Last updated 28 July 2026
Privacy.
Your files are your business. This page explains exactly what leaves your Mac, what we store, and what we never do, in plain language.
The short version
If you read nothing else on this page, read this. Each of these is a property of how the app is built, not a promise of good behaviour.
- Nothing is used for training: your documents are never used to train or improve any AI model.
- Nothing is stored: document content is processed to suggest a name, then discarded. We keep no copies.
- Nothing is logged: our relay records the method, path, status and duration of a request, never its content. That rule is enforced in the code.
- No analytics in the app: no tracking, no telemetry, no phoning home. The app has none.
- You review every rename: nothing is renamed automatically, and every rename can be undone.
Who we are
nymos is a product of Mejunda, a sole proprietorship (eenmanszaak) under Dutch law, Steile Oever 5, 7731 PP Ommen, the Netherlands, registered with the Dutch Chamber of Commerce under KVK number 73264253, VAT NL002215140B29 ("we", "us"). We are the controller for the personal data described here. For anything on this page, write to support@nymos.io.
This website
nymos.io is a static site hosted by Vercel. Serving a page means Vercel processes your IP address and request details to deliver it and to protect the service from abuse. That is the ordinary technical record any web server keeps.
We use Vercel Web Analytics, which is cookieless and aggregate. It sets no cookies, builds no visitor profile, and does not follow you across sites. We see counts and general regions, never who you are. Fonts are served from our own domain, so visiting the site makes no request to any third party.
- Cookies: we set none, which is why you see no cookie banner.
- Forms: the site has none. The only way to reach us is email, and an email tells us whatever you put in it.
- Legal basis: our legitimate interest in running a secure website and knowing roughly how it is used (Article 6(1)(f) GDPR).
The app: what stays on your Mac
nymos is a sandboxed Mac app. It reads a folder only after you grant access to it, and only the files you add to a batch.
- Text is extracted on your Mac. PDF, Word, Excel, PowerPoint, CSV and plain text are all parsed locally.
- When a PDF has no usable text layer, the app reads it with Apple's on-device Vision framework. That OCR happens on your Mac and nowhere else.
- A document with no readable text never reaches the model at all. The app stops and tells you it found no text.
- Your rename history, your templates and your settings are stored locally on your Mac. We never receive them.
- Keychain: your own API key, if you use one, and your license identifier are stored in the macOS Keychain. Your key never reaches our servers.
- No telemetry: the app contains no analytics, tracking or usage reporting of any kind.
The app: what leaves your Mac
When you ask for suggestions, the extracted text of the document is sent for analysis. For images, a downscaled copy of the image is sent instead. Nothing else on your Mac is read or transmitted: not your other filenames, not your folder structure, not your other files.
What happens next depends on which mode you are in. The two modes are genuinely different data paths, so they are described separately.
Managed mode (the default)
In managed mode you never handle an API key. Requests go to our relay server, which runs in Amsterdam on infrastructure operated by Railway, with its database in the same region.
- The relay stores: an anonymous license identifier, whether that license is on trial or subscribed, and a count of documents processed. That is the whole record.
- The relay does not store: filenames, document content, or an email address. Its request log is one line per request: method, path, status, duration.
- Then it forwards: your document content to the AI provider that performs the analysis, and returns the suggested name. It keeps nothing.
- Legal basis: performing our contract with you, meaning providing the app you installed or subscribed to (Article 6(1)(b) GDPR).
The AI provider
The model that reads your document is operated by a provider based in the United States. Content is processed per request to produce the suggestion and is not used to train or improve models, under that provider's API terms for business use. The provider retains standard API logs for a limited period for safety and abuse monitoring; we do not have a zero-data-retention arrangement and do not claim one.
Because that provider sits outside the EU, sending content for analysis is an international transfer. That transfer is safeguarded by the European Commission's Standard Contractual Clauses (SCCs), which are part of the provider's data processing terms.
Self-managed mode
In self-managed mode you supply your own API key. Document content goes directly from your Mac to the provider you chose. Our relay, our database and our servers are not involved at any point, and we have no record that the rename happened.
In that mode the provider's own privacy policy governs what happens to the content, and your agreement is with them. We never see your key: it stays in your Keychain and is sent only to your provider.
Payment and licensing
Paid plans are sold through Polar.sh, acting as Merchant of Record. Polar processes your payment details and billing information, handles tax, and is the party named on your invoice.
We do not see or store your card details. What reaches us is the status of a license: active or not. Subscription management, invoices and cancellation happen in Polar's own customer portal.
How long we keep things
- Document content: not retained. It is processed to produce a suggestion and discarded.
- License record: kept while your trial or license exists, so that reinstalling the app does not reset your trial and your subscription keeps working.
- Server logs: short-lived operational logs kept by our hosting providers for reliability and abuse prevention.
- AI provider logs: the provider that performs the analysis keeps standard API logs for a limited period for safety and abuse monitoring.
- Email: if you write to us, we keep the correspondence as long as we need it to deal with the matter.
Who else processes data for us
We keep this list as short as the product allows.
- Vercel: hosting and cookieless analytics for nymos.io.
- Railway: hosting for the relay server and its database, in Amsterdam.
- An AI provider in the United States: performs the analysis that produces a suggested filename, in managed mode only.
- Polar.sh: payment and billing as Merchant of Record.
Your rights
Under the GDPR you can ask for access to the personal data we hold about you, correction of it, erasure of it, a copy of it, or restriction of its processing, and you can object to processing based on legitimate interests.
Because we store so little, the honest answer to most such requests is that there is very little to look up: an anonymous license identifier and a document count. Write to support@nymos.io and we will answer. If you are not satisfied, you can complain to the Dutch Data Protection Authority, the Autoriteit Persoonsgegevens.
Children
nymos is a tool for work. It is not directed at children, and we do not knowingly collect data from them.
Changes to this policy
If we change how the product handles data, we change this page and update the date at the top. Material changes to how your documents are processed will be announced in the app's release notes as well, not only here.