Privacy Policy
Last updated: 23 December 2025
Protecting your personal data is very important to us. This Privacy Policy explains in a transparent manner how we process personal data when you use NANI, for what purposes, and which rights you have under applicable data protection laws, including the GDPR.
This English version is provided for convenience. In case of discrepancies, the German version prevails, unless mandatory local law requires otherwise.
1. Controller
The data controller within the meaning of the GDPR is:
Bitlink GmbH
Schönbornstr. 33
76646 Bruchsal, Germany
Managing Directors: Dmitry Nilsen, Ruslan Ragimov
HRB 753206, District Court Mannheim
Privacy contact: privacy@nani-app.com
We have not appointed a Data Protection Officer, as there is currently no legal obligation to do so.
2. Scope of this Privacy Policy
This Privacy Policy applies to the use of the NANI services, including:
- mobile apps (iOS, Android, Android TV)
- web app at https://nani-app.com/app/
- marketing website https://nani-app.com
3. Personal data we process
3.1 Account data
- Email address
- Name (optional)
- Profile picture URL (optional)
- OAuth identifiers (Apple / Google)
Login is possible only via Apple or Google authentication.
3.2 Device and usage data
- Device or hardware identifiers
- Browser fingerprint
- Operating system and device model
- IP address
- Push notification tokens (FCM / APNs)
3.3 Audio and video transmission
Live audio and video streams are transmitted exclusively in real time via encrypted WebRTC connections. Live streams are not recorded or stored.
3.4 Monitoring events
If enabled, sound or motion detection may generate events with photos or short video clips. These data:
- are stored in the EU (Google Cloud Platform, Europe)
- are automatically deleted after no more than 30 days
- can be deleted manually at any time
4. Purposes and legal bases
- Performance of a contract (Art. 6(1)(b) GDPR) – providing and operating the NANI services
- Legitimate interests (Art. 6(1)(f) GDPR) – security, stability, fraud prevention, and error analysis
- Consent (Art. 6(1)(a) GDPR) – analytics, optional cookies, and marketing features
5. Third-party services
- Google Firebase (authentication, analytics, push notifications, Crashlytics)
- Google Analytics
- Google Cloud Platform (EU storage)
- SendGrid (email delivery)
- Rollbar (server error monitoring)
- Apple App Store / Google Play (billing)
7. Data retention
- Account data: until account deletion
- Monitoring events: up to 30 days
- Backups: up to 7 days
8. Account deletion
You can delete your NANI account at any time via the web profile interface. Deletion is immediate and irreversible.
9. Your rights
- Right of access
- Right to rectification
- Right to erasure
- Right to restriction of processing
- Right to data portability
- Right to object
- Right to lodge a complaint with a supervisory authority
10. Children
NANI is intended for use by parents or legal guardians only and is not directed at children.
11. Data security
We apply appropriate technical and organizational measures, including TLS encryption, DTLS/SRTP for WebRTC, access controls, and signed URLs for media access.