Privacy policy
This policy describes what personal data we process when you use the Navamu website and the Navamu application, for what purpose, and on what legal basis.
Navamu is operated from Germany and the GDPR applies. The German version of this policy is the legally binding one; this translation is provided for convenience.
Last updated: 29 September 2026
Controller
The controller under the GDPR is:
Fabian Mürmann
Kurfürstenstr. 143
10785 Berlin
Germany
hi@nava.mu
We have not appointed a data protection officer; we are not required to.
The short version
- Board content is yours. We do not mine it, sell it, or use it to train models.
- Audience measurement runs without cookies until you allow more. We use PostHog on European servers. Until you consent, nothing is stored on or read from your device. No profiling, no ad networks.
- The servers are in Germany, operated on our behalf by a processor (see "Hosting").
Hosting and server logs
The application and this website run on a server we rent from
Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany
Hetzner acts as our processor under Art. 28 GDPR and a processing agreement is in place. The server is located in Germany.
Every page request causes the web server to record what your browser sends:
- the IP address of the requesting device
- date and time of the request
- the requested address and the HTTP status code
- the amount of data transferred
- the referrer URL
- browser type and version, and operating system
The purpose is technical operation, troubleshooting and defence against attacks. The legal basis is Art. 6 (1) (f) GDPR; our legitimate interest is the secure and uninterrupted operation of the service. This data is not combined with other sources. Log files are deleted after 30 days at the latest, unless they are needed to investigate a specific security incident.
Cookies and similar technologies
We only set cookies and storage entries that are necessary to run the service, that provide a function you asked for, or that you have explicitly allowed. There are no advertising cookies, and no analytics cookies unless you agree to them (see "Audience measurement").
better-auth.session_token— keeps you signed in. Lifetime: until the session expires or you sign out.sc_guest— recognises the same anonymous guest when they re-enter a shared board, so a single guest can be removed without revoking the link for everyone. Lifetime: limited.NEXT_LOCALE— remembers your language. Lifetime: 1 year.consent— remembers your choice in the cookie notice. Lifetime: 6 months. You can change the choice at any time via "Cookie settings" in the footer.ph_…_posthog— set by our analytics service only after you click "Allow", as a cookie and a matching local storage entry. It holds a randomly assigned identifier. Lifetime: 1 year; removed when you withdraw your consent.
The legal basis for strictly necessary cookies is § 25 (2) no. 2 TDDDG together with Art. 6 (1) (b) or (f) GDPR. You can delete or block cookies in your browser; signing in and shared boards will then stop working.
Audience measurement
To understand how Navamu is used and where it gets in the way, we use the analytics
service PostHog, exclusively in its European deployment with servers in the EU
(eu.i.posthog.com). PostHog acts as our processor under Art. 28 GDPR and a
processing agreement is in place. We use no advertising networks, no social media
plugins and no cross-site tracking.
Without consent: measurement without cookies
Until you consent — and also if you decline — PostHog runs cookie-free: nothing is stored on your device and nothing is read from it, neither cookies nor local storage. To still count visits in aggregate, PostHog computes an irreversible hash on its own servers from your IP address, your browser identification (user agent), the domain you opened and a random value that changes every day and is deleted once that day has been processed. Recognising you beyond a single day is therefore impossible. We do not receive an IP address as an identifier, and no location lookup takes place.
The legal basis is our legitimate interest in data-minimising audience measurement, Art. 6 (1) (f) GDPR. § 25 TDDDG does not apply in this state, because no information is stored on or read from your device. You may object at any time under Art. 21 GDPR — an informal message to the address in our legal notice is enough. If your browser sends a "Do Not Track" or "Global Privacy Control" signal, we treat that as a refusal.
With your consent: measurement that recognises you
On your first visit we ask you in a notice whether we may do more. Only if you explicitly agree does PostHog set cookies and store a randomly assigned identifier in your browser. That lets us join visits by the same person across several days and, if you are signed in, attribute them to your account.
The legal basis is your consent under Art. 6 (1) (a) GDPR and § 25 (1) TDDDG. You may withdraw it at any time with effect for the future using the "Cookie settings" link in the footer. After a withdrawal the cookies PostHog set are deleted and measurement falls back to the cookie-free state. Processing carried out beforehand is unaffected.
With your consent we process: that identifier, the pages you open, your browser and device type, your approximate region, and individual product events — that a board was created, a share link minted, or a plan purchased, for example.
Your IP address is not among them. PostHog needs it to receive the request at all and derives the approximate region from it, but the project is configured to discard client IP data, so it is not stored alongside these events.
Events from your account
Regardless of that choice, we record a few events server-side under your user id while you are signed in: registration, creating a board, completing a purchase. This recording happens exclusively on our servers, does not access your device, and does not concern visitors who are not signed in. The legal basis is Art. 6 (1) (b) GDPR insofar as it serves the performance of our contract with you, and otherwise Art. 6 (1) (f) GDPR.
What is never sent
Board content is excluded. What you draw or write is never sent to PostHog. Even in the AI settings we record only that something happened — when a provider preset is used, only which preset was clicked, never the endpoint or model name you typed.
Account and sign-in
For an account we process:
- your name and email address, and whether the address has been confirmed
- optionally a profile picture and a username
- your chosen language
- when the account was created and last changed
- if you sign in with a password: the password hash (never the password itself)
- if you sign in with Google or GitHub: the identifier of that account and the tokens that provider issues
- if two-factor authentication is enabled: the encrypted TOTP secret and the encrypted backup codes
- if you use a passkey: the public key and the authenticator's metadata
For each sign-in session we additionally store the IP address, the user agent and the expiry time, so that you can see and end your active sessions.
