business"; Nimu records each request with its originating IP address to prevent abuse. If someone claims a listing, Nimu processes the email address at the website's domain or the listing's phone to send the verification code (the SMS or call is sent by a messaging provider), and keeps the signed declaration with its date, the IP address, and the device, as proof of the claim. If the business publishes an email on its website, Nimu may write to it once and remind it once after 30 days; it records the send date, its delivery receipt, whether the email was opened, whether its link was tapped, and the unsubscribe, which is per address and forever.

5. Who we share information with

Only with providers that process data at our instruction, and only what each needs for its function. As a general rule we do not name them, but describe them by the category of service they provide; we name a company only when its role toward you requires it: because it charges in its own name, because the law or our contract with it requires it, or because it is you who connects your own account with it.

Providers that process data on Nimu's behalf:

  1. Database and storage infrastructure: hosts our database, account authentication, files, and server functions, in data centers in the United States. It receives every category of data Nimu stores.
  2. Web hosting and content delivery: serves nimuapp.app and the public pages and, like any web server, receives the IP address and technical data of each visit in order to deliver and protect it.
  3. Transactional email delivery: delivers the emails you schedule, the documents you send, appointment reminders, NIMU Events notices, security notices, and service emails; it receives the recipient, subject, content, and attachments, and returns delivery receipts to us.
  4. Error monitoring: receives the technical failure reports described in section 1, item 6.
  5. Subscription management: receives from the stores the status of your in-app purchases, linked to your account's internal identifier, without your name or email.
  6. Notification delivery: relays your notifications to Apple's and Google's notification services with your device token and the text of the notice.
  7. Artificial intelligence models: performs automated review of published content (texts, links, and images of cards, profiles, coupons, invitations, and announcements) to detect prohibited content, and writes the text suggestions you request with "NIMU writes for you" from the instructions you type. That content is processed only for those purposes; we do not send it your Vault, your documents, your notes, Moments guests' photos, or the photos in job applications.
  8. Map and font services in the browser: when you open some public pages, your browser downloads the map tiles, the library that draws the map, and the fonts from third party servers, which receive your IP address as in any web download.

Companies we name and why:

  1. Apple and Google: process subscription payments and NIMU Events one-time purchases. They are the merchant that charges you, under their own terms and privacy policies, and they decide refunds of those purchases.
  2. Stripe: provides payment processing for payments made on Nimu's website and for businesses' online payments, as detailed in section 13. It receives payment data directly from the payer; Nimu never receives or stores complete card details.
  3. Google Maps and Places: maps, business locations, and public reviews. When you search for an address or a business, the text you type and the coordinates are sent to Google, subject to the Google Maps Additional Terms of Service and the Google Privacy Policy.
  4. Google and Apple as sign in providers, if you choose to sign in with them.
  5. Google Drive and Dropbox: only if you, as host, choose to export your Moments album photos there; they are saved to your own account. Nimu's use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements: with the Drive permission, Nimu only creates the files you export and reads no others.
  6. Meta (Facebook and Instagram) and TikTok: only if an authorized account connects its own networks for social publishing; we store its permission encrypted and send them the public poster and its text to publish on that account.

We will also share information if the law requires it through a valid order, or to protect the rights, safety, or integrity of people or of Nimu.

In the event of a merger, acquisition, reorganization, or sale of all or part of the business, data may be transferred to the entity that continues to provide the service, which will be bound by this Policy or by one offering at least equivalent protection, and we will notify you. We require each provider, by contract, to process data only in accordance with our instructions, with appropriate security measures and a duty of confidentiality.

6. Notifications

We send useful notifications: your business activity, saved coupons about to expire, and at most one nearby opportunity per day. If you use NIMU Events, also notices about your events: your guests' RSVPs (you can mute them), pause, expiration, and the notices before Moments deletion; some also arrive by email. You can turn them off in your device settings.

In addition, depending on the features you use, you will receive notices of new quote requests, appointments, files, and applications, of the opening and acceptance of your documents, of payments received, of the expiration of your job postings, of your notes' reminders, and of your subscription's renewal when it affects an event. Vault expiration reminders are scheduled on your own phone. A copy of each notification is kept in your inbox inside the app. Service emails necessary for the account, such as verification, password recovery, and security emails, cannot be turned off while the account exists. Nimu does not send third party marketing emails.

