Niiwaa — Privacy Policy
Effective date: 2026-06-09 · Data controller: 2IS (Inbound Intelligence Solutions) · Contact: contact@niiwaa.com
This policy explains what personal data the Niiwaa mobile app (com.niiwaa.app) processes, why, and the rights you have. Niiwaa is a professional news-monitoring (“veille”) app: members of an organization review and rate articles relevant to their monitored topics.
1. Who the app is for
Niiwaa is a business application. You sign in with an account provisioned by your organization; there is no public self-registration. Your organization owns the monitoring data.
2. Data we process
CategoryExamplesWhy
Account & identity
email, name, user ID, company ID, role, languages
authenticate you, scope content to your company
Authentication
password (verified, never stored by the app), access & refresh tokens
secure sign-in and session
Session security
device label, IP address at sign-in
detect/limit suspicious sessions, audit
App activity
relevance votes on articles, notification & language preferences
core functionality, customization
Device identifier
Firebase Cloud Messaging (FCM) push token
deliver push notifications
Audit log
key actions (sign-in, device changes, account events), integrity-chained
security, traceability, compliance
Diagnostics (optional)
crash & error reports
consent (off by default)
We do not collect location, contacts, photos, financial or health data, or advertising identifiers, and we do not use your data to advertise or sell it.
3. On-device storage
Data cached on your device is stored in a fully encrypted local database (SQLCipher). The key is held in the operating system’s secure storage, excluded from OS backups, and wiped at logout.
4. Transmission
All traffic is encrypted in transit (HTTPS/TLS).
5. Who we share data with
Only with service providers acting on our instructions:
- Google / Firebase Cloud Messaging — to deliver push notifications (receives the device push token).
- Sentry — to receive crash/diagnostic reports, only if you enable diagnostics; reports are scrubbed of personal identifiers.
- Our hosting/infrastructure provider — to operate the backend.
We do not otherwise share your personal data with third parties.
6. Retention
- Account and monitoring data are retained while your account is active.
- Account deletion: deactivated immediately and permanently deleted/anonymized after a 30-day grace period; monitoring data belonging to your company is retained by the company.
- Audit records: tiered retention by event type (from 3 months up to 3 years).
7. Your rights
Subject to applicable law (incl. the GDPR) you may request access, rectification, erasure, restriction, portability, and objection. The app provides in-app account deletion and a data export (sent to your email). To exercise other rights, contact contact@niiwaa.com. You may also lodge a complaint with your data-protection authority (in France, the CNIL).
8.Children
Niiwaa is not intended for children and is not directed at users under 16.
9. Changes
We may update this policy; the “Effective date” above reflects the latest version. Material changes are surfaced in the app.
10. Contact
2IS (Inbound Intelligence Solutions) — contact@niiwaa.com
Niiwaa — Privacy policy
Effective date: 2026-06-09 · Data controller: 2IS (Inbound Intelligence Solutions) · Contact : contact@niiwaa.com
This policy describes the personal data processed by the mobile application Niiwaa (com.niiwaa.app), their purposes and your rights. Niiwaa is a professional monitoring application: members of an organization consult and evaluate articles related to their monitored themes.
1. Target audience
Niiwaa is a professional application. You log in with an account provided by your organization; there is no public registration.
2. Data processed
CategoryExamplesPurpose
Account & identity
email, name, user/company credentials, role, languages
authentication, partitioning by company
Authentication
password (verified, never stored by the app), access and refresh tokens
secure connection and session
Session Security
device label, IP address at connection
detection of suspicious sessions, audit
Application activity
relevance votes, notification and language preferences
operation, customization
Device ID
Firebase push token (FCM)
sending notifications
Audit log
key actions (login, device change, account events), integrity chaining
security, traceability, compliance
Diagnostics (optional)
crash and error reports
consent (disabled by default)
We do not collect not : location, contacts, photos, financial or health data, advertising identifiers. No advertising, no resale of data.
3. On-device storage
Cached data is stored in a local database fully encrypted (SQLCipher), key in the system's secure vault, excluded from backups, erased upon disconnection.
4. Transmission
All exchanges are encrypted in transit (HTTPS/TLS).
5. Subcontractors
- Google / Firebase (FCM) — sending notifications (receives the push token).
- Sentry — crash reports, only if you enable diagnostics; redacted of personal identifiers.
- Our host — operation of the backend.
6. Preservation
- Account data retained as long as the account is active.
- Account deletion: immediate deactivation then deletion/anonymization afterwards 30 days ; the company's monitoring data is kept by it.
- Audit logs: conservation by type of event (from 3 months to 3 years).
7. Your rights
In accordance with the GDPR: access, rectification, erasure, limitation, portability, opposition. The application offers the account deletion and a data export (via email). Other rights: contact@niiwaa.com. You can contact the CNIL.
8. Children
Niiwaa is not intended for minors under 16 years of age.
9. Changes
This policy may evolve; “Effective Date” indicates the latest version.
10. Contact
2IS (Inbound Intelligence Solutions) — contact@niiwaa.com