Who we are
Nylio is a collaborative document editor with AI-assisted writing, web research, workspace collaboration, document sharing, billing, and import features. In this Privacy Policy, "Nylio," "we," "us," and "our" refer to the operator of the Nylio service.
If you have privacy questions or requests, contact us at hello@nylio.app.
Data we collect
We collect data you provide directly, data created through use of the service, and limited technical data generated automatically.
- Account and profile data, such as your name, email address, authentication identifiers, organization membership, and session information.
- Workspace and document data, such as documents, comments, version history, titles, document metadata, permissions, and share settings.
- AI and chat data, such as prompts, instructions, selected text, chat history, model outputs, uploaded files, and documents or excerpts sent to AI features.
- Import and integration data, such as files and metadata imported from providers like Google or Microsoft when you connect those accounts.
- Billing and subscription data, such as plan status, customer identifiers, invoices, and payment-related metadata provided by our billing partners. We do not store full payment card details on our own servers.
- Communications data, such as emails you send to us and emails we send for invitations, account verification, password resets, and product notices.
- Usage and device data, such as IP address, browser type, app events, approximate location inferred from IP, cookie or session identifiers, logs, diagnostics, and performance data.
How we use data
We use personal data to operate and improve Nylio, including to:
- Create and manage accounts, sessions, workspaces, and access controls.
- Store, sync, display, edit, share, and back up documents and related content.
- Provide AI features, including document editing assistance, web research, search, fact-checking, and analysis.
- Process imports, uploads, exports, and file previews.
- Provide subscription management, usage tracking, and billing support.
- Send transactional messages such as invites, verification emails, and support replies.
- Maintain security, detect abuse, troubleshoot issues, and enforce our Terms.
- Measure product performance, understand usage patterns, and improve the service.
Legal bases for EEA, UK, and similar jurisdictions
If data protection laws such as the GDPR apply, our legal bases for processing generally are:
- Contract: to provide the services you request, including accounts, collaboration, imports, storage, AI features, sharing, and billing.
- Legitimate interests: to secure the service, prevent abuse, improve reliability, analyze usage, and support our business operations.
- Consent: where required for certain cookies, optional communications, or other processing that requires consent under applicable law.
- Legal obligation: where we must keep or disclose data to comply with law, lawful process, accounting, or regulatory duties.
AI processing and third-party models
Nylio includes AI features. To provide them, we may send prompts, document excerpts, uploaded files, chat content, tool outputs, or related context to third-party AI and search providers that process data on our behalf or as independent service providers.
You should not submit content to AI features unless you are comfortable with that processing and authorized to share the content with us and our providers for that purpose.
We use this processing to generate responses, suggest edits, answer questions, search public sources, and improve feature reliability. We do not use your content to train our own foundation models. Third-party provider retention and model training practices may differ, so review our product settings and contact us if you need more detail.
Data retention
We keep personal data for as long as reasonably necessary for the purposes described in this Privacy Policy, including to provide the service, maintain records, resolve disputes, enforce agreements, and comply with law.
Retention periods vary by data type. For example, account and billing records may be retained longer than routine logs, and shared or imported content may remain available until deleted by you, your workspace, or our retention rules.
International data transfers
Nylio is offered globally. Your personal data may be processed in countries other than your own, including countries that may not provide the same level of legal protection.
Where required, we will use appropriate safeguards for cross-border transfers, such as contractual protections or other lawful transfer mechanisms.
Security
We use reasonable technical and organizational measures designed to protect personal data. No system is perfectly secure, and we cannot guarantee absolute security.
You are responsible for safeguarding your account credentials, carefully managing sharing permissions, and using share links only when you intend the linked content to be accessible to recipients.
Your privacy rights
Depending on where you live, you may have the right to request access to, correction of, deletion of, or export of your personal data, as well as the right to object to or restrict certain processing.
If the GDPR or similar laws apply, you may also have the right to withdraw consent where processing relies on consent and the right to lodge a complaint with your local supervisory authority.
To exercise rights, email hello@nylio.app. We may ask you to verify your identity before acting on a request.
Children
Nylio is not directed to children under 13, and if a higher minimum age applies in your jurisdiction, to users below that age. If you believe a child provided personal data to us unlawfully, contact us so we can review and remove it where appropriate.
Changes to this policy
We may update this Privacy Policy from time to time. If we make a material change, we may provide notice through the service, by email, or by updating the effective date above.
Your continued use of Nylio after an updated Privacy Policy takes effect means the updated version applies going forward, subject to applicable law.