Privacy
Privacy Policy
How the Nimayu desktop application and Nimayu-operated services handle data.
Effective date: 14 August 2026.
Who operates Nimayu
Nimayu is currently operated by Javier Cuenca Perez, an individual in Spain. Privacy and support requests can be sent to support@nimayu.com. Relevant Nimayu infrastructure is hosted with OVHcloud in Gravelines (GRA), France.
Data stored on your PC
Nimayu stores settings, installed companions, encrypted OAuth sessions, sanitized local logs, runtime state, and diagnostic packages under the legacy-compatible %APPDATA%\AniMates directory. Provider credentials are kept in the encrypted credential store. Uninstall keeps this directory by default; explicit complete removal deletes data for the current user.
Streaming providers
Twitch
When explicitly connected, Nimayu uses Twitch OAuth and direct Twitch API/EventSub connections. Access and refresh tokens, required identity information, and granted scopes are stored locally in encrypted form.
Google and YouTube
Nimayu uses OAuth, state, PKCE S256, and a local callback. The Nimayu YouTube Token Broker temporarily processes the minimum exchange and refresh data required to communicate with Google; it does not persist codes, verifiers, or tokens. Tokens and the broker grant remain encrypted on the PC.
Kick
Nimayu uses OAuth with PKCE and the Nimayu Kick Relay for operations and webhooks that require server-side credentials. The relay retains only the information needed for sessions and subscriptions; pending payloads are encrypted until acknowledgement and subject to TTL and deduplication.
Disconnecting a provider removes its local credentials. Users may also revoke access through that provider's account controls. Twitch, Google/YouTube, Kick, and future Valve/Steam services operate their own infrastructure and policies; they are not represented as processing data only in France.
Marketplace Community
Marketplace Community processes server-resolved identity and community activity such as likes and associated download records. PostgreSQL persists community records; Redis is ephemeral. Rate-limit identifiers, including IP-derived identifiers where applicable, are protected with HMAC.
The authenticated DELETE /v1/me/community-data operation removes associated likes and downloads transactionally and idempotently, and removes an empty Community user. A separate HMAC-protected deletion ledger preserves minimum deletion evidence for at most 93 days so deletions can be reapplied after a backup restore.
Retention and diagnostics
Marketplace operational logs are sanitized and retained for no more than 14 days. PostgreSQL backups follow 7 daily, 4 weekly, and monthly retention up to 93 days. Diagnostic packages are created locally only when requested by the user, contain sanitized evidence, and are never uploaded automatically. Nimayu has no automatic telemetry.
Steam
Steam Identity is not currently enabled. The technical foundation exists, but identity, ownership, or purchase processing will be documented before activation.
Security, rights, and children
Nimayu separates server secrets from the public client, uses HTTPS for public services, encrypts local credentials, limits ephemeral state, and sanitizes logs. Requests for access or deletion can be initiated at support@nimayu.com and will be answered within periods required by applicable law. Verification will not request passwords, tokens, client secrets, or rely on a user-supplied account identifier as the only identity proof.
The minimum age to use Nimayu is 13. Nimayu is not directed to children under 13. This is not a PEGI, ESRB, or Steam rating.
Policy changes
The current version and its update date will be published at https://nimayu.com/privacy.
