Last updated July 2, 2026
This privacy notice for Nimo Direct Inc. ("Company," "we," "us," or "our"), describes how and why we might collect, store, use, and/or share ("process") your information when you use our services ("Services"), such as when you:
• Use our OS and system applications (NimoOS), or any other application of ours that links to this privacy notice
Questions or concerns?
Reading this privacy notice will help you understand your privacy rights and choices. If you do not agree with our policies and practices, please do not use our services.
As a company that started with community and open source software, we care deeply about your feedback. If you still have any questions or concerns, please contact us at service@nimopc.com.
SUMMARY OF KEY POINTS
What personal information do we process? When you visit, use, or navigate our Services, we process personal information depending on how you interact with Nimo Direct Inc. and the Services, the choices you make, and the products and features you use.
How do we process your information? We only receive and process your device information and encrypted information to provide Services. Except as described in this notice — for example, where you choose to enable a cloud-based AI model or connect a third-party cloud storage account — we do not collect, store, use, or analyze your personal information and data.
Do we process any sensitive personal information? Except as described in this notice, we do not process any sensitive personal information.
How do we keep your information safe? Except as described in this notice, we do not store your data, so there is generally no such processing to protect.
What are your rights? Depending on where you are located geographically, the applicable privacy law may mean you have certain rights regarding your personal information. You can always contact us with your concerns and suggestions at service@nimopc.com.
WHAT INFORMATION DO WE COLLECT?
Personal information you disclose to us
We only receive your device information and encrypted information to provide Services. Except as described in this notice, we do not collect, store, use, or analyze your personal information and data.
We do not process sensitive information. We receive personal information you disclose to us, such as your Internet Protocol (IP) address and/or browser, encrypted transferred data, and device characteristics, which is received automatically when you visit our Services. Except as described in this notice, this information is not stored, used, or analyzed in any form.
Here are some common data privacy levels and scopes you might see disclosed by internet companies when discussing personal information:
|
Category |
Examples |
Collected |
|
A. Identifiers |
Contact details, such as real name, alias, postal address, telephone or mobile contact number, unique personal identifier, online identifier, Internet Protocol address*, email address, and account name |
NO |
|
B. Personal information categories listed in the California Customer Records statute |
Name, contact information, education, employment, employment history, and financial information |
NO |
|
C. Protected classification characteristics under California or federal law |
Gender and date of birth |
NO |
|
D. Commercial information |
Transaction information, purchase history, financial details, and payment information |
NO |
|
E. Biometric information |
Fingerprints and voiceprints |
NO |
|
F. Internet or other similar network activity |
Browsing history, search history, online behavior, interest data, and interactions with our and other websites, applications, systems, and advertisements |
NO |
|
G. Geolocation data |
Device location |
NO |
|
H. Audio, electronic, visual, thermal, olfactory, or similar information |
Images and audio, video or call recordings created in connection with our business activities |
NO |
|
I. Professional or employment- related information |
Business contact details in order to provide you our Services at a business level or job title, work history, and professional qualifications if you apply for a job with us |
NO |
|
J. Education Information |
Student records and directory information |
NO |
|
K. Inferences drawn from other personal information |
Inferences drawn from any of the collected personal information listed above to create a profile or summary about, for example, an individual's preferences and characteristics |
NO |
|
L. Sensitive Personal Information |
|
NO |
* IP addresses are automatically received as part of standard internet connections, but are not stored, used, or analyzed. See "What Information Do We Collect" above for details.
AI features: local processing vs. cloud processing
NimoOS includes AI-powered features, such as the "Ask Nimo" assistant and semantic/natural-language search. By default, these features run entirely on AI models hosted locally on your own device. When operating in this default mode, your data does not leave your device, and we cannot access it.
You may choose, through system settings, to enable a cloud-based AI model instead of the local model. If you enable this option, the content of your requests will be sent to the cloud model provider you select for processing. In that case, the processing of your information is governed by that provider's own privacy policy, which we encourage you to review. We do not ourselves access, store, or analyze the content of these requests.
