As of: 4 October 2026
This is a courtesy translation. In case of doubt, the German version prevails.
This policy applies to Nema Crew with the apps for Mac and iPhone, the website crew.nema.im, the programming interfaces (API) of the Nema Services and the technical addresses under workspace.nema.im, which today only redirect to crew.nema.im or complete sign-ins, invitations and payments. A separate privacy policy at nema.im/legal/privacy applies to the website nema.im.
1. Controller
Leonardo Antonio Carta (sole proprietor)
c/o Emperon Studio GmbH
Sachsenring 51a
50677 Cologne, Germany
Email: leonardo@nema.im
Phone: +49 221 27645575
We have not appointed a data protection officer. The contact person for data protection is Leonardo Antonio Carta at the email address above.
2. Who is responsible for which data
That depends on how you use the Nema Services:
- As a private individual or in your personal area, we are responsible for the processing of your data. This policy describes what we do.
- In an organisation that a business uses for its work, the organisation is responsible for the content of that organisation — channels, agents, emails, data from connected services. We process this content only on its behalf and according to its instructions (Data Processing Agreement, crew.nema.im/legal/dpa). Please contact the organisation first with questions about this content.
- We are in any case responsible for your account, sign-in, billing and the security of our systems.
- If you use the Claude Code or Codex runtimes, Anthropic or OpenAI process your requests under their own responsibility (Section 6.4).
3. Account and registration
Account: We process your name, email address, your password (only as a bcrypt hash, not in plain text), language setting, time of registration and your roles in organisations.
Minimum age: At registration, you confirm that you are at least 18 years old; we store the time.
Consent to the Terms: At registration, we store which version of the Terms you agreed to, with time, language, IP address and browser or app identifier (user agent). We merely point you to this Privacy Policy at that point; it does not require consent (Section 21).
Confirmation of the email address: After registration, we send you a six-digit code and a link. Both are valid for 24 hours; we store them only as a check value (hash), count failed attempts and sends to prevent misuse, and store the time of confirmation. Until confirmation, agents do not start runs and you cannot place paid orders.
Purpose: Provision of the account, sign-in, proof of consent.
Legal basis: Art. 6(1)(b) GDPR; for proof of consent, Art. 6(1)(f) GDPR (our legitimate interest in being able to prove the conclusion of the contract and the applicable terms).
4. Content in the Nema Services
We store what you and your agents write and generate: chats, messages in channels, direct messages and threads, instructions and settings of your agents, memories and knowledge entries, uploaded files and attachments (in our database), previews and the steps of an agent run (which tool was called with which result).
For searching memories and knowledge, we create numerical vectors from your content. This is done on our own servers with a locally operated model; nothing goes to third parties for this.
Purpose: Provision of the service, in particular so that your agents remember earlier conversations and decisions.
Legal basis: Art. 6(1)(b) GDPR; in organisations we process the content on their behalf (Section 2).
Content often contains personal data of third parties — such as names of customers in an email. We process this data on your behalf or, in the personal area, on the basis of our legitimate interest in providing you with the service you requested (Art. 6(1)(f) GDPR). You check whether you may entrust this data to the Nema Services.
5. How agents work
Agents are triggered by a schedule, events from connected services (webhooks), regular queries of these services, incoming emails or a message from a human or another agent. In each run, we process the triggering event, the history needed for the task and the results of the tools called.
We store the steps of a run for 7 days in a cache so that you can follow what an agent did. Up to 50 steps of a run are additionally stored with the agent's response; they and the other messages an agent writes remain stored like other content (Section 17).
If an agent of the Nema runtime searches the web, the search term goes from our server to a search engine; your IP address is not transmitted. If an agent retrieves a website, its operator receives the request from our server.
Agents make no decisions within the meaning of Art. 22 GDPR about you that produce legal effects concerning you. Whether you yourself use agents for decisions about others is your responsibility (Terms Annex 2).
Emails that an agent sends via its mailbox always carry a notice that they were created with the help of AI (Terms Section 3.8).
6. Runtimes: where your content goes for processing
For a language model to respond, it must read the request. What is sent is the conversation context, not just the last message: what is at the beginning of a conversation is sent again with further requests, as are results of tools and content from connected services, insofar as the task needs them.
