Privacy Policy
Nekra gives the AI assistants you choose access to folders you choose. This page explains exactly what we store, what we never store, and what only passes through.
The short version. Nekra has no account name, no email address and no password for you. We never store the contents of your files — they are read on your own device and passed straight to the assistant you granted. The two exceptions are written plainly below: GitHub repositories are fetched by our server, and Mirror (which is off unless you switch it on) keeps an encrypted copy so a folder stays reachable while your Mac is off.
1. Who we are
Nekra is operated by AANQA LLC, Villa 2490, Way 8261, Ansab Heights, Muscat, Oman. For anything in this policy, contact privacy@nekra.ai.
2. What we collect
We collect as little as the product can function on. There is no sign-up form: an account is created by registering a passkey on your device.
| What | Why | Notes |
|---|---|---|
| Account identifier | To own your grants | A random ID. No name, email address or password. |
| Passkey public keys | To sign you in | Public keys and a device label only. The private key never leaves your device and we never see it. |
| Recovery codes | Last-resort account recovery | Stored only as Argon2id hashes; the codes themselves are shown once and never stored by us. |
| Folder grants | To know what you shared | Includes folder and repository names and, for cloud sources, the path or mailbox you selected. |
| Assistant connections | To enforce access | Which assistant connected, when, and which folders you granted it. |
| Activity log | So you can see every access | Includes the file paths an assistant read or wrote, the outcome and the time. Not file contents. |
| Provider credentials | To reach Dropbox, Drive, OneDrive, email | Stored only as ciphertext we cannot decrypt — see §4. |
| Mirror copies (opt-in) | Offline availability | Encrypted file copies, only for folders you explicitly mirror — see §5. |
We do not collect
- Your Apple ID password, or any provider password in a form we can read.
- Analytics, advertising identifiers, tracking pixels or third-party trackers.
- Your location, contacts list, or anything you have not shared with Nekra.
- The contents of your files — except mirrored folders, described below.
3. How your files are served
Most sources are served from your own device. When an assistant asks for a file, the request travels to your Mac, your Mac reads the file, and the content travels back to the assistant.
Being precise about "never touches our servers". That content passes through Nekra's relay in transit, over an encrypted connection, in order to reach the assistant. We do not store it, log it, or inspect it — but we will not claim it never reaches our infrastructure, because in transit it does.
Two sources work differently, by design:
- GitHub repositories are read by our server directly from GitHub, using a short-lived access token (about an hour) that we do not store. This is why GitHub folders stay reachable when your devices are off.
- Mirror folders are stored with us in encrypted form — see §5.
4. Provider logins are stored so that we cannot read them
When you connect Dropbox, Google Drive, OneDrive or an email mailbox, the credential is encrypted on your device with a key derived from your passkey, and only the resulting ciphertext is sent to us. We hold an unreadable blob. Only one of your own unlocked devices can decrypt it, which is also how the same source works across your devices.
Apple sources — Calendar, Reminders, Photos and Contacts — involve no credential at all: they are read on your device through Apple's own frameworks.
5. Mirror (optional, and the one place we hold your files)
Mirror is off by default and set per folder. If you enable it, an encrypted copy of that folder is kept on our servers so an assistant can still reach it when your devices are offline. To serve it while you are away, our server decrypts that copy. Only mirror folders you are comfortable trusting us with. Turning Mirror off deletes the stored copy.
6. Who else receives your data
- The AI assistants you connect. When you grant an assistant a folder, its provider (for example Anthropic, OpenAI, Google, xAI, Mistral or Perplexity) receives the file contents it requests. Their handling is governed by their privacy policies, not this one. Granting is per assistant and per folder, and you can revoke it at any time.
- The sources you connect. Dropbox, Google, Microsoft, GitHub or your email provider, when you authorise them.
- Our hosting. Nekra runs on servers we operate in Muscat, Oman.
We do not sell your data, share it for advertising, or use your files to train any model.
7. Retention
- Grants, connections and credentials — kept until you revoke them or delete your account.
- Activity log — kept so you can audit access, and removed with your account.
- Mirror copies — removed when you turn Mirror off for that folder, or delete the folder or your account.
- Deleting your account removes your grants, connections, credentials, activity and mirrored copies. Your own files, wherever they live, are never deleted by us.
8. Your rights
You can see what an assistant has accessed at any time in the app's Activity screen, revoke any grant or connection immediately, export a diagnostics report, and delete your account. To request a copy of your data or its deletion, contact privacy@nekra.ai. Depending on where you live you may also have rights of access, correction, portability, restriction and objection, and the right to complain to a data-protection authority.
9. Security
- Sign-in is by passkey (WebAuthn) — there is no password to leak or reuse.
- Connections use TLS; devices reach the relay over an encrypted WebSocket.
- Provider credentials are encrypted on your device before we ever see them (§4).
- Each assistant reaches only the folders you granted it; every request is checked against that grant.
- Signing out of all devices stops your devices serving within seconds. It does not revoke an assistant's own grant — disconnect the assistant to do that.
No system is perfect. If you find a security issue, please tell us at security@nekra.ai; we would rather hear it than not.
10. Children
Nekra is not intended for children under 16, and we do not knowingly collect their data.
11. Changes
If we change this policy we will update the date above, and for anything material we will say so in the app rather than expecting you to notice.