7. How long we keep your information

Your account and your card, for as long as your account exists. Coupons are permanently deleted 30 days after they expire. If you delete your account, it is deactivated immediately and permanently erased after 30 days, unless you sign in before then to recover it. Redemption records are deleted together with the coupon. A NIMU Events invitation, until it expires; after the list of confirmed guests is sent to you, it is deleted together with your guests' responses. Moments photos, at most six months from when you activate the album; trial photos, 7 days. When an invitation or album closes we keep a minimal record, with no guest data or content (dates, counts, and the purchase), for support and refunds. Your Vault, until you delete the document or your account. System backups rotate and are deleted in short cycles.

The other periods are as follows:

  1. Quote requests: 30 days after the business closes them, or 60 days after they are received if they are never closed.
  2. Appointments: 90 days after their date, once the business and the client have archived them.
  3. Files received through "Send a file": 24 hours, whether or not they were downloaded.
  4. Change history of your notes: 30 days. Notes, until you delete them.
  5. Fingerprints of visits and taps by people without an account: two days. Fingerprints for usage limits and redemption attempts: one or two days.
  6. NIMU Beam codes: they expire after 10 minutes and are deleted the next day.
  7. NIMU Office documents and their open and acceptance records: for as long as the document and your account exist, because they are your business records and the evidence of what was accepted. The stored PDF is deleted after 60 days and regenerated if needed.
  8. Job postings: they expire on their own on the date you set, up to a maximum of 30 days; applications received are kept until the business deletes them or the business's or the applicant's account is deleted.
  9. Logs of access by artificial intelligence agents: 90 days.
  10. Social publishing permissions: until the account disconnects them or Nimu revokes the authorization.

When an account is deleted, its files are erased and, in cascade, the data linked to it. What survives, without public access and only for the purposes indicated, are the records that the law or the defense of rights require us to keep: records of purchases, transactions, and refunds (tax and accounting obligations and handling of claims from the stores and the payment processor); internal notices of NFC card claims already shipped; moderation, report, and sanction records (to prevent repeat violations); and minimal event closing records. Providers keep their own technical logs for the periods set by their policies, and the stores and the payment processor keep the data of the transactions they themselves processed in accordance with their legal obligations.

8. Children

Nimu is not directed to children under 13 and we do not knowingly collect their information. If you believe a child under 13 created an account, write to us and we will delete it.

NIMU Moments photos may show minors. Whoever uploads them and the event host are responsible for having permission from their parents or guardians. If you are a parent or guardian and want a photo removed, ask the host or write to us at soporte@nimuapp.app.

Purchasing the subscription and making purchases require legal age. An event's guests do not need an account, and the album page does not ask the age of whoever uploads a photo; for that reason the responsibility for obtaining permission from parents or guardians rests with the host, who knows the guests, and Nimu will give priority to any request to remove images of minors, even if it does not come from the host.

9. Your rights, in the United States and in Mexico

You can view and correct your information from the app, and delete your account from Profile at any time.

If you reside in the United States, depending on your state, you may have the right to know what data we hold, obtain a copy, correct it, delete it, and not be discriminated against for exercising these rights. We do not sell personal data.

If you reside in Mexico, under the Federal Law on Protection of Personal Data Held by Private Parties, you have ARCO rights: access, rectification, cancellation, and opposition to the processing of your data, as well as the right to withdraw your consent. To exercise them, write to soporte@nimuapp.app stating your request and your registration email; we will handle your request within the periods set by law. You may also contact the Mexican personal data protection authority (currently, the Secretaría Anticorrupción y Buen Gobierno).

To exercise any of these rights in any country, write to soporte@nimuapp.app. Your data is processed in the United States; by using Nimu you understand that your information is transferred and processed there.