6.1 Nema runtime
The request goes to an intermediary service for model interfaces and from there to the operator of a language model. These are two recipients. We ourselves specify which operators may handle a request: with every request we give the intermediary service a fixed list of operators for the respective model, prohibit it from falling back to other operators, and allow only operators that the intermediary service lists as not storing requests (zero data retention). If none of the specified operators is available, the request fails instead of going to another operator. Who the operators are and where they process is stated in the list of providers (Section 15).
Images and videos that are to be viewed — including screenshots of your Mac — go the same way to the operator of a model for image analysis.
If your organisation has switched on pseudonymisation, terms are replaced before sending (Section 7). Otherwise the content is transmitted unchanged.
Legal basis: Art. 6(1)(b) GDPR. The intermediary service and operators process the content on our behalf (Art. 28 GDPR): with the intermediary service, its data processing agreement applies, which is part of its terms of service; it uses the operators as its sub-processors. On the transfer to the USA see Section 16.
6.2 Claude Code runtime with your own Claude subscription
You sign in with your own account at Anthropic. The sign-in token is stored in a container on our server assigned only to you; in our database we store only whether the connection exists, the email address and the type of subscription. Model calls go via a proxy of our own on our server to Anthropic (USA); in doing so — if pseudonymisation is switched on — terms are replaced (Section 7). The sign-in itself takes place directly between you and Anthropic.
6.3 Codex runtime with your own ChatGPT subscription
You sign in with your own account at OpenAI (sign-in via a device code). The credentials are stored in a container on our server assigned only to you. Model calls go via a proxy of our own on our server to OpenAI (USA). The following do not run via this proxy and therefore without pseudonymisation: sign-in and renewal of the credentials, and auxiliary calls by Codex to OpenAI (for example regarding account and settings).
6.4 What applies to both own subscriptions
Anthropic and OpenAI are not our processors here. They process your requests on the basis of your own contract with them and under their own responsibility; whether they store your requests or use them for their models is governed by that contract and your settings there. We transmit the content because you have chosen this runtime.
In organisations, these runtimes are available only once an Admin or Owner has confirmed once that the organisation bears responsibility for the processing by the respective provider. The organisation thereby decides, as controller, that content of the organisation may go to these providers under a member's own subscription; we transmit it on this instruction. We store who gave the confirmation and when. If it is withdrawn, agents with these runtimes no longer start a new run in the organisation. We do not check which account a member uses to sign in with the provider.
Legal basis: Art. 6(1)(b) GDPR (execution of the runtime you have chosen); in organisations, the organisation's instruction (Art. 28(3)(a), Art. 29 GDPR).
7. Pseudonymisation and field masks
7.1 Pseudonymisation
Admins and Owners of an organisation can switch on pseudonymisation and maintain a list of terms — persons, companies, customers, products, places. In the messages of a conversation that go to a language model, each term on this list is replaced by a placeholder, such as PER_k3x9, and the response is translated back. Pseudonymisation is switched off until the organisation switches it on, and does not apply to personal areas without an organisation.
So that the back-translation works, we store a mapping of placeholder to term — in the Nema runtime per conversation, for Claude Code and Codex per member and organisation. The terms in it are encrypted. The mapping is deleted together with the conversation, the account or the organisation; for Claude Code and Codex it exists until the account or the organisation is deleted. We store the list of terms itself unencrypted.
Where it does not apply — and you should know this before relying on it:
- Only what is literally on the list is replaced. Names not on the list go out unchanged.
- Images, files, screenshots go to the model unchanged.
- Input to your own MCP servers and other tools outside the Nema Services goes out in plain text — the tool is supposed to work with the real terms.
- Codex: see Section 6.3.
- Nema runtime — what is not replaced: When a long conversation is summarised, the summarised part and the summary go to the model unchanged. Likewise unchanged are an agent's instructions, the inputs with which an agent calls tools, summaries of incoming events and the creation of task titles. Web search terms go to the search engine with the real terms.
- Nema runtime — in the event of a technical error in pseudonymisation, the request goes to the model without (complete) replacement; the same applies when memories are derived from conversations. With Claude Code and Codex, the request is aborted in this case.
- A language model can infer a person from the context even if their name has been replaced. Pseudonymised data remains personal data.
