Privacy Policy
Last updated: June 26, 2026
This policy explains what data we process when you use the Naucturne site and application, why, and how end-to-end encryption limits what we can see.
1.Data controller
The data controller is [Company name], [legal form], registered under number [registration number], with its registered office at [full address].
For any question about your personal data, you can contact us at support@naucturne.com.
2.Data we collect
Account data: email address, and optionally the display name and avatar color you provide.
Team data: team membership, roles and permissions, invitations sent (email addresses of invited people).
Subscription data: subscription status, plan, seat count and billing identifiers, managed via Stripe.
Minimal technical data needed to operate the service (authentication tokens, security logs).
3.End-to-end encrypted data
Sensitive server credential fields (passwords, private keys, passphrases, proxy settings and database profiles) are encrypted on your device with a key derived from your master password (AES-256-GCM, PBKDF2-SHA512) before synchronization.
Connection metadata (server name, protocol, host, port and username) is stored separately to synchronize your inventory and protected by Row Level Security. We never receive your master password, decryption key, plaintext sensitive fields or transferred file contents.
Team sharing relies on a team key individually sealed for each member (RSA-OAEP): only authorized machines can decrypt.
4.Purposes and legal bases
Providing the service (account creation, encrypted sync, team collaboration): performance of the contract.
Subscription management and billing: performance of the contract and legal accounting obligations.
Security, fraud prevention and proper operation: legitimate interest.
Service-related communications: performance of the contract; any marketing communications: consent.
5.Processors and recipients
Supabase: database hosting, authentication and storage of encrypted content.
Stripe: payment processing and subscription management. Your card data is processed directly by Stripe and does not pass through our servers.
GitLab: distribution of the application binaries downloaded from the site.
We do not sell your personal data and only share it with the processors necessary to operate the service.
6.Retention period
Your account data, connection metadata and encrypted sensitive credential fields are kept as long as your account is active.
After account deletion, this data is erased within [period, e.g. 30 days], except where the law requires retention (notably billing records, kept for the applicable legal duration).
7.Transfers outside the European Union
Some processors may process data outside the European Union. Where applicable, such transfers are governed by appropriate safeguards (standard contractual clauses or equivalent mechanisms).
State here the chosen hosting region [e.g. Supabase EU region] and the associated safeguards.
8.Your rights
Under the GDPR, you have the right to access, rectify, erase, restrict, object to and port your data.
You can exercise these rights by writing to support@naucturne.com. You also have the right to lodge a complaint with your supervisory authority.
9.Cookies
The site uses cookies strictly necessary for its operation (authentication session, language preference, theme).
With your prior consent (consent banner), we use Google Analytics 4 for audience measurement: pages visited, app downloads and pricing page visits. No measurement cookie is set if you decline, and you can withdraw your consent at any time by clearing the site data.
IP addresses are anonymized and we do not use this data for personalized advertising.
10.Security
We implement appropriate technical and organizational measures: end-to-end encryption of access, Row Level Security, storage of local secrets in the operating system vault, SSH fingerprint verification.
To learn more, see our Security page.
11.Contact
For any question about this policy or your data, contact us at support@naucturne.com.