Privacy Policy

Effective Date: August 19, 2026

Nekt ("Nekt," "we," "our," or "us") provides contact-sharing, scheduling, artificial-intelligence, and communication-assistant features through our website, iOS app, App Clip, Nektbot, and connected services (collectively, the "Service"). This notice explains what information we collect, where it comes from, why we use it and on what legal basis, who receives it, how long we keep it, and the rights you have over it.

It is written in plain language on purpose. If anything here is unclear, ask us — the contact details are at the end.

Who Is Responsible for Your Information

Alexander Weingart, sole proprietor trading as Nekt, is the data controller for the personal information described in this notice. That means we decide what information is collected and why.

  • Controller: Alexander Weingart, sole proprietor trading as Nekt (unincorporated — no company number).
  • Postal address: PO Box 15272, San Francisco, CA 94115-0272, United States.
  • Privacy contact: alex@nekt.us.
  • Data Protection Officer: none appointed. A DPO is not required under GDPR Article 37 for processing of this size and nature — we do not carry out large-scale systematic monitoring and we do not process special-category data at scale.

We act as a controller for all of the processing described here, including when you use Nekt inside a Microsoft Teams, Slack, or Google Workspace environment. Individuals sign themselves up, connect their own calendars, and choose to invite Nektbot into a conversation; we are not acting on an employer's instructions when we do that work. If we later offer an organization-managed deployment in which an employer directs the processing, we will act as that organization's processor for it and will say so here before it launches.

Who This Notice Is For

This notice covers three groups of people, because we hold information about all three.

If you have a Nekt account

It describes the information you gave us, the information we collect as you use the Service, and the information we receive from accounts you connected.

If someone shared your contact details with us

A Nekt user may have synced their address book, exchanged contact details with you, or added you as a guest to a meeting. In that case we hold information about you that we obtained from that person rather than from you — typically your name, phone number, email address, and whatever else was in their contact record for you. We use it so that person can schedule with you and so invitations reach you. You have the same rights as anyone else, listed below, and you can exercise them without holding a Nekt account.

If you took part in a conversation Nektbot was in

That could be a Teams chat or channel, a Slack channel, a group iMessage, an SMS thread, an email thread, or a Discord channel. We processed the messages in that conversation in order to work out what meeting was being arranged. Nektbot is a visible participant in any conversation it takes part in.

Information We Collect

Information you give us

  • Your name, email address, phone number, profile details, social usernames, interests, and profile and background images.
  • Addresses and locations you save, your time zone, and the hours you are willing to be scheduled in.
  • Messages and instructions you send to Nekt or to Nektbot, and any feedback or support requests.

Information from accounts you connect

  • Sign-in: an account identifier and basic profile from Apple, Google, or Microsoft. We never receive your password for those accounts.
  • Calendars: OAuth access and refresh tokens, your connected mailbox address, calendar names and identifiers, your free/busy windows, your working hours and time zone, and — for your own calendars only — event titles, descriptions, locations, and attendee lists.
  • Your office location and work-location plan, where your Microsoft 365 or Google Workspace account publishes one, so we only propose in-person times on days you are actually in the office.
  • Contacts you choose to sync from your device, your Google account, or your Microsoft account: names, phone numbers, email addresses, labels, photos, addresses, company, and job title.

Information from conversations Nektbot takes part in

  • Message text from the conversation Nektbot was invited into, together with the display name of whoever sent each message.
  • Who is in the conversation. On Teams we read the membership roster. Display names and user principal names from that roster are held in memory only for about a minute and are never written to storage; the underlying Microsoft user identifiers are stored.
  • The text of files you link in the conversation. If you paste a link to a SharePoint or OneDrive document — an agenda, an itinerary — Nektbot reads the text of that document so it can pick up the times and places in it. This is deliberately bounded: only hosts on an allowlist, at most 256 KB of text per file, and at most three files per turn.

Information about other people's availability

When you schedule with someone, we read their free/busy times. We do not read, store, or send anyone else's event titles. Another person's calendar is reduced to opaque start-and-end intervals before it reaches storage or the AI model — the only event details that ever leave an account are that account holder's own.

Location

  • Precise location when you tap "Use Current Location." Nekt does not use background location on any platform.
  • Coordinates derived from addresses you save, used to find a venue that is convenient for everyone. When there are several participants we compute a midpoint and search around it.
  • Approximate location from your IP address, used as a fallback and for the bump-to-exchange feature.