7.2 Field masks
Independently of pseudonymisation, Admins can hide individual fields of events from modules or replace them with an identifier before an agent sees them — such as the sender address or phone number of an email. The identifier is formed with a secret key from the field value and the organisation; it cannot be reversed without this key. Field masks apply to webhooks, regular queries and incoming emails, not to your own MCP servers. No masks are set by default.
Legal basis for both: Art. 6(1)(b) GDPR; Art. 25, 32 GDPR.
8. Workshop, previews and SSH keys
Workshop: In the plans that include it, there are isolated environments (containers) with data storage on our server, in which agents edit files and run commands. They hold the files that you or agents create or upload, and the logs of the commands. Each person has a personal workshop and, in each organisation, a separate workshop for that organisation; an agent sees only the workshop of its context. The histories of Claude Code and Codex are also separated by context; the sign-in with Anthropic or OpenAI applies to you as a person. The organisation is responsible for the data in an organisation's workshop (Section 2). If you leave an organisation, your workshop there is paused and deleted after 30 days; it does not pass into your personal workshop, and after leaving you no longer receive its archive — only the organisation does. A container that has not been used for 7 days is removed; the data storage remains.
Previews: Previews are initially visible only to you and the members of the agent's organisation. Via a share link, anyone who knows it can access it without signing in until it expires (1 hour, 24 hours or 7 days) or you revoke it. A server running in the workshop is, for technical reasons, also reachable at an address containing a randomly generated key that cannot be guessed; anyone who knows this address can access it without signing in. What you make accessible via a preview can be read by third parties. When a preview is accessed, we process the data of the request (Section 13.1) and the time of the last access in order to stop unused previews (servers after 2 hours, static files after 30 days).
SSH keys: For each agent we can generate a key pair so that it can access your repositories via Git. We store the private key encrypted in our database. For a run, we place it in the workshop in a directory created only for that run and readable only by the agent; after the run it is overwritten and deleted. In addition, each workshop generates its own key pair on first start, whose private key lies unencrypted in the workshop's data storage until the workshop is deleted.
Legal basis: Art. 6(1)(b) GDPR.
9. Operating your Mac
If you switch it on in the Nema Crew app for Mac and enable it for an agent, the agent can take screenshots, read windows and controls and — at the "Operate" level — use the mouse, keyboard, files and command line of your Mac.
- Screenshots go to our server and to the language model of the respective runtime, without pseudonymisation. Everything currently visible on the screen — including messages from other people, notifications, passwords in plain text — is then seen by the model.
- Output of commands and files read also go to the model.
- The app stores a log of actions only on your Mac.
Close confidential windows before you let an agent view your screen.
Legal basis: Art. 6(1)(b) GDPR. For data of third parties on your screen: Art. 6(1)(f) GDPR, limited to the task you initiated.
10. Mailbox for agents
If you store the credentials of an email mailbox (IMAP/SMTP) for an agent, we store them encrypted. The agent retrieves new emails about every minute; we process their content, sender and recipients so that the agent can respond to them. By default, the agent creates replies as a draft for approval; only after your approval do we send them via your mail server. Sent emails always carry a notice that they were created with the help of AI.
The senders of such emails are mostly third parties. For them: your email is read and answered by an AI agent on behalf of the mailbox owner. This information under Art. 13, 14 GDPR is generally owed to the senders by the mailbox owner as controller.
Legal basis: Art. 6(1)(b) GDPR; for the senders' data Art. 6(1)(f) GDPR (handling their request on behalf of the mailbox owner) or data processing on behalf (Section 2).
11. Modules, connected accounts and your own MCP servers
Modules: If you connect an account with a service — such as GitHub, GitLab, Slack, Microsoft Teams, Notion, Gmail, Outlook, Google Calendar, Microsoft Calendar, Google Drive, Salesforce, App Store Connect, Sentry, Freshdesk or DHL —, we store the credentials (OAuth tokens, keys) encrypted and exchange with the service the data needed for the task, reading and, if you set it up that way, writing. We receive events from the service via webhooks or query them regularly.
The services are not our processors. They act on the basis of your contract with them; their privacy policies apply. You can disconnect any connection at any time.
