Privacy Policy
01 Summary
02 Who we are
This policy explains how Null Space (“we”, “us”), the operator of the Service, established in Ukraine, handles personal data in connection with the Null Space desktop app, the nullspace.codes website and its subdomains, the companion mobile web apps, and the NullNews portal (together, the “Service”). For the purposes of data-protection law, we are the data controller for the limited personal data described below. Contact us at support@nullspace.codes.
03 What we collect
Account data
- Email address — to create your account, verify it, sign you in via secure links, and contact you about the Service.
- Authentication data — login tokens and, where used, a hashed password. We store passwords only in hashed form and never in plain text.
- Subscription status — your tier (
basicorplus) and, for paid tiers, the start/expiry of your subscription.
Notification data (only if you enable phone push)
- Web-push subscription — the endpoint and keys your browser generates so we can deliver notifications to your device. We do not receive your phone number.
- Notification history — recent alerts we sent you, kept (capped) so the companion app can show an alerts feed.
Phone companion data (only if you use the companion app)
- Live agent snapshot — to mirror your desktop to your phone, the desktop app sends us one live snapshot per account: the name of the open environment and, for each running AI agent, its name, state, and a short tail of its recent output. The snapshot is overwritten on every update and removed when nothing is open. If you never use the companion features, this is not sent.
- AI usage gauges — if you enable usage tracking, the current usage-window percentages of the AI tools you connect (numbers only — never your prompts or their content).
Feedback & diagnostics (only what you choose to send)
- Feedback — your message, optional rating, optional attached screenshot, and coarse client info (app version, macOS version, hardware model).
- Crash reports — if the app crashes, a report (stack trace, app version, macOS version, hardware model — never your projects, terminals, or notes) is written locally and uploaded on a later launch. You can turn uploading off in Settings ▸ About.
- Performance captures — a short (~60 s) trace of frame rate, CPU/memory figures, and scene counts that you can record and submit on request. It never contains your code or content.
Website & technical data
- First-party analytics — when you visit our pages, follow one of our short links, or download the app, we record the event with a coarse country code (derived at our CDN’s edge), a truncated user agent, the referrer, and a salted one-way hash of your IP address used only to estimate unique visitors — we do not store your raw IP. Download events are linked to your account so we can enforce download limits. We do not use third-party advertising or analytics trackers.
- Email delivery events — our email provider reports delivery status (sent, delivered, bounced, complained) for the transactional emails we send you.
- Basic server logs — our hosting provider processes standard request metadata (such as IP address and user agent) to deliver and secure the Service.
Payment data
- If and when paid subscriptions are processed through a payment provider, your card details are handled by that provider — we never see or store full payment-card numbers. We retain only the status of your subscription.
04 What stays on your device
Your workspace content — terminals, command history, browser panes, notes, Git panes, local server output, and the layout of your canvas — is stored locally on your Mac. It is not transmitted to us and is not part of the data we process, with two exceptions that are entirely under your control: the live agent snapshot mirrored to your phone while you use the companion app, and anything you choose to attach to feedback. Voice dictation, where installed, runs entirely on your Mac — audio never leaves your machine. If a future feature would change any of this, we will update this policy and ask for your consent where required.
06 Why we use it
- To create and secure your account and authenticate you.
- To provide the Service and unlock the features included in your tier.
- To send transactional messages (verification, sign-in, password reset, important Service notices) from
no-reply@nullspace.codes. - To deliver the push notifications you opt into and mirror your agents to your phone when you ask for it.
- To respond to your support requests and feedback, and to fix crashes and performance problems you report.
- To understand, in aggregate, where visitors and downloads come from, so we know which channels matter.
- To detect, prevent, and address abuse, security incidents, and technical problems.
- To comply with legal obligations.
07 Legal bases
Where the GDPR or similar laws apply, we rely on: performance of a contract (to run your account and subscription); consent (for push notifications, the phone companion mirror, and diagnostics uploads — all of which you can withdraw at any time); legitimate interests (to keep the Service secure and working and to measure, in aggregate, how it is found and used, balanced against your rights); and legal obligation (where the law requires us to process or retain data).
09 Push notifications
If you enable phone notifications, your browser creates a push subscription that we store so the Service can mirror desktop alerts to your device. Notifications are sent using the Web Push standard via VAPID-authenticated requests. You can turn notifications off at any time from your device’s site settings or by removing the subscription, after which we delete it.
10 How long we keep it
We keep account data for as long as your account exists and for a reasonable period afterward to meet legal, accounting, and security needs. Push subscriptions are kept until you disable notifications or they expire; notification history is capped to recent entries. The live agent snapshot is overwritten on each update and removed when no environment is open. Feedback, crash reports, and performance captures are kept while they are useful for triage and improvement, then deleted. When data is no longer needed, we delete or anonymize it.
11 Security
We use industry-standard measures to protect personal data, including encryption in transit (HTTPS), hashed passwords, scoped authentication tokens, and a strict content-security policy on our web properties. No method of transmission or storage is perfectly secure, but we work to protect your information and to limit what we collect in the first place.
12 Your rights
Depending on where you live, you may have the right to access, correct, delete, restrict, or port your personal data, to object to certain processing, and to withdraw consent. To exercise any of these, email support@nullspace.codes from the address on your account. We will respond within the time required by applicable law. You also have the right to complain to your local data-protection authority.
13 International transfers
Our providers operate globally, so your data may be processed in countries other than your own. Where data is transferred internationally, we rely on appropriate safeguards (such as standard contractual clauses) as required by applicable law.
14 Children
The Service is not directed to children under 16, and we do not knowingly collect their personal data. If you believe a child has provided us data, contact us and we will delete it.
15 Changes
We may update this policy from time to time. We will revise the “Last updated” date above and, for material changes, take reasonable steps to notify you. Your continued use of the Service after changes take effect constitutes acceptance of the updated policy.
Contact
Questions or privacy requests? Email support@nullspace.codes.