System updates (OTA) and device diagnostic information
To provide software update ("OTA") services, our servers receive the following information from your device: a randomly generated device identifier (a UUID that is not a hardware serial number and is not directly linked to your identity), the device model, the current software version, and upgrade process logs, which do not contain any personal information.
This information is used solely to determine the appropriate update package for your device and to diagnose upgrade issues. We retain this information for a maximum of one (1) year, after which it is automatically and permanently deleted. We do not use this information to build user profiles, analyze behavior, or link it with other data to identify you.
HOW DO WE KEEP YOUR INFORMATION SAFE?
In Short: Except as described in this notice, we do not store any of your data, so there is generally no such processing.
We Don't Store Your Data, Unlike Others. In a world where data collection is the norm, we stand apart. Your data security and privacy are our top priorities, which means that, except as described in this notice (such as the limited OTA diagnostic information described above, which is retained for up to one year), we do not store any of your information.
Unlike many mainstream internet companies that collect and analyze vast amounts of user data, we operate on a fundamentally different principle: transparency and respect for your privacy. Except as described in this notice, we do not collect, save, use, or analyze your identifiers, location information, or any other personally identifiable information.
Because we do not store most categories of your data, there is, in most cases, no data processing to speak of. You can use our services with confidence, knowing that your privacy is protected.
WILL YOUR INFORMATION BE SHARED WITH ANYONE?
While many big data and internet companies collect, analyze, and sell your information, we are committed to a different approach. Except as described in this notice, we do not store, analyze, or sell your personal information. Nimo Direct Inc. will never engage in any commercial activity involving the sale of user data based on our services. Your privacy is paramount to us. Below, we describe the specific circumstances in which your information may pass through parties other than you and your intended destination.
Software update distribution
To deliver software update files efficiently, we use third-party cloud storage and content delivery network (CDN) services. As part of this process, your device's IP address and other connection information may be logged by the infrastructure of these service providers to ensure successful delivery. We do not access, collect, or use these logs ourselves.
Remote access to your NAS device
To support remote access to your NAS device over the public internet, when a direct connection between your device and your access point cannot be established, the relevant traffic may be relayed through our cloud servers in encrypted form. Our servers act solely as a relay for this traffic; we do not read, store, analyze, or otherwise use the content being relayed.
Third-party cloud storage connections (Dropbox / OneDrive / Google Drive)
1. Feature description
When you connect a supported third-party cloud storage provider, such as Dropbox, OneDrive, or Google Drive,within NimoOS, you can browse, read, write, and manage the files in that cloud storage account directly from your own NimoOS device. This feature is optional and is activated only if you choose to connect an account.
2. Scope of authorization requested
When you connect an account, you will be directed to the relevant cloud service provider's own authorization page to complete the connection. We request the following permissions, solely to enable the file-management functionality described above:
• Dropbox: basic account information (to display your account name/email), and read/write access to the files, folders, and associated metadata in your Dropbox account.
• OneDrive: read/write access to your OneDrive files (Files.ReadWrite.All), and offline access (offline_access), which is used to maintain the connection while you are not online.
• Google Drive: uses a "bring your own credentials" model, where you create and authorize access through your own Google Cloud project; the requested scope is read/write access to Google Drive files.
3. How data flows and is stored
• Your file content does not pass through our servers. Files are transferred directly between your device and the cloud service provider. NimoOS and its operator do not receive, relay, or store any of your file content.
• Authorization tokens are stored only on your local device. The access and refresh tokens obtained after authorization are stored only in your NimoOS device's local configuration and are never uploaded to or stored on our servers.
• Our authorization relay service plays a limited role. For technical reasons, the authorization process passes through a relay service we operate (under the domain cloudoauth.files), which — at the moment of authorization only — forwards the one-time authorization code returned by the cloud service provider back to your own device. This relay service does not store or log the authorization code, any tokens, or any file data. The step of exchanging the authorization code for a token is completed locally on your device.
4. What we do not do
We do not collect, store, upload, read, or sell your cloud storage files or account data.