Your own MCP servers: If you connect your own MCP server, we store its credentials encrypted. What an agent sends to the server goes there in plain text. We do not know who operates the server or what it does with the data.
Legal basis: Art. 6(1)(b) GDPR (execution of the connection you set up).
12. Notifications, voice and communication
- Email (registration, password, invitations, notices about the contract): sent via a mail server we operate on our own server.
- Push notifications to the iPhone: For a direct message from an agent or when you are mentioned, a notification goes to your device via the Apple Push Notification Service. It contains the name of the agent, where applicable the channel and the first 180 characters of the message; for an email draft, recipient and subject. Apple receives this text in order to deliver it. You can switch off notifications in your iPhone settings. We delete delivery jobs 14 days after sending.
- Mac app: The app generates notices itself on your Mac; nothing goes to Apple for this.
- Speech output and speech recognition: If you have a response read aloud or we convert a voice recording into text, this happens on our own server; nothing goes to third parties for this.
- Dictation in web and app via the speech recognition of your browser or operating system: what happens there is determined by its manufacturer.
- Messengers: A connection to messenger services is not currently active. If we switch such a connection on, we will update this policy beforehand.
Legal basis: Art. 6(1)(b) GDPR.
13. Websites and apps
13.1 Access
When crew.nema.im, workspace.nema.im, previews and our interfaces are accessed, our server processes, as technically necessary, the IP address, time, requested address, browser and operating system. We keep these server logs for no longer than 14 days.
Legal basis: Art. 6(1)(f) GDPR (secure and stable operation).
13.2 Cookies and local storage
We use technically necessary cookies and entries in local storage: for your sign-in, your language (cookie NEXT_LOCALE, one year) and your settings in the interface (such as light/dark and colour palette). To open private previews, we set an access cookie on the preview's address (12 hours; for share links until they expire).
Legal basis: Section 25(2) no. 2 TDDDG; Art. 6(1)(b) GDPR.
13.3 Reach measurement
We measure the use of crew.nema.im with Umami, software that we operate ourselves on our server (analytics.nema.im). Umami does not set cookies. It records the page accessed, referrer, approximate origin, device type, browser and screen size. We do not create a cross-device profile; no data goes to third parties in the process.
Legal basis: Art. 6(1)(f) GDPR (reach measurement).
The apps for Mac and iPhone contain no analytics or crash reporting services.
We do not use third-party tracking services — such as Google Analytics, Meta Pixel or advertising networks.
14. Payment
Before your first order, the app asks for your billing details: country, private or business, name or company, address and, where applicable, your VAT or tax identification number. We store them with the payment service provider in your customer account, together with the resulting tax treatment. If you, as a business in another EU state, provide a VAT ID, we check it with the European Commission's confirmation procedure (VIES); the number and our own VAT ID go there, and validity, where applicable name and address, and a request number come back, which we store as evidence.
For paid plans, add-on packages and credit packages we use a payment service provider. There you enter your payment data; card numbers do not reach our servers. We receive a customer ID, the plan and the payment status. In organisations, Admins and Owners book.
Orders, withdrawal and cancellation: For each order we store the order number, content, price and your consents with wording and time (Terms, for consumers early commencement) and send you the confirmation by email. We store withdrawals and cancellations — also via the pages crew.nema.im/legal/withdraw and crew.nema.im/legal/cancel without signing in — with their content, the contact details provided and the time of receipt, and confirm them by email. We keep this information as long as claims under the contract are possible and, as business letters or accounting records, for the statutory periods (Section 17.4).
Legal basis: Art. 6(1)(b) GDPR; for invoices, VAT and retention Art. 6(1)(c) GDPR.
15. Recipients — by category
We pass on data only to service providers we need for the service, and only for the stated purpose. We do not sell data.
