Privacy Policy
Your privacy is the core design principle of Niobium. Your notes are end-to-end encrypted so neither we nor third parties can read your content.
1. Data Controller
The data controller for Niobium and Niobium Cloud is Yogie Stefanus (individual), located at Perumahan Bumi Alam Indah, Jl. Kruing 2 B3 No 161, Lempake, Kec. Samarinda Utara, Kota Samarinda, Kalimantan Timur 75118, Indonesia. Privacy contact: admin@niobium.web.id.
2. Summary and Privacy Principles
The Niobium app can be used without an account for local note-taking. The Niobium Cloud service applies end-to-end encryption (E2EE), designed so that we cannot read your notes. All notes are encrypted on your device before transmission to the server.
3. Personal Data Processed
The following table details personal data categories processed when using Niobium Cloud, processing purposes, legal bases under the Indonesian Personal Data Protection Law (UU PDP No. 27/2022), and retention schedules.
| Data Category | Purpose | Legal Basis | Retention Period |
|---|---|---|---|
| Email address | Account identification, OTP code delivery, security verification, and service notices. | Contract performance (Art. 20(2)(b) PDP Law) | While account is active plus 30 days after account closure. |
| Hashed login credentials | Secure authentication without storing plaintext passwords. | Contract performance | While account is active; deleted immediately upon account deletion. |
| Public and wrapped keys | End-to-end encryption of notes across user devices. | Contract performance | While account is active. |
| Encrypted notes (blobs & manifest) | Synchronization of encrypted notes across devices; content is unreadable to us. | Contract performance | During active subscription plus grace period and deletion window (total 37 days after subscription expires). |
| Active sessions (device name, platform, app version) | Management of connected devices and revocation of session access. | Contract performance and legitimate interest (security) | Until session is revoked or expires after 60 days of inactivity. |
| IP addresses | Abuse prevention, rate limiting, and intrusion detection. | Legitimate interest (system security) | Maximum 30 days in server access logs. |
| Daily active flag | Aggregate usage metrics without tracking granular activity. | Legitimate interest | Aggregated and anonymized after 90 days. |
| Orders and transaction history | Payment recording, tax compliance, and accounting. | Legal obligation and contract performance | 10 years as required by Indonesian statutory and tax law. |
| Promo code redemptions | Preventing duplicate redemptions per person on free promotions. | Contract performance and fraud prevention | Duration of promotion plus 90 days. |
| Email delivery logs | Verifying transactional email delivery and delivery failure audits. | Contract performance and legitimate interest | 30 days. |
| Database backup snapshots | Disaster recovery. | Legitimate interest (service resilience) | Maximum 14 days. |
| Consent records | Proof of compliance with user terms and policy consents. | Legal obligation | While account is active plus statutory limitation period. |
| Security and audit logs | Security incident investigation and intrusion prevention. | Legitimate interest | 180 days. |
4. Data Processors
We partner with trusted service providers: Domainesia (hosting and email services located in Indonesia) and Midtrans (payment processing licensed by Bank Indonesia). If you connect personal cloud storage such as Google Drive, Dropbox, or WebDAV, connections occur directly from the app on your device without passing through our servers.
5. Cookies and Local Storage
The Niobium marketing website does not use cookies or third-party trackers. The web Account portal (/account) uses only a single essential session cookie named nb_web for login authentication.
6. Application Update Checks
The app may periodically check for updates at the app/latest endpoint. Requests include only the app version number and operating system platform; IP addresses are not stored in update check logs.
7. Data Subject Rights
Under the PDP Law, you have the right to access, obtain copies, rectify data, request deletion of your account and associated data, and withdraw consent. You can download copies of data or delete your account directly in the Account menu, or email admin@niobium.web.id and we will respond within 3×24 hours.
8. Data Security
We implement strict technical security measures: end-to-end encryption for notes, TLS for all network transmissions, password credential hashing via Argon2id, and strictly restricted access controls.
9. Data Breach Notification
In the event of a personal data breach impacting your data, we will provide formal notifications to you and the supervisory authority within 3×24 hours pursuant to Article 46 of the PDP Law.
10. Children's Data
Niobium Cloud is not intended for individuals under 18 years of age without guidance and written consent from a parent or legal guardian.
11. Retention and Deletion
Encrypted note data is retained during active subscription plus a total 37-day grace and deletion window. Server backups are retained for up to 14 days and account deletions are reapplied across any restored backups.
12. Changes to Privacy Policy
This Privacy Policy may be updated periodically. Material changes will be announced via email prior to the effective date of the revised policy.