Privacy Policy

Last updated: 1 August 2026

Niffler is a personal link and note keeper. It is built and run by one person — Mario Canas, an individual in Spain, not a company — so wherever this policy says "we", it means him. He is the data controller, and his details are at the bottom of this page. Being one person rather than a company does not reduce his obligations to you: every right described below applies in full. We designed Niffler to collect only what is necessary to provide the service.

Information We Collect

How We Use Information

We process your information based on the following legal bases:

Waitlist and Invitations

Niffler is currently invite-only. Two small records exist because of that, and neither of them is an account:

Neither list is reachable through the app or its public API. Both are held in a part of our database that is not published to the internet and can be read only by the operator.

Removing yourself. Because there is no account involved, there is nothing to log in to and delete. Email mario@mariocanas.com and we will erase your entry from either list. We keep waitlist entries until we invite you, until you ask to be removed, or until we stop operating a waitlist — whichever comes first. If we stop running the waitlist, we erase the outstanding entries rather than keeping them.

Data Storage and Security

How Your Files Are Stored and Served

The files you upload — images, PDFs and other attachments, the small preview thumbnails we generate from them, and your profile picture — are stored with Cloudflare, in a private storage bucket located in Cloudflare's Western Europe region. Everything else, including your account and the bookmarks and notes themselves, stays in the Supabase database described above. Files moved from Supabase to Cloudflare on 30 July 2026; the Western Europe setting is where Cloudflare places the bucket, which is a placement preference rather than a contractual guarantee that no copy is ever held elsewhere.

During the changeover, a second copy exists. Files uploaded before 30 July 2026 were copied to Cloudflare rather than moved, and the originals are still held in Supabase's storage in the United Kingdom while we satisfy ourselves that nothing was lost in the transfer. Those originals are not what the app serves you any more, and they are deleted along with everything else if you delete your account. They will be removed once that check is finished.

The bucket is private and cannot be listed or browsed. Every request for a file goes first to a small program of ours running on Cloudflare's network, which decides whether you may have it:

Cloudflare acts as our processor here: it holds and delivers these files on our instructions and does not use them for its own purposes. Cloudflare, Inc. is established in the United States — see International Data Transfers below.

Two things this does not change. Your bookmarks, notes, tasks and calendar entries are not sent to Cloudflare — only the files attached to them. And the site icon shown next to a saved link still comes from Google or DuckDuckGo, fetched by your own device, exactly as described under Data Sharing.

Local Data

We use localStorage for preferences (e.g., language), offline actions, and share-target data; and service worker caches for faster loads. You can clear this via your browser settings.

Data Sharing

We do not sell your data. We never have and never will. We share data only with our infrastructure and service providers to operate the service:

The last two entries are worth understanding, because they work differently from the rest: Google, DuckDuckGo and jsDelivr are not servers we send your data to. They are resources your own browser or phone fetches directly while the app is running. We cannot see those requests, but the third party can, and in the case of site icons the request necessarily discloses which domain you saved.

Sharing a Space With Someone

Niffler lets you invite another person into a space so you can both work in it. Doing that discloses things about you, so it is worth stating exactly what:

If you would rather not disclose your email address to a collaborator, do not accept or send an invitation — there is currently no way to be in a shared space anonymously.

The Browser Extension

Niffler has an extension for Chrome that saves the page you are on. It is worth being precise about what it can and cannot see, because browser extensions are an area where people are right to be suspicious.

For a complete list of our service providers and how they handle your data, see our Subprocessors page.

Who Can See Your Data

Leaving aside anyone you have deliberately shared with — collaborators in a shared space, or anyone holding the link to something you made public, both covered under Sharing a Space With Someone — Niffler has no employees, and the only human who can reach your content is the one person who runs it. He has technical access to the database because somebody has to be able to fix things when they break. His commitment is not to look. He does not access your bookmarks, notes, or other stored content except:

Google Calendar Integration

Niffler offers optional Google Calendar integration to help you manage your schedule alongside your bookmarks and notes. Here's how it works:

Limited Use Disclosure: Niffler's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

Automatic AI Processing

This section is important, so we want to be plain about it: some of your content is sent to OpenAI automatically as part of saving it, whether or not you ever use the AI assistant. This is what makes search work. Specifically:

Separately, the Niffler iOS Share Extension uses an on-device Apple model to suggest which space to file something into. That suggestion is computed entirely on your device; nothing about it is sent to us or to OpenAI.

AI Assistant (Mr. Niffs)

In addition to the automatic processing above, Niffler includes an optional AI assistant called Mr. Niffs. Here's how your data is handled when you use it:

Public Content

If you mark a category or item as public, its content becomes accessible to anyone with the link. Keep this in mind when sharing.

Leaderboard Game

Our website includes a small game. If you finish a round you may optionally submit a score, which stores the display name you type together with your score. No account is required and we do not attach the entry to your Niffler account, but the resulting leaderboard is readable by anyone, so please do not enter your real name or any other personal detail unless you are happy for it to be public. To have an entry removed, email us at mario@mariocanas.com.

