Privacy Policy
Last updated 26 July 2026
Nibor is operated by Bor Ventures ("we", "us"), based in Sweden. This policy explains what personal data we process when you use nibor.io and the Nibor platform, and the choices you have. We process personal data in accordance with the EU General Data Protection Regulation (GDPR).
Two roles, two kinds of data
It matters whose data it is:
- Your account data (you as our user): here we are the data controller.
- Data inside apps you build (your customers, employees, records): you are the controller of that data; we process it on your behalf, only to operate the platform.
What we collect
- Account information: email address, name if you provide one, organisation membership and role.
- Content you create: app specifications, the prompts and chat messages you write while building, app data stored by your applications, and files you upload.
- Usage and technical data: logs of requests (IP address, timestamps, endpoints), usage counters (for example generations per month) and error reports. We use these to operate, secure and improve the service.
- Billing data: handled by Stripe. We never see or store full card numbers.
How AI generation works with your data
When you build or edit an app, your prompt and the relevant app specification are sent to an AI model provider (currently Anthropic; organisations can configure their own provider, including EU-hosted options) to generate the result. We send what is needed for the task and do not permit our providers to train their models on your data under our agreements with them. Your app data is not sent to AI providers except where a feature you explicitly invoke requires it (for example asking the assistant a question about your data).
Who else touches data (processors)
- Stripe — payment processing.
- Anthropic (or the AI provider your organisation configures) — AI generation.
- Email delivery provider — transactional email (sign-in links, invitations), when enabled.
- Infrastructure hosting — the servers the platform runs on.
We do not sell personal data, and we do not use it for third-party advertising.
Cookies
We use only strictly necessary cookies: a session token so you stay signed in. No advertising or cross-site tracking cookies.
Security
Every generated application receives database-level row-level security and tenant isolation. Traffic is encrypted with TLS. Credentials such as API keys are encrypted at rest and are never returned by our APIs after you save them. Access to production systems is restricted.
Retention and deletion
We keep your data for as long as your account or organisation is active. You can delete apps (which deletes their data) and organisations from within the product. When your account is deleted, we remove or anonymise personal data within 30 days, except where a law requires longer retention (for example bookkeeping records) or where residual copies persist briefly in backups.
Your rights
Under the GDPR you can request access, correction, deletion, restriction, portability, or object to processing. Contact hello@nibor.io and we will respond within 30 days. You can also complain to your supervisory authority; in Sweden that is IMY (Integritetsskyddsmyndigheten).
Changes
If we make material changes to this policy we will notify account holders by email or in the product before they take effect.