Skip to main content

Privacy Policy

Privacy Policy for the Nearbyto.me Service (nearbyto.me)

1. General Provisions

1.1. This Privacy Policy (hereinafter — the "Policy") describes how personal data of users of the Nearbyto.me Service, available at https://nearbyto.me, is collected, processed, stored, transferred, and destroyed.

1.2. The Controller of personal data is the operator of the Nearbyto.me Service (hereinafter — the "Controller", the "Company", "we"). Full registration details are available on request via [email protected].

1.3. The Nearbyto.me Service is an AI assistant for emotional support based on cognitive behavioral therapy (CBT) methods. The Service is not a medical service, does not render diagnoses, and does not substitute for qualified psychological or psychiatric assistance.

1.5. By using the Service, the User confirms that they have read this Policy, understand its contents, and give their free, informed, and unambiguous consent to the processing of personal data on the terms set forth herein.

1.6. If the User does not agree with the terms of this Policy, they must cease using the Service.


2. Definitions

2.1. The following terms are used in this Policy:

2.1.1. Personal Data — any information relating to an identified or identifiable natural person (data subject), as defined by the Data Protection Law (No. 3144/2023).

2.1.2. Data Subject (User) — a natural person to whom personal data relates.

2.1.3. Controller — a natural or legal person, public authority, or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.

2.1.4. Processor — a natural or legal person, public authority, or other body which processes personal data on behalf of the Controller.

2.1.5. Processing — any operation or set of operations performed on personal data, whether or not by automated means, including collection, recording, organization, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure by transmission, dissemination, alignment, combination, restriction, erasure, or destruction.

2.1.6. Sensitive Data — special categories of personal data, including data concerning health (physical and mental), biometric data, racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, and data concerning sex life or sexual orientation.

2.1.7. Profiling — any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyze or predict aspects concerning that natural person's behavior, preferences, interests, or emotional state.

2.1.8. Cross-Border Transfer — transfer of personal data to the territory of a foreign state.


3. Categories of Personal Data Collected

3.1. The Controller collects and processes the following categories of personal data:

3.1.1. Identification Data

DataRequired
Name or nicknameRequired
Email addressRequired
Mobile phone numberIf registering via phone

3.1.2. Usage Data

DataRequired
Date and time of registrationAutomatic
Login events (date, time)Automatic
Session data (start/end time, duration, number of sessions)Automatic
User-selected settings and preferencesUser-provided
Features used, pages visitedAutomatic

3.1.3. Dialogue Content

DataRequired
Text messages sent by the User to the AI AssistantUser-provided
AI Assistant responses (stored as part of session history)Automatic

3.1.4. Emotional State Data (treated as Sensitive Data)

DataRequired
User-reported emotional stateUser-provided
Emotional indicators derived from dialogue text analysisAutomatic
Psychotyping / profiling resultsAutomatic

Important: Data concerning emotional and psychological state is treated as sensitive data (health data) and requires explicit consent for processing. See the Sensitive Data Consent document.

3.1.5. Technical Data

DataRequired
IP addressAutomatic
Device type and versionAutomatic
Operating system type and versionAutomatic
Browser type and versionAutomatic
Interface languageAutomatic
Approximate geolocation (country/region level, derived from IP)Automatic

3.1.6. Payment Data

Note: Payment data (credit card numbers, bank details) is processed by Lava.top. The Company does not collect, process, or store payment card data. Refer to Lava.top's privacy policy for details on how Lava processes payment information.


4.1. The Controller processes personal data for the following purposes and on the following legal bases:

PurposeData CategoriesLegal Basis
Account creation and managementIdentification, TechnicalPerformance of a contract (Terms of Service)
User authenticationIdentification, TechnicalPerformance of a contract
Provision of the Service (AI interaction)Dialogue Content, UsagePerformance of a contract
Personalization of content and recommendationsEmotional State, ProfilingExplicit consent (Sensitive Data Consent)
Psychotyping / profilingDialogue Content, Emotional StateExplicit consent (Art. 6, 19 of Data Protection Law)
Service improvement and analyticsUsage, Technical (aggregated/anonymized)Legitimate interest
Service-related notificationsIdentification (email)Performance of a contract
Marketing communicationsIdentification (email)Explicit opt-in consent
Security and fraud preventionTechnical, UsageLegitimate interest
Legal complianceAll categories as requiredLegal obligation

