Nedion Privacy Policy
Version: 2026-09-21
Effective: 21 September 2026
Controller / Provider: 7StockApp OÜ — a private limited company incorporated in the Republic of Estonia, registry code 16976938, registered address Harju maakond, Tallinn, Kesklinna linnaosa, Ahtri tn 12, 15551, Estonia
Contact: [email protected]
This policy explains which personal data we process, why and for how long when you use the Nedion mobile app (iOS and Android), the nedion.org website and the Nedion API (together, the "Service"). 7StockApp OÜ is an Estonian company; the framework of this policy is the EU General Data Protection Regulation (GDPR) and the Estonian Personal Data Protection Act. Our supervisory authority is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon).
1. What Nedion does
Nedion collects the public publications of official bodies, screens them with AI for importance, turns the selected ones into short news cards, translates them into Turkish, English and Spanish and publishes them. You follow the countries and topics you care about, receive notifications, comment on news and, optionally, ask an AI assistant.
2. What data we collect
You can use the app without an account; the news feed is public. In that case only the technical data in 2.1 is processed.
2.1 On every visit (including without an account)
| Data | Why | Legal basis |
|---|---|---|
| IP address, request time, page requested, app version | To provide the Service, prevent abuse, fix errors | Legitimate interest (GDPR Art. 6(1)(f)) |
| Language and content-language preference | To show news in your language | Legitimate interest |
The IP address is kept in server logs for a short period and is not used for profiling.
2.2 When you create an account
Nedion has no passwords. A one-time code is sent to your e-mail address.
| Data | Why | Legal basis |
|---|---|---|
| E-mail address | Sign-in, account recovery, confirming account deletion | Contract (GDPR Art. 6(1)(b)) |
| Sign-in codes and the device they were sent to | To verify the code came from you and to limit attempts | Contract; legitimate interest |
| Session records: device, last use | To show your open sessions and let you sign out a device remotely | Contract |
| The version of the terms you accepted and when | To prove which text you accepted | Legal obligation |
| Profile: nickname, title, avatar (optional) | Your identity as shown on comments | Contract |
| Preferences: languages, theme, time zone, quiet hours, default countries and topics | To open the app with your settings | Contract |
| Watchlists and saved filters: countries, topics, keywords | Your personalised feed and notifications | Contract |
2.3 In-app activity
| Data | Why | Legal basis |
|---|---|---|
| Comments, likes, reports | Community feature; moderation | Contract; legitimate interest |
| Push notification token, platform (iOS/Android) | To send notifications | Consent — you turn notifications on |
| Assistant conversations: your questions, the answers, the news cited in them | To show your chat history; to count your daily question allowance | Contract |
| Daily usage counters | To apply the free and Premium limits | Contract |
2.4 Premium subscription
Payment is made through the Apple App Store or Google Play. Nedion never sees your card details. What reaches us is the subscription status (active / expired / cancelled), the plan type, the renewal date and an anonymous subscriber identifier used to match the subscription to your account.
2.5 Optional: analytics and crash reports
The app sends usage statistics (Google Analytics for Firebase) and crash reports (Firebase Crashlytics) only if you allow it. Both permissions are off by default and can be withdrawn at any time in Settings → Privacy. The app works fully without them. While they are on, device model, operating system, app version, event names and crash traces are processed by Google; your e-mail is not used as the analytics identifier, and events are tied to the device, not to your account.
2.6 Data we do not collect
Location, contacts, photos, microphone, camera, advertising identifiers, cross-device tracking. Nedion has no advertising, and your data is never passed on for advertising.
3. AI and your data
- News processing (scoring, writing the card) works only on public official documents; it contains none of your personal data.
- Translation is done by a model running on our own infrastructure.
- Assistant: the question you ask and the related news summaries are sent to an AI model provider to generate the answer. Your e-mail, identity and account data are not sent. We recommend not writing personal data into the assistant.
- AI output is informational; it is not investment, legal or tax advice (see the Terms of Use).
