Privacy Policy
Effective: 1 November 2026
This policy explains what happens to your data when you use Nia: the website at niaspark.com, the Nia app at app.niaspark.com, the Notes, Todo and Calendar apps, the Nia CLI, desktop and mobile apps, browser extension, Office add-in, and Nia Bots (together, “Nia”). It's written to be read, not skimmed past.
Who is responsible for your data
Nia is built and run by one person, Mapalo William Chipili, based in Zambia, not by a company. That person is the “controller” of your personal data under data protection law, and “we” in this policy means them. Postal address: Lusaka, Zambia. Privacy questions and requests: privacy@niaspark.com.
What we collect
- Account details — your name, email address and profile picture from the sign-in provider you choose (Google, GitHub, Microsoft, Discord, Spotify or Slack). We never see your password for those services.
- What you give Nia — your messages, the files, images and documents you upload (including anything in the Vault), and what you keep in Notes, Todo and Calendar.
- What Nia remembers — facts and memories Nia saves so it doesn't start from zero in every conversation, stored as searchable text and a numeric “embedding” of that text.
- Connected services — if you connect Gmail, Google Calendar, Drive, Docs, Sheets, Slides, Photos, Contacts, YouTube, GitHub, Slack, Microsoft, WhatsApp or another integration, the access tokens for it and whatever data Nia reads or writes there to do what you asked.
- Device control — if you turn on computer, phone or browser control: screenshots, on-screen text, and on Android your notifications, clipboard and device state. The camera and microphone are used only while you're in live voice mode.
- Usage and technical data — which tools were called, timings, token counts, errors, session timestamps, and IP address (for sign-in security and rate limiting).
- Contact form — your name, email, message and IP address (the IP only to limit spam).
We don't run advertising, ad tracking, or third-party analytics on any of this.
How your messages get answered
Depending on which model is active for your account, your messages (and any files, memories or tool results needed to answer them) are sent to one of these AI providers to generate a response: OpenAI (GPT), Anthropic (Claude), Google (Gemini), DeepSeek, or Zhipu AI (GLM). They process that content under their own terms, which we don't control. DeepSeek and Zhipu AI are based in China, and OpenAI, Anthropic and Google in the United States.
Nia can also run on local models on our own hardware or yours, and in that case your messages don't go to any of those providers. The full list of outside services is on the subprocessors page.
We don't use your content to train AI models, and we don't sell it or use it for advertising.
Why we use it (legal bases)
- To provide Nia to you (performance of our contract with you): running your account, answering your messages, storing your files, notes, tasks and events, and carrying out actions you ask for.
- With your consent: connecting third-party services, computer, phone and browser control, camera and microphone, and push notifications. You can withdraw consent at any time by disconnecting the service or turning the feature off.
- Legitimate interests: keeping Nia secure, preventing abuse and spam, fixing bugs, and understanding which features break or get used.
- Legal obligation: when the law requires us to keep or disclose something.
Who we share your data with
We don't sell your data and we don't share it for advertising. We share it only with the services needed to run Nia, and only the minimum each of them needs to do its job. They are:
- AI model providers — OpenAI and Anthropic (Claude), Google (Gemini) and Zhipu AI (GLM), plus DeepSeek. Whichever model is active for your account receives your messages and the files or tool results needed to answer them.
- Cloudflare — network, DNS, TLS and attack protection in front of niaspark.com. All traffic passes through it, so it sees your IP address.
- Google (Gmail SMTP) — delivers your contact-form message to us, when you use the contact form.
- Browser push services (Google, Mozilla, Apple and Microsoft) — deliver the notifications you switch on. They receive the notification text and a device push token.
- Sign-in providers — Google, GitHub, Microsoft, Discord, Spotify or Slack, whichever you choose. That provider shares your name, email address and profile picture with us.
- Services you connect yourself — Gmail, Google Calendar, Drive, Docs, Sheets, Slides, Photos, Contacts, YouTube, GitHub, Slack, Microsoft 365, WhatsApp, Hostinger, and any MCP server you add. Data reaches them only when you connect the service, and only for what you ask.
We may also disclose data where the law requires it, or where it's necessary to investigate abuse or protect someone's safety. This is the complete list of parties your data can reach — none of them are permitted to use it for their own advertising. The subprocessors page below gives the detail for each one, including where it is located and the safeguards that apply to transfers outside your country (see “Where your data is stored”).
