NOBODY Files Privacy Policy

Version and last updated: 2026-08-24

1. Company, controller and scope

ITSNOBODY.NET, the registered business name of Yakov Ganam, 16 Yitzhak Ben Zvi St., Petah Tikva, Israel (the "Company"), operates NOBODY Files and determines the purposes and means of processing for account, billing, model-delivery, support and other Company-operated services. Privacy contact: privacy@itsnobody.net. Support: support@itsnobody.net.

This notice covers the Android app, related online services and explicit external-open, recovery-export and diagnostic-share actions. Processing only on the device is still described because local access and analysis can affect privacy. A recipient selected by the User applies its own privacy terms to its copy.

2. Media and analysis processed on the Android device

With permissions you choose, the app can read file names and paths, file size and type, creation and modification dates, MediaStore records, image, video and audio content, EXIF capture and location metadata, installed-app and usage information, and free-space information. It uses this information to index, search, find duplicates, assess quality and recommend cleanup.

Local AI can create OCR text, captions, tags, hashes, quality signals, duplicate groups, cleanup recommendations and visual embeddings. The app does not upload media bytes, file paths, OCR text, hashes, embeddings, face or intimate tags, or scan results to the account or billing server.

Basic face-presence analysis runs locally to estimate face count and create selfie, people and group-photo tags. Optional Android Face Re-identification creates potentially biometric numerical templates and groups only after a separate, versioned opt-in for photo-library organization. Photos, temporary face crops, templates, groups and user-provided names stay on the Android device and are never sent to the Company, cloud models, diagnostics, exports, the desktop companion or external identity databases. The feature does not perform internet identity lookup.

The local sensitive-content classifier can create advisory safety tags. It can be wrong and cannot automatically delete a file. Face and sensitive-content outputs must not be used for surveillance, mass identification, discrimination or a decision producing legal or similarly significant effects.

Local analysis can also store prompts, conversational outputs and tool results in the encrypted on-device database until the User clears them, clears App data or uninstalls.

3. Information that can leave the device

If you create or use an account, the service receives the email address, user identifier, salted password verifier, authentication tokens and timestamps, email-verification status, and the Terms version and acceptance timestamp. Email verification and password recovery create short-lived, single-use challenge records containing only keyed or one-way digests rather than the code, reset link or plaintext password. The service also receives deletion requests.

For purchases, subscriptions and cleanup credits, the service can receive product identifiers, purchase or subscription tokens, order and entitlement state, aggregate requested and actual cleanup byte counts, and random reservation/idempotency identifiers. It never receives selected file names, paths, per-file sizes or media bytes for credit enforcement. Google Play receives a domain-separated SHA-256 account reference rather than the raw NOBODY user ID. Deleting the NOBODY Files account does not cancel an auto-renewing Google Play subscription.

Cloudflare processes API, transactional-email and model-download traffic and can receive the recipient email address, message delivery content, network and security data such as IP address, request time and device or application headers. The service stores only a keyed one-way reference to the client address for its short-lived rate-limit records, rather than the raw address. A model host receives ordinary download-request data when you request an optional model.

Google states that current ML Kit Android SDKs can collect device and app information, per-installation identifiers, performance metrics, API configuration, input and output size, feature version, event type and error codes for diagnostics and usage analytics. Translation can also report configured source and destination languages. The App does not intentionally send media, recognized text or face-analysis results through these diagnostic flows.

Crash support and database recovery are never uploaded. If you explicitly export recovery data, the SQLCipher-encrypted database file is offered to the share target you choose. Opening a file externally gives the selected app temporary read access. Diagnostic sharing sends only allow-listed crash structure after messages, paths, emails, URLs and tokens are removed.

Each saved assistant message offers an in-App generated-content report action. If the User selects a safety category and confirms, the service receives the generated message (limited to 12,000 characters), its local identifier, the selected category, authenticated account identifier and submission time. Reports contain no media or attachments. The Company uses them for safety review, abuse prevention, support and service improvement and deletes them within 180 days, or earlier when the associated account is deleted, unless a specific legal preservation duty applies.