Technical and usage information

  • Device, browser, operating system, app version, IP address, and session and technical identifiers.
  • Feature usage, authentication and security events, error and crash reports, and performance data.

What we do not collect

We do not collect payment details, government identifiers, or any special-category data under GDPR Article 9 — health, biometrics, race, religion, political opinions, sex life or orientation, or trade-union membership. We do not ask for it and there is no field for it. Free text you type into a scheduling conversation is not filtered, so please do not put sensitive information there.

Why We Use Your Information, and Our Legal Basis

Under the GDPR we must have a lawful basis for every purpose. Ours are set out below, purpose by purpose.

Performance of a contract with you — Article 6(1)(b)

  • Creating and maintaining your account and signing you in.
  • Building your profile and sharing the fields you choose with people you connect with.
  • Exchanging contact details with another person by QR code, Bluetooth, or bump.
  • Syncing and organizing your contacts.
  • Reading your calendar's free/busy times and working hours, and proposing times.
  • Creating, updating, or canceling a calendar event after you confirm it.
  • Reading messages in a conversation you invited Nektbot into, to work out what is being scheduled.
  • Reading the text of a SharePoint or OneDrive file you linked in a conversation.
  • Sending the conversation to OpenAI so the scheduling assistant can respond.
  • Fetching the public bio from a LinkedIn or Instagram handle you typed in yourself.
  • Sending you transactional email — invitations, confirmations, and security notices.

Consent — Article 6(1)(a)

  • Using your precise device location, which you grant through the operating-system permission prompt and can withdraw in your device settings.
  • Analytics and session recording that rely on storing information on your device, which you accept or decline in the banner shown on your first visit and can change at any time in Settings.

Legitimate interests — Article 6(1)(f)

  • Holding contact details for people in a user's address book, so that user can schedule with them. Balanced against the fact that we use those details only for what the user asked for, and never to market to that person.
  • Processing messages from other participants in a conversation Nektbot was invited into. Balanced against the fact that Nektbot is a visible participant and the conversation record is kept for seven days.
  • Looking up approximate location from an IP address, for proximity matching and to make venue results useful.
  • Measuring feature usage, diagnosing errors, and improving reliability.
  • Keeping verbatim AI prompts and responses for debugging. This is bounded: capture is first-party — the records stay with us and are not sent to any analytics provider — and they carry a seven-day retention, after which they are deleted automatically.
  • Preventing abuse, rate-limiting, and protecting the Service and its users.
  • Establishing, exercising, or defending legal claims.

Legal obligation — Article 6(1)(c)

Meeting legal obligations and responding to lawful requests.

What this means for you

Where we rely on legitimate interests, you have the right to object, and we will stop unless we can show compelling grounds that override your interests. Where we rely on consent, you can withdraw it at any time, which does not affect anything we did before you withdrew it. We have carried out and documented a balancing assessment for each legitimate-interests purpose above, and you can ask us for a summary of it.

We do not use your information for advertising, sell it, share it for cross-context behavioral advertising, or use it to train general-purpose AI models.

No automated decisions with legal effects. The scheduling assistant proposes times, venues, and rooms; it does not make decisions about you that produce legal or similarly significant effects. Nothing is written to your calendar until you confirm it.

Cookies, Device Storage, and Session Recording

We store a small amount of information on your device. Some of it is strictly necessary to run the Service — keeping you signed in, remembering your consent choice, and protecting against abuse. That category does not require your consent and cannot be turned off while you are using the Service.

Everything else is analytics, and it only starts after you accept it. Our analytics provider, PostHog, records product events and also records browsing sessions — a replay of the pages you visited and how you moved through them — which helps us find and fix problems. Scheduling conversations and event details are masked out of those recordings, and we no longer capture browser console output into them.

You choose on your first visit, and you can change your mind at any time in Settings. Declining is as easy as accepting, and the Service works either way.

How Long We Keep Information

Different kinds of information have genuinely different lifetimes, so this is set out category by category rather than as one sentence.

Kept while your account exists, and deleted when you delete it

  • Your profile, saved locations, working hours, and time zone.
  • Your synced contacts and saved connections.
  • Your profile and background images.
  • Your groups and group memberships.
  • Encrypted calendar credentials — also deleted when you disconnect that calendar.
  • Records linking your Microsoft Teams or Slack identity to your Nekt account — also deleted when you unlink.