Google user data
When you connect a Google account, Nia asks only for the access needed for the features you use: reading and changing Gmail, Calendar, Drive, Docs, Sheets and Slides, and read-only access to Photos, Contacts, Forms and YouTube. Nia uses that data only to do what you ask in the moment, for example “summarise my unread email” or “add this to my calendar”.
Nia's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular, Google user data is not used to train AI models, not sold, not used for advertising, and not read by a person unless you ask us to (for example, for support), it's needed for security, or the law requires it. To answer your request, Google data may be sent to the AI provider active for your account, as described above.
Notes, Todo and Calendar
Notes, Todo and Calendar are separate web apps (notes.niaspark.com, todo.niaspark.com, calendar.niaspark.com) that share your Nia sign-in. They keep your data under your own account, so other users can't see it, and Nia can read and change it from chat on your behalf. You can open them without signing in as a guest, but guests can only look around, not save anything.
Computer, phone and browser control
None of this runs until you turn it on. Sensitive actions (sending email, moving files, opening apps, controlling your screen) ask for your approval first unless you choose to auto-approve them in settings. Screenshots taken to carry out an action are sent to the AI provider like any other message.
The browser extension
The Nia browser extension is a chat sidebar that works with the sites you're already on. When you ask it to do something, it can read the page you're viewing, your open tabs and tab groups, your bookmarks, downloads and cookies for the sites involved, and take a screenshot of the active tab. It uses these only to carry out what you asked — for example “summarise this page” or “click the checkout button” — not to read pages in the background.
Browser permissions of this kind can't be granted one page at a time, so the extension asks for them when you install it. Whatever it reads in order to answer a request is handled like any other message with Nia, and is sent to the AI provider active for your account.
WhatsApp and Nia Bots
If you connect WhatsApp, your phone number and the messages sent through that connection are handled like any other conversation with Nia. Each Nia Bot can have its own computer session and its own credentials, kept separate from the rest of your account. What a bot does and stores is visible to you.
Chat lock, folder lock and masked emails
You can lock chats and folders behind a PIN. The server holds locked content back until you unlock it, rather than just hiding it in the app. Email addresses in conversations are masked before storage. These are access controls, not end-to-end encryption: the underlying data is still in our database.
Where your data is stored
Nia runs on servers we operate ourselves, reached through Cloudflare. Your data is also processed in the countries of the providers listed on the subprocessors page, which may be outside your own country, including the United States and China. Where the law requires safeguards for those transfers, such as the EU's Standard Contractual Clauses, we rely on the ones those providers offer.
How long we keep it
- Your account and content: for as long as your account exists, or until you delete individual items.
- After you delete your account: removed from our live systems within 30 days, and from backups within 90 days.
- Server and error logs: up to 30 days.
- Contact form messages: up to 12 months, unless an ongoing conversation needs them longer.
Your rights, and how to use them
Depending on where you live, you have the right to access, correct, export or delete your data, to object to or restrict how we use it, and to withdraw consent.
- Export: Settings → Export data downloads your chats, facts and preferences as a file.
- Delete: Settings → Delete account removes your account, chats, messages, memories and preferences straight away. Files in the Vault, and data in Notes, Todo and Calendar, are stored separately. To remove those as well, follow the steps on Delete your data.
- Anything else: email privacy@niaspark.com. We'll answer within 30 days and may need to confirm the request comes from the account's owner.
If you think we've handled your data wrongly, you can complain to the data protection authority where you live. We'd appreciate the chance to fix it first.
Security
Connections are encrypted in transit (HTTPS). Access to the servers is limited to a private network. Sign-in uses established providers rather than passwords we store. No system is perfectly secure. If we learn of a breach that puts your data at risk, we'll tell you and, where required, the relevant authority, without undue delay. Found a problem? See Security.
Children
Nia isn't for anyone under 16. We don't knowingly collect data from children under that age. If you believe a child has an account, email privacy@niaspark.com and we'll delete it.
Changes to this policy
If we change this policy in a way that matters, we'll update the date at the top and, for significant changes, tell signed-in users by email or in the app before the change takes effect.