Privacy
Privacy policy
This covers nublivault.com, NubliVault Desktop, and the NubliVault app for iPhone. They are different things and the difference matters: with both apps, your files are stored on Nublify's infrastructure.
Last updated: September 11, 2026
Who the controller is
NUBLIFY CONSULTORIA E SERVICOS DE TECNOLOGIA DA INFORMACAO LTDA, in São Paulo, Brazil, is the data controller. For any request about personal data — access, correction, deletion, portability, or withdrawal of consent — write to contato@nublify.com.br. We reply within 15 days.
The iPhone app
The mobile app does two different things, and how your data is handled depends on which one you use:
- Backing up your photos: the photos you choose are encrypted inside the iPhone, with AES-256-GCM, before any upload. What travels and what is stored is already ciphertext, and the key is created on the device.
- A wrapped copy of that key is held in escrow by Nublify, protected by an email address you provide, and it is what allows us to give your photos back if you lose the device. The same warning as Desktop applies: with that copy, NUBLIFY IS TECHNICALLY ABLE TO OPEN YOUR PHOTOS. We do not do it, and access is restricted and audited — but the capability exists.
- The recovery email is used only for that: sending the code that returns the key. It is not added to any mailing list.
- Monitoring the computer backup: in this mode the phone receives no key and opens no file. It reads only dates, sizes, and counts.
- Device identifiers: an access token and, if you allow notifications, a notification token. They exist to know whose device it is and to warn you when a backup stops.
- The app asks for Photos access only to read what you ask it to back up. It does not read contacts, does not use location, does not access the microphone or camera, and contains no advertising, cross-app tracking, or analytics.
Two products, two very different situations
Reading the wrong section leads to the wrong conclusion about where your files live:
- NubliVault Desktop — the free Windows app. Backup packages are uploaded to infrastructure contracted by Nublify. That is what this policy describes in detail.
- NubliVault enterprise — the version installed inside the customer's own infrastructure. There, files never pass through Nublify, and the customer is the controller of their own data.
What leaves your computer with Desktop
Everything is encrypted on your device, with AES-256-GCM, before anything is sent. The key is born on your computer. Only these are uploaded:
- Packages holding your file contents, already encrypted.
- Manifests holding file names and paths — also encrypted; they never travel or rest in readable form.
- Device registration and how much space you use, so we can enforce the quota.
What we can see — and what we could open
This is the part most policies hide. In Desktop's default model, Nublify keeps a wrapped copy of your key so we can give your files back if you lose your computer. The consequence is direct and you need to know it:
- Without using that copy, we see only: your email and name from your Google account, how many files and bytes you store, upload dates, and which devices you registered.
- File contents and file names are NOT visible that way — they are encrypted.
- But because we hold the wrapped copy of your key, NUBLIFY IS TECHNICALLY ABLE TO OPEN YOUR FILES. We do not do it, and access is restricted and audited — but the capability exists, and saying otherwise would be dishonest.
- This is the same commitment stated in the terms you accept during installation. If that model does not work for you, do not use the product.
Signing in with Google
Sign-in uses Google. Nublify never sees your password — we receive only what Google returns after you authorize: email, name, and an account identifier. We keep those three so we know whose backup is whose and can return your access during recovery.
Where the data is stored
There is an international transfer, and Brazilian law requires it to be stated:
- Packages and manifests are stored on Amazon Web Services, region us-east-1, in the United States.
- The service that handles accounts and quotas runs on Google Cloud.
- By using Desktop you agree to that transfer. It is necessary to perform the contract.
How long we keep it, and how to erase everything
Your backups stay for as long as the account exists. To erase, write to contato@nublify.com.br asking for deletion — we remove the packages, the manifests, the wrapped copy of the key, and the identity record, and confirm by email.
- Deletion is performed by a separate, manual process, not by the server that serves the app. This is deliberate: the production service has no permission to delete anything, so no bug of ours and no intrusion can destroy someone's backup.
- The trade-off is that erasing is not instant. We complete it within 15 days.
- Access audit records may be kept longer where a legal obligation requires it.
What the website collects
Only if you accept in the banner. If you decline, or do not answer, no measurement tool is loaded.
- With consent: Google Analytics and Google Ads, to know which channels bring visitors.
- Without consent: only the technical logs every hosting provider keeps.
- You can change your mind by clearing this site's data in your browser.
Who we share with
Only the providers needed for the service to work, and only the data they need:
- Amazon Web Services — storage of the encrypted packages and manifests.
- Google Cloud — hosting for the website and the accounts service.
- Google — authentication, when you choose to sign in with Google.
- SendGrid (Twilio) — sending recovery emails and notices.
- We do not sell, rent, or hand over personal data to third parties for marketing.
Your rights
Brazilian data protection law guarantees you can confirm that processing exists, access your data, correct it, request anonymization or deletion, know who we share with, withdraw consent, and request portability. Just write to contato@nublify.com.br.