The legal basis is Art. 6 (1) (b) GDPR (performance of the contract) and, as far as sign-in security is concerned, Art. 6 (1) (f) GDPR.
Organizations and invitations
If you create an organization, we process its name, an optional logo, and the membership list with each member's role. If you invite someone, we store the email address you entered, the intended role and the status of the invitation until it is accepted, declined or expires. The legal basis is Art. 6 (1) (b) GDPR.
Board content
What you draw, write or upload on a board is stored so that it is still there when you reopen it and so that several people can work on it at the same time. Technically, a board's state is held as a document in our database, and uploaded images are stored as files on the same server.
This content is your data. We do not read through it, analyse it, pass it on, or use it to train AI models. We access it only where operation makes it unavoidable — for example to fix a specific fault you reported — or where we are legally required to.
The legal basis is Art. 6 (1) (b) GDPR. If you put other people's personal data on a board, you are the controller for that processing and we act as your processor in that respect.
Shared boards and guests
A board can be shared with a link. The link consists of a public identifier and a
secret. The secret sits in the URL fragment (after the #) and is never sent
to any server by your browser; we store only a SHA-256 hash of it, against
which a request can be checked. A working link therefore cannot be reconstructed
from our database.
Anyone opening a shared board through a link needs no account. For such guests we
process only the sc_guest cookie described above, the display name the guest
chooses, and — while they are connected — their cursor position. If a guest is
removed from a board, we store that guest identifier and the time.
Transactional email (address confirmation, password reset, sign-in link, organization invitation, notifications) is sent through
Resend, Inc., 2261 Market Street #5039, San Francisco, CA 94114, USA
as our processor. Your email address and the content of the message are transferred to the USA. The transfer is based on the European Commission's standard contractual clauses under Art. 46 (2) (c) GDPR. The legal basis for the processing is Art. 6 (1) (b) GDPR.
You choose which notifications you receive by email in your account settings.
Paid plans and payments
If you take out a paid plan, the payment is handled by
Stripe Payments Europe, Limited, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland
You enter your payment details directly with Stripe; we never see full card details. For payment processing Stripe is its own controller and processes your data under its own privacy policy. From Stripe we receive and store the customer identifier, the subscription identifier, the price you bought and the subscription status, in order to unlock and bill your plan.
The legal basis is Art. 6 (1) (b) GDPR, and for the retention of invoice data under commercial and tax law Art. 6 (1) (c) GDPR together with § 147 AO and § 257 HGB.
AI features
Navamu operates no AI models of its own and, by default, sends no board content to any third party for that purpose.
An organization may optionally configure its own AI provider: the endpoint, model identifier and API key are supplied by the organization. Only once an authorized person additionally enables the feature does using an AI function transmit the board content required for it to the provider that organization chose. The configuring organization is the controller for that transmission and for its legal basis towards the provider; we recommend a data-processing agreement with the chosen provider.
The API key is stored encrypted (AES-256-GCM) and is never displayed or returned after it is entered.
For each AI call we log metadata only: organization, user, calling feature, provider host, model identifier, token counts, status and timestamp. No request or response content is stored. These records exist for usage and abuse control.
With no AI configuration in place, no transmission occurs and the features are not offered.
Access by your own programs (MCP)
You can mint an access token that lets a program you run — an AI assistant on your own machine, for example — read your boards. Of that token we store only a SHA-256 hash and a short prefix so you can tell tokens apart, never the token itself. For each call we log metadata: token, user, organization, the tool called, the board identifier concerned, status, error class, duration and timestamp. No board content is logged. The purpose is to make access auditable; the legal basis is Art. 6 (1) (b) and (f) GDPR.
Contacting us
If you email us, we process what your message contains in order to answer it. The legal basis is Art. 6 (1) (b) GDPR where the enquiry concerns a contract, and Art. 6 (1) (f) GDPR otherwise. We delete such messages once they are no longer needed and no retention obligation applies.
The same applies to the contact form on this website. We process what you enter there — your name, email address and message — in order to reply. The message is not stored in a database; it is delivered to our mailbox as an email and then treated like any other email. Delivery goes through the processor named under "Email".
To protect against automated bulk submissions we limit how many messages may be sent from one IP address. For that we hold the IP address in memory for ten minutes; it is not stored, not logged, and not transmitted with your message. The legal basis is Art. 6 (1) (f) GDPR; our legitimate interest is preventing abuse. The form loads no third-party services — no captcha, no spam-filtering service.
Retention and deletion
We keep account data, boards and board content for as long as your account exists. If you delete your account, the associated data is deleted — except data we must retain under commercial or tax law (invoice data: ten years) and content-free log records kept to make billing and access auditable, from which your user identifier is removed.
Recipients
Apart from the processors named above (Hetzner, Resend, PostHog) and Stripe, we do not pass your data to third parties. We disclose data only where we are legally required to.
Your rights
You have the right of access (Art. 15 GDPR), rectification (Art. 16 GDPR), erasure (Art. 17 GDPR), restriction of processing (Art. 18 GDPR), data portability (Art. 20 GDPR), and to object to processing based on Art. 6 (1) (f) GDPR (Art. 21 GDPR). You may withdraw any consent you have given at any time, with effect for the future.
To exercise these rights, contact hi@nava.mu.
You may also lodge a complaint with a data protection authority. The authority responsible for us is:
Berliner Beauftragte für Datenschutz und Informationsfreiheit
Alt-Moabit 59–61, 10555 Berlin, Germany
https://www.datenschutz-berlin.de
Security
Connections to the website and the application are encrypted with TLS throughout. Passwords are stored only as a hash, share and access tokens only as a SHA-256 hash, and stored AI provider keys only encrypted with AES-256-GCM.
Changes to this policy
We update this policy when the service or the law changes. The version published here is the one that applies; the date above states when it was last changed.