Privacy Policy
1. The data controller
The data controller, meaning the company that decides what gets collected and what happens to it, is Namup, LLC, a Delaware company whose address is 2810 N Church St STE 89757, Wilmington, DE 19802, United States. Namup is the trading name that company publishes the site and the app under. Because Namup, LLC sits outside Europe, European data-protection law asks it to appoint someone inside Europe you can reach without crossing an ocean. That representative is the company DataRep, appointed on 31 July 2026 for the European Union and the European Economic Area; its addresses are in section 13. Questions about the app itself go to privacy@namup.net.
2. Data we collect
The minimum necessary: email, your sign-in method (Google, or a sign-in link sent to your email, no password), subscription details (via Stripe), region/language preference, and technical metadata (IP at login, app version). Your financial declarations are processed locally on your device, we never read them. We do not collect your bank credentials, we use no advertising tracker (a program a site places to follow what you do from one site to another), and we never sell your data.
3. How we use data
To provide the service, process subscriptions, secure accounts, detect your region for pricing, answer support, and, if you enable it, generate AI insights. No use for advertising or resale.
What the contract makes necessary
The legal basis is the legal reason that permits a processing, and European law provides several of them. Your account, sign-in, subscription row and the payment taken by Stripe rest on performance of the contract between us: without an email address there is no account, without a subscription row there is no access, and the subscription is what you buy. The features you open yourself, the calculators and the preview of a link you paste, rest on the same basis.
What rests on your consent
These processings start only after a yes, each behind a setting of its own, off to begin with: the encrypted backup, reading your monthly text, smart search in your vault, the AI assistant, crash reports, noting the ad your visit came from, joining the waitlist and the mail that follows from it, and the answer you write if you leave the sign-up. You withdraw a consent where you gave it. Withdrawal works forward: it does not undo what has already happened.
What rests on our legitimate interest, and which one
A legitimate interest is an interest we pursue that does not override your rights. Four processings rest on one, and here is the interest in each. Securing accounts and limiting abuse: stopping someone else from using the service at your expense. Hosting the site and the app, and reading which country a visit comes from: serving the pages and showing a price in the right currency. Measuring usage in its aggregate form: knowing where the app helps and where it loses its reader. Keeping the fingerprint of your email address (a one-way calculation: the same address always gives the same result, and the result cannot be turned back into the address) once that address has had its free month: stopping the free month from being taken over and over by deleting the account and creating it again. Usage measurement stops from the app settings or from the pages of the site; for the other three, write to us.
What the law requires of us
Answering a request for access, rectification or erasure is a legal obligation, and that is the basis on which we handle the mail carrying it. The accounting trail of a payment already taken is kept by Stripe under its own obligations.
4. Where data is stored
Local by default: your financial data stays on your device, and we never read it. Cloud backup (opt-in): end-to-end encrypted (the key never leaves your device, so it's unreadable to us), hosted in the EU. Account data (email, subscription): servers hosted in the EU/EEA (Supabase).
5. Sub-processors
A sub-processor is a company that handles data on our behalf, on our instructions, and on nothing else. Here is the full list, and what each one receives.
Stripe, payments and VAT
Stripe handles payments and VAT, in the European Union and the United States, under Standard Contractual Clauses, the template contract the European Commission publishes to govern exactly this kind of exchange.
Anthropic, the AI if you enable it
Anthropic receives, if you enable the AI, a derived and aggregated context, and nothing more by default. Reading your monthly text, if you enable it, adds the sentence you type, your contact details stripped on-device. None of this is used to train the AI, and retention is short, anti-abuse only. That processing happens in the United States, under Standard Contractual Clauses.
Anthropic too, your document or your photo if you enable those features
Two features go further, each behind a switch of its own, off to begin with. Smart search in your vault sends the document you point at, as it is: what a document holds cannot be masked without making it unreadable. The “Decide” tool sends the photo you show it, with the capture data, location included, stripped on your device; what the picture shows goes as it is. Same rules as above: never used for training, short retention, United States under Standard Contractual Clauses.
What the AI context can reveal, if you enable Zakat and the AI
If you enable both the participatory-finance mode and the AI assistant, the context sent to Anthropic can carry the Zakat amount the app has worked out and what is left to set aside for it. Those two figures say that you discharge the Zakat, so they say something about your religious practice. They travel only while both settings are on, and turning either one off stops them.
Supabase, your account and your encrypted backup
Supabase hosts your account and your encrypted backup, in the European Union.
Netlify, hosting for the site and the app
Netlify provides the hosting: it serves the pages of the site and of the app, and it runs the small function that reads which country a visit comes from so the price you see is the right one. Like any host, it sees the IP addresses of the visits it serves; that function itself calls no outside service.
Resend, the delivery of our emails
Resend delivers the emails Namup sends you: the passwordless sign-in link, service messages, and the mail you signed up for. Resend receives your email address and the content of the message. That company is established in the United States, and so are the sub-processors it relies on. The transfer is made under Standard Contractual Clauses or the EU-US Data Privacy Framework.
Cloudflare and Google, the mail you send us
Mail addressed to hello@namup.net and to privacy@namup.net is routed by Cloudflare, a sub-processor bound by a data-processing agreement, then delivered into a Google mailbox where it is read and kept. Those two companies receive your email address and what you write. Both are established in the United States, and the routing by Cloudflare is made under Standard Contractual Clauses.
