Effective August 25, 2026

Privacy Policy

Nittro collects only what it needs to publish the board, settle payments, measure traffic, and protect the service.

Information we process

  • Public listing data: app URL or X profile, name, pitch, category, owner or creator handle, sponsored rank, community votes, bid, and destination clicks.
  • Payment and contact data: Stripe receives the payer's email and payment details. For sponsored placements, Nittro stores a one-way hash of the contact email for placement control, not the plaintext email in its leaderboard database. Free nominations do not collect a contact email. Payment and an email address do not verify ownership of the destination.
  • Traffic and funnel data: first-party visitor and 30-minute session cookies, allowlisted public page paths, board views, bid and checkout milestones, timestamps, referring host, and restricted campaign tags such as UTM source and content. Identifiers are signed by Nittro and stored as one-way hashes; Nittro does not put an IP address, full referring URL, email address, or payment details in its analytics tables.
  • Voting data: a signed browser cookie and a weekly one-way voter hash are used to enforce vote limits. Nittro does not store the cookie identifier, IP address, or user agent in the vote table.

How information is used

Data is used to operate ranking and checkout, prevent abuse, count traffic, understand the conversion funnel, support customers, enforce rules, reconcile payments, and produce clearly labeled aggregate insights for builders.

Service providers

Stripe processes payments. Cloudflare-backed infrastructure stores application records and serves the site. X and app destination providers host public pages opened through submitted links. These providers process data under their own terms and security commitments. Nittro does not sell personal data.

Revenue verification

Any future payment-provider verification is optional and read-only. Only aggregate metrics selected for the profile may be published. Customer names, emails, card data, and transaction-level personal information are not public. A verification badge identifies its provider and freshness.

Retention and choices

Public bid history and accounting records may be retained to preserve the integrity of the board and meet legal obligations. Raw first-party analytics events use a 90-day retention window, inactive analytics sessions use a 180-day window, and hashed click-event identifiers use a 90-day window; these records are purged as traffic is processed. Weekly vote records may be retained to audit and correct abuse; short-lived abuse-control records expire with their rate-limit window. Security logs are retained only as reasonably needed. To request access, correction, or deletion of eligible personal data, email hello@nittro.co. Removing eligible personal data may not remove non-personal payment totals or records Nittro must legally keep.

Browser privacy signals

Nittro does not create first-party analytics identifiers when a browser sends Global Privacy Control or Do Not Track. Blocking or clearing Nittro cookies also resets the pseudonymous visitor and session identifiers. Essential security, payment, and abuse-prevention processing may still occur when needed to provide the service.

Security and international use

Reasonable technical and organizational safeguards are used, but no internet service is risk-free. Nittro is designed for a US-market launch; information may be processed in the United States or other locations where its providers operate.