4. How long we keep data
| Data | Period |
|---|---|
| Account, profile, preferences, watchlists | While your account is open; deleted on a deletion request |
| Sign-in codes | Invalid once used or expired (minutes); the record is deleted shortly after |
| Sessions | An expired or revoked session is deleted within 30 days at most |
| Push notification token | When you turn notifications off or the token becomes invalid |
| Notification records | 14 days after sending |
| Assistant conversations | Deleted automatically 90 days after the last message; you can delete earlier |
| Comments | Until you delete them; a deleted comment is kept briefly as a moderation record, then purged |
| Server logs (including IP) | 30 days at most |
| Record of accepted terms | 3 years after account deletion, for legal proof |
When you delete your account, your e-mail, sessions, preferences, watchlists, conversations and notification tokens are deleted and your comments are removed. Only the record required by law (the version of the terms you accepted and the date) remains.
5. Who we share data with
We do not sell, rent or give your data away for advertising. The following categories of service provider process data only for the stated purpose and on our instructions:
| Category | For | Data |
|---|---|---|
| Hosting provider (EU) | Running the servers, database and translation service | All Service data |
| CDN and security provider | Delivery of nedion.org and protection against attacks | IP and request headers on site visits |
| Apple App Store / Google Play | Subscription payment | Payment, store account — under the store's own policy |
| Subscription verification provider | Confirming subscription status to our server | Anonymous subscriber ID, subscription status |
| Google (Firebase) | Push notifications; with your consent, analytics and crash reports | Notification token; with consent, the data in 2.5 |
| AI model provider | Assistant answers | Your question and the related news text (no identity data) |
We also share the minimum necessary data where the law requires it (court order, request from a competent authority) and inform you where possible.
Transfers outside the EU. Your data is hosted inside the EU. Where a provider above processes data in the USA (subscription verification, the AI model provider, Google, the CDN provider), the transfer is made under Chapter V of the GDPR using the European Commission's standard contractual clauses and, where applicable, the EU-US Data Privacy Framework. You can ask for details of the safeguards at [email protected].
6. Cookies
The nedion.org website sets no cookies of its own. Our CDN and security provider sets strictly necessary security cookies to protect the site against bots and attacks; these need no consent. There are no advertising or analytics cookies, so there is no cookie banner. If analytics cookies are ever added, consent will be asked first.
7. Your rights
The GDPR gives you the following rights; you can exercise all of them from the app or by e-mail:
- Access and portability: Settings → Account → Download my data — you receive all data linked to your account in a machine-readable format.
- Rectification: you can change your profile and preferences in the app.
- Erasure: Settings → Account → Delete account — confirmed by a code sent to your e-mail and applied immediately.
- Objection and restriction: you can turn off analytics and crash reports and stop notifications.
- Withdrawal of consent: every permission is withdrawn where it was given.
- Complaint: Estonian Data Protection Inspectorate — Andmekaitse Inspektsioon, Tatari 39, 10134 Tallinn, [email protected], www.aki.ee — or the data protection authority of the EU country you live in.
Requests: [email protected]. Under GDPR Art. 12 we respond within one month at most; for complex requests this may be extended by two months, and we will tell you.
8. Security
All traffic is encrypted in transit. Sign-in credentials and session tokens are stored in a form that cannot be read back, on the device in its secure store and on our side as hashes. Sensitive actions such as account deletion are confirmed a second time by e-mail.
9. Children
Nedion is not designed for anyone under 16. Under GDPR Art. 8 and Estonian law, parental consent would be required for ages 13–16, and Nedion does not collect it. If we learn a user is under 16 we delete the account and its data.
10. Changes
When we change this policy we update the version number and effective date. For a change that affects your account, the app asks you to accept the new version; the version you accept is recorded.
11. Governing language
This policy is written in English. Turkish and Spanish translations are provided for convenience only; if a translation differs from the English text, the English text prevails.
12. Contact
7StockApp OÜ (registry code 16976938)
Ahtri tn 12, 15551 Tallinn, Estonia
[email protected]