The audited production configuration has no advertising SDK, behavioral analytics SDK or remote crash-reporting SDK. We do not sell personal or sensitive data.

4. Purposes and legal bases

Local file processing provides the scanning, organization and cleanup features you request. Account authentication, purchase verification, subscriptions, entitlements and account deletion are used to perform the service contract. Security, fraud prevention and minimal service records rely on legitimate interests and legal obligations where applicable.

Media, all-files, media-location, app-visibility, usage-access and notification permissions are optional and can be withdrawn in Android settings. Refusal prevents or limits the related feature where technically possible.

Face re-identification uses a separate opt-in where consent is the applicable basis. The Company does not use that consent as a condition for unrelated account processing.

5. Retention and deletion

Local indexes, metadata, derived analysis, settings, checkpoints, chat history and action records remain until a specific screen deletes them, Android App data is cleared or the App is uninstalled. Disabling a feature does not generally delete historical data unless the screen says so. Face Re-identification is a specific exception: the User can delete one person, clear all face data, or withdraw consent. Per-person deletion retains only opaque local suppression tokens to prevent silent recreation; clearing all face data removes them. Withdrawing consent deletes local templates, identities, groups, names and relationship data without deleting photos.

Files moved to the app-protected Recycle Bin become eligible for permanent deletion at the configured deadline, which is 30 days by default. Android background scheduling can delay enforcement. Manual permanent deletion or uninstall can remove them earlier, and uninstall removes the ability to restore them.

A temporary recovery-export share copy is scheduled for deletion from the App's share cache within 24 hours, but the selected recipient controls its copy.

Account and billing-service records remain while the account is active. An authenticated in-app request or the public deletion form deletes the live account, authentication, entitlement, subscription, reservation, device, ledger and order records held by this service.

Unused email-verification and password-reset challenges expire after 15 minutes. Used or expired challenge records are removed by scheduled cleanup and are also deleted with the account.

Generated-content safety reports are retained for no longer than 180 days and are deleted earlier with the associated account unless a specific legal preservation duty applies.

After account deletion, the service may retain only detached, pseudonymous transaction facts for up to 2557 days (approximately seven years) when needed for documented accounting and tax duties. Those records cannot restore the account, subscription, credits or access. Payment providers may retain their own records under their policies and legal duties.

6. Processors, transfers and security

Cloudflare provides hosting, D1 database, transactional email delivery, object storage and network security. Google Play provides Android distribution, billing and subscription services. Google provides ML Kit components. Optional model hosts provide model files. The Company does not sell personal or sensitive data or share it for cross-context behavioral advertising.

These providers can process data in other countries. Where applicable law requires a transfer mechanism, the Company relies on an adequacy decision, approved contractual safeguards or another lawful basis. Their independent processing is also governed by their own notices.

Supported network requests use HTTPS. Authentication secrets are stored in encrypted Android storage, the backend stores password verifiers rather than plaintext passwords, and account deletion removes live server-side access records. No system can guarantee absolute security.

7. Your choices and rights

You can decline optional permissions, delete one person or all Face Re-identification data, clear all Android App data or uninstall for complete local deletion, permanently delete Recycle Bin items, withdraw Face Re-identification consent, delete the Company account, and separately manage or cancel a Google Play subscription.

Subject to applicable law, you may request access, correction or deletion of eligible Company-held personal data. Where another privacy law applies, rights may also include restriction, portability, objection, withdrawal of consent and complaint to a competent authority. Most media and derived data are held only on the device, so the Company cannot access or delete them remotely.

For privacy requests contact privacy@itsnobody.net. For service support contact support@itsnobody.net. We may need to verify the request before acting on account data.

8. Children, automated outputs and changes

The Service is not directed to anyone under 18. If local law requires a higher age or parental authorization, that rule also applies. Contact us if you believe a child's account data was provided contrary to this restriction.

AI outputs are suggestions and can be wrong. The App does not make solely automated decisions producing legal or similarly significant effects; the User reviews file actions.

We may update this notice when the product, providers or law changes. We will change the date and provide additional notice or renewed consent where required.