Back to home

Privacy policy

This English text is provided for convenience; the German Datenschutzerklärung is the legally binding version.

1. Controller

Controller under the GDPR: Shio Ventures GmbH, Straßburger Straße 55, 10405 Berlin, Germany, email: kontakt@nx1-app.com. See also the imprint.

2. Principle: privacy-first, no account

NX1 works without an account or sign-in. Your bookmarks, history and settings are processed locally on your device by default. Only the data needed for a specific feature is sent to our servers. We build no user profile for advertising and do not sell personal data. Some offers are monetized; the attribution required for this is limited to whether/which offer was shown or used (see “Rewards and attribution” below). For one feature — type-ahead search suggestions — we use a processor acting on our behalf (see sections 5 and 6).

3. Hosting

The web app, the API and this website are hosted via Cloudflare. For each request Cloudflare processes technically necessary connection data, in particular the IP address, to deliver the request and protect the services from abuse (Art. 6(1)(f) GDPR).

4. This website

The landing page is static, with no accounts and no tracking cookies. Fonts and icon symbols are self-hosted (no third-party CDNs) — visiting the page therefore transmits no personal data to third parties beyond the technically necessary hosting connection data in section 3.

5. The NX1 extension and web app

Local storage and permissions. Your configuration is stored locally. The extension only requires the “storage” permission at install; access to bookmarks, history, top sites and favicons is requested on demand and only after your explicit consent, and analyzed on your device.

AI personalization (extension only). At optional first-run setup, NX1 analyzes your history and bookmarks on your device. Only anonymized patterns (registrable domains and individual keywords — no full URLs, no directly identifying data) are sent to our server and an AI service to suggest topics (Art. 6(1)(a) GDPR).

Areas, content and news. Creating an area by AI sends the chosen topic label and rough region to our server and the AI service. For news, our server fetches the public RSS/Atom feeds of the sources you added.

Content widgets. For an area's content widgets (e.g. sports tables, weather, news, finance/market data, music charts) our server fetches topic-related data from specialized, publicly available content sources and delivers it bundled and cached. Only the content reference (e.g. league, keyword, region) is transmitted — not your history and no directly identifying data. Which sources are used evolves with the available widgets; examples are OpenLigaDB (sports), Open-Meteo (weather) and RSS/Atom feeds and news services (news). For the weather widget, our server additionally transmits your approximate location (derived from the network connection and rounded to about 11 km — no GPS, no precise address) to the weather service to obtain local forecasts.

Search and suggestions. Web search opens your default search engine directly in your browser. Topic-specific search sources (e.g. the search of a particular portal or shop) are briefly routed through our server on submit, which immediately redirects you to the source's results page. This serves a function: it lets us centrally repair broken search addresses so you land on a working results page instead of an error page. Your search text only passes through technically and is neither stored nor analyzed; we only count anonymously which search source was used (see “Anonymous usage statistics” below). For type-ahead suggestions our server queries SearchTurbo (instantsearch.net), transmitting the entered query. SearchTurbo acts as our processor under our instructions (Art. 28 GDPR): the query is used solely to generate suggestions and is not used for the processor's own advertising or sale purposes and not resold. No user profile is built.

Wallpapers. Our server queries image services (Unsplash, Pexels and Pixabay) with a topic keyword and caches the images. Only the keyword is transmitted, not your history.

Screenshot help (gaming). Using screenshot help sends the pasted image to our server and an AI vision service (Anthropic). A daily allowance applies; a random install ID and the IP address are processed to enforce it (Art. 6(1)(a) GDPR).

Device sync. If you enable sync, settings, areas and tiles are stored server-side so you can share them across devices. No account or password is required: pairing uses a secret code (QR or 8-character code). Only the storage key is a non-reversible hash of that code; the contents themselves are stored in plain text server-side (no end-to-end encryption) and are technically readable by us / Cloudflare. You can delete the server-side sync data at any time in the settings under “Device sync” (Art. 6(1)(b) GDPR). Settings also cover details you enter in widgets yourself — among them a linked Roblox player name and a Solana wallet address for the Sandwatch leaderboard. Enabling sync therefore stores those on our server too; without sync they stay on the device only. As long as you keep them for a widget only, we do not evaluate them — they are there so your widget looks the same on every device. That changes only if you explicitly unlock a wallet address for a crypto project; see “Crypto projects” below. If you also create an NX1 account, we store that secret code with your account so that signing in on a new device brings back your areas and tiles as well. This makes the synced contents attributable, for us, to the hash of your email address; without an account that link does not exist. If you sign out on a device, we remove the synced contents from that device — they stay in your account until you delete them.

