Version 2.4. Effective October 8, 2026.
Data controller: IBRSTUDIO LLC, Colorado, United States. Email: soporte@nimuapp.app.
In one sentence: we keep the minimum needed for Nimu to work, your business card is public because that is what it is for, we do not sell your data, and we show no third party advertising. What you keep in your Vault, not even we can read.
Scope. This Privacy Policy (the "Policy") describes how IBRSTUDIO LLC ("Nimu," "we") collects, uses, retains, discloses, and protects the personal data of those who use the Nimu mobile application for iOS and Android, the nimuapp.app website, and the public pages Nimu generates at its users' request (business cards, coupons, documents, job postings, NIMU Events invitations and albums, among others), as well as of people who, without an account, interact with those pages. It forms an integral part of the Nimu Terms and Conditions. Capitalized terms not defined here have the meaning given to them in the Terms. In this Policy, "personal data" means any information that identifies a natural person or makes that person reasonably identifiable; "processing" means any operation performed on that data, such as collecting, storing, consulting, transmitting, or erasing it; and "provider" or "processor" means a company that processes data on behalf of and at the instruction of Nimu.
Our role. With respect to the data of your account, your card, and your use of the service, Nimu acts as data controller. With respect to third party data that you upload for your own activity (the recipients of your scheduled emails, the clients on your documents, the guests at your events, or the people who apply to your job postings), you decide what data is processed and for what purpose, and Nimu processes it on your behalf, as processor, for the sole purpose of providing the service you request. This does not reduce the obligations this Policy assumes toward those people.
We collect only the categories of data described below, to the extent you use the corresponding feature. Where a category is optional, we say so; where a feature is not used, its data is not collected.
We process your data to perform our service contract with you, with your consent where applicable, and for our legitimate interest in operating and protecting Nimu. The purposes are: operate the directory and cards, show nearby coupons, deliver quote requests, send the emails you schedule, send you useful notifications, give statistics to businesses, moderate prohibited content, prevent fraud, and improve the app.
In greater detail, each purpose rests on the basis indicated:
We do not use your data for purposes incompatible with those described here. If in the future we wished to use it for a new purpose, we will inform you and, where the law requires it, ask for your prior consent.
We do not sell or rent your data, and we do not share it for third party advertising. We show no third party advertising. We do not record the identity of who visits or taps a card. We do not read your personal to dos for any purpose other than showing and executing them. We do not use facial recognition. We cannot read the contents of your Vault.
Nor do we build profiles for advertising purposes, track your activity across other companies' apps or websites, share your data with data brokers, use your location in the background, record audio, or use the private content of your documents, notes, events, or Vault to train artificial intelligence models. Within the meaning of California privacy law, Nimu does not "sell" or "share" personal data for cross context behavioral advertising.
Your business card, your coupons, and your business information are public: anyone can view and share them, and they can appear in search engines and artificial intelligence assistants. Do not publish on your card information you do not want to make public. An account that Nimu authorizes for social publishing may post the poster of public cards from its country's directory, with their link and QR code, on its own Facebook, Instagram, or TikTok pages; it never posts hidden cards.
Your job postings and your NIMU Celebrate announcements are likewise public while they are active. The Google reviews shown on a card are public at their source, belong to their authors, and include the name under which each author published them on Google. Nimu also offers read only access for artificial intelligence agents, which queries exclusively the public information in the directory, subject to the same country and visibility limits as the app. A card's link and QR code are permanent: if the NIMU Pro subscription ends, the card leaves the directory and its page shows only the name, the logo, and the notice that the business is renewing its NIMU, without phone, links, coupons, or documents. Once another person has copied, shared, or saved public content, Nimu cannot remove it from third parties' devices or services.
Prefilled listings. Nimu shows listings of independent businesses built from public data in open sources (INEGI's DENUE and Overture Maps) and checked on the business's own website: name, category, address, phone, hours, the source, and the verification date. This is business data, not personal data, and anyone can remove the listing free of charge with "Remove my business"; Nimu records each request with its originating IP address to prevent abuse. If someone claims a listing, Nimu processes the email address at the website's domain or the listing's phone to send the verification code (the SMS or call is sent by a messaging provider), and keeps the signed declaration with its date, the IP address, and the device, as proof of the claim. If the business publishes an email on its website, Nimu may write to it once and remind it once after 30 days; it records the send date, its delivery receipt, whether the email was opened, whether its link was tapped, and the unsubscribe, which is per address and forever.
Only with providers that process data at our instruction, and only what each needs for its function. As a general rule we do not name them, but describe them by the category of service they provide; we name a company only when its role toward you requires it: because it charges in its own name, because the law or our contract with it requires it, or because it is you who connects your own account with it.