Details on exercising your rights:

  1. Verification: to protect your information, we will ask you to write from your account email or to confirm your identity by reasonable means before providing or modifying data. You may act through an authorized agent, who must prove their authority.
  2. Time periods: in Mexico, we will communicate our response within a maximum of 20 business days and make it effective within the following 15 business days, as provided by law; in the United States, we respond within the 45 days set by state laws, extendable where the law allows it and with notice to you.
  3. Sensitive data: we treat as sensitive the documents in the Vault, which we cannot read, and guests' allergy notes, which are optional and used only for the event. We do not use sensitive data to infer anyone's characteristics; if your state recognizes the right to limit its use, you may exercise it by writing to us.
  4. Third party data: if your data was uploaded by a Nimu user (for example, as the client on a document, a guest at an event, or the recipient of an email), you may direct your request to that user or to us; we will handle it in coordination with them.
  5. Appeal: if we deny your request, we will explain the reason and you may appeal by replying to the same email; if the appeal is denied, you may contact the data protection authority or your state's attorney general.
  6. Deletion without an account: the page nimuapp.app/delete-account explains how to request deletion without opening the app.

10. Security

We use encryption in transit, encrypted passwords, per user access controls, and protected keys. No system is infallible, but security is part of Nimu's design, not an afterthought.

Specifically: all communication between the app, the website, and our servers travels encrypted; every table in the database has row level access rules that let each account see only its own data; public pages read information through functions that return exclusively the public fields; private files are served through short lived signed links; service keys and secrets live outside the code; the permissions of connected social networks are stored encrypted; and IP addresses, when they serve only to curb abuse, are stored as irreversible fingerprints. If we become aware of a security breach that significantly affects your rights, we will notify you without undue delay and as required by applicable law, with a description of what happened and the measures you can take. You contribute to your account's security by protecting your password, access to your phone, and your 12 Vault words.

11. NIMU Events: host and guest data

From the host: the event details you write (names, date, places, texts, photos, and audio), the list of families with their passes, tables, and phone numbers, and the contacts you choose to import: contacts permission is requested only when you tap Import, and only the contacts you choose are used. We also keep a record of your one-time purchases (store, transaction ID, price, and date), never your card details.

From the event we also store the addresses and coordinates of the ceremony and the reception, the WhatsApp number at which you want to receive RSVPs, the password for the general page if you decide to set one (stored as an irreversible hash), the menu options, the sections of your album, the managers you invite (up to three besides you), and the record of what you send to each family. The one-time purchase is verified on the server with the store; the app never activates anything on its own.

From NIMU Invitations guests: guests do not need an account or the app. When they RSVP we store their response: whether they attend and how many of their passes they use (adults and children) and, only if they enter them, names, a note on allergies or dietary needs, and their menu choice. The allergies note may reveal health information: it is optional and used only for the event. If they leave their phone number, which is also optional, we store an irreversible fingerprint and the last four digits, only so they can change their response from another device. So that a forwarded link cannot change a family's response, the page places a cookie in the browser with a random number, valid for one year and only for that invitation; we store only an irreversible fingerprint of that number. Our server uses the IP address to limit abuse and stores it only as an irreversible fingerprint, deleted in short cycles. Invitation pages are not indexed by search engines.

We also keep the change history of each response (what changed, through which channel, and when) and the date on which the family opened its invitation, so that the host knows who saw it. Each family's phone number, when the host enters it, is stored so the host can send the invitation and is seen only by the event's managers.

From NIMU Moments guests: the photos they upload and the time they were taken (read from the photo itself or from the device clock), to order them in the album. Before their first photo, each guest sees a one line consent notice: their photos will be seen by the host and the guests of that event. We do not use facial recognition.

A guest may also leave an audio or video message of up to 60 seconds, which only the hosts hear or see, and may write their name next to their photos if they wish. The consent notice reads: "By sharing, your photos and messages will be seen by the hosts and the guests of this event.", and links to this Policy. The original file is kept as the guest uploads it, with whatever metadata it contains; Nimu reads only the date and orientation from it, but if the phone recorded in the photo the place where it was taken, that data may remain inside the file the host downloads. The views and thumbnails shown in the album are generated on the guest's phone without that metadata. To limit abuse and resume interrupted uploads, the page places a cookie with a random number, valid for one year and only for that album, and counts uploads by irreversible fingerprint of the IP address.

Who sees it: the event's managers see the list and the responses; a family never sees another family's responses. Moments photos are seen by the host and, depending on how the host sets it up, by the event's guests.