Your Rights

Under applicable data protection laws (including GDPR and CCPA), you have the following rights:

To exercise these rights, email mario@mariocanas.com. We will answer within one month, which is the deadline data protection law sets. If a request is genuinely complex the law allows that to be extended by up to two further months; if that ever happens we will tell you within the first month and explain why.

Cookies and Tracking

Niffler does not set any cookies. Your sign-in session is held in your browser's own localStorage rather than in a cookie, and localStorage and sessionStorage are also what hold your app preferences and the offline cache. Signing out clears them.

This is why you have never seen a cookie banner on Niffler, and it is not an oversight: there are no analytics, advertising or tracking cookies to ask you about, and storage that is strictly necessary to deliver a service you asked for does not require consent. If you sign in with Google or Apple, those providers may set cookies on their own sign-in pages, under their policies rather than ours.

Data Retention

We retain your data for as long as your account is active. When you delete your account, your profile, bookmarks, notes, and associated content are erased from our live systems immediately — this is a real deletion, not a flag or a grace period. Your uploaded files are deleted from Cloudflare's storage in the same operation, along with your profile picture. Encrypted backups taken before that point roll off within 30 days, after which no copy of your content remains. Cached copies of your files held in Cloudflare's network are dropped where we can reach them and expire on their own where we cannot, as described in How Your Files Are Stored and Served. Synced Google Calendar events are removed when you disconnect the integration, and the stored token with them.

Logs. Niffler does not run a logging system of its own — there is no log database we own and no archive we keep. What exists are the operational logs of the providers who run the infrastructure: Supabase for the database and edge functions, Vercel for the website, Cloudflare for file delivery, Upstash for rate limiting. Each expires those on its own schedule, which is measured in days rather than months, and none of them is a place we go to read your content. A leaderboard entry, being tied to no account, stays until you ask us to remove it.

Waitlist and invitation entries are held separately from accounts and are not covered by account deletion, because they exist before — and independently of — any account. Their retention is described in Waitlist and Invitations above.

Children's Privacy

Niffler is not intended for children under 14, the minimum age under Spanish law (Ley Orgánica 3/2018, art. 7) at which a person can consent to the processing of their own personal data. We do not knowingly collect personal information from children under 14. If we become aware that a child under 14 has provided us with personal information, we delete it without undue delay once we know. Parents who believe their child has provided information should contact us.

International Data Transfers

Niffler is operated from Spain. Your account and your saved content are stored in the United Kingdom, in Supabase's West EU (London) region. Your uploaded files are stored with Cloudflare in its Western Europe region, and cached copies of them are held temporarily in whichever Cloudflare data centres serve them — which, depending on where they are viewed from, can be anywhere in the world. That is explained in How Your Files Are Stored and Served above. Other providers we rely on — including OpenAI, Vercel, RevenueCat, Resend and Upstash, and Cloudflare itself, which is a United States company — process data in the United States, so some of your data does leave the European Economic Area. Where a transfer requires it, we rely on appropriate safeguards, including:

Data Breach Notification

In the event of a data breach that poses a risk to your rights and freedoms, we will:

One honest note about how that works in practice. Niffler is run by one person, with no monitoring desk and no on-call rota. The 72-hour clock above runs from the moment we become aware of a breach, which is what the law requires — but in most cases we would learn of one from a provider's notification or from a user, not from our own alerting. We would rather tell you that than imply a watch that does not exist.

Changes to This Policy

We may update this Privacy Policy from time to time. When we make significant changes, we will notify you via email and/or through an in-app notification. The updated policy will include the new "Last updated" date at the top. Your continued use of Niffler after changes constitutes acceptance of the updated policy.

California Privacy Rights (CCPA)

California residents have additional rights under the California Consumer Privacy Act (CCPA):

To exercise these rights, contact us at mario@mariocanas.com with "California Privacy Request" in the subject line.

Under the CCPA we act as a "business" rather than a "service provider", because we decide how and why personal information is processed. We have never sold or shared personal information, and there is no revenue stream to tempt us to: Niffler is free, sells nothing, and takes no payment of any kind. We only use your personal information to provide the service as described in this policy.

In the interest of not overstating our own obligations: Niffler is one person's free side project and almost certainly falls below every revenue and volume threshold that makes the CCPA binding. We set out these rights because they are the right ones to offer, not because we have determined that the statute applies to us. If you are a California resident, ask and we will honour them either way.

Tracking and Do Not Track Signals

Niffler does not run analytics, advertising, or behavioural-tracking software. There is no tracking pixel, no advertising network, and no third-party analytics script in the product, so there is nothing for a "Do Not Track" (DNT) browser signal to switch off — we do not track you across sites whether or not you send one. We do keep server-side error and request logs, which are necessary to operate and debug the service.

Contact & Data Controller Information

The data controller responsible for your personal information is Mario Canas, an individual established in Spain who builds and runs Niffler as a personal side project. There is no company — the controller is one person, and you can reach him directly at mario@mariocanas.com. See Who Runs Niffler in our Terms for what that means in practice. Being an individual rather than a company does not reduce his obligations to you under data protection law, and every right described above applies in full.

For privacy inquiries, data requests, or to exercise your rights, contact us at:

We will respond within one month, as data protection law requires.