This Data Processing Agreement is part of the Terms of Service. It applies as soon as you have a Nitpick account, and meets the requirements of Article 28 of the GDPR.
1. Parties and roles
- You, the app builder who holds the account, are the controller of the feedback reports that users of your apps send.
- We, [TO FILL IN: legal name of the business], [TO FILL IN: business address], KvK number [TO FILL IN: KvK number], are your processor. We process the reports only for you.
For the data of your own account (your email address, apps, tokens and subscription), we are the controller. Our Privacy Policy covers that.
2. Subject
We receive the reports that users of your apps send with the Nitpick component, store them, and make them available to you in the dashboard and to your coding agent through the API, the CLI and the MCP server. We also answer the requests in which the component fetches your feedback settings.
3. Duration
This agreement runs as long as your account exists, and after that until we have deleted the reports, as set out in section 9.
4. Nature and purpose
- Nature: receiving, storing, showing, making available with a token of your account, and deleting reports.
- Purpose: letting you receive feedback from the users of your apps and act on it.
We process the reports only on your instructions. Your instructions are these terms, and what you do in the dashboard and through the API, the CLI and the MCP server. If the law requires us to process data in another way, we tell you first, unless the law forbids that. We do not run AI on the reports.
5. Personal data and data subjects
Data subjects: the users of your apps who send feedback, and anyone whose data is visible on a screenshot they send.
Personal data in a report:
- the comment of the user;
- if the user points at something: a screenshot of the app screen, the tap position, the size of the screen, and the screen and element names you marked;
- device model identifier, operating system and version, language, app version and build number, and the version of the component;
- the time on the device and the time of receipt, and the status you set.
A report never contains the user's name, email address, or an account or device identifier. A screenshot shows what was on the screen, which can include personal data your app displays. Mask those views, so they are black on the screenshot. Do not use Nitpick to collect special categories of personal data.
Requests from the component carry an IP address and a User-Agent. We use them only to answer the request and to limit the number of reports per minute, and we do not store them with a report. Our application does not write IP addresses to its logs.
6. Subprocessors
You give us general permission to use these subprocessors for the reports:
| Subprocessor | What for | Where |
|---|---|---|
| Supabase | Database and file storage for the reports and screenshots | Central EU region (Frankfurt, Germany) |
| Vercel | Hosting of the platform; every request passes through it | Functions in the Frankfurt region |
Vercel keeps request logs, which can include IP addresses: [TO FILL IN: how long Vercel keeps request logs on the chosen plan].
Resend (for sending emails about your subscription and usage) and Paddle (for payments) work for us as well. Resend operates from its EU region. Vercel and Resend are companies based in the United States, but the services they provide for Nitpick run from EU data centers. Neither Resend nor Paddle ever receive reports or other data of your app users.
Before we add or replace a subprocessor for the reports, we tell you by email at the address of your account. If you object, you can cancel your subscription.
7. Confidentiality
Only people who work for us and need access to do their work can access the reports, and they are bound to confidentiality.
8. Security
- Reports and screenshots can only be read with your sign-in session or with a token of your account. You can revoke tokens in the dashboard.
- The platform limits the number of reports per minute per app and per IP address, and limits the size of what it accepts.
- Comments are passed to your agent marked as text from users, not as instructions.
- Our application does not write IP addresses to its logs, and our deletion runs log only numbers per account.
- The data is stored in the EU.
9. Deletion
- A screenshot is deleted 12 months after its report came in. The report stays, without the screenshot.
- When your subscription stops, locked reports are deleted from 46 days, and the other reports from 136 days, after the end of the last paid period. The Terms of Service explain these steps. If you pay again before then, nothing is deleted.
- Until they are deleted, you can fetch the reports that are not locked through the API or the CLI. Locked reports can be fetched once you pay again.
- If you want reports deleted earlier, write to support@appsko.com.
10. Assistance
- Requests from data subjects: if a user of your app asks us about a report, we pass the request on to you. We help you answer requests about reports.
- Data breaches: if we become aware of a personal data breach that affects your reports, we tell you without undue delay, with what we know at that moment.
- Other duties: we give you the information you need for a data protection impact assessment or a question from a supervisory authority about the reports.
11. Information and audits
On request, we give you the information you need to show that this agreement is met. If that is not enough, we agree with you on an audit.
12. Contact
Questions about this agreement: support@appsko.com.