Privacy Policy

Last updated: 30 August 2026

Data controller

Nessa is operated by Clinton Ukegbu ("we", "us", "our"), a sole trader registered in England. We are the data controller for personal data processed through Nessa. For data protection enquiries, contact us at privacy@nessa-app.com.

Your records belong to you

The workplace incidents, notes, and evidence you create in Nessa are your records. We do not sell them, use them for advertising, or use them to train AI models.

Nessa processes this information only as necessary to provide the features you request, maintain the service, protect the service, and comply with our legal obligations.

You can export your records at any time and should consider keeping an independent copy of important information or evidence.

What we collect

  • Account information: your name, email address, and country when you register.
  • Profile details: nationality and job title, if you choose to provide them during onboarding.
  • Conversations: text messages you send to Nessa, including text derived from voice transcription.
  • Incident records: dates, summaries, narratives, categories, severity assessments, people involved, and other details extracted from your conversations.
  • Third-party personal data: names, roles, and actions of people you mention in your incidents (colleagues, managers, witnesses). This data is stored as part of your records.
  • Evidence files: photos, screenshots, or documents you upload as supporting evidence.
  • Community posts: content you choose to share in the community feature, visible to other users.
  • Payment data: subscription and billing information is processed by Stripe. We do not store your card details.
  • Usage data: anonymous analytics to help us improve the product (via PostHog). We never use your conversations or incident data for analytics.

Special category and sensitive data

When you describe workplace incidents, your conversations may contain special category data as defined under UK GDPR Article 9. This could include information relating to your racial or ethnic origin, health, religious beliefs, sexual orientation, or trade union membership.

Your conversations may also include allegations about other people, which could relate to alleged criminal conduct or other sensitive matters.

We process this data on the following bases:

  • Article 6(1)(b) — Contract: processing your conversations and storing your records is necessary to provide the service.
  • Article 9(2)(a) — Explicit consent: during onboarding, you give explicit consent for Nessa to process sensitive personal data that you voluntarily share in your conversations. You can withdraw this consent at any time through your account settings, or by deleting your data or account.
  • Article 9(2)(f) — Legal claims: processing is necessary for the establishment, exercise, or defence of legal claims. Nessa helps you create records that may be used in workplace grievances or legal proceedings.

We do not process special category data for any purpose other than providing you with the Nessa service.

Legal basis for processing

Under UK GDPR Article 6, we process your data on the following grounds:

  • Contract: processing your conversations and storing your incidents is necessary to provide the service you signed up for.
  • Consent: you choose to provide voice input, upload evidence, post in the community, and share profile details. You can withdraw consent by deleting this content or your account.
  • Legitimate interest: anonymous usage analytics help us improve the product. We ensure this does not override your privacy rights.
  • Legal obligation: we may process data where required by law, for example in response to a court order.

How we use your data

  • To provide the service: your conversations are processed by AI (Anthropic Claude) to extract incident details and provide supportive responses.
  • To store your records: incidents, evidence, and conversation history are saved so you can access them later.
  • To improve Nessa: anonymous usage analytics help us understand how the app is used. We never use your conversations or incident data for analytics.
  • To communicate with you: verification emails, account notifications, and support responses.
  • To process payments: subscription management and billing through Stripe.

AI-assisted processing

Nessa uses AI to analyse information you provide, structure incident records, categorise reported events, assess severity, identify potential patterns, and provide workplace information and guidance.

These outputs are generated automatically and may contain errors. They are intended to assist you and do not constitute a determination that a person or organisation has acted unlawfully, nor do they replace professional legal advice.

Nessa does not make employment, legal, disciplinary, or other decisions about you on behalf of an employer or other organisation.

Your conversations are sent to Anthropic's Claude API for processing. Under Anthropic's commercial API terms, your data is not used to train their models. For details on Anthropic's data handling, see Anthropic's privacy policy.

We do not use your conversations, incident records, evidence, or other personal data to train or fine-tune our own or third-party AI models.

Voice input

When you use voice input, your audio is processed to produce a text transcription. We do not retain the original audio after transcription is completed.

The resulting transcript is treated as part of your conversation data and may contain personal or sensitive information. It is stored and processed in the same way as text messages you type directly.

Who can access your data

Your data is private to your account and is not made available to other Nessa users, except where you choose to share it through the community feature or export and share it yourself.

Certain service providers process data on our behalf to operate Nessa. These processors only access your data as necessary to provide their services and are bound by data processing agreements.

We do not share, sell, or provide your personal data to any third party for marketing or advertising purposes.