We name categories here, not company names, because providers change — a model is discontinued, a better one comes along, a provider changes its terms. Which provider specifically stands behind which category, with its seat, place of processing and basis for any third-country transfer, is stated in the continuously maintained list of providers at crew.nema.im/legal/subprocessors. We announce a change of provider, or a new provider, that processes your content at least 30 days in advance (Terms Section 3.14).
| Category | What goes there | Role |
|---|---|---|
| Data centre operator | all data, on our own server | processor |
| Intermediary service for model interfaces | conversation context, images (Nema runtime) | processor |
| Operators of language models, specified by us per request | conversation context (Nema runtime) | sub-processor of the intermediary service |
| Operator of a model for image analysis, specified by us per request | images, screenshots (Nema runtime) | sub-processor of the intermediary service |
| Payment service provider | payment, billing and tax data | processor; independent controller for its own statutory obligations |
| Apple's push service (iPhone only) | notification text | recipient under Apple's developer terms |
| Search engine (web search of the Nema runtime) | search term | independent controller |
| European Commission's VAT ID confirmation procedure (VIES) | VAT IDs of businesses in other EU states | independent controller |
| Anthropic, OpenAI (only with your own runtime) | conversation context | your contracting party, independent controller |
| Services and MCP servers connected by you | what the task needs | your contracting party, independent controller |
Authorities receive data only if we are legally obliged to provide it.
16. Transfers to countries outside the EU
Some recipients are established outside the EU and the EEA or process data there, in particular in the USA. For the USA there is an adequacy decision of the EU Commission (EU-US Data Privacy Framework); it covers a transfer only if the recipient is certified under it. Otherwise other safeguards are needed, such as standard contractual clauses of the EU Commission (Art. 46(2)(c) GDPR).
- Nema runtime: The intermediary service is established and processes in the USA and is not certified under the Data Privacy Framework. We base the transfer to it on the standard contractual clauses that are part of its data processing agreement. It passes the requests on, within the USA, to the operators of the language model for text that we have specified; it is answerable for this onward transfer under the standard contractual clauses. The model for image analysis is operated in the EU.
- Payment service provider: Our contractual partner is established in Ireland and transfers data to its parent company in the USA. That company is certified under the Data Privacy Framework; standard contractual clauses apply in addition.
- Apple's push service: Apple is not certified under the Data Privacy Framework and, by its own account, bases transfers from the EEA on standard contractual clauses.
You can obtain a copy of the standard contractual clauses we rely on by request at leonardo@nema.im.
Standard contractual clauses bind the recipient, not the authorities of its state. Where the law of the recipient state allows authorities far-reaching access, you have practically no enforceable legal remedy against it. Do not entrust to the Nema Services anything that must not fall into other hands, or switch on pseudonymisation for such terms and observe its limits.
Which provider stands behind which category, with country and basis for the transfer, is stated in the list of providers.
17. Retention period
17.1 Principle: until you delete
We store content — chats, messages, channels, attachments, memories, knowledge entries, agents — without a fixed period, until you delete it, individually or with your account. The reason is the service itself: your agents are supposed to remember what you decided months ago. A deletion period set by us would remove exactly that. Storage is therefore necessary for the performance of the contract (Art. 6(1)(b) GDPR). If you delete a memory (also with “Reset everything” in Memory), it disappears from the app and from the search index immediately; we delete the memory itself and its earlier versions permanently after 30 days at the latest.
In organisations, the organisation decides on the deletion of its content.
17.2 Switch to the Free plan
If the trial period has expired, a plan ends through cancellation or is not paid, the Free plan applies to your account or your organisation (Terms Section 4.7). Agents, channels, history and memories remain stored; agents beyond the scope of the Free plan are paused. We keep the data storage of the workshop of the affected context and the histories of Claude Code and Codex there for a further 30 days from the switch so that the files can be downloaded, send reminders 7, 3 and 1 day beforehand by email, show the remaining days in the app and delete them afterwards. If a plan is booked again within this period, everything is retained. Workshops in other contexts are not affected.
17.3 Deletion after inactivity
If you do not use an account on the Free plan for 90 days — what counts is the last use with your sign-in, not just signing in itself —, we delete the account. For this, we store the time of last use. 14 days beforehand, we write to you by email and point out the export; without this email we do not delete, and any use during this time cancels the deletion. We do not delete accounts that use a booked plan or the trial period, themselves or via an organisation, because of inactivity; their agents often work without anyone signing in.