Sentry, crash reports if you enable them
Sentry receives the crash reports, if you enable that setting: when the app breaks, it sends the error message, the technical path through the code, and the handful of pages walked before the break. Amounts, balances, your email and your IP address are stripped on your device first, and the message is filtered to blank out anything shaped like a sum of money. Those reports land on servers in Germany, so inside Europe, and the site's security policy forbids the browser from sending them anywhere else.
Crash reports have a setting of their own, apart from usage measurement
Crash reporting follows a different rule from usage measurement: it fires on a breakage rather than on a visit, and it lives inside the app alone, never on the public pages of the site. So it has a switch of its own, “Send crash reports”, in Settings, Data & AI. It is off until you turn it on, the usage-measurement setting neither turns it on nor turns it off, and turning it off in that same place stops the sending straight away.
PostHog, usage measurement
PostHog receives the screen events of usage measurement, tied to the visit marker (a random number with no name, no email and no amount), never your identity and never your financial data. Those events are sent for as long as usage measurement has not been refused on this device. The “Anonymous usage measurement” setting inside the app, and the “Turn off usage measurement” link on the pages of the site, stop them. Hosting in the European Union.
What holds for every sub-processor
Every sub-processor named in this section is bound by a data-processing agreement. No other sharing happens without your consent, except where required by law.
6. Your rights (GDPR)
Access, rectification, erasure, portability, restriction, objection, withdrawal of consent. Exercise them in-app (data export, account deletion, privacy settings) or by email. Response within 30 days. Account deletion erases the cloud backup, then purges the device. The device is purged only once the server-side erasure has succeeded; if it fails, the device is not purged and the screen says so. No confirmation message is sent.
7. Retention periods
How long data is kept depends on where it is kept, and most of Namup's data is kept on your device. Your financial data stays on your device until you erase it, and we hold no copy of it, so we have no period to state for it. You erase it from the app (reset, account deletion) or by clearing your browser's data. The visit marker is kept for the length of the tab, and the browser deletes it when the tab closes. Your encrypted backups, if you turn them on: we keep the five most recent and delete the older ones automatically on each new upload, without ever being able to read a single one. Your account and the subscription row attached to it are kept for as long as the account exists; when you delete the account, the database deletes the subscription row with it, automatically. The accounting trail of a payment already taken is kept by Stripe, under its own obligations. The fingerprint of an address that has had its free month is kept for 24 months from the start of that month, then deleted by a scheduled job that runs every day in the database. It survives the deletion of the account, deliberately: without it, deleting the account and creating it again with the same address would hand out a free month every time. It answers one thing only, and only when an address is put to it: whether that address has had its free month. The right to erasure has limits, set out in Article 17.3 of the European regulation, and the one that applies here is the establishment of a right: the free month is given once per address, and the fingerprint is what establishes it. Emails between us stay in the contact inbox; no automatic deletion runs on it, and we erase them when you ask.
8. Cookies, advertising trackers and the visit marker
Namup sets no cookie (a small text file a site places in the browser), in the app or on the site, and carries no advertising tracker. What the device holds: your data and your display preferences (language, region), the choice you made about usage measurement and, if you were asked the question, the choice you made about the ad your visit came from, plus, for the length of your visit, the visit marker. A refusal of usage measurement is held on the device so it holds on later visits; a measured visit has nothing held for it. The choice about the ad your visit came from is held whether it is an acceptance or a refusal, so the question does not come back. The visit marker exists so we can tell whether the pages of the site lead people to the app. The browser deletes it when the tab closes. Namup does not link one visit to another.
9. Children
The service is not directed at anyone under 16, and we do not knowingly collect their data. This 16 threshold is the age of independent consent to the processing of personal data (being able to agree to that processing without a parent), set by Article 8 of the GDPR (the European regulation that governs the use of personal data). The Terms of Use state a second threshold, 18, which is about the legal capacity to enter into a contract, in section 4. The two thresholds settle two different questions and both apply. Contact us and we delete the data.
10. Authorities & law
We disclose data to authorities only when required by law (court order, regulatory demand), and we notify you where legally permitted.
11. International transfers
Primary processing is in the EU/EEA. The transfers to the United States are the ones described in section 5, and there are no others: Stripe for payments and VAT, Anthropic for the AI if you enable it, Resend for the delivery of our emails, and Cloudflare then the Google mailbox for the mail you send us. The transfers to Stripe, Anthropic, Resend and Cloudflare occur under Standard Contractual Clauses (GDPR Art. 46) or the EU-US Data Privacy Framework. No other transfer will occur until section 5 names it.
12. Changes to this policy
We notify you by email at least 30 days before any change to this policy that adds a recipient of your data, adds a purpose, or reduces your rights. Continued use after the effective date constitutes acceptance.
13. Contact and supervisory authority
Privacy: privacy@namup.net (Namup, LLC, 2810 N Church St STE 89757, Wilmington, DE 19802, United States). That address receives anything touching the app itself. Our representative in Europe: Namup, LLC has appointed the company DataRep to represent it before people and authorities in the European Union and the European Economic Area, from 31 July 2026. Write to datarequest@datarep.com, or use the form at www.datarep.com/data-request, quoting Namup, LLC. By post: DataRep, 72 rue de Lessard, 76100 Rouen, France, or DataRep, Rue des Colonies 11, 1000 Brussels, Belgium. The envelope must carry the word DataRep, otherwise the letter will not arrive. This appointment covers the European Union and the European Economic Area; the United Kingdom and Switzerland fall outside it. You may also complain to the public authority responsible for data protection in your country (in France, the CNIL).