Providers that process data on Nimu's behalf:
Companies we name and why:
We will also share information if the law requires it through a valid order, or to protect the rights, safety, or integrity of people or of Nimu.
In the event of a merger, acquisition, reorganization, or sale of all or part of the business, data may be transferred to the entity that continues to provide the service, which will be bound by this Policy or by one offering at least equivalent protection, and we will notify you. We require each provider, by contract, to process data only in accordance with our instructions, with appropriate security measures and a duty of confidentiality.
We send useful notifications: your business activity, saved coupons about to expire, and at most one nearby opportunity per day. If you use NIMU Events, also notices about your events: your guests' RSVPs (you can mute them), pause, expiration, and the notices before Moments deletion; some also arrive by email. You can turn them off in your device settings.
In addition, depending on the features you use, you will receive notices of new quote requests, appointments, files, and applications, of the opening and acceptance of your documents, of payments received, of the expiration of your job postings, of your notes' reminders, and of your subscription's renewal when it affects an event. Vault expiration reminders are scheduled on your own phone. A copy of each notification is kept in your inbox inside the app. Service emails necessary for the account, such as verification, password recovery, and security emails, cannot be turned off while the account exists. Nimu does not send third party marketing emails.
Your account and your card, for as long as your account exists. Coupons are permanently deleted 30 days after they expire. If you delete your account, it is deactivated immediately and permanently erased after 30 days, unless you sign in before then to recover it. Redemption records are deleted together with the coupon. A NIMU Events invitation, until it expires; after the list of confirmed guests is sent to you, it is deleted together with your guests' responses. Moments photos, at most six months from when you activate the album; trial photos, 7 days. When an invitation or album closes we keep a minimal record, with no guest data or content (dates, counts, and the purchase), for support and refunds. Your Vault, until you delete the document or your account. System backups rotate and are deleted in short cycles.
The other periods are as follows:
When an account is deleted, its files are erased and, in cascade, the data linked to it. What survives, without public access and only for the purposes indicated, are the records that the law or the defense of rights require us to keep: records of purchases, transactions, and refunds (tax and accounting obligations and handling of claims from the stores and the payment processor); internal notices of NFC card claims already shipped; moderation, report, and sanction records (to prevent repeat violations); and minimal event closing records. Providers keep their own technical logs for the periods set by their policies, and the stores and the payment processor keep the data of the transactions they themselves processed in accordance with their legal obligations.
Nimu is not directed to children under 13 and we do not knowingly collect their information. If you believe a child under 13 created an account, write to us and we will delete it.
NIMU Moments photos may show minors. Whoever uploads them and the event host are responsible for having permission from their parents or guardians. If you are a parent or guardian and want a photo removed, ask the host or write to us at soporte@nimuapp.app.
Purchasing the subscription and making purchases require legal age. An event's guests do not need an account, and the album page does not ask the age of whoever uploads a photo; for that reason the responsibility for obtaining permission from parents or guardians rests with the host, who knows the guests, and Nimu will give priority to any request to remove images of minors, even if it does not come from the host.
You can view and correct your information from the app, and delete your account from Profile at any time.
If you reside in the United States, depending on your state, you may have the right to know what data we hold, obtain a copy, correct it, delete it, and not be discriminated against for exercising these rights. We do not sell personal data.
If you reside in Mexico, under the Federal Law on Protection of Personal Data Held by Private Parties, you have ARCO rights: access, rectification, cancellation, and opposition to the processing of your data, as well as the right to withdraw your consent. To exercise them, write to soporte@nimuapp.app stating your request and your registration email; we will handle your request within the periods set by law. You may also contact the Mexican personal data protection authority (currently, the Secretaría Anticorrupción y Buen Gobierno).
To exercise any of these rights in any country, write to soporte@nimuapp.app. Your data is processed in the United States; by using Nimu you understand that your information is transferred and processed there.
Details on exercising your rights:
We use encryption in transit, encrypted passwords, per user access controls, and protected keys. No system is infallible, but security is part of Nimu's design, not an afterthought.
Specifically: all communication between the app, the website, and our servers travels encrypted; every table in the database has row level access rules that let each account see only its own data; public pages read information through functions that return exclusively the public fields; private files are served through short lived signed links; service keys and secrets live outside the code; the permissions of connected social networks are stored encrypted; and IP addresses, when they serve only to curb abuse, are stored as irreversible fingerprints. If we become aware of a security breach that significantly affects your rights, we will notify you without undue delay and as required by applicable law, with a description of what happened and the measures you can take. You contribute to your account's security by protecting your password, access to your phone, and your 12 Vault words.