Install ID and abuse protection. To limit paid services (e.g. AI calls) we process a random install ID and, briefly, the IP address. These are not linked to your identity. If you reach an offer or the install via a referral or partner link, our server briefly processes a referral identifier and the IP address to attribute the referral to the correct source (e.g. for partner/commission programs); the IP is only stored briefly (see section 7). If you join the voluntary leaderboard (see “Leaderboard” below), the install ID is additionally processed there to limit abuse; any resulting link to the participation identifier is dissolved after at most 2 days.

Chrome Web Store data policy (Limited Use). For the browser extension: our use and transfer of information received from Chrome APIs (e.g. bookmarks, history, top sites) adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. This data is used only for the user-facing features you enable, analyzed on your device, not sold and not used for advertising.

Anonymous usage statistics (service logs). To improve NX1 and find defects — such as broken search addresses, missing website icons or unreachable news feeds — our server counts the use of its own endpoints in aggregated, anonymous form. Only counts and coarse attributes are recorded: which website domain requested an icon, which search source was used, which topic an area was generated for, whether a news feed was reachable, plus country, language and platform (extension or web app). Not recorded: search texts, visited pages or your history, full web addresses, IP addresses, or identifiers of your installation. To count “active installations per day”, the random install ID is irreversibly hashed with a random value that changes daily; that value is deleted after at most 48 hours, so even we can neither link the counts across days nor attribute them to an installation. This applies to the anonymous statistics; the NX1 Pass program (see “NX1 Pass” below) processes the install ID separately as described there. Statistics are deleted automatically after at most 90 days. No user profile is built. Legal basis: our legitimate interest in improving and securely operating the service (Art. 6(1)(f) GDPR).

NX1 Pass (rewards / loyalty program). NX1 may reward loyal, active use with benefits (the “NX1 Pass” program — e.g. unlocking ad-free, discounted or additional offers). Whether a benefit is granted is decided solely by our server, based on usage signals that arise anyway during normal use: per random install ID, our server records on which days certain features were used (e.g. search or opening an area) to count “active days” within a rolling window (currently 28 days) and to cap repeated abuse. Only coarse feature- and day-markers per installation are recorded — no search texts, no visited pages, no history. The data is not linked to your identity and is deleted after the window expires. Legal basis: our legitimate interest in an abuse-resistant rewards program (Art. 6(1)(f) GDPR); you are not disadvantaged if you use no benefits.

Rewards and attribution. Some offers and suggestions in NX1 are monetized (e.g. partner/affiliate links or sponsored search/navigation suggestions). So the respective source can correctly credit a display or use, an attribution request (a “counting pixel”) may fire to the relevant partner when it is shown or clicked. Only whether/which offer was shown or used is transmitted; we build no cross-device advertising profile and sell no personal data. This attribution may be used both in the web app and in the extension. Legal basis: our legitimate interest in the economic operation of the free service (Art. 6(1)(f) GDPR).

Leaderboard (optional, opt-in). NX1 includes a voluntary leaderboard. It is active only if you explicitly enable it (consent, Art. 6(1)(a) GDPR); without participation, nothing described here is processed. On joining, our server creates a random participation identifier and an auto-generated player name (no real name, regenerable at any time). You may replace it with a name of your choice and optionally add a profile picture — both are content you decide and both are visible to other participants; please avoid anything that identifies you or others if you don't want that. An uploaded picture is resized and re-encoded on your device, which removes embedded capture information (e.g. GPS coordinates). Publicly visible are only your name, your picture and your score/rank; you can change or remove both at any time. What is recorded is day-level usage: that NX1 was used on a given day and on which (at most three) topic start pages — no search texts, no visited pages, no history, no full URLs. In addition, server-observed events that occur on our side anyway (e.g. that an install came via your shared link) and the list of unlocked achievements reported by your installation may contribute; scores are always computed by our server. To limit abuse (e.g. repeated sign-ups) we briefly process the IP address and the install ID; any link between install ID and participation identifier is dissolved after at most 2 days. If you later actively redeem points with a partner (e.g. on a partner start page for their rewards), that partner receives your point total and links it to your account there — not to your name and not to your NX1 usage outside their space; this transfer happens solely at your direction at the moment of redemption. You can pause participation at any time (no new days are recorded for the leaderboard; existing season data expires through normal retention — if you have also unlocked a crypto project, we keep counting for that one until you withdraw the unlock, see “Crypto projects” below) or delete your entry — deletion removes identifier, score and leaderboard entry and doubles as a score reset. Retention: day entries at most two seasons (calendar months); season totals and player name until you delete your entry; pseudonymized redemption stubs 90 days; abuse counters (IP/install ID) at most 2 days.

