Privacy policy
Last updated August 29, 2026
NYA is project software for design and construction studios. This policy describes what the product actually collects and what it deliberately does not. If something here is unclear, ask us rather than guessing — idan@nyainteriors.com.
What you give us
Your account: email address, phone number, a hashed password (we never see the plaintext), and the role you pick at signup. If you sign in with Google we receive your email, name and profile picture from Google instead of a password. We use your phone number for account support and onboarding. Providing it does not give us permission to send marketing texts; those require separate consent.
Your work: everything you enter to run your business — clients and leads, project names and addresses, proposals, estimates, invoices, change orders, purchase orders, tasks, schedules, daily logs, time entries, expenses, uploaded files, floor plans and ceiling plans, mood boards and product selections.
Your clients' details: when you add a client or lead, you give us their name, email, phone and project details. You are responsible for having a basis to share those with us; we process them on your behalf.
Location, only if you allow it: the jobsite time clock records latitude and longitude when you clock in, and only then. Decline the browser prompt and the clock still works without it.
Google data — what we read and what we never touch
Connecting Google is entirely optional, separate from signing in, and each permission is requested on its own.
Gmail: we read message metadata only— subject line, participants, timestamps, and the short preview snippet Gmail itself generates. We request messages with Google's format=metadata parameter, which means message bodies and attachments are never sent to us and cannot be. We use this to match conversations to the right client and show them in your inbox; “Open” links back to the real thread in Gmail. We sync the last 90 days on demand when you press the button — never continuously in the background. We never send email as you.
Calendar: we read event titles, times, locations and attendee names from your primary calendar to place them on your NYA schedule. We do not create, edit or delete your events.
Limited Use:NYA's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Concretely: we do not use Google data for advertising, we do not sell it, we do not transfer it except as needed to provide the feature you enabled, and we do not let humans read it except with your explicit permission, for security, or where required by law. We do not use Gmail or Calendar data to train AI models.
Disconnect at any time in Settings. That immediately revokes our stored token; delete the synced conversations to remove what was already pulled.
Payments
Subscriptions and client invoice payments run through Stripe. Card numbers never reach our servers — they go directly to Stripe, which is PCI-certified. We store only what we need to show you the state of things: Stripe customer and subscription identifiers, plan, amounts, and payment status.
When your clients pay an invoice, the money settles into your own connected Stripe account. You remain the merchant of record for your clients.
Analytics and measurement
We measure how the site and the product are used so we can improve them and see whether our own marketing works: PostHog for product analytics and Google Analytics for traffic and ad-campaign measurement. They record pages visited, buttons pressed, and the usual device signals, using cookies and similar identifiers. If you hold an account, that activity is tied to your account id and email so we can see real funnels; anonymous visitors are not tied to a profile.
PostHog also creates session replays so we can see where someone hesitated, clicked repeatedly, or left a signup or trial flow. A replay reconstructs page structure and interactions; it is not a camera recording. All form inputs are masked before data leaves your browser, workspace text is masked, and we do not capture network request or response bodies, canvas contents, passwords, payment details, project names, client details, notes, or money.
Who else processes your data
We keep this list short on purpose. Each of these is a processor acting on our instructions, not a party we sell data to:
- Supabase — database, login and file storage (United States).
- Vercel — application hosting and delivery (United States).
- Stripe — payments and subscription billing.
- Google — only if you connect it, and only for the permissions you granted.
- PostHog — product analytics and privacy-masked session replay (United States).
- Google Analytics — site traffic and ad-campaign measurement.
- Anthropic and OpenAI — only when you use an AI feature, and only the content of that request. Neither is permitted to train on it.
Client portals
When you share a project with a client, we mint a long random link. Anyone holding that link sees exactly the sections you enabled — and nothing else. We record when a link was last opened and how many times, so you can tell whether your client has seen something. Revoke a link at any time and it dies immediately.
What we do not do
We do not sell your data. We do not show third-party advertising in the product. We do not use your workspace content, your clients' details, or your Google data to train AI models. Analytics is limited to the tools named above, measuring how NYA itself is used — we do not let data brokers or ad networks track you across the web from our pages.
Keeping it, and getting rid of it
We keep your data while your account is open, because it is your business records. Delete individual records at any time from inside the product. Ask us to close your account and we will delete your workspace and its contents within 30 days, except where we are required to retain billing records for tax and accounting purposes.
Depending on where you live you may have the right to access, correct, export, or delete your personal data, and to object to processing. Email us and we will action it — we will not make you jump through hoops.
Security
Data is encrypted in transit and at rest. Access is enforced at the database level, so one workspace cannot read another's rows. Credentials such as payment keys and Google refresh tokens are stored where browser sessions cannot read them at all. No system is perfect; if we ever discover a breach affecting your data, we will tell you.
Children
NYA is a business tool and is not directed at anyone under 16. We do not knowingly collect their data.
Changes
If we change this policy in a way that materially affects you, we will say so in the product rather than quietly editing this page.
Questions, requests, or complaints: idan@nyainteriors.com. See also our terms of service and the NYA Clipper policy covering the browser extension.