From the host: the event details you write (names, date, places, texts, photos, and audio), the list of families with their passes, tables, and phone numbers, and the contacts you choose to import: contacts permission is requested only when you tap Import, and only the contacts you choose are used. We also keep a record of your one-time purchases (store, transaction ID, price, and date), never your card details.
From the event we also store the addresses and coordinates of the ceremony and the reception, the WhatsApp number at which you want to receive RSVPs, the password for the general page if you decide to set one (stored as an irreversible hash), the menu options, the sections of your album, the managers you invite (up to three besides you), and the record of what you send to each family. The one-time purchase is verified on the server with the store; the app never activates anything on its own.
From NIMU Invitations guests: guests do not need an account or the app. When they RSVP we store their response: whether they attend and how many of their passes they use (adults and children) and, only if they enter them, names, a note on allergies or dietary needs, and their menu choice. The allergies note may reveal health information: it is optional and used only for the event. If they leave their phone number, which is also optional, we store an irreversible fingerprint and the last four digits, only so they can change their response from another device. So that a forwarded link cannot change a family's response, the page places a cookie in the browser with a random number, valid for one year and only for that invitation; we store only an irreversible fingerprint of that number. Our server uses the IP address to limit abuse and stores it only as an irreversible fingerprint, deleted in short cycles. Invitation pages are not indexed by search engines.
We also keep the change history of each response (what changed, through which channel, and when) and the date on which the family opened its invitation, so that the host knows who saw it. Each family's phone number, when the host enters it, is stored so the host can send the invitation and is seen only by the event's managers.
From NIMU Moments guests: the photos they upload and the time they were taken (read from the photo itself or from the device clock), to order them in the album. Before their first photo, each guest sees a one line consent notice: their photos will be seen by the host and the guests of that event. We do not use facial recognition.
A guest may also leave an audio or video message of up to 60 seconds, which only the hosts hear or see, and may write their name next to their photos if they wish. The consent notice reads: "By sharing, your photos and messages will be seen by the hosts and the guests of this event.", and links to this Policy. The original file is kept as the guest uploads it, with whatever metadata it contains; Nimu reads only the date and orientation from it, but if the phone recorded in the photo the place where it was taken, that data may remain inside the file the host downloads. The views and thumbnails shown in the album are generated on the guest's phone without that metadata. To limit abuse and resume interrupted uploads, the page places a cookie with a random number, valid for one year and only for that album, and counts uploads by irreversible fingerprint of the IP address.
Who sees it: the event's managers see the list and the responses; a family never sees another family's responses. Moments photos are seen by the host and, depending on how the host sets it up, by the event's guests.
For what and for how long: guest data is used only for that event, never for advertising or any other purpose. The host decides whom to invite and what to ask; Nimu processes that data on the host's behalf to run the event. An invitation is deleted when it expires, after the list of confirmed guests is sent to the host; Moments photos, no later than six months after the album is activated, and those of a trial that was not activated, after 7 days. The list the host exports or receives by email is in the host's care.
Before Moments deletion we send the host notices at 30, 90, 150, 165, and 175 days and a final notice, and deletion takes place on the scheduled date even if the host has not exported the photos. If the host's subscription ends, the invitation and the album are paused: guests see a neutral page with no event data, the list remains exportable, and the deletion dates do not change. Photos the host downloads or exports to their phone, to Google Drive, or to Dropbox are in the host's care and outside the scope of Nimu's retention periods.
If you are a guest: you can change your response until the deadline. To remove your response or a photo, ask the host or write to us at soporte@nimuapp.app.
The Vault is zero knowledge: your documents, their fields, and their images are encrypted on your phone before they leave it, with keys that come from your 12 words and that we never receive. Our servers store only encrypted packages that we cannot open. The only things we see are what is needed to store them: how many documents and files you have, their size, and their dates.
Encryption uses exclusively the cryptographic functions provided by your phone's operating system: your 12 words are turned into a master key through a slow derivation (PBKDF2), from which, in layers, an account key, a key per document, and a key per file are derived; each package is encrypted with AES-256-GCM and bound to its place, so that the phone detects any alteration. Nimu also stores, alongside your account, the public parameters of that derivation and your wrapped account key, which is useless without your 12 words.
What we store about the issuing business: the trade name, phone, address, logo, tax rate, and country you use on your documents, and the series and number of each one.
