Privacy

This describes what happens to what you give nib. It is written against the code rather than from a template, so where the behaviour is more complicated than a one-line promise, it says so.

Who is responsible

Write to that address for anything in this document, including a request to delete everything. There is no form and no ticket system; it is read by a person.

What we collect

The material you hand over

Photographs, voice notes and typed text — whatever you give the front door. Photographs and audio are uploaded straight from your browser to our storage; they never pass through our application server.

What was read out of it

A photograph becomes a description of what is in it. A voice note becomes a transcript. That text is what every later step works from, and it is stored separately from the file it came from. This matters for how long things last — see below.

Your work

The summary, your answers to the questions, the stack you picked, and every version of the spec.

An account, if you make one

Only an email address and which way you signed in. No password exists to be stolen: it is either a link we mail you, or GitHub or Google telling us your verified address. If you sign in with a provider we ask for your name and verified email and nothing else — never access to your repositories.

A cookie

One, named prd_sid. It is a random identifier with no meaning outside our own database, it lasts thirty days, and it is what lets you use the whole product without an account. It is strictly necessary — without it there is nowhere to put your idea — which is why there is no consent banner asking you about it.

Counters

How many projects and photographs you have used today, against the daily limits. Kept for forty-eight hours.

How long we keep it

Uploaded files: thirty days. Every photograph and voice note is deleted thirty days after it arrives, by a storage rule rather than by anyone remembering to run something. This applies whether or not you have an account.

The text read out of them: until you delete the project. The transcript of your voice note and the reading of your sketch are not on that timer. They are what the spec was built from, so deleting them would leave a document with no provenance. Delete the project from your dashboard and they go with it, along with the files, the summary, your answers and every version of the spec.

One exception, and it is deliberate. A project you have paid for cannot be deleted from the dashboard, because the purchase is a financial record we are required to keep and the pack is something you bought. Write to us and we will handle it by hand.

What survives a deletion: a row recording that a model call happened and what it cost us, with the link to your project removed. It carries no part of your material. We keep it because what the service costs to run must not change when somebody tidies their dashboard.

Who else sees it

Cloudflare

The whole product runs on Cloudflare: the site, the database, the file storage, the bot check and the models on the free lane. Your material is read by models hosted by Cloudflare — Whisper for audio, Mistral Small 3.1 for photographs, Qwen3 for the writing. It is not used to train them.

Anthropic, but only if you buy something

The free lane never leaves Cloudflare. When you buy a build pack, your spec is sent to Anthropic's models through Cloudflare's AI Gateway to be refined. That gateway caches responses, which means the text of the request and the answer sits in a Cloudflare cache for a period Cloudflare controls. If that is not acceptable to you, do not buy a pack — nothing on the free lane goes there.

Stripe

If you buy a pack, Stripe is the seller, not our payment processor. It collects the money, calculates and remits the VAT, and owns disputes and buyer support. We send it your email address, which project and which pack. We never see your card details — they are entered on Stripe's own page and never touch our servers.

GitHub and Google

Only if you choose to sign in with one, and only to confirm your verified email address.

Analytics

Two measurements, neither of which identifies you. One runs on our own server and counts page views and steps of the flow; it sets no cookies and stores no personal data. The other counts the same steps inside the application, keyed by a project identifier that means nothing outside our database — no IP address, no user agent, no email, no part of your material. Cloudflare also collects basic performance measurements for the site itself.

Nobody else

We do not sell anything to anyone, there is no advertising, and there are no third-party trackers on this site.

Where it is

Cloudflare, Stripe and Anthropic are organisations with infrastructure outside the European Economic Area, so your data may be processed outside it. Those transfers rely on the European Commission's standard contractual clauses, which form part of each provider's terms.

Why we are allowed to

What you can do

Under the GDPR you can ask for a copy of your data, ask us to correct it, ask us to delete it, ask us to restrict or stop a particular use, and ask for it in a portable form. Most of it you can do yourself: every project on your dashboard has a delete button, and it removes the files as well as the rows.

For anything else, write to hola@origenmodular.com. If you think we have handled your data badly and we have not put it right, you can complain to the Spanish data protection authority, the Agencia Española de Protección de Datos (aepd.es).

Children

nib is not intended for anyone under 14. We do not knowingly collect anything from a child; if you believe we have, write to us and we will delete it.

Changes

If this document changes, the date at the top changes with it. There is no mailing list to announce it on, so the date is the honest signal.