Privacy Policy

Last updated: April 8, 2026

1. Introduction

nilbox ("we", "us", "our") operates the nilbox application store and related services at store.nilbox.run. This Privacy Policy explains how we collect, use, and protect your personal data, and describes your rights under the General Data Protection Regulation (GDPR) and other applicable privacy laws.

This policy applies to all users of the nilbox service, including registered account holders and Pro plan waitlist subscribers.

2. Data Controller

nilbox is the data controller responsible for your personal data.

Contact:

3. Data We Collect

[A] Registered Members

DataEmail address, hashed password, display nickname
Collected whenAccount registration
PurposeAccount authentication and service access

[B] Pro Plan Waitlist

DataEmail address, consent timestamp, anonymised IP hash
Collected whenJoining the Pro waitlist
PurposeSending a one-time notification when nilbox Pro launches

[C] Website Analytics

DataAnonymised usage data: pages visited, session duration, device/browser type, approximate location (country-level)
Collected whenBrowsing our website (only after you accept analytics cookies)
PurposeUnderstanding how visitors use our service so we can improve it

We do not collect sensitive personal data, payment information, or data from minors under 16.

4. How We Use Your Data

We do not use your data for advertising, profiling, or sell it to third parties.

5. Legal Basis for Processing (GDPR Art. 6)

Processing activityLegal basis
[A] Account managementPerformance of a contract — Art. 6(1)(b)
[B] Waitlist notificationConsent — Art. 6(1)(a)
[C] Website analyticsConsent — Art. 6(1)(a)

You may withdraw consent for waitlist notifications at any time using the unsubscribe link included in every email we send.

6. Data Retention

[A] MembersRetained until you delete your account. You can request deletion at any time via .
[B] WaitlistDeleted immediately after the Pro launch notification is sent, or when you unsubscribe — whichever comes first.

7. Your Rights (GDPR Art. 15–22)

You have the following rights regarding your personal data:

To exercise any of these rights, contact us at . We will respond within 30 days.

Waitlist subscribers can unsubscribe instantly using the link in any notification email.

8. International Data Transfers

Your data may be processed outside the European Economic Area (EEA) by our infrastructure providers:

These providers are contractually obligated to process data only on our instructions and to maintain appropriate security measures.

9. Cookies

Functional Cookies

nilbox uses a single functional cookie (nilbox_lang) to remember your language preference. This cookie contains no personal data and is not used for tracking.

Analytics Cookies (consent-based)

If you accept analytics cookies via the consent banner, Google Analytics sets the following cookies:

CookiePurposeRetention
_gaDistinguishes unique visitors2 years
_ga_*Maintains session state2 years

Analytics cookies are only loaded after you give explicit consent. You can withdraw consent at any time by clearing your browser's local storage or cookies. We do not use advertising cookies.

10. Changes to This Policy

We will notify registered users and waitlist subscribers by email at least 7 days before any material changes take effect. The "Last updated" date at the top of this page reflects the most recent revision.

11. Contact & Complaints

For any privacy-related requests or questions, contact us at .

If you are located in the EU/EEA and believe we have not adequately addressed your concern, you have the right to lodge a complaint with your local Data Protection Authority (DPA).