Nikapps
Home Blog
Home / Privacy Policy
Legal

Privacy Policy

This policy explains what happens to personal data when you visit nik.app. The short version: almost nothing.

Effective 18 August 2026 · Last updated 18 August 2026

The short version

  • No user accounts. There is nothing to sign up for.
  • No cookies, no local storage, no tracking pixels set by us.
  • No analytics. We do not measure, profile, or A/B test you.
  • No advertising, no data sales, no data sharing for marketing.
  • Our hosting provider keeps standard server logs, and your browser fetches fonts from Google. Both are explained below.

Contents

  1. Who is responsible
  2. What this policy covers
  3. What we process, and why
  4. Cookies and local storage
  5. Recipients and processors
  6. Transfers outside the EU/EEA
  7. How long data is kept
  8. Your rights under the GDPR
  9. Security
  10. Children
  11. Changes to this policy
  12. Contact

1. Who is responsible

The controller for the processing described here, within the meaning of Article 4(7) of the General Data Protection Regulation (GDPR), is:

Nikapps

Email: hossein@moradgholi.com

Website: nik.app

We have not appointed a Data Protection Officer, as we are not required to under Article 37 GDPR. Data protection questions go to the address above.

2. What this policy covers

This policy applies to the nik.app website and its blog, and to email you send us.

It does not cover our mobile apps or their websites. Each app is a separate product with its own privacy policy — for example, Placetory is covered by the policy at placetory.ai/privacy. Downloads through the Apple App Store or Google Play are additionally subject to those stores' own privacy terms, which we do not control.

3. What we process, and why

We do not ask you for any personal data on this website. There is no form, no login, no newsletter signup. The processing below happens as a technical consequence of loading a web page.

Server log data

The site is hosted on Cloudflare's network. When your browser requests a page, the hosting infrastructure automatically records standard connection data: your IP address, the requested URL, the date and time, the HTTP status, the amount of data transferred, the referring page, and your browser's user agent string.

These logs exist to deliver the site, to keep it available, and to detect and defend against attacks and abuse. We do not use them to build profiles, and we do not combine them with other data.

Legal basis
Article 6(1)(f) GDPR — our legitimate interest in a functioning, secure website.
Processor
Cloudflare, Inc. and Cloudflare Germany GmbH, under a data processing agreement pursuant to Article 28 GDPR.

Web fonts from Google Fonts

The site uses the typefaces Space Grotesk and Space Mono, loaded by your browser from Google's font servers (fonts.googleapis.com and fonts.gstatic.com). To fetch them, your browser connects to Google, which means your IP address and user agent are transmitted to Google. Google states it does not set cookies for font requests and does not use them for advertising.

This request happens as the page loads, before you can interact with it. If you would rather not connect to Google at all, a content blocker or a browser configured to block third-party requests will prevent it; the site remains fully readable in a fallback system font.

Legal basis
Article 6(1)(f) GDPR — our legitimate interest in a consistent, legible presentation of the site.
Recipient
Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, and Google LLC (USA).

Embedded videos on blog posts

Some blog posts may embed a YouTube video. We use a two-step embed: the page first shows only a preview image, which is loaded from Google's image servers (i.ytimg.com). No YouTube player and no YouTube cookies load until you click play.

When you do click play, an iframe from youtube-nocookie.com loads and YouTube receives your IP address, the page you are on, and — if you are signed in to Google — potentially your account information. From that point, Google's own privacy policy governs the processing.

Legal basis
Article 6(1)(f) GDPR for the preview image; Article 6(1)(a) GDPR (your consent, given by clicking play) for the player itself.
Recipient
Google Ireland Limited and Google LLC (USA).

Email you send us

If you email us, we process your address, your name if you give it, and whatever you write, for the sole purpose of answering you.

Legal basis
Article 6(1)(b) GDPR where your message concerns a contract or pre-contractual steps; otherwise Article 6(1)(f) GDPR — our legitimate interest in responding to enquiries.

Outbound links

Links to Placetory, X, LinkedIn, or any other site are ordinary links. Nothing is transmitted to those services until you actually click through, at which point their own privacy policies apply.

4. Cookies and local storage

This website sets no cookies. It writes nothing to local storage or session storage, uses no fingerprinting, and runs no analytics or advertising scripts. That is why you do not see a cookie banner here — there is nothing to consent to.

Cloudflare may set a strictly necessary security cookie in the course of mitigating an attack. Such a cookie is used only to distinguish legitimate visitors from automated traffic and carries no tracking function.

5. Recipients and processors

Personal data is disclosed only to the parties named above, and only to the extent described:

  • Cloudflare — hosting and content delivery, acting as our processor under Article 28 GDPR.
  • Google — font delivery, and video delivery if you press play, acting as an independent controller for that data.
  • Our email provider — for messages you send us.

We do not sell personal data and we do not share it for advertising purposes. Disclosure to public authorities occurs only where we are legally obliged to make it.

6. Transfers outside the EU/EEA

Cloudflare and Google are US-based companies, so processing may involve a transfer of data to the United States. Both are certified under the EU–US Data Privacy Framework, which the European Commission recognised as providing an adequate level of protection in its adequacy decision of 10 July 2023, and both additionally rely on the EU Standard Contractual Clauses. You have the right to request a copy of the relevant safeguards from us.

7. How long data is kept

  • Server logs: retained for a short period for security and diagnostics — generally no longer than 30 days — then deleted or aggregated beyond recognition, unless a specific incident requires us to keep a record longer.
  • Email: kept for as long as needed to deal with your enquiry, and afterwards only where statutory retention obligations under German commercial and tax law require it.

8. Your rights under the GDPR

Where we process your personal data, you have the following rights:

  • Access (Article 15) — to know whether and what data we process about you, and to receive a copy.
  • Rectification (Article 16) — to have inaccurate data corrected.
  • Erasure (Article 17) — to have data deleted, where no legal ground requires us to keep it.
  • Restriction (Article 18) — to have processing limited in the cases the law provides for.
  • Data portability (Article 20) — to receive data you provided in a structured, machine-readable format.
  • Objection (Article 21) — to object at any time, on grounds relating to your particular situation, to processing based on legitimate interests. We will then stop unless we can demonstrate compelling legitimate grounds that override your interests.
  • Withdrawal of consent (Article 7(3)) — where processing rests on consent, you may withdraw it at any time, without affecting the lawfulness of processing carried out beforehand.

To exercise any of these, write to hossein@moradgholi.com. Exercising them is free of charge.

You also have the right to lodge a complaint with a supervisory authority under Article 77 GDPR — in particular in the EU member state of your residence, your workplace, or the place of the alleged infringement.

9. Security

The site is served exclusively over HTTPS (TLS), so traffic between your browser and the server is encrypted in transit. We keep the site's dependencies current and hold the amount of data involved to the minimum the web requires. No system on the internet is perfectly secure, and we make no claim otherwise.

10. Children

This website is not directed at children and knowingly collects no data from them. If you believe a child has sent us personal data, contact us and we will delete it.

11. Changes to this policy

We will update this policy when the site changes — for instance if we ever add analytics or self-host our fonts. The current version always lives at this address, and the "last updated" date at the top tells you when it last moved. Continued use of the site after a change means the revised policy applies.

12. Contact

Questions about this policy, or about your data:

Nikapps

Email: hossein@moradgholi.com

See also our Terms of Service.

nik.app
Privacy Terms
© 2026 Nikapps