Kept for a fixed period, then deleted automatically

  • What Nektbot remembers of a conversation while it is working on it — the message text, sender names, extracted file text, and availability snapshots the assistant holds so it can follow the thread: 7 days from the last message in that conversation. This is the assistant’s working memory, not the messages themselves; the next entry covers those.
  • The messages themselves, on the channels Nekt runs itself: 365 days — one year — from the date of each message. Your iMessage and SMS conversations with Nektbot sit in the macOS Messages database on the Mac we operate to relay those two channels, and your email sits in the nektbot@nekt.us mailbox. That is the running record of the correspondence, kept the way a phone keeps your texts and a mail app keeps your mail, so that you and we can look back at what was arranged. It is a separate copy from the 7-day working memory above and it lasts longer, so please do not read the 7 days as meaning the messages disappear in a week. Anything you send through Teams, Slack, or Discord stays in those services under their retention rules rather than ours.
  • Verbatim AI prompts and responses kept for debugging: 7 days.
  • Shareable scheduling sessions and pending contact-exchange sessions: 7 days.
  • Approximate location looked up from an IP address, and geocoding and venue-search caches: 7 days.
  • Interactive cards we sent into Teams, Slack, or another channel, so we can redraw them when you tap an option: 30 days.
  • Records of which conversations Nektbot has been invited into and who was present, so we know whose messages to respond to: 90 days.
  • Records of invitations we sent — event title, description, location, and the email addresses invited: 90 days after the event ends.
  • Setup state for someone who started linking an account and did not finish, and a marker noting we already prompted you to finish setup so we do not prompt you repeatedly: 90 days.
  • Onboarding state and setup handoff links: 24 hours.
  • Cached free/busy calculations: 2 to 5 minutes.
  • Abuse-prevention counters: 1 minute to 24 hours, matching the rate-limit window.
  • Server logs held by our hosting provider: retained on that provider's standard schedule and used only for security, debugging, and abuse investigation.

After you delete your account

Deleting your account in Settings removes your profile, synced contacts, connected calendars and stored credentials, uploaded images, groups, scheduling sessions, and analytics records. Some information may persist briefly or permanently, and we would rather be specific about it than vague:

  • Cached items expire on their own schedule, at most 90 days for the longest of them.
  • Copies that other Nekt users hold. If you exchanged contact details with someone, their saved copy of your name, photo, and contact details stays in their contact list, and we hold that copy on their behalf. We do not delete it when you close your account, because it is their record of a contact they chose to save — in the same way that deleting someone's number from your own phone does not remove yours from theirs. This is permitted under GDPR Article 17(3), which allows erasure to be declined where processing is necessary for another party's legitimate interests. If you want a specific person to remove their copy, ask them, or contact us and we will help.
  • Anything a third party already received — a calendar invitation sitting in someone's mailbox, a message in a Teams channel — stays with them and is governed by their own policies.
  • Backups, for up to 7 days. Our database keeps a rolling seven-day recovery window so we can restore it if something goes wrong, such as a faulty release or data deleted by mistake. Information you delete disappears from the live Service immediately, but a copy remains inside that recovery window until it rolls off, at most seven days later. We do not use the recovery window to look anything up; it exists only to restore the database as a whole.
  • The channel record described above — your iMessage, SMS, and email correspondence with Nektbot on the equipment and mailbox we run. Deleting your account does not reach it, because it is the record of the conversation itself; it is removed on its own one-year schedule, or sooner if you ask us at the privacy contact address.
  • Anything we are required to keep by law.

Who We Share Information With

We do not sell personal information and we do not share it for advertising.

Other people, when you choose

Profiles you exchange, invitations you send, and messages you send through Nektbot go to the people you send them to.

Service providers (sub-processors)

These companies process personal information on our behalf, under written contract, and only for the purposes listed.

