Privacy Policy
Last updated: 11th January 2026
1. Introduction
Nevaberry Oy (“we”, “our”, or “us”), a Finnish limited liability company, operates the nevaberry.com website and related services. This Privacy Policy explains how we collect, use, and protect your personal information.
We do not sell your personal data. We do not display third-party advertisements.
We are the data controller for the personal data we process. For questions about this policy, contact us at privacy@nevaberry.com.
2. Information We Collect
Information You Provide
- Account information: Email address and name when you create an account
- User content: Any content you create using our services, such as pastes or saved data
- Communications: Messages you send us for support or feedback
Information Collected Automatically
- Device fingerprint: We use FingerprintJS to generate a unique device identifier for security and fraud prevention purposes
- Usage data: How you interact with our services, pages visited, features used
- Technical data: IP address, browser type, device type, operating system, screen resolution
Information from Third Parties
- Authentication data: Profile information from Clerk when you sign in
- Payment status: Transaction confirmation from Stripe (we do not receive or store your payment card details)
3. Legal Basis for Processing
Under GDPR, we process your personal data based on the following legal grounds:
- Contract: To provide the services you signed up for
- Legitimate interest: For security, fraud prevention, service improvement, analytics, and device fingerprinting
- Legal obligation: To comply with tax requirements and legal requests
4. How We Use Your Information
We use collected information to:
- Provide, maintain, and improve our services
- Process transactions and manage your account
- Detect and prevent fraud, abuse, and security threats
- Analyze usage patterns to improve user experience
- Communicate with you about service updates (transactional emails only)
- Comply with legal obligations
We never use your data for advertising or sell it to third parties.
5. Third-Party Services
We use the following third-party services to operate our platform:
| Service | Purpose | Location |
|---|---|---|
| Neon | Database hosting | EU |
| PostHog | Analytics | EU |
| Clerk | Authentication | USA* |
| FingerprintJS | Device identification | USA* |
| Stripe | Payment processing | USA* |
| Cloudflare R2 | File storage | EU |
* These services are covered by the EU-US Data Privacy Framework.
6. International Data Transfers
Your personal data is primarily stored in the European Union (Neon database, PostHog analytics). Some data is processed by third-party services in the United States (Clerk, Stripe, FingerprintJS), which participate in the EU-US Data Privacy Framework, ensuring adequate protection for your data.
7. Data Retention
We retain your data for the following periods:
- Account data: Until you delete your account, plus 30 days for backup purposes
- Analytics data: 24 months
- Device fingerprint mappings: 12 months from last activity
- Payment records: 7 years (legal requirement)
- Security logs: 90 days
8. Cookies and Tracking Technologies
We use the following technologies:
Essential (Required)
- Session cookies for authentication
- CSRF protection tokens
- Language preference
Analytics (Legitimate Interest)
- PostHog analytics to understand how our services are used
Security (Legitimate Interest)
- FingerprintJS device fingerprinting for fraud prevention and abuse detection
To opt out of device fingerprinting, contact us at privacy@nevaberry.com.
9. Your Rights (GDPR - EU/EEA Users)
Under GDPR, you have the right to:
- Access: Request a copy of your personal data
- Rectification: Correct inaccurate data
- Erasure: Request deletion of your data (“right to be forgotten”)
- Restrict processing: Limit how we use your data
- Data portability: Receive your data in a machine-readable format
- Object: Object to processing based on legitimate interest
- Withdraw consent: Where processing is based on consent
You may also lodge a complaint with your local data protection authority. For Finland, contact the Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto) at tietosuoja.fi.
10. Your Rights (CCPA - California Users)
Under the California Consumer Privacy Act, you have the right to:
- Know: What personal information we collect and how it is used
- Delete: Request deletion of your personal information
- Opt-out of sale: We do not sell your personal information
- Non-discrimination: We will not discriminate against you for exercising your rights
Do Not Sell or Share My Personal Information: We never sell or share your personal information with third parties for monetary or other valuable consideration.
11. How to Exercise Your Rights
To exercise any of your privacy rights, contact us at privacy@nevaberry.com. We will respond within:
- 30 days for GDPR requests
- 45 days for CCPA requests
We may need to verify your identity before processing your request. Data exports will be provided in JSON format.
12. Data Storage and Security
Your data is stored securely using industry-standard encryption at rest and in transit. We implement access controls, regular security audits, and incident response procedures to protect your information.
13. Children's Privacy
Our services are not intended for children under 16 years of age (or 13 for US users under COPPA). We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us immediately.
14. App-Specific Privacy Terms
Certain applications within our platform, particularly those handling health, wellness, or other sensitive data, may have supplemental privacy policies. These will be presented to you before you use those specific applications and will extend (not replace) this general Privacy Policy.
15. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by posting a notice on our website and updating the “Last updated” date. Continued use of our services after changes constitutes acceptance of the updated policy.
16. Contact Us
For privacy-related questions or to exercise your rights, contact us at:
- Email: privacy@nevaberry.com
- Company: Nevaberry Oy
- Country: Finland