Last updated: 10 August 2026
Privacy & Storage Notice
1. Who is responsible
The controller identified for NomiaWeave is ElaronWorks sp. z o.o., ul. Kalwaryjska 69/9, 30-504 Kraków, Poland (KRS 0001207366, NIP 6793349283, REGON 54333337900000).
For privacy questions or requests, contact privacy@nomiaweave.com.
2. Data NomiaWeave handles
- Account and authentication data: internal user and session identifiers, email address, display name, email-verification state, sign-in method, provider identifier, timestamps, and authentication and security events. Sign in with Apple can supply an Apple private relay email address and records that it is a relay address. Session and one-time sign-in credentials are also processed.
- Profile and preference data: country of residence, country of origin, reason for joining, preferred countries and languages, and surname preferences.
- Projects and choices: weave/project titles and settings, given and family names, name combinations, ratings, favourites, comments, shortlist or draft state, activity and reveal history, and the final choice. A collaborator's individual ratings, favourites, and history are kept private from other collaborators by the current product; shared aggregates and project content remain visible within the weave.
- Collaboration: memberships, permissions, trust relationships, display names, invitation identifiers and expiry times. Anyone who has a valid invitation URL or QR code can see its limited preview, including the project title, project gender setting, offered permission, and inviter display name. The destination chosen in the device share sheet is controlled by the user.
- First-party analytics: authenticated user and session identifiers, an optional weave identifier, event name and timestamp, app platform/version, entry point, and constrained outcome or reason values. These events exclude emails, names and surnames, free-text comments, prompts, provider subjects, invitation tokens, and purchase receipts.
- Diagnostics and security: IP address, user agent, request method and route, response status and duration, associated user identifier where available, rate-limit events, and errors or traces when application logging or tracing is enabled. Authentication headers and URL query values are not intentionally logged.
- AI feature data: only when an AI feature is requested, the configured provider receives bounded naming context such as the project gender setting, requested count, countries, languages, surname preferences, candidate and rejected names, aggregate ratings, and favourite state. Email, account identifiers, comments, invitation tokens, and individual collaborators' ratings are not intentionally included. NomiaWeave stores generated suggestions or insights, provider/model identifiers, status/error metadata, and token and cost measurements.
- Family Pass: internal user identifier, Apple/RevenueCat customer and transaction references, product identifier, purchase and validity times, store and ownership state, and revocation state. Payment-card details are handled by Apple and are not received or stored by NomiaWeave.
- Support and rights requests: messages and the information needed to identify, investigate, and answer the request.
3. Why data is used
NomiaWeave uses the data described above to:
- create and authenticate accounts and maintain secure sessions;
- provide projects, name discovery, private preferences, collaboration, and final-choice features;
- generate AI suggestions or insights only after a user asks for them;
- validate, restore, and administer a Family Pass;
- operate, secure, troubleshoot, and measure the reliability and use of the service; and
- answer support, privacy, and lawful requests.
Processing that is objectively necessary to create an account and provide requested NomiaWeave features is based on performance of the Terms of Service or steps requested before entering them. A separate controller-approved assessment is required before relying on legitimate interests for security logging or first-party product analytics, or on a legal obligation to retain a particular record. NomiaWeave does not treat source-code configuration alone as establishing those legal bases.
4. AI providers and other recipients
Data is disclosed only as needed for the selected feature or operation. Depending on the user's choices and the production configuration, recipients can include Apple or Google for authentication, Apple and RevenueCat for an iPhone purchase or restoration, an email-delivery provider, an anti-abuse provider, infrastructure and storage providers, and a configured AI provider for an on-demand AI request. Other project members receive the shared collaboration data described above.
The source supports Resend for email, Cloudflare Turnstile for anti-abuse checks, an OpenAI-compatible AI adapter, S3-compatible object storage, and optional telemetry export, but source code does not establish which of these are enabled in production. The OpenAI adapter requests that the provider not store a response, but provider-side retention and model-training terms depend on the approved account, contract, and configuration. NomiaWeave therefore makes no broader provider training or retention claim here.
