Last updated: 30 August 2026
Nessa is operated by Clinton Ukegbu ("we", "us", "our"), a sole trader registered in England. We are the data controller for personal data processed through Nessa. For data protection enquiries, contact us at privacy@nessa-app.com.
The workplace incidents, notes, and evidence you create in Nessa are your records. We do not sell them, use them for advertising, or use them to train AI models.
Nessa processes this information only as necessary to provide the features you request, maintain the service, protect the service, and comply with our legal obligations.
You can export your records at any time and should consider keeping an independent copy of important information or evidence.
When you describe workplace incidents, your conversations may contain special category data as defined under UK GDPR Article 9. This could include information relating to your racial or ethnic origin, health, religious beliefs, sexual orientation, or trade union membership.
Your conversations may also include allegations about other people, which could relate to alleged criminal conduct or other sensitive matters.
We process this data on the following bases:
We do not process special category data for any purpose other than providing you with the Nessa service.
Under UK GDPR Article 6, we process your data on the following grounds:
Nessa uses AI to analyse information you provide, structure incident records, categorise reported events, assess severity, identify potential patterns, and provide workplace information and guidance.
These outputs are generated automatically and may contain errors. They are intended to assist you and do not constitute a determination that a person or organisation has acted unlawfully, nor do they replace professional legal advice.
Nessa does not make employment, legal, disciplinary, or other decisions about you on behalf of an employer or other organisation.
Your conversations are sent to Anthropic's Claude API for processing. Under Anthropic's commercial API terms, your data is not used to train their models. For details on Anthropic's data handling, see Anthropic's privacy policy.
We do not use your conversations, incident records, evidence, or other personal data to train or fine-tune our own or third-party AI models.
When you use voice input, your audio is processed to produce a text transcription. We do not retain the original audio after transcription is completed.
The resulting transcript is treated as part of your conversation data and may contain personal or sensitive information. It is stored and processed in the same way as text messages you type directly.
Your data is private to your account and is not made available to other Nessa users, except where you choose to share it through the community feature or export and share it yourself.
Certain service providers process data on our behalf to operate Nessa. These processors only access your data as necessary to provide their services and are bound by data processing agreements.
We do not share, sell, or provide your personal data to any third party for marketing or advertising purposes.
The following organisations process data on our behalf to operate Nessa:
| Provider | Purpose | Data processed |
|---|---|---|
| Anthropic | AI processing | Conversation content |
| Neon | Database hosting | Account data, incident records |
| Cloudflare R2 | Evidence storage | Uploaded files |
| Vercel | Application hosting | Application and request data |
| Stripe | Payment processing | Billing and subscription data |
| Resend | Transactional email | Email address, message content |
| PostHog | Product analytics | Anonymous usage data |
To provide the service, your data is processed by services located outside the United Kingdom. We ensure appropriate safeguards are in place for each transfer:
When you document incidents, you may include names and details of other people (colleagues, managers, witnesses). This may include allegations about their conduct, which could constitute sensitive personal data about those individuals.
By entering this data, you confirm that:
We process third-party personal data on the basis that it is necessary for the performance of our contract with you (providing the documentation service) and, where the data relates to legal claims, under Article 9(2)(f) (establishment, exercise, or defence of legal claims).
We do not notify individuals named in your incident records. If a named individual contacts us with a data subject access request, we will assess it on a case-by-case basis, balancing their rights under UK GDPR against your right to document your own workplace experiences and the potential impact on any ongoing or future legal proceedings.
Where disclosure of your records would reveal your identity or the content of your confidential workplace documentation, we may restrict or refuse the request under the exemptions available in UK data protection law.
We retain different categories of data for different periods:
When you delete your account, we will delete your data from our active production systems, subject to limited retention in encrypted backups and any information we are required to retain by law.
Your data is stored securely using industry-standard encryption. Evidence files are stored in encrypted cloud storage (Cloudflare R2). Your password is hashed using bcrypt and is never stored in plain text.
We use HTTPS for all data transmission. Access to your account is protected by your credentials and, where applicable, email verification.
You are responsible for keeping your login credentials confidential and for notifying us at privacy@nessa-app.com if you believe your account has been accessed without authorisation. Given the sensitive nature of workplace documentation, we strongly recommend using a unique password for your Nessa account.
Under UK GDPR and UK data protection law, you have the right to:
To exercise any of these rights, email us at privacy@nessa-app.com. We will respond to valid data protection requests within the timeframe required by applicable data protection law, and normally within 30 days.
If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO).
Where a personal data breach is likely to result in a risk to individuals' rights and freedoms, we will notify the ICO without undue delay and, where feasible, within 72 hours of becoming aware of the breach. Where the breach is likely to result in a high risk to affected individuals, we will notify those individuals without undue delay where required by law. We will explain what happened, what data was involved, and what steps we are taking.
We use essential cookies only: a session cookie to keep you logged in. We do not use advertising or tracking cookies. PostHog analytics uses localStorage, not cookies. For full details, see our Cookie Policy.
Nessa is not intended for anyone under 18. We do not knowingly collect data from minors. If you believe a minor has created an account, please contact us and we will delete it.
We may update this policy from time to time. If we make significant changes, we will notify you via the app or by email. The "last updated" date at the top of this page reflects when the policy was last revised.
Nessa is registered with the Information Commissioner's Office (ICO) under registration number CSN2538921.
If you have any questions about this policy or how your data is handled, email us at privacy@nessa-app.com.
Nessa | Terms · Cookies · Refunds · Accessibility