  • Vercel — hosting and serving the application. Receives all request traffic and server logs, which include email addresses, phone handles, and place names.
  • Google (Firebase — Firestore, Cloud Storage, Authentication) — database, file storage, and authentication. Receives everything stored durably: profiles, contacts, groups, invitations, encrypted credentials, and identity records.
  • Upstash — fast temporary state store. Receives conversation state, caches, contact-exchange matching, and rate-limit counters.
  • OpenAI — the AI scheduling assistant. Receives the scheduling conversation and current message; participant names, email addresses, and phone numbers; participants' location context including coordinates; your own event titles, locations, and attendee lists; and candidate times and room addresses. Separately, it receives raw inbound iMessage, SMS, and Discord text in order to decide whether Nektbot should respond at all.
  • PostHog — product analytics, error diagnosis, and AI reliability. Receives a pseudonymous identifier for you (for people we have not linked to an account, a salted hash of their address rather than the address itself), plus event names, counts, and durations, and session recordings with scheduling content masked out.
  • Microsoft (Graph, identity platform, Azure Bot Service) — the Microsoft 365 integration itself. Receives calendar reads and writes, event bodies and attendee lists, free/busy queries, directory and room lookups, and message delivery into Teams.
  • Apple — Sign in with Apple and iCloud Calendar. Receives sign-in token verification and, for iCloud calendars, an app-specific password and the full event including title, times, attendees, and location.
  • Slack — delivering Nektbot into Slack. Receives reply text, channel and thread identifiers, and member names, emails, and Slack IDs read from the channel. Where you have connected a Microsoft calendar, a reply can carry times derived from your Microsoft free/busy and details of your own events.
  • Resend — sending transactional email. Receives recipient email addresses, subject lines containing the event title and organizer's first name, and message bodies with date, time, time zone, and venue.
  • PrivateEmail (IMAP) — receiving email into the email channel. Receives the contents and headers of email sent to Nektbot.
  • Google Places, Geoapify, and Radar — suggesting somewhere to meet and checking addresses. Receive venue search text and coordinates, and addresses you enter.
  • IPinfo — approximate location. Receives your IP address.
  • Instagram and LinkedIn — optional profile import, only if you use it. Receive a username or profile address you supply.
  • A Nekt-operated relay for the iMessage and SMS channels. Handles outbound message text and the recipient's phone number or Apple ID, and inbound message text and sender handle. This is our own equipment rather than a third-party company.

What OpenAI keeps

We instruct OpenAI not to retain the conversations we send for the scheduling assistant, and OpenAI does not use them to train its models.

Others

  • Law enforcement or other authorities, where required by law or legal process, or where reasonably necessary to protect rights, safety, and the integrity of the Service.
  • A buyer or successor, in a merger, acquisition, financing, or sale of assets, subject to confidentiality and to notice where required.

Google API Services and Limited Use

If you connect a Google account, Nekt may access Google account profile information, Calendar data, Contacts data, Workspace directory information, and room-resource information only as needed to provide the user-facing features you authorize, such as sign-in, contact syncing, people and room resolution, availability, scheduling, and event creation.

Nekt's use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including its Limited Use requirements. We do not sell Google user data, use it for advertising, or use it to train generalized artificial-intelligence or machine-learning models.

Where Your Information Is Processed

Nekt is established in the United States, and our service providers operate in several countries, so your information will be processed outside the country you live in.

  • Our database and file storage run in the United States.
  • Our cache and temporary state store runs in the United States (US West), with no replicas elsewhere.
  • Our application hosting runs in the United States.
  • OpenAI processes AI requests in the United States.
  • PostHog processes analytics data in the United States.
  • Microsoft handles Teams message delivery through a regional endpoint that Microsoft selects for your tenant; we do not pin a region.

Where information leaves the European Economic Area or the United Kingdom, we rely on the European Commission's Standard Contractual Clauses, together with the UK International Data Transfer Addendum where the UK GDPR applies, and we assess the transfer risk for each recipient. You can ask us for a copy of the safeguards that apply to a particular provider.

How We Protect Information

  • Everything travels over encrypted connections (HTTPS/TLS).
  • Calendar credentials get an extra layer of encryption we apply ourselves — AES-256-GCM, cryptographically bound to the owning account and calendar, so a stored credential cannot be moved between records and still work.
  • Our databases and file storage are encrypted at rest by their providers and are configured so no client application can read or write them directly — every access goes through our server with the account checked first.
  • One exception, which we would rather name than leave the line above to imply: the Mac we run the iMessage and SMS channels on does not have full-disk encryption. We tried twice to turn it on, and it cannot run that way without leaving the service unable to restart by itself after a power cut or an update. Your messages on those two channels are protected instead by a bounded retention period — 365 days — a private location, and credentials that serve only that machine and that we can revoke.
  • Profile images you upload and imported contact photos are stored privately and require an authenticated request from their owner.
  • On iPhone, credentials are held in the iOS Keychain rather than in ordinary app storage.
  • Requests are rate-limited, and identifiers are hashed before being used as cache keys.
  • Security-relevant events — sign-ins, permission changes, deletions — are logged and retained for 90 days.

No system is completely secure, and information you choose to share with another person is outside our control once they have it.

Your Rights

If the GDPR or UK GDPR applies to you, you have the rights below. They are free to exercise, and we will not treat you differently for using them.

