01 Introduction
NURSOVA LLC (“NURSOVA,” “we,” “us,” or “our”), a limited liability company registered in Wyoming, USA, develops SovaSpace, a local-first, client-side encrypted application for notes, documents, reading and media. This Privacy Policy applies to the SovaSpace applications, SovaSpace account services, nursova.com pages that describe or support SovaSpace, and related support communications (collectively, the “Service”).
This Privacy Policy describes how we collect, use, store and protect information when you use SovaSpace.
The short version: supported user content is encrypted on an authorized device before cloud storage. Encrypted Entries and attachments are stored locally and in SovaSpace-created locations in your Google Drive. NURSOVA’s service infrastructure is not designed to receive plaintext Entry bodies or attachment bytes, but NURSOVA and its providers still process the limited account, device, transaction and operational metadata described below.
02 Information We Collect
Account information: SovaSpace uses Google identity for account creation and sign-in. We process the Google email address, provider account identifier, and profile name or image when supplied and used by the sign-in flow. NURSOVA does not ask for or store your Google password.
Encrypted content: Entries, titles, tags, documents, images, audio, video, attachments and supported sidecars are encrypted on the device before persistent cloud storage. The encrypted cloud objects are stored in your Google Drive; NURSOVA does not operate a plaintext content repository for them.
Sync metadata: To coordinate cross-device state, we process limited control metadata such as opaque Entry or object identifiers, sync versions or cursors, operation identifiers, timestamps, approximate sizes, counts and completion states. This control plane is not designed to receive plaintext Entry bodies, titles, tags, raw source URLs, subtitle text, annotation text or media bytes.
Device notification token: On Android, if push messaging is enabled and supported, the device’s Firebase Cloud Messaging token is sent to Google Firebase and stored with the relevant SovaSpace device/session record so service and session notifications can be delivered. The token does not contain note or attachment content.
Device information: We process a SovaSpace device identifier, device display name, platform, application version, trusted-device state, active-session state and related authentication or revocation events for device management and the current single-active-device policy.
Subscription and transaction information: Depending on purchase channel, we process plan and product identifiers, purchase token or order reference, entitlement status, transaction dates, renewal, expiration or refund state, and the currency or amount reported by the provider. NURSOVA does not need your full payment-card number.
Technical and support information: Standard service and website records can include IP address, request time, route or response status, user agent, limited error categories, and information you deliberately provide in a support, billing, privacy or security request.
We do not add third-party behavioral advertising to SovaSpace, sell private user content, or use private user content to train a NURSOVA generative model.
03 How We Use Your Information
We use the information described above only as reasonably necessary to provide and secure SovaSpace: authenticate accounts and devices; apply trusted-device and session rules; coordinate sync; store encrypted objects in the user’s Google Drive; verify trials, purchases and entitlements; deliver requested notifications; diagnose errors and abuse; respond to support, deletion and rights requests; meet accounting or legal duties; and communicate service or security information.
We do not use private user content for advertising, marketing profiles or sale to data brokers.
04 End-to-End Encryption Architecture
SovaSpace is designed so supported user content is encrypted on the device before persistent cloud storage. Current persistent formats use authenticated encryption, and content, attachments and supported sidecars remain encrypted when stored in SovaSpace-created Google Drive locations.
NURSOVA’s service infrastructure is not designed to receive the cryptographic material required to decrypt plaintext user content. Authorized endpoints and valid recovery material remain security-critical. Encryption does not hide every fact: providers can still observe account activity, object existence, approximate size, timing, quota activity and other operational metadata, and an unlocked or compromised device can expose content while it is being used.
A valid legal request directed to NURSOVA may require disclosure of account, device, transaction or operational information that NURSOVA actually possesses. It does not make NURSOVA able to supply plaintext content that its systems do not hold.
05 Google Drive — Encrypted Storage & Backup
How SovaSpace uses your Google Drive: SovaSpace requests Google Drive access for SovaSpace-created data. Depending on the current platform and feature, this includes the private Drive AppData area and visible Nursova/ storage created by SovaSpace.
Drive AppData: SovaSpace can store recovery-supporting key or configuration material, encrypted data-key envelopes, routing maps and other application data required for authorized restore and cross-device operation.
Nursova storage: SovaSpace stores encrypted Entries, attachments, media, subtitles, annotations, reading data and related encrypted objects using opaque application-controlled names and locations.
