1.Who we are
Nima is operated by Nima ("Nima", "we", "us"). We are the controller of the personal data described in this policy. You can reach us at uptocodejs@gmail.com.
If you have a question about this policy, or want to exercise a right described in it, contact us at that address and we will respond within 30 days.
2.What we collect
We collect only what the service needs to work. We do not buy data about you, and we do not use advertising trackers.
- Account data. If you sign in with Google or Apple we receive your name, email address, profile image, and the provider's account identifier. You may edit your display name and photo in Nima.
- Guest data. If you continue as a guest we create an anonymous account with a random identifier. It contains no name or email. If you later sign in, your guest reading data is moved to your account and the anonymous account is deleted.
- Reading data. Favorites, reading and listening history, the last position in each story, and your reader preferences (text size, spacing, Arabic font, playback speed, language, appearance).
- Technical data. Server logs record IP address, browser or app version, and the pages or endpoints requested, for security and error diagnosis.
- Purchase data (when paid plans are available). Whether you hold an active plan, its product identifier, renewal state, and the store transaction identifier. We never receive your card number; payment is handled by Apple, Google, or the payment provider named at checkout.
- Support messages. Anything you send us when reporting a problem or requesting a book.
3.How we use it
- To provide the service: sign you in, restore your place, sync your library across devices, and play narration.
- To operate the library: keep published content current and respond to reader reports.
- To keep the service safe: detect abuse, debug failures, and secure accounts.
- To manage paid plans: recognise your entitlement, handle renewals and refunds through the stores, and send receipts where the store does not.
- To communicate with you: reply to support requests and send essential notices about your account or changes to these terms. We do not send marketing email.
4.Legal bases
Where data-protection law requires a legal basis, we rely on: performance of a contract (providing the service you asked for), our legitimate interests (security, improving the library, preventing abuse) balanced against your rights, your consent where we ask for it, and compliance with legal obligations such as tax and accounting rules for purchases.
5.Who processes data for us
We use a small number of providers to run Nima. Each acts under a contract that limits its use of your data to providing the service to us.
- Vercel — hosting of the website and API.
- MongoDB Atlas — the database that stores accounts, published content, and reading records.
- Better Auth — the sign-in system, running on our servers.
- Google and Apple — sign-in providers, when you choose them. Their handling of your data is governed by their own policies.
- UploadThing — storage of images such as story artwork and profile photos.
- ElevenLabs — generation of story narration. Only editorial text is sent to ElevenLabs; your personal data is not.
- RevenueCat, Apple App Store, and Google Play — purchases and entitlements, when paid plans are enabled.
We do not sell personal data and we do not share it with advertisers. We disclose data to authorities only when required by law, and we tell you when we are permitted to.
6.How long we keep it
- Account and reading data: for as long as your account exists. Deleting your account removes it within 30 days, except where we must keep a record for legal reasons (for example, purchase records for tax purposes).
- Guest data: on your device until you sign in or clear it. Anonymous accounts that have not been used for 12 months are deleted.
- Server logs: 30 days.
- Support messages: 24 months after the conversation closes.
7.Your rights and choices
Depending on where you live you may have the right to access, correct, export, restrict, object to, or delete your personal data, and to complain to a supervisory authority. You can exercise most of these directly:
- Edit your name and photo in Account.
- Clear favorites and history from My Library.
- Delete your account and all associated reading data from Account, or by following the steps on the Delete account page.
- Ask us for a copy of your data, or for anything else, at uptocodejs@gmail.com.
We will never require you to keep an account in order to read: guest access remains available.
8.Children
Nima is not directed at children under 13 (or the higher age required in your country) and we do not knowingly collect their data. If you believe a child has created an account, contact us and we will delete it.
9.Security
Data is encrypted in transit. Sessions are protected with signed, HTTP-only cookies. Access to production systems is restricted to the people who operate the service. No system is perfectly secure; if we learn of a breach affecting you, we will notify you and the relevant authority as the law requires.
10.International transfers
Our providers may store data in countries other than yours, including the United States. Where required, transfers are protected by recognised safeguards such as standard contractual clauses.
11.Changes to this policy
We will post any revised policy here with a new date at the top. If a change materially affects how we use your data, we will tell you in the app or by email before it takes effect.
12.Contact
Nima · uptocodejs@gmail.com