17.4 Individual data
- Account: until the account is deleted
- Credentials of connected services, mailboxes, MCP servers: until you disconnect or delete the account
- SSH key of an agent: until the agent is deleted; the workshop's key until the workshop is deleted
- Confirmation of an organisation for Claude Code and Codex: until withdrawn or until the organisation is deleted
- Exports: the file 7 days, the information about the export (time, status) 30 days
- Steps of an agent run: 7 days in the cache; up to 50 steps with the agent's response, for as long as it exists
- Delivery jobs for push notifications: 14 days after sending
- Workshop: until you delete the files, at the latest until the account is deleted, 30 days after the respective context switches to the Free plan (Section 17.2) or — for a workshop in an organisation — 30 days after you leave
- Previews: until you delete them; share links until they expire or are revoked
- Consents to Terms: for the duration of the contract and until the limitation period for possible claims has expired
- Backups of the database: up to about 6 months (Section 17.6)
- Invoices and accounting records: 8 years, business letters 6 years, books and financial statements 10 years (Section 147 German Fiscal Code (AO), Section 257 German Commercial Code (HGB))
17.5 Deleting your account
You can delete your account at any time in the settings. The associated data is then deleted immediately, including your agents, organisations of which you are the only member, attachments, memories, credentials, the entries in the search index, all your workshops with their data storage and the containers for Claude Code and Codex. If the service for the workshop cannot be reached at that moment, we automatically catch up on its deletion. We revoke your agents' SSH keys at GitHub or GitLab. In other people's channels, your messages remain as deleted entries without content or sender. Channels that you created are deleted with all their messages — also in organisations, there including the messages of other members. We end a running subscription immediately; we keep invoices for the statutory periods (Section 17.4). Restoration is not possible. The data remains contained in our backups for up to about 6 months (Section 17.6). Export beforehand whatever you want to keep.
17.6 Backups
We back up our database — with accounts, organisations, agents, channels, messages and memories — completely every day, encrypted (AES-256), on our server and additionally on storage of Hetzner Online GmbH in data centres in the EU. We keep every backup of the last 7 days, then one per week for 4 weeks and one per month for 6 months. Data that you or we delete therefore remains contained in backups for up to about 6 months. We do not remove it there individually; it drops out as the backups expire. Until then, we use the backups only to restore operation after a failure; if we restore a backup, we delete data that had already been deleted again.
Not backed up are the workshops with their files, the histories of Claude Code and Codex, the search index and caches. You back up important files yourself via the workshop archive or the export.
Legal basis: Art. 6(1)(b) and (f) GDPR; Art. 32(1)(c) GDPR.
18. Your rights
You have the right to
- access your data (Art. 15 GDPR),
- rectification (Art. 16),
- erasure (Art. 17),
- restriction of processing (Art. 18),
- data portability (Art. 20) — in the settings you can download your data yourself as a ZIP file (JSON and attachments) and the data storage of each of your workshops as an archive; whatever is missing there you receive on request,
- object to processing based on Art. 6(1)(f) GDPR on grounds relating to your particular situation (Art. 21),
- withdraw consent with effect for the future (Art. 7(3)).
Please contact leonardo@nema.im for this. If your rights concern content of an organisation, we forward the request to the organisation.
You can lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), for example at your place of residence. The authority responsible for us is:
Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen
Kavalleriestraße 2–4, 40213 Düsseldorf, Germany
https://www.ldi.nrw.de
19. Security
We protect data, among other things, as follows:
- transmission encrypted via TLS,
- passwords only as bcrypt hashes,
- credentials of connected services, mailboxes, MCP servers and SSH keys as well as jobs in our queue encrypted (AES-GCM),
- each workshop and each own subscription in its own container,
- access to an organisation's content only for its members according to their roles.
20. Data centre
Our platform, the database, the workshops, email sending and reach measurement run on a server managed by ourselves from Hetzner Online GmbH (Germany). The server is located in the European Union. A data processing agreement under Art. 28 GDPR is in place with Hetzner. Hetzner has access to the hardware, not to your content during operation.
Legal basis: Art. 6(1)(b) and (f) GDPR.
21. Changes to this policy
We adapt this policy when our services or the legal situation change. We communicate significant changes — in particular new recipients or new purposes — by email.
A privacy policy is not a contract. It fulfils our information obligation under Art. 13 and 14 GDPR. You cannot agree to it or object to it, and your continued use is not consent. Where we need consent, we obtain it separately — individually, for a named purpose and revocable at any time.