Skip to content

Legal

Data Processing Agreement

Last updated:

This Data Processing Agreement is part of the Terms of Service. It applies as soon as you have a Nitpick account, and meets the requirements of Article 28 of the GDPR.

1. Parties and roles

For the data of your own account (your email address, apps, tokens and subscription), we are the controller. Our Privacy Policy covers that.

2. Subject

We receive the reports that users of your apps send with the Nitpick component, store them, and make them available to you in the dashboard and to your coding agent through the API, the CLI and the MCP server. We also answer the requests in which the component fetches your feedback settings.

3. Duration

This agreement runs as long as your account exists, and after that until we have deleted the reports, as set out in section 9.

4. Nature and purpose

We process the reports only on your instructions. Your instructions are these terms, and what you do in the dashboard and through the API, the CLI and the MCP server. If the law requires us to process data in another way, we tell you first, unless the law forbids that. We do not run AI on the reports.

5. Personal data and data subjects

Data subjects: the users of your apps who send feedback, and anyone whose data is visible on a screenshot they send.

Personal data in a report:

A report never contains the user's name, email address, or an account or device identifier. A screenshot shows what was on the screen, which can include personal data your app displays. Mask those views, so they are black on the screenshot. Do not use Nitpick to collect special categories of personal data.

Requests from the component carry an IP address and a User-Agent. We use them only to answer the request and to limit the number of reports per minute, and we do not store them with a report. Our application does not write IP addresses to its logs.

6. Subprocessors

You give us general permission to use these subprocessors for the reports:

Subprocessor What for Where
Supabase Database and file storage for the reports and screenshots Central EU region (Frankfurt, Germany)
Vercel Hosting of the platform; every request passes through it Functions in the Frankfurt region

Vercel keeps request logs, which can include IP addresses: [TO FILL IN: how long Vercel keeps request logs on the chosen plan].

Resend (for sending emails about your subscription and usage) and Paddle (for payments) work for us as well. Resend operates from its EU region. Vercel and Resend are companies based in the United States, but the services they provide for Nitpick run from EU data centers. Neither Resend nor Paddle ever receive reports or other data of your app users.

Before we add or replace a subprocessor for the reports, we tell you by email at the address of your account. If you object, you can cancel your subscription.

7. Confidentiality

Only people who work for us and need access to do their work can access the reports, and they are bound to confidentiality.

8. Security

9. Deletion

10. Assistance

11. Information and audits

On request, we give you the information you need to show that this agreement is met. If that is not enough, we agree with you on an audit.

12. Contact

Questions about this agreement: support@appsko.com.