Service: Nido (the "Service") Effective date: 14 June 2026 Last updated: 14 June 2026
This summary is for convenience; the full policy below governs.
Nido ("we", "us") operates the Service and is responsible, as data controller, for the personal data described here. You can reach us about privacy by replying to any email we send you, or at [[PRIVACY_EMAIL]].
You give us:
| Data | Why |
|---|---|
| Email address | Your identity for the Service and the address we send the digest to. |
| List of stock symbols you follow | The companies you want the digest to cover. You type these in yourself; we never import them from a broker or account. |
| Optional relevance marker | For any symbol you may optionally set a coarse relevance - high / medium / low - used only to order your digest. It is never an amount, quantity, or value, and you can leave it blank. |
| Language | Spanish or English, your choice. |
| Feedback | When you click "more like this" / "less like this" on an item, we record that to tune future selection. |
We create or collect automatically:
| Data | Why |
|---|---|
| Subscription state & timestamps | When you signed up, confirmed, and (if applicable) unsubscribed. |
| Sign-in token & session cookie | A single-use link token to confirm it's you, and a signed cookie that keeps you signed in on your device for up to 30 days. The cookie is signed, not a stored password - we hold no passwords. |
| Delivery & click events | Whether a given week's email was sent, and clicks on the links we own (unsubscribe, edit, feedback). |
| Server and error logs | Standard technical logs (e.g. IP address, browser/user-agent, timestamps, error traces), kept for security and debugging. |
What we deliberately do NOT collect: broker or custodian statements, account or IBAN numbers, share quantities, cost basis, portfolio value, net worth, or any monetary amount. The Service is built so that this information never reaches us.
We do not knowingly collect special-category data (health, biometrics, etc.), and we ask you not to put such data, or anyone else's personal data, into any field.
| Purpose | Legal basis (GDPR terms; equivalents apply elsewhere) |
|---|---|
| Run your subscription and send the weekly digest you asked for | Performance of a contract with you, and/or your consent to receive the emails |
| Confirm your email (double opt-in) and keep you signed in | Contract / consent |
| Choose and order the news using your symbols and feedback | Contract; legitimate interests in giving you a useful product |
| Secure the Service, prevent abuse, debug, keep records of consent | Legitimate interests in a safe, reliable Service; legal obligation where applicable |
| Aggregate, non-identifying product analytics (e.g. overall unsubscribe rate) | Legitimate interests |
| Comply with law and respond to lawful requests | Legal obligation |
Where we rely on consent, you can withdraw it at any time (e.g. by unsubscribing); this doesn't affect processing already carried out. Where we rely on legitimate interests, you can object - see Your rights. We do not use your data for automated decisions that produce legal or similarly significant effects about you.
We use a single, essential cookie: the signed session cookie that keeps you signed in after you click a magic link. It carries no advertising identifiers. We do not use third-party advertising, profiling, or cross-site tracking cookies, so there is no non-essential cookie to consent to - because we set none.
Email link clicks (unsubscribe, edit, feedback) are processed through our own web routes, which necessarily means we can see that a link was clicked. If we ever introduce email open-tracking, we will update this policy before relying on it.
We do not sell, rent, or trade your personal data. We share it only with the third-party providers that operate the Service on our behalf - by category, our cloud hosting and database providers, our email-delivery provider, and operational and security tooling (such as error monitoring). Each acts only on our instructions and is bound to protect your data, and we may change providers as the Service evolves.
We may also disclose data if required by law, to enforce our terms, or to protect rights and safety; and we may transfer it as part of a merger, acquisition, or asset sale, in which case this policy will continue to protect you.
We and our providers operate across borders, so your data may be processed outside your country, including in the United States. Where the law requires it (for example, transfers out of the EEA, UK, Brazil, or Argentina), we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses, adequacy decisions, or equivalent mechanisms. Ask us for details using the contact above.
Depending on where you live, you have some or all of these rights over your personal data:
How to exercise them: email [[PRIVACY_EMAIL]] from your subscribed address, or use the unsubscribe and edit links in any digest. We'll verify your request and respond within the time your law requires - generally 15 days (Brazil), 30 days (EU/UK), or 45 days (California), extendable where permitted. There's no charge unless a request is manifestly unfounded or excessive.
We keep your account data while you're subscribed, and for a short period afterward to honor unsubscribe and suppression obligations and keep basic records. When you ask us to delete your account, we remove your personal data from our active systems and from backups on our normal backup cycle, except where we must retain limited information to comply with law or resolve disputes. Aggregated or de-identified data that can no longer identify you may be kept.
We protect your data with measures appropriate to its sensitivity: encrypted transport (HTTPS), a passwordless design that stores no passwords to leak, signed (not stored) session credentials, access controls, and reputable infrastructure. No system is perfectly secure, but the architecture intentionally minimizes what we hold, so there is less to lose. If a breach affects your rights, we'll notify you and the relevant authority as required by law.
The Service is for adults and is not directed to anyone under 18 (or the age of majority where you live). We don't knowingly collect data from minors. If you believe a minor has subscribed, contact us and we'll delete the account.
These supplement, and where they conflict, override, the rest of this policy for the residents named.
We may update this policy as the Service evolves. We'll post the new version here with a fresh "Last updated" date and, for material changes, notify subscribers by email before the change takes effect.
Questions or requests: [[PRIVACY_EMAIL]], or reply to any email we send you.