Privacy Policy
Nuvio App · Last updated: April 23, 2026
Protecting your personal data is important to us. This privacy policy informs you about what data the Nuvio app collects, how it is processed, and what rights you have.
1. Data Controller
Responsible for data processing within the Nuvio app:
Daniel Filler
DMF-Labs
Karlsruhe, Germany
For privacy-related questions, you can reach us at:
E-Mail: info@dmf-labs.com
2. Collected Data & Processing Purposes
a) Local Data Storage
All your data – orders, products, and settings – is stored exclusively on your device by default.
b) Account Data
During registration, we collect your email address and a self-chosen password (stored encrypted). This data is necessary to create your account and authenticate you.
c) Online Synchronization (when signed in)
When signed in, your app data (products, categories, orders, statistics, and settings) is synchronized via Google Firebase Firestore (Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA) to make it available across devices. Data is stored exclusively on servers within the European Union. You can disable synchronization at any time in the settings.
d) Manual Backup
You can manually back up your data online and retrieve it at any time. These backups are also stored on EU servers and are accessible only to you.
e) Digital Product Catalogue
If you activate the digital product catalogue, your uploaded products and selected profile information will be displayed publicly. This only happens at your explicit request. You can disable this feature at any time in the app settings.
3. Anonymous Telemetry Data
We collect anonymous telemetry data about app usage to continuously improve it. This data contains no personal information and cannot be traced back to you. It is used exclusively for internal analysis purposes. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in improving our service).
4. Error Tracking – Sentry
To detect and fix technical errors, we use Sentry (Sentry Inc., 45 Fremont Street, San Francisco, CA 94105, USA). Sentry captures anonymized crash reports and error messages that cannot be directly traced back to you. Sentry processes data in compliance with GDPR under EU Standard Contractual Clauses. sentry.io/privacy
5. Subscription Management – RevenueCat
For managing in-app purchases and subscriptions, we use RevenueCat (RevenueCat, Inc., 633 Tasman Dr, Sunnyvale, CA 94089, USA). RevenueCat processes transaction and subscription data necessary for processing through the Apple App Store (iOS) or Google Play Store (Android). RevenueCat does not store complete payment data; actual payment is handled exclusively by Apple or Google. revenuecat.com/privacy
6. AI Import Feature (optional)
Nuvio offers an optional AI import feature that allows you to automatically capture product and category data from an image or PDF. This feature is voluntary and only activates when you explicitly use it.
What data is transmitted?
When you use the AI import feature, your uploaded image or PDF is first sent to Google Cloud Vision (Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA) for text recognition (OCR). The extracted text is then sent to OpenAI (OpenAI, L.L.C., 3180 18th St, San Francisco, CA 94110, USA) to create product and category data.
Only the image contents are transmitted – no personal data from your profile, orders, or other app data.
Consent
Since you actively and voluntarily trigger this feature, by using the AI import feature you consent to the transmission of image contents to Google Cloud Vision and OpenAI. You can decline the feature at any time by not using it. The legal basis for this processing is Art. 6(1)(a) GDPR (consent).
More information about third-party privacy policies:
7. AI Summary (optional)
When you use the optional AI summary in statistics, aggregated sales data (e.g., order count, best-selling products, peak times) is sent to OpenAI (openai.com) to generate analysis and recommendations. No personal data, customer data, or payment information is transmitted – only anonymized statistics. Use of this feature is voluntary.
8. Data Storage & Server Locations
All servers and databases directly operated by Nuvio are located exclusively within the European Union. Data processing is based on Art. 6(1)(b) GDPR (contract performance) and Art. 6(1)(f) GDPR (legitimate interest in secure and error-free operation of the app).
9. Data Sharing with Third Parties
Nuvio is ad-free. We do not sell data to third parties and do not display personalized advertising. Data is only shared in the following cases:
- To Sentry (error tracking, see section 4)
- To RevenueCat (subscription management, see section 5)
- To Google Cloud Vision and OpenAI (AI import feature, when voluntarily used, see section 6)
- To OpenAI (AI summary, when voluntarily used, see section 7)
- To Google Firebase (cloud synchronization, when enabled, see section 2c)
- To Apple (payment processing via App Store, iOS)
- To Google (payment processing via Play Store, Android)
- When we are legally obligated to do so
10. Data Deletion & Retention
Your data is stored for the duration of active use of your account. After account deletion, all personal data is irreversibly deleted within 30 days, unless statutory retention obligations apply. You can delete local data on your device at any time via the app settings or by uninstalling the app.
11. Your Rights (GDPR)
You have the following rights regarding your personal data:
- Access – What data we store about you (Art. 15 GDPR)
- Rectification – Correction of inaccurate data (Art. 16 GDPR)
- Erasure – Deletion of your data ("right to be forgotten", Art. 17 GDPR)
- Restriction – Restriction of processing (Art. 18 GDPR)
- Data portability – Export of your data in a common format (Art. 20 GDPR)
- Objection – Objection to processing (Art. 21 GDPR)
To exercise these rights, contact . You also have the right to lodge a complaint with a data protection supervisory authority. info@dmf-labs.com
12. Data Security
We employ technical and organizational security measures to protect your data against loss, manipulation, and unauthorized access. Data transmission is always encrypted via HTTPS/TLS. Passwords are stored exclusively in hashed form and are not visible to us.
13. Changes to This Privacy Policy
We reserve the right to update this privacy policy when changes to the app or legal requirements occur. The current version is always available in the app and at datenschutz.nuvio.app. In case of significant changes, we will inform you via an in-app notice.
14. Contact
For privacy-related questions, you can reach us at: info@dmf-labs.com