For what and for how long: guest data is used only for that event, never for advertising or any other purpose. The host decides whom to invite and what to ask; Nimu processes that data on the host's behalf to run the event. An invitation is deleted when it expires, after the list of confirmed guests is sent to the host; Moments photos, no later than six months after the album is activated, and those of a trial that was not activated, after 7 days. The list the host exports or receives by email is in the host's care.

Before Moments deletion we send the host notices at 30, 90, 150, 165, and 175 days and a final notice, and deletion takes place on the scheduled date even if the host has not exported the photos. If the host's subscription ends, the invitation and the album are paused: guests see a neutral page with no event data, the list remains exportable, and the deletion dates do not change. Photos the host downloads or exports to their phone, to Google Drive, or to Dropbox are in the host's care and outside the scope of Nimu's retention periods.

If you are a guest: you can change your response until the deadline. To remove your response or a photo, ask the host or write to us at soporte@nimuapp.app.

12. The Vault (Baúl)

The Vault is zero knowledge: your documents, their fields, and their images are encrypted on your phone before they leave it, with keys that come from your 12 words and that we never receive. Our servers store only encrypted packages that we cannot open. The only things we see are what is needed to store them: how many documents and files you have, their size, and their dates.

Encryption uses exclusively the cryptographic functions provided by your phone's operating system: your 12 words are turned into a master key through a slow derivation (PBKDF2), from which, in layers, an account key, a key per document, and a key per file are derived; each package is encrypted with AES-256-GCM and bound to its place, so that the phone detects any alteration. Nimu also stores, alongside your account, the public parameters of that derivation and your wrapped account key, which is useless without your 12 words.

  1. Reading the text of your documents, to fill in fields, happens on your phone; nothing leaves it for that.
  2. You open the Vault with Face ID, fingerprint, or a PIN of its own. Biometrics are verified by your phone's system: Nimu never receives your biometric data. The key that spares you from typing the 12 words lives only on that device, with no cloud copy.
  3. Expiration reminders are scheduled on your phone; our servers do not see your documents' dates.
  4. We cannot read or recover the contents of your Vault, or hand them over in readable form to anyone. If you lose your 12 words and your phone, those contents are lost.
  5. We treat the Vault as sensitive information and you turn it on with your express consent. You can withdraw it at any time by deleting your documents or your account, and their encrypted copies are deleted. The export, which is not encrypted, and the copies you share with the COPY mark are in your care.
  6. The Vault PIN allows five attempts; on the fifth failure it is erased from the device and only your 12 words open the Vault. If you change the fingerprints or faces enrolled on the phone, the biometric key is invalidated.
  7. When you copy a field, the clipboard clears itself after 45 seconds. On Android, screenshots are blocked inside the Vault; on iPhone they can only be detected.
  8. Because we cannot read the contents, we cannot hand them over to any authority in readable form, or use them for any other purpose.

13. NIMU Office: documents, signatures, and online payments

What we store about the issuing business: the trade name, phone, address, logo, tax rate, and country you use on your documents, and the series and number of each one.

What we store about the business's clients: on each quote, estimate, invoice, or payment note, the client's name, email, phone, and address that the business enters, the line items, amounts, notes, and the document's previous versions. The business is the one that decides to include that data and is responsible for having obtained it lawfully; Nimu processes it on the business's behalf to generate, send, and collect payment for the document.

Opening and acceptance: when the client opens a document's public link, we record the date and time, a random identifier their browser stores locally, their IP address and user agent, and whether the opening was by the issuer itself or by a link preview robot; this lets the business know its document was seen. When the client accepts and signs, we store the signature they draw, the name under which they accept, the accepted text, the date and time, the IP address, and the user agent, as evidence of the acceptance. We also note the IP address from which the issuer created the document.

Businesses' online payments: in the United States, a business may collect payment for its documents online through a Stripe connected account. To create it, Nimu communicates to Stripe the business name and the account's internal identifier, and Stripe collects directly from the business the identity, tax, and banking data the law requires, under its own privacy policy; Nimu does not receive or store banking data. The payer pays on a Stripe payment page, which collects their card and billing details; Nimu receives only the payment confirmation, its identifier, the amounts, and the date, and notifies the business with the client name shown on the document.

