Our primary application infrastructure is intended to be hosted on AWS infrastructure located in India. We apply technical and organizational safeguards designed to protect data against unauthorized access, alteration, disclosure, misuse, or loss. These safeguards may include encryption in transit and at rest where appropriate, access controls, least-privilege permissions, secrets management, audit logging, environment separation, monitoring, incident response processes, and periodic security reviews.
No system can guarantee absolute security, and users should also take steps to protect their devices, email accounts, SIMs, passwords, and linked credentials.
Although our primary infrastructure is intended to be located in India, some processing may occur outside India, particularly where third-party service providers such as AI inference or communication vendors process data from other jurisdictions. Nance treats Google user data, including email content accessed through the Gmail API, as sensitive information.
Google user data is protected using technical and organizational safeguards designed to prevent unauthorized access, alteration, disclosure, misuse, or loss.
Access to Google user data is restricted to authorized systems and personnel based on the principle of least privilege. Nance uses appropriate encryption, access controls, secure credential and secrets management, logging, monitoring, environment separation, and other security controls to protect Google user data.
Google OAuth credentials, access tokens, refresh tokens, and other authentication information are protected using appropriate security controls and are not intentionally exposed to unauthorized users.
Nance accesses Google user data only to provide the functionality for which the user has granted permission.