5. Data Retention Periods

5.1. Personal data is retained for the following periods:

Data CategoryRetention PeriodBasis
Identification DataDuration of account + 30 days after deletion requestContract performance, legal obligations
Usage Data24 months from collectionLegitimate interest (analytics)
Dialogue Content12 months from session date, or until deletion by UserContract performance
Emotional State / Profiling Data12 months from session date, or until deletion by UserExplicit consent
Technical Data6 months from collectionLegitimate interest (security)
Cookie Consent Records24 monthsLegal obligation (proof of consent)
Marketing Consent RecordsDuration of consent + 24 months after withdrawalLegal obligation (proof of consent)

5.2. Upon expiry of the retention period, personal data is destroyed (deleted from all active systems and backups within 30 days).

5.3. Data of inactive accounts (no login for 12 consecutive months) is automatically deleted after a 30-day advance notice sent to the registered email address.


6. Data Processing Location and Cross-Border Transfers

6.1. Personal data is processed and stored on servers located in the European Union (AWS infrastructure, Frankfurt region, Germany).

6.2. EU/EEA countries are included in the list of countries with an adequate level of personal data protection.

6.3. Accordingly, the transfer of personal data to EU-based servers does not require:

  • Separate consent from the data subject for cross-border transfer;
  • Written agreement between the Controller and the data recipient specifically for cross-border transfer purposes;
  • Permission from the PDPS for cross-border transfer.

6.4. The Company does not transfer personal data to countries that are not on the PDPS adequacy list. If this changes, the Company will obtain the necessary authorization and/or explicit consent from data subjects before any such transfer.


7. Third-Party Data Recipients (Processors)

7.1. The Controller may share personal data with the following categories of processors:

Processor CategoryPurposeData SharedLocation
AWS (Amazon Web Services)Cloud infrastructure, hosting, AI processing (Bedrock)All categories stored/processed on serversEU (Frankfurt)
Lava.topPayment processingEmail, transaction dataPer Lava.top's privacy policy
Analytics provider (e.g., PostHog)Service analytics, aggregated statisticsUsage Data, Technical Data (anonymized)EU
Email service providerTransactional and marketing emailsEmail address, nameEU

7.2. Data Processing Agreements (DPA) are in place with all processors in accordance with Article 17 of the Data Protection Law.

7.3. AI model provider clarification. Nearbyto.me is an independent product and is not affiliated with, endorsed by, or sponsored by Anthropic or Amazon Web Services. The Service uses third-party AI models (currently Claude by Anthropic) accessed via AWS Bedrock in the EU region. When using AWS Bedrock, the data processor is AWS; Anthropic provides the model but does not receive access to user data, and user data does not leave the EU region.


8. Data Subject Rights

8.1. In accordance with the Data Protection Law (No. 3144/2023), the User has the following rights:

RightDescriptionResponse Time
Right of AccessObtain confirmation of whether personal data is being processed, and receive a copy of that data10 working days
Right to RectificationRequest correction of inaccurate personal data10 working days
Right to ErasureRequest deletion/destruction of personal data10 working days
Right to Data PortabilityReceive personal data in a structured, commonly used, machine-readable format10 working days
Right to ObjectObject to processing based on legitimate interest, including profiling10 working days
Right to RestrictionRequest restriction of processing in certain circumstances10 working days
Right re: Automated DecisionsNot be subject to a decision based solely on automated processing (including profiling) that produces legal or similarly significant effects10 working days

8.2. To exercise these rights, the User may:

  • Send a request to [email protected];
  • Use the data management functions in the Account settings (export, deletion);
  • Contact the Company at the address specified in Section 1.2.

8.3. The exercise of the right of access is free of charge. If requests are manifestly unfounded or excessive (e.g., due to repetitive character), the Company may charge a reasonable fee or refuse to act on the request, providing justification.