Purchases on Nimu's website: the document plans and printed cards Nimu sells at nimuapp.app are also paid through Stripe. For printed cards we store the shipping name, address, city, state, ZIP code, and phone, the tax calculated by the processor and, as evidence that you accepted the order's conditions, the date, IP address, and user agent of that acceptance.

14. Jobs

A business may publish job postings on its card. Whoever applies gives us their name, phone, email, a description of their experience, and a photo of their face, which is mandatory in order to apply. The application is seen only by the business that published the posting, inside the app; it is not published or shared with anyone else, and it is not sent to any artificial intelligence model. Nimu does not use the photo to identify anyone or to make decisions. The business is responsible for its use of the application in accordance with applicable labor and anti discrimination laws; it may delete its application history, and the applicant may request deletion of their application by writing to soporte@nimuapp.app.

15. NIMU Celebrate

Businesses with NIMU Pro may publish announcements about their own business with NIMU Celebrate, of the types in a closed list the app offers. The fixed data of the announcement (name, logo, address, and link) is taken from the business's card, and the text added goes through the automated moderation described in section 5. Celebrate announces only business matters, never personal ones: it is not designed to publish data about people, and it rejects announcements of personal events except for event venue and banquet businesses. The announcement is public content while it is published; it can be reported, and each report is recorded with the account that makes it, which is never revealed to the business.

16. Social publishing by authorized accounts

Only accounts that Nimu expressly authorizes may connect their Facebook page, their Instagram business account, and their TikTok account, through each network's official sign in. We store the identifier and name of the connected account and its access permission, encrypted, and use it only to publish on that same account, at the pace it sets, the public poster of cards from its country's directory with its text, link, and QR code, and to read the identifier and link of each post. We record each post and its result. We never publish hidden, test, or other country cards. The holder of a business may ask at any time, by writing to soporte@nimuapp.app, that its card not be published on other accounts' networks; once the request is handled, its card is excluded and anything awaiting a retry is skipped. Disconnecting or revoking erases the stored permission, and the account may also withdraw it from each network's settings. What each network does with what is published is governed by its own policies.

17. Cookies, local storage, and similar technologies

Nimu does not use third party advertising or analytics cookies. On the website and the public pages we use only these items, all necessary for the function indicated:

  1. A language cookie, to remember the language you choose.
  2. The cookies with a random number for a NIMU Events invitation or album, valid for one year and only for that event, described in section 11.
  3. In the browser's local storage (localStorage): the date you saw the invitation to create your card, the light or dark theme, the Moments guest preferences, the queue of photos waiting to be uploaded, and the random device identifier used by the document open record.
  4. In the app, the phone's local storage keeps your session, your preferences, your recent cities, the invitation code you arrived with, and the Vault keys in the system's secure keychain.

You can delete these items from your browser or phone settings; some features, such as changing a guest response from the same device, will stop working as expected.

18. Automated decisions and moderation

Nimu does not make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you, except for content moderation. An automated filter reviews content when it is published and may reject or hide it if it detects content prohibited by the Terms; reports from several users, confirmed by a second automated review, may hide content for everyone. We keep a sample of the rejected content and the reason, to handle complaints and prevent repeat violations. If you believe a moderation decision is wrong, write to us at soporte@nimuapp.app and a person will review it. The order of businesses in the directory depends on proximity, activity, and subscription, not on a profile of the person searching.

19. International transfers

Nimu is operated from the United States and its providers process data mainly in that country. If you use Nimu from Mexico or another country, your data is transferred to the United States, where data protection law may offer a level of protection different from that of your country. Transfers to our providers are necessary to provide you with the service you request and are made with contractual commitments of confidentiality and security. Under Mexican law, transfers to processors do not require your consent; those we make to the stores, the payment processor, or the networks you connect are necessary to perform the contract with you or are requested by you.

20. Changes to this policy

If we change this policy in a significant way, we will notify you inside the app before the change takes effect.

Each version states in its header the date from which it applies, and the history at the bottom summarizes what changed. Previous versions may be requested at soporte@nimuapp.app. When a change expands the use of data we collect with your consent, we will ask for that consent again.

21. Contact

Privacy questions or exercise of rights: soporte@nimuapp.app, or through Help and support inside the app.

IBRSTUDIO LLC, Colorado, United States.

Version history

Nimu · IBRSTUDIO LLC · soporte@nimuapp.app · v2.4