What we store about the business's clients: on each quote, estimate, invoice, or payment note, the client's name, email, phone, and address that the business enters, the line items, amounts, notes, and the document's previous versions. The business is the one that decides to include that data and is responsible for having obtained it lawfully; Nimu processes it on the business's behalf to generate, send, and collect payment for the document.
Opening and acceptance: when the client opens a document's public link, we record the date and time, a random identifier their browser stores locally, their IP address and user agent, and whether the opening was by the issuer itself or by a link preview robot; this lets the business know its document was seen. When the client accepts and signs, we store the signature they draw, the name under which they accept, the accepted text, the date and time, the IP address, and the user agent, as evidence of the acceptance. We also note the IP address from which the issuer created the document.
Businesses' online payments: in the United States, a business may collect payment for its documents online through a Stripe connected account. To create it, Nimu communicates to Stripe the business name and the account's internal identifier, and Stripe collects directly from the business the identity, tax, and banking data the law requires, under its own privacy policy; Nimu does not receive or store banking data. The payer pays on a Stripe payment page, which collects their card and billing details; Nimu receives only the payment confirmation, its identifier, the amounts, and the date, and notifies the business with the client name shown on the document.
Purchases on Nimu's website: the document plans and printed cards Nimu sells at nimuapp.app are also paid through Stripe. For printed cards we store the shipping name, address, city, state, ZIP code, and phone, the tax calculated by the processor and, as evidence that you accepted the order's conditions, the date, IP address, and user agent of that acceptance.
A business may publish job postings on its card. Whoever applies gives us their name, phone, email, a description of their experience, and a photo of their face, which is mandatory in order to apply. The application is seen only by the business that published the posting, inside the app; it is not published or shared with anyone else, and it is not sent to any artificial intelligence model. Nimu does not use the photo to identify anyone or to make decisions. The business is responsible for its use of the application in accordance with applicable labor and anti discrimination laws; it may delete its application history, and the applicant may request deletion of their application by writing to soporte@nimuapp.app.
Businesses with NIMU Pro may publish announcements about their own business with NIMU Celebrate, of the types in a closed list the app offers. The fixed data of the announcement (name, logo, address, and link) is taken from the business's card, and the text added goes through the automated moderation described in section 5. Celebrate announces only business matters, never personal ones: it is not designed to publish data about people, and it rejects announcements of personal events except for event venue and banquet businesses. The announcement is public content while it is published; it can be reported, and each report is recorded with the account that makes it, which is never revealed to the business.
Only accounts that Nimu expressly authorizes may connect their Facebook page, their Instagram business account, and their TikTok account, through each network's official sign in. We store the identifier and name of the connected account and its access permission, encrypted, and use it only to publish on that same account, at the pace it sets, the public poster of cards from its country's directory with its text, link, and QR code, and to read the identifier and link of each post. We record each post and its result. We never publish hidden, test, or other country cards. The holder of a business may ask at any time, by writing to soporte@nimuapp.app, that its card not be published on other accounts' networks; once the request is handled, its card is excluded and anything awaiting a retry is skipped. Disconnecting or revoking erases the stored permission, and the account may also withdraw it from each network's settings. What each network does with what is published is governed by its own policies.
Nimu does not use third party advertising or analytics cookies. On the website and the public pages we use only these items, all necessary for the function indicated:
You can delete these items from your browser or phone settings; some features, such as changing a guest response from the same device, will stop working as expected.
Nimu does not make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you, except for content moderation. An automated filter reviews content when it is published and may reject or hide it if it detects content prohibited by the Terms; reports from several users, confirmed by a second automated review, may hide content for everyone. We keep a sample of the rejected content and the reason, to handle complaints and prevent repeat violations. If you believe a moderation decision is wrong, write to us at soporte@nimuapp.app and a person will review it. The order of businesses in the directory depends on proximity, activity, and subscription, not on a profile of the person searching.
Nimu is operated from the United States and its providers process data mainly in that country. If you use Nimu from Mexico or another country, your data is transferred to the United States, where data protection law may offer a level of protection different from that of your country. Transfers to our providers are necessary to provide you with the service you request and are made with contractual commitments of confidentiality and security. Under Mexican law, transfers to processors do not require your consent; those we make to the stores, the payment processor, or the networks you connect are necessary to perform the contract with you or are requested by you.
If we change this policy in a significant way, we will notify you inside the app before the change takes effect.
Each version states in its header the date from which it applies, and the history at the bottom summarizes what changed. Previous versions may be requested at soporte@nimuapp.app. When a change expands the use of data we collect with your consent, we will ask for that consent again.
Privacy questions or exercise of rights: soporte@nimuapp.app, or through Help and support inside the app.
IBRSTUDIO LLC, Colorado, United States.