Privacy Policy – Nevö

Last updated: July 2026

This Privacy Policy explains how Nevö ("Nevö", "we", "us") processes personal data when you use the Nevö mobile app and related cloud services (including pairing and reminder delivery). Nevö is intended for families and households — for example a parent scheduling a school wake-up on a child’s phone.

The Nevö Terms of Use are published at https://nevo.righthere.fi/terms.html.

1. Data controller

Righthere Oy (operator of Nevö)
Erkki Koiso-Kanttilan katu 1
90014 University of Oulu, Finland
Business ID: 2893031-4

Contact: Petri Ahokangas (petri@righthere.fi)
Support: tuki@righthere.fi

2. Scope

This policy applies to:

3. Personal data we collect

We collect only data needed to provide and improve the Service.

Nevö does not access or collect device location (GPS, Wi‑Fi, or network-based location). The app does not request location permission on iOS or Android.

Account and profile

DataExamples
IdentityDisplay name / nickname you choose in the app
AuthenticationFirebase user ID (anonymous authentication identifiers treated as your Nevö account for this device)

Reminders and pairing

DataExamples
Reminder contentMessage text, schedule time, status (scheduled, acknowledged, cancelled, etc.)
RecipientsPaired connection names and linked device identifiers
PairingShort-lived pairing tokens used to connect devices

Reminder messages, nicknames and schedules may be provided by another paired Nevö user (for example a parent sending a reminder to a child’s device).

Device and notifications

Speech / dictation

When you use dictation, speech recognition is provided by the device operating system (Apple Speech framework on iOS; Android SpeechRecognizer / Google speech services on Android, depending on the device). Nevö receives the resulting text and does not store or transmit the raw audio to Nevö’s own servers. If you then use AI reminder parsing, only the recognised text (not the audio) may be sent to OpenAI as described below.

AI reminder parsing (OpenAI)

When AI parsing is enabled (after you allow it in the app), Nevö sends the entered reminder text, paired-client context (recipient names/ids available on your device), locale, current time and timezone to OpenAI. OpenAI returns structured reminder information. Nevö does not use OpenAI to make decisions producing legal or similarly significant effects. You can create and edit reminders manually without allowing AI parsing.

Technical and usage data

Sensitive content you may enter

Reminder content is entered by users and may contain personal or sensitive information about the recipient (for example health-related instructions). Users should only include information that is necessary and that they are authorised to provide. Nevö does not ask for health data as a separate category; any such content is processed only because it appears in reminder text you choose to send.

4. Purposes and legal bases

PurposeLegal basis (GDPR Art. 6)
Creating and managing device accounts and nicknamesPerformance of a contract (Art. 6(1)(b))
Creating, scheduling, delivering, and acknowledging remindersPerformance of a contract (Art. 6(1)(b))
Pairing devices and managing connectionsPerformance of a contract (Art. 6(1)(b))
Sending push notifications and alarms related to reminders you create or receivePerformance of a contract (Art. 6(1)(b))
AI parsing of free-text reminders via OpenAIConsent (Art. 6(1)(a)), which you can grant or decline in the app
Securing services, preventing abuse, and fixing errorsLegitimate interests (Art. 6(1)(f)) — keeping the Service secure and reliable for users
Complying with legal obligationsLegal obligation (Art. 6(1)(c))

If you voluntarily include special categories of personal data in a reminder (GDPR Art. 9) — for example health-related information — we process that content only because you chose to enter it, and only to provide the reminder service. Please do not include such information unless you are authorised to provide it and it is necessary for the reminder. Nevö is a general-purpose reminder app and is not intended for medical or medication management.

5. Recipients and third parties

Service providers processing data for Nevö

Platform providers acting under their own terms

6. International transfers

Our primary infrastructure uses Google Cloud / Firebase, which may store or process data in the European Economic Area and in other countries (including the United States). OpenAI may also process AI-parsing requests outside the EEA. When data is transferred outside the EEA, we rely on appropriate safeguards such as the EU Standard Contractual Clauses and the provider’s compliance programs.

7. Retention

DataRetention
Account / nickname / Firebase identityUntil you delete your account and cloud data, or request erasure
Pairing tokensValid for 30 minutes. After expiry they cannot be used; token records are removed when you delete your account
Active reminders (server)Until delivered, cancelled, acknowledged, or otherwise finished, or until account deletion
Past reminders (server)Removed from the server after the creating device has synced them into its local history (typically shortly after they become past). Local copies remain on devices until you delete them there
Revoked connections / device linksMarked revoked when you remove a connection; removed when you delete your account
Push / notification tokensUntil token rotation, you delete your account, or the app is uninstalled and tokens become invalid
Application / Cloud Function logsTypically up to 30 days in Google Cloud / Firebase logging
Provider backupsRemoved according to Google Cloud / Firebase backup cycles, normally within 30 days after deletion from primary storage
OpenAI API abuse-monitoring logsUnder OpenAI’s default settings, up to 30 days. OpenAI does not use API inputs to train models by default

8. Your rights

Under the EU General Data Protection Regulation (GDPR), you have the right to access, rectify, erase, restrict or object to certain processing, data portability where applicable, withdraw consent, and lodge a complaint with a supervisory authority.

Account and data deletion

You can delete your Nevö account and associated cloud data from the app on that device: Settings → Delete data. Because Nevö uses anonymous sign-in, in-app deletion on the device is the most reliable path.

You may also request deletion through our account deletion page (including by emailing tuki@righthere.fi with your data recovery code from Settings, nickname, and approximate usage times so we can try to locate matching records). Email requests are handled without undue delay and normally within 30 days when the data can be identified.

Deletion includes the Firebase identity for this device (when deleted from the app), active pairings, server-side reminder data and notification tokens, except information that we are legally required to retain (for example limited security logs until they expire as described above). In-app deletion is processed immediately when the cloud request succeeds.

Stopping reminders or removing a single connection is not the same as deleting your account and all related cloud data.

You can also update your nickname in Settings. To exercise other rights, contact petri@righthere.fi or tuki@righthere.fi.

Finnish supervisory authority: Tietosuojavaltuutettu (Office of the Data Protection Ombudsman).

9. Children and family use

Nevö is designed for family and household use. A common use case is a parent or guardian sending wake-up and other reminders to a child’s or other household member’s device.

Where a client device is used by a child under 13, the parent or guardian must set up and supervise the device and authorise the processing required to deliver reminders. The child should not independently manage pairings or provide personal data through the Service.

Parents and guardians should only pair devices and send reminder content appropriate for their child. If you believe a child’s data was processed without appropriate parental authority, contact us and we will delete or correct it where required.

10. Security

We use industry-standard measures including encrypted connections (HTTPS/TLS), authenticated access to backend systems, and access controls. No method of transmission or storage is completely secure.

11. Changes to this policy

We may update this Privacy Policy from time to time. The current version is always published at this URL. We will notify users of material changes where appropriate. Where required by law, we will request renewed consent before applying a change.