NX1 account (optional). You can use NX1 entirely without an account — the leaderboard works without one too. If you voluntarily create an NX1 account, we additionally process your email address. Legal basis is the performance of the usage relationship you requested (Art. 6(1)(b) GDPR). The email address is used solely to sign you in (we send you a six-digit sign-in code) and to restore access to your score, name, achievements and — if you use device sync — your areas and tiles on further devices and after a reinstall. We send no advertising and no newsletter through it, and we do not pass the address to third parties. It is not visible to other users: publicly visible remain only your chosen display name, a profile picture if you set one, and your score/rank. Display name and any uploaded profile picture are content you choose yourself — please avoid anything identifying you or others if you do not want that. You can change your email address at any time in the account area and delete the account together with email address, name, profile picture, score and leaderboard entry; deletion takes effect immediately and cannot be undone. Without deletion we store the account data as long as the account exists; after prolonged inactivity (currently about 24 months without sign-in) we delete it automatically. An account does not add any logging of your usage — what changes is that the leaderboard data described above is tied to your account rather than to your device alone and, if you use device sync, that the secret code described there is stored with the account.

Partner account and partner start pages. Anyone who creates their own start page through the NX1 partner programme sets up a partner account. We then process the email address for passwordless sign-in (a single-use code by email), briefly the IP address to limit abuse, the details the partner enters in the account themselves (contact person, partner type, country, optionally billing email, responsible person and imprint link for the public start page) and the time they accepted the partner terms. Legal basis is performance of the partner contract (Art. 6(1)(b) GDPR), and our legitimate interest for abuse limitation (Art. 6(1)(f)). We store this data for as long as the partner account exists; after the contract ends we delete it within 30 days unless a statutory retention obligation applies. For the content a partner puts into their start page (images, logos, texts, campaigns, connected channels), that partner is the controller; we store and publish it on their behalf under a data processing agreement pursuant to Art. 28 GDPR, and we forward requests about such content to the partner. For the figures about a partner start page — installations, install clicks and campaign counts — we are the controller ourselves; they arise as anonymous server statistics as described under “Anonymous usage statistics”. A partner receives only aggregated totals without identifiers — no personal data about the fans of their start page and no profiles.

Crypto projects: unlocking a wallet address (optional, opt-in). Some crypto projects reward people for using NX1 regularly — with the first partner, Sandwatch, that is a higher multiplier on their own points. The feature is voluntary and off by default. It starts only once you store a wallet address in your NX1 account and explicitly unlock it for a specific project (consent, Art. 6(1)(a) GDPR). What we transmit to that project is this list and nothing else: the wallet address you stored, whether you used NX1 on the given day (active / not active), when you unlocked it, and whether you use a paid NX1 offering (tier “free” or “premium”). Not transmitted: your name, email address, profile picture, start pages, bookmarks, searches or visited sites — nor any figure for how often or how long you use NX1. The wallet address is a public identifier of the respective blockchain; on entry we only check whether an account exists for it there. Each project is unlocked separately — a new one receives your address only once you unlock it too; there is no automatic hand-on. To determine whether you were active on a day, our server keeps one “seen on this day” marker per account and day — day-level, without a time of day and without content. We delete those markers after at most 40 days; the link itself keeps only totals (number of days, current streak, last day). If you are away for a day, the reward pauses for that day and resumes by itself; the unlock stays. If no usage at all was seen for about half a year, we dissolve it automatically. You can withdraw an unlock at any time in your NX1 account; we report the end to the project at the next sync, and no further data flows. Deleting your NX1 account withdraws all unlocks. Whatever the project credited on its side is governed by its own privacy policy — we are not responsible for it and receive no data about you back from there. NX1 and the respective project are separate controllers under the GDPR.

6. Processors and third parties

We use the following service providers. Where they act as processors on our behalf, this is based on data-processing agreements under Art. 28 GDPR:

The US-based recipients (Cloudflare, Anthropic, Resend, Unsplash, Pexels, DuckDuckGo) involve a transfer to a third country. Cloudflare and Anthropic are certified under the EU-US Data Privacy Framework (DPF); the transfer to Resend is based on the EU Standard Contractual Clauses; for the other US services we base the transfer on the EU Standard Contractual Clauses or — where the provider is certified — the DPF (Art. 44 et seq. GDPR). SearchTurbo and Pixabay process in Germany; the specialized content sources are located partly in the EU, partly in third countries (in the latter case based on SCC or the DPF). Further information is available on request at kontakt@nx1-app.com.

7. Retention

Local data stays on your device until you delete it. Server-side data has short, feature-specific retention periods:

Server-side synced data (settings, areas, tiles) is kept while you use device sync; without further use it is deleted automatically after at most about 13 months. You can delete it yourself at any time in the settings under “Device sync” (or request deletion at kontakt@nx1-app.com, see section 8).

8. Your rights

You have the rights of access, rectification, erasure, restriction, portability and objection (Art. 15–21 GDPR), and may withdraw consent at any time with future effect. Contact kontakt@nx1-app.com. You also have the right to lodge a complaint with a supervisory authority. The authority competent for us is the Berlin Commissioner for Data Protection and Freedom of Information (BlnBDI), Alt-Moabit 59–61, 10555 Berlin, Germany.

9. Status

Last updated: August 2026.