9. Automated Decision-Making and Profiling

9.1. The Service uses automated processing of personal data for the following purposes:

Type of Automated ProcessingPurposeData Used
Content personalizationSelecting exercises, techniques, and recommendations relevant to the UserDialogue content, emotional state data
PsychotypingIdentifying behavioral and communication patterns to improve Service personalizationDialogue content
Emotional state assessmentAdapting AI responses to the User's current emotional stateDialogue content

9.2. The automated processing described above is based on analysis of the User's dialogue text. No solely automated decisions with legal or similarly significant effects are made without the User's explicit consent.

9.3. The User has the right to:

  • (a) Object to profiling at any time by contacting [email protected];
  • (b) Request human review of any automated decision;
  • (c) Withdraw consent to profiling (note: withdrawal may affect the Service's ability to provide personalized recommendations).

9.4. For more details, see the Profiling Disclosure section of the Sensitive Data Consent document.


10. Cookies and Tracking Technologies

10.1. The Service uses cookies and similar technologies. Detailed information is provided in the separate Cookie Policy.

10.2. Non-essential cookies require active consent before being set. The User may manage cookie preferences through the cookie consent banner displayed on the website.


11. Data Security

11.1. The Company implements the following technical and organizational measures to protect personal data:

MeasureDescription
Encryption in transitTLS 1.2 or higher for all data transmission
Encryption at restAES-256 or equivalent for stored data
Access controlRole-based access, minimum necessary privilege
Access loggingAll access to user data is logged
Regular security assessmentsPeriodic review of security measures
Incident response planProcedures for detecting, assessing, and responding to data breaches

11.2. Despite implementing appropriate security measures, the Company cannot guarantee absolute security of data transmission over the internet or electronic storage.


12. Data Breach Notification

12.1. In the event of a personal data breach:

ActionTimeframeRecipient
Notification to PDPSWithin 72 hours of discoveryPersonal Data Protection Service (PDPS)
Notification to data subjectsImmediately if the breach poses a significant threat to rights and freedomsAffected Users

12.2. The Company maintains an internal incident register documenting all data security incidents, regardless of severity.


13. Children's Data

13.1. The Service is intended for users aged 16 and older. Users under 16 may use the Service only with the consent of a parent or legal guardian.

13.2. The Company does not knowingly collect personal data from children under 16 without parental consent. If the Company becomes aware that personal data of a child under 16 has been collected without appropriate consent, such data will be deleted promptly.


14. Marketing Communications

14.1. The Company may send marketing communications (including information about new features, promotions, and related content) only with the User's explicit opt-in consent.

14.2. Consent to marketing communications is collected separately from consent to the Terms of Service and the Privacy Policy. Pre-checked boxes are not used.

14.3. The User may withdraw consent to marketing communications at any time by:

  • Clicking the "Unsubscribe" link in any marketing email;
  • Adjusting preferences in the Account settings;
  • Contacting [email protected].

14.4. Withdrawal of consent to marketing communications does not affect the lawfulness of processing based on consent before its withdrawal.


15. Amendments to the Policy

15.1. The Company reserves the right to amend this Policy at any time.

15.2. The User will be notified of material changes at least 14 calendar days before the changes take effect, via email and/or in-app notification.

15.3. Continued use of the Service after the changes take effect constitutes the User's acceptance of the amended Policy. If the User does not agree, they must cease using the Service and may request data deletion.

15.4. The current version of the Policy is always available at nearbyto.me/legal/privacy-policy.


16. Contact Information

For any questions regarding this Policy or the processing of personal data:

ChannelContact
General inquiries[email protected]
Data protection inquiries[email protected]
Nearby

AI companion for emotional support. Pro and Pro Max — billed in USD.

Navigation


Nearby is an independent product and is not affiliated with Anthropic or AWS. AI responses are generated by third-party large language models and are provided for informational and self-help purposes only. Nearby is not a medical device and does not provide medical services — its information and practices are not a substitute for consultation, diagnosis, or treatment by a licensed mental health professional.

© 2026 Nearby. All rights reserved.