5. International transfers
Some selected service providers may process data outside Poland or the European Economic Area. The production provider locations, roles, and applicable transfer safeguards must be confirmed before release. NomiaWeave does not claim that a particular adequacy decision, certification, or Standard Contractual Clause applies until that confirmation is complete. Contact privacy@nomiaweave.com for the safeguard applicable to a particular transfer.
6. Retention and deletion
- First-party server product events are scheduled for deletion after 30 days.
- Unsent mobile product events are limited to 100 events and seven days on the device. Expired server sessions are removed after a 24-hour grace period; used or expired sign-in links and expired invitations are removed after seven days.
- Account and project data otherwise remains while the account or shared weave is active, unless the user deletes it or a shorter period applies.
- Account deletion immediately revokes NomiaWeave sessions, removes or scrubs profile data and private activity, and deletes projects owned only by that account. A sole owner must first remove other collaborators from a shared weave. Shared content and generated output can remain behind a deleted weave record. Opaque sign-in deny-list identifiers remain to prevent account relinking. Pseudonymous AI usage rows and limited purchase evidence also remain under the current deletion implementation; their purpose and retention periods require controller approval.
Final periods for account/project content, retained deletion records, AI usage/output, purchase evidence, security logs, traces, support records, and backups have not been approved. Those periods must be set from documented purpose and legal requirements before release; the service must not retain this data longer than necessary for the approved purpose.
7. Account deletion
In the iPhone app, open Settings and choose Delete account. On the website, open Profile Settings and choose Delete account. A confirmation and a recently created session are required. If recent authentication is required, sign out, sign in again, and retry. The flow explains when collaborators must be removed first. Contact privacy@nomiaweave.com if the in-product flow cannot be used or to request deletion of other data associated with you.
8. Your rights
Subject to applicable conditions and exceptions, you may request access, correction, erasure, restriction, or portability of your data; object to processing based on legitimate interests; or withdraw consent where processing relies on consent. Withdrawal does not affect earlier lawful processing. Contact privacy@nomiaweave.com; we may need information to verify the request.
You may also complain to the supervisory authority where you live, work, or believe an infringement occurred. In Poland this is the President of the Personal Data Protection Office (UODO). We invite you to contact us first so we can investigate, but doing so does not limit that complaint right.
9. Children
The Terms require an account holder to be at least 16 years old. The current service does not ask for date of birth or implement age verification. Do not create an account or provide personal data if you do not meet that requirement. A parent or guardian concerned that a child provided data may contact privacy@nomiaweave.com so the controller can investigate and take appropriate action.
10. Camera, cookies, and device storage
On iPhone, camera permission is requested only when the user chooses to scan a collaborator invitation QR code. Camera frames are processed on the device and are not uploaded; the invitation identifier extracted from a valid NomiaWeave link is sent to the service. Pasting a link is available instead. NomiaWeave does not request microphone, contacts, location, or photo-library access for this flow.
The website uses browser local or session storage for sign-in tokens and profile state, recent sign-in method, invitation and demo handoff state, and the notice acknowledgement. A short-lived, secure, HTTP-only cookie is used for the Apple web sign-in handoff. The mobile app uses secure device storage for session/profile and pending-invitation state and ordinary device storage for short-lived analytics and interface state. First-party product events are sent to NomiaWeave's API rather than through an advertising analytics SDK.
11. Advertising and tracking
The current product does not include advertising, an advertising SDK, cross-company tracking, or use of the Apple advertising identifier. NomiaWeave does not sell personal data. A future change to these practices would require an updated notice and any consent or platform permission required at that time.
12. Contact and changes
Privacy and data-subject requests: privacy@nomiaweave.com
Legal inquiries: legal@nomiaweave.com
This notice will be updated when practices or approved legal decisions change. Material changes will be communicated as required by applicable law.