Security

What actually happens to your data.

Naumu is operated by Harmonik Studio d.o.o., a company in Croatia, under the GDPR. This page is the plain version of our privacy policy: where your space lives, who else touches it, and what you can take back. Nothing here is a promise we have not already put in writing.

Where your data lives

Your space - graphs, nodes, threads, notes, canvases and files - lives in Naumu's cloud, on EU infrastructure operated by our hosting provider, Dokploy. Product analytics are processed in the EU (PostHog, Frankfurt) and only if you accept analytics in the consent banner.

Connections are encrypted in transit with TLS. Sessions expire after 365 days of inactivity. We use secure session management and access controls; no system is perfectly secure, and we are not going to pretend otherwise.

Who else processes it

These are every sub-processor we use, named, with what they do and where they sit. Two of them are in the United States, which is the honest cost of running the models that answer your questions.

  • Google Cloud (Vertex AI), United States - Google sign-in and our primary AI provider: inference for graph and chat, the embeddings behind search, and audio transcription.
  • Anthropic, United States - Additional AI model provider for graph and chat features.
  • Dokploy, EU - Infrastructure hosting.
  • PostHog, EU (Frankfurt) - Feature flags (functional, always on) and product analytics (consent-gated).
  • Stripe Payments Europe, Ltd., Ireland, with infrastructure in the US - Payments, subscriptions, invoicing and the billing portal. Card details go straight to Stripe; we never see or store full card numbers.

How the US transfers are covered

Transfers to sub-processors operating in the United States - Google, Anthropic and Stripe - are covered by Standard Contractual Clauses approved by the European Commission, or by adequacy decisions where those apply.

Your content is never training data

We do not train models on your data, and we do not sell your personal data. Per Google Cloud's terms, content processed through Vertex AI is not used to train Google's models. Content sent to Anthropic is not used for model training either.

What we do send is what the feature needs: the content the model has to read to answer you, build your graph, embed it for search, or transcribe an audio file you recorded.

You can take the whole thing with you

Every space exports to JSON from inside the app, whenever you want, with no request to file and nobody to ask. Under the GDPR you can also request access to your personal data, correct it, delete your account and its data from Settings, withdraw consent, object to processing based on legitimate interest, and complain to your data protection authority.

Account data is deleted within 30 days of account deletion; content is deleted when you delete it or your account. The one exception is billing and tax records, which Croatian law requires us to keep for 11 years. For anything you cannot do in the app, email [email protected] and we respond within 30 days.

Every change is attributed, and reversible

Naumu applies changes on its own - that is what makes it proactive - so every change is logged with a before and after, attributed to the member or the agent that made it, and reversible one row at a time. An undo is itself a recorded change linked back to the original, so the log never quietly rewrites itself.

Who can see what

Access is per member, per space. Roles run owner, admin, editor, viewer and guest, and threads are grouped into topics that carry a visibility level: restricted (its participants, plus space admins), internal (everyone with a seat in the space) or open (guests too). A member only ever sees the threads their role and the topic's level allow.

A connected AI client - Claude or ChatGPT over MCP, say - acts as the person who connected it, with that person's permissions and nothing more. Content it reads is transmitted to that provider and handled under their policy, which we do not control. You can revoke any connected application from Settings > Connected Apps, and revocation takes effect immediately.

What we do not claim

Naumu holds no security certifications. We are not SOC 2 audited and not ISO 27001 certified, and you will not find either badge on this site. When that changes we will say so here, with the date and the auditor.

If you have a security question this page does not answer, or you want to report a vulnerability, email [email protected].

Team chat that does the work.

no signup to try