SovaSpace does not request general permission to browse unrelated Drive files and does not intentionally read files it did not create through its approved Drive scopes. NURSOVA’s control service does not keep plaintext copies of Drive content. Google can still observe provider metadata such as object existence, approximate size, timing, folder structure and quota use.
You can revoke SovaSpace’s Google access through Google Account permissions. Revocation disables Drive-dependent sync, storage and recovery operations and does not itself erase every local or Drive copy.
06 Data Sharing and Third Parties
We do not sell your personal information to advertisers or data brokers. We use the following providers only for their relevant roles:
- Cloudflare: website delivery, network security and NURSOVA’s account, device, subscription and sync-control infrastructure. This infrastructure processes limited metadata and approved control data; it is not the persistent plaintext Entry or attachment store.
- Google: Google identity and OAuth, Google Drive encrypted storage, and Firebase Cloud Messaging on Android where enabled.
- App stores and payment providers: the applicable store, or Paddle.com Market Limited for direct checkout on this site, processes purchase, tax, fraud, refund and entitlement records for the selected channel.
- Email delivery: Resend or another identified transactional provider can process the destination address and message-routing information needed to deliver account, service or support email.
- Legal and professional recipients: we may disclose information we possess when reasonably necessary to comply with valid legal process, protect users or the Service, obtain professional advice, or complete a lawful corporate transaction.
These providers operate under their own privacy notices and can process limited data for security, fraud prevention and legal obligations.
07 Data Retention and Deletion
Account, device, entitlement and operational records are retained while the account or associated service obligation is active and afterward only as reasonably necessary to complete deletion, prevent fraud, secure the Service, resolve disputes, keep required transaction records and comply with law. Support correspondence is retained while resolving the request and as needed to maintain an accurate support or legal record.
Encrypted user objects remain locally and in the connected Google Drive until removed through SovaSpace, deleted by the account owner or provider, or processed through final account deletion. An Entry placed in SovaSpace Trash is normally retained for 30 days before its permanent-cleanup workflow; this is not a guarantee against every form of provider, device or user deletion.
You may initiate account deletion inside SovaSpace or through the SovaSpace account-deletion page. If a grace period is selected, deletion is scheduled and can be cancelled before the displayed deadline; the account is not represented as already erased during that period. When final deletion succeeds, SovaSpace attempts to remove its normal Drive storage and AppData, NURSOVA account records, local account data on the deleting installation and stored credentials. User-created exports, Cold Backup packages, protected recovery folders and independently copied encrypted mirrors are not automatically deleted and must be removed separately by their holder.
Limited transaction, security, fraud-prevention or legal records can remain for the period required for that purpose. External provider backups and security logs roll off under the provider’s retention process.
08 Your Rights
Depending on your jurisdiction, you may have rights to request access, correction, deletion, restriction, objection or portability for personal data NURSOVA controls. You can also decline optional permissions, revoke Google access, manage notifications in operating-system settings, export supported content, delete Entries, request account deletion and cancel future subscription renewal.
To exercise a privacy right, contact legal@nursova.com. We may need to verify control of the account. Do not send a Google password, Secret Space credential, recovery key or full payment-card number. Some requests are subject to lawful exceptions.
09 Children’s Privacy
SovaSpace is not directed to children under 13. We do not knowingly solicit personal information from a child where parental consent is required. A parent or guardian who believes a child supplied information without valid authorization should contact us for review and deletion.
10 Security
We use client-side authenticated encryption for supported user content, encrypted transport, access controls, protected credentials and service-level security controls appropriate to the data and threat model. No software, endpoint, cloud provider or transmission method can guarantee absolute security or permanent availability.
Users remain responsible for protecting their device, operating-system account, Google account, Secret Space credentials, recovery material, plaintext exports and user-managed backups. If a security incident affects personal data for which notice is legally required, we will provide the required notice.
11 Changes to This Policy
We may update this Privacy Policy to reflect changes in SovaSpace, providers, security practices or law. The “Last updated” date will change. We will provide additional notice of a material change when required by applicable law.
12 Contact Us
NURSOVA LLC
30 N Gould St Ste N
Sheridan, WY 82801, USA
Wyoming Reg. No. 2026-001978913
+1 (508) 499-8816
Privacy and legal inquiries: legal@nursova.com
Product support: support@nursova.com
Security reports: security@nursova.com