Privacy Policy
Last updated 17 June 2026
Nilo is a timer app with optional end-to-end encrypted sync. This policy explains what we collect, why, and the rights you have. The short version: we store as little as possible, and what we store about your timers is encrypted so that we cannot read it.
Who is responsible
The service at nilo.sp33c.tech and the Nilo apps are operated by Alexander Fitterling (sp33c.tech), Wöhrder Kreuzgasse 8, 90489 Nürnberg, Germany.
For any privacy question or request, email info@sp33c.tech.
What we collect
Using Nilo without an account collects nothing — your timers stay on your device.
If you create a Nilo account to sync, we store your email address, an encrypted copy of your timers, and a key derived from your password that lets us verify your login. We never receive your actual password.
If you buy Nilo Pro, our payment provider tells us your subscription status (active or expired) so we can unlock sync. We never see your card details.
How we use your data, and the legal basis
We use this data only to run the service: to authenticate you and to sync your encrypted timers across your devices. Under the GDPR, the legal basis is the performance of our contract with you (Art. 6(1)(b)).
We do not use your data for advertising or profiling, we run no tracking, and we never sell data.
End-to-end encryption
Sync is end-to-end encrypted. On your device, your password is turned into a key using PBKDF2-HMAC-SHA256 (120,000 iterations). Your timers are encrypted with AES-256-GCM before they leave your device, and everything is transmitted over TLS (HTTPS).
Your password and the decryption key never leave your device. This means we cannot read your timers — and neither can anyone who might gain access to our servers (zero-knowledge).
Service providers
We rely on a small number of processors, each bound to protect your data:
• Amazon Web Services (AWS), Frankfurt (eu-central-1) — hosting and storage of the encrypted data.
• Amazon SES — sending account emails such as confirmation and password-reset links.
• RevenueCat — managing purchases and subscription status.
We embed no advertising or analytics SDKs.
How long we keep it
We keep your account data for as long as your account exists. You can delete your account at any time from within the app, which removes your email and encrypted timers from our servers. You can also ask us to delete it by emailing info@sp33c.tech.
Your rights
Under the GDPR you have the right to access, rectify, erase, restrict, port, and object to the processing of your data (Art. 15–21). To exercise any of these, email info@sp33c.tech. You also have the right to lodge a complaint with a data protection authority.
Children
Nilo is not directed at children and we do not knowingly collect data from them. The optional Kids mode runs entirely on your device and creates no account.
Changes to this policy
If we change this policy we will update the date above and, for significant changes, notify you in the app.