Service providers (processors)

The following organisations process data on our behalf to operate Nessa:

ProviderPurposeData processed
AnthropicAI processingConversation content
NeonDatabase hostingAccount data, incident records
Cloudflare R2Evidence storageUploaded files
VercelApplication hostingApplication and request data
StripePayment processingBilling and subscription data
ResendTransactional emailEmail address, message content
PostHogProduct analyticsAnonymous usage data

International data transfers

To provide the service, your data is processed by services located outside the United Kingdom. We ensure appropriate safeguards are in place for each transfer:

  • Anthropic (United States): AI processing. Protected under their Data Processing Agreement with UK International Data Transfer Agreement / UK Addendum to EU Standard Contractual Clauses.
  • Vercel (United States): application hosting. Protected under their DPA with UK Addendum to EU Standard Contractual Clauses.
  • Neon (United States): database hosting. Protected under their DPA with UK Addendum to EU Standard Contractual Clauses.
  • Cloudflare R2 (EU region): evidence file storage. Our R2 bucket is configured in the EU jurisdiction. Protected under their DPA.
  • Stripe (United States): payment processing. Protected under their DPA with UK Addendum to EU Standard Contractual Clauses.
  • Resend (United States): transactional email. Protected under their DPA with Standard Contractual Clauses.
  • PostHog (European Union): product analytics. Our PostHog project is configured to process data within the EU.

Third-party personal data

When you document incidents, you may include names and details of other people (colleagues, managers, witnesses). This may include allegations about their conduct, which could constitute sensitive personal data about those individuals.

By entering this data, you confirm that:

  • The information is truthful and accurate to the best of your knowledge.
  • You understand this data is stored as part of your private records.
  • If you export or share your records, you are responsible for how third-party data is disclosed.

We process third-party personal data on the basis that it is necessary for the performance of our contract with you (providing the documentation service) and, where the data relates to legal claims, under Article 9(2)(f) (establishment, exercise, or defence of legal claims).

We do not notify individuals named in your incident records. If a named individual contacts us with a data subject access request, we will assess it on a case-by-case basis, balancing their rights under UK GDPR against your right to document your own workplace experiences and the potential impact on any ongoing or future legal proceedings.

Where disclosure of your records would reveal your identity or the content of your confidential workplace documentation, we may restrict or refuse the request under the exemptions available in UK data protection law.

Data retention

We retain different categories of data for different periods:

  • Account data: retained while your account is active.
  • Incident records and conversations: retained while your account is active, unless you delete them earlier.
  • Evidence files: retained while your account is active, unless you delete them earlier.
  • Community posts: deleted when you delete the post or your account.
  • Payment records: Stripe may retain billing information for legal and accounting obligations independently of your Nessa account.
  • Encrypted backups: residual copies may persist for up to 30 days after deletion before being automatically overwritten. These are encrypted and only accessed for disaster recovery.
  • AI provider: Anthropic's retention of API data is governed by their own terms and policies.

When you delete your account, we will delete your data from our active production systems, subject to limited retention in encrypted backups and any information we are required to retain by law.

Data storage and security

Your data is stored securely using industry-standard encryption. Evidence files are stored in encrypted cloud storage (Cloudflare R2). Your password is hashed using bcrypt and is never stored in plain text.

We use HTTPS for all data transmission. Access to your account is protected by your credentials and, where applicable, email verification.

Keeping your account secure

You are responsible for keeping your login credentials confidential and for notifying us at privacy@nessa-app.com if you believe your account has been accessed without authorisation. Given the sensitive nature of workplace documentation, we strongly recommend using a unique password for your Nessa account.

Your rights

Under UK GDPR and UK data protection law, you have the right to:

  • Access: request a copy of all data we hold about you.
  • Rectification: correct any inaccurate information.
  • Erasure: request deletion of your account and all associated data.
  • Portability: export your data in a structured format (Excel, PDF, or ZIP via the Export page).
  • Restriction: request we limit how we process your data.
  • Objection: object to processing of your data based on legitimate interest.
  • Withdraw consent: where processing is based on consent, you can withdraw it at any time by deleting the relevant content or your account.

To exercise any of these rights, email us at privacy@nessa-app.com. We will respond to valid data protection requests within the timeframe required by applicable data protection law, and normally within 30 days.

If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO).

Data breach notification

Where a personal data breach is likely to result in a risk to individuals' rights and freedoms, we will notify the ICO without undue delay and, where feasible, within 72 hours of becoming aware of the breach. Where the breach is likely to result in a high risk to affected individuals, we will notify those individuals without undue delay where required by law. We will explain what happened, what data was involved, and what steps we are taking.

Cookies

We use essential cookies only: a session cookie to keep you logged in. We do not use advertising or tracking cookies. PostHog analytics uses localStorage, not cookies. For full details, see our Cookie Policy.

Children

Nessa is not intended for anyone under 18. We do not knowingly collect data from minors. If you believe a minor has created an account, please contact us and we will delete it.

Changes to this policy

We may update this policy from time to time. If we make significant changes, we will notify you via the app or by email. The "last updated" date at the top of this page reflects when the policy was last revised.

Data protection registration

Nessa is registered with the Information Commissioner's Office (ICO) under registration number CSN2538921.

Contact

If you have any questions about this policy or how your data is handled, email us at privacy@nessa-app.com.