We do not use this data for advertising, user profiling, or model training, and we do not share it with third parties. Your cloud storage data remains under your control at all times and flows only between your device and the relevant cloud service provider.
5. Third-party services
This feature relies on the following third-party services, whose handling of your data is governed by their respective privacy policies:
• Dropbox Privacy Policy: https://www.dropbox.com/privacy
• Microsoft (OneDrive) Privacy Statement: https://privacy.microsoft.com/privacystatement
• Google (Google Drive) Privacy Policy: https://policies.google.com/privacy
6. Revoking authorization
You may disconnect at any time by:
• Selecting "Disconnect / Remove" for the relevant cloud storage account within NimoOS, which deletes the locally stored authorization token; or
• Revoking the app's access from the relevant cloud service provider's own account security settings (Dropbox "Linked Apps," Microsoft account "Privacy/App permissions," or Google Account "Third-party access").
7. Data retention
Authorization tokens are stored locally on your device only for as long as the account remains connected and are removed from your device immediately upon disconnection. Our servers do not retain any user data related to this feature.
DO WE MAKE UPDATES TO THIS STATEMENT?
In Short: Yes, we will update this notice as necessary to stay compliant with relevant laws.
We may update this privacy notice from time to time. The updated version will be indicated by an updated "Revised" date and the updated version will be effective as soon as it is accessible. If we make material changes to this privacy statement, we may notify you either by prominently posting a notice of such changes or by directly sending you a notification. We encourage you to review this privacy statement frequently to be informed of how we are protecting your information.
CHILDREN'S PRIVACY
Our Services are not directed to children under the age of 13 (or the applicable age of digital consent in your jurisdiction), and we do not knowingly collect personal information from children. If we become aware that we have inadvertently received personal information from a child without verification of parental consent, we will delete such information from our records as soon as reasonably possible. If you believe a child may have provided us with personal information, please contact us using the details in the "How Can You Contact Us About This Policy" section below.
DO NOT TRACK SIGNALS
Most web browsers, and some mobile operating systems, include a "Do Not Track" ("DNT") feature. Because there is currently no uniform industry standard for recognizing or responding to DNT signals, we do not currently respond to DNT browser signals or any other mechanism that automatically communicates your choice not to be tracked online.
WHAT ARE YOUR PRIVACY RIGHTS?
Depending on where you are located, applicable privacy laws — such as the California Consumer Privacy Act ("CCPA") — may give you certain rights regarding your personal information, including:
• Right to Know — the right to request that we disclose the categories and specific pieces of personal information we have processed about you.
• Right to Delete — the right to request that we delete personal information we have collected from you, subject to certain exceptions.
• Right to Opt-Out of Sale or Sharing — the right to direct us not to sell or share your personal information. As described throughout this notice, we do not sell your personal information under any circumstances.
• Right to Non-Discrimination — the right not to receive discriminatory treatment for exercising any of your privacy rights.Because we do not, in the ordinary course of providing our Services, collect or store personal information about you (except as described elsewhere in this notice, such as the limited OTA diagnostic information described above), in most cases there is no additional personal data for us to disclose or delete beyond what is described in this notice.
How to exercise your rights
To exercise any of the rights described above, or if you have questions about how we handle your information, you may contact us at service@nimopc.com. We will respond to verifiable requests within thirty (30) days of receipt. Where data results from a third-party account you have chosen to connect, such as a cloud storage account, you can manage or delete that data directly from your device's local settings, or by revoking the relevant authorization as described above.
HOW CAN YOU REVIEW, UPDATE, OR DELETE THE DATA WE COLLECT FROM YOU?
Since we do not store or analyze most categories of your data, in most cases we are not able to provide you with data for review or deletion beyond what is described in this notice. For data associated with the specific features described above, such as OTA diagnostic information or third-party cloud storage connections, please refer to the relevant section of this notice for how that data can be reviewed, managed, or deleted.
HOW CAN YOU CONTACT US ABOUT THIS POLICY?
If you have questions or comments about this notice, you may email us at service@nimopc.com or by post to:
Nimo Direct Inc.
51 Steel Dr., Unit A
New Castle, Delaware 19720
United States