  • To be informed — know who is processing your information, what is collected, why, on what legal basis, who receives it, and how long it is kept. That is what this notice is for, and it applies whether or not you have a Nekt account. (Articles 13 and 14)
  • Access — get confirmation of whether we hold information about you, a copy of it, and an explanation of how it is used and who receives it. (Article 15)
  • Rectification — have inaccurate information corrected and incomplete information completed. (Article 16)
  • Erasure — have your information deleted where one of the grounds in Article 17 applies, for example because it is no longer needed or you withdrew the consent it relied on. (Article 17)
  • Restriction — have us pause processing while a dispute about accuracy or lawfulness is resolved. (Article 18)
  • Portability — receive the information you gave us in a structured, commonly used, machine-readable format, and have it sent to another provider where technically feasible. This applies to processing based on consent or contract. (Article 20)
  • Objection — object to processing we base on legitimate interests. We will stop unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms. (Article 21)
  • Withdraw consent — at any time, where we relied on consent. Withdrawing does not affect processing carried out before you withdrew. (Article 7(3))
  • Automated decision-making and profiling — not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects. We do not make any such decisions. The scheduling assistant proposes times, venues, and rooms, a person confirms them, and nothing reaches your calendar until you do. We do not profile you. (Article 22)
  • Complain to a regulator — you can lodge a complaint with the data protection supervisory authority in the EU member state where you live, where you work, or where you think the problem happened. In the United Kingdom that is the Information Commissioner's Office (ico.org.uk). Complaining to a regulator does not stop you raising the matter with us first, and does not affect your right to a judicial remedy. (Articles 77 and 79)

Nekt has no establishment in the European Union, so no single lead supervisory authority is responsible for us and the one-stop-shop mechanism does not apply. You may complain to the supervisory authority for your own country.

If you are in California or another US state with a comprehensive privacy law, you also have rights to know, delete, correct, opt out of sale or sharing, limit uses of sensitive information, and appeal a decision we make about your request. We do not sell personal information or share it for cross-context behavioral advertising.

How to Exercise Your Rights

Email alex@nekt.us and say what you want. You do not need to use particular wording, and you do not need a Nekt account.

  • We will respond within one month. If your request is complex, or you have made several, we may extend that by up to two further months — we will tell you within the first month if that happens, and why. (Article 12(3))
  • There is no charge, unless a request is manifestly unfounded or excessive, in which case we may charge a reasonable fee or decline it, and will explain why. (Article 12(5))
  • We may need to verify who you are before we act, particularly for access and deletion requests, because releasing someone's information to the wrong person is itself a breach. We will only ask for what we need to be confident.

You can also do some of this yourself

  • Edit your profile in the app at any time.
  • Choose which profile fields you share, and with whom.
  • Disconnect a calendar or a messaging channel in Settings.
  • Change your analytics choice in Settings.
  • Change device permissions — contacts, location, Bluetooth, photos — in your device settings.
  • Delete your account in Settings, under Delete Account.
  • Revoke Nekt's access from the provider's own settings: Google at myaccount.google.com/permissions, Microsoft at myapps.microsoft.com.

Representatives in the EU and UK

Nekt has no establishment in the European Union or the United Kingdom. Where GDPR Article 27 or UK GDPR Article 27 requires a controller outside those territories to designate a local representative, we have not yet appointed one. We are assessing that obligation, and this section will name the representative and their address once an appointment is made. In the meantime you can reach us directly using the contact details below, and you retain the right to complain to your own supervisory authority.

Children's Privacy

Nekt is not intended for children or for anyone under 16. You must be at least 16 years old to use Nekt, anywhere in the world. We apply that single age everywhere rather than the lowest age each country allows, so that we hold no information about anyone under 16.

We do not knowingly collect information from children below those ages. If you believe a child has given us information, contact us and we will investigate and delete it.

Changes to This Notice

We update this notice when the Service changes or when the law requires it. When we do, we change the effective date at the top. For changes that materially affect how we use your information, we give you notice in the app or by email before the change takes effect, and where the law requires your consent we ask for it rather than assuming it. We keep the previous version available on request, so you can see what changed.

Continuing to use Nekt after an update means the updated notice applies, except where the law requires a fresh consent.

Contact Us

  • Privacy questions and requests: alex@nekt.us
  • Postal: Alexander Weingart, trading as Nekt, PO Box 15272, San Francisco, CA 94115-0272, United States
  • In-app: Settings, then Send Feedback