Privacy Policy
What Nasaq holds about you, and who can see it.
Last updated September 5, 2026
About Nasaq and this page
Nasaq is the workspace an organization uses to run its work: projects, tasks, meetings, resources, and documents. Every organization has its own private workspace, and the people who use it are its members.
This page explains what information Nasaq holds about you, why it holds it, and who can see it. It covers the Nasaq web app at isnasaq.com and the Nasaq mobile app. It describes what the software actually does — there are no general promises here about practices Nasaq does not have.
What we collect
About you: your name, your email address, your phone number if you add one, a profile picture if you upload one, and the language you prefer. You sign in with an email and password, or with Google — and when you use Google, Google passes your name, email address, and profile picture to Nasaq.
The work your organization creates inside Nasaq: projects, tasks, meetings, comments, labels, attributes, and saved views — together with who created or changed each item, and when.
Which organization and which teams you belong to, and the access role you hold in each space. That is what decides what you are able to open.
Your notification settings: the spaces you have muted, and whether the push and WhatsApp channels are on for you. If you allow notifications in the mobile app, that device’s push token is stored so a notification can reach it. Nasaq also keeps a record of the notifications sent to you and whether delivery succeeded.
That is the whole list. Nasaq does not ask for a national ID or a date of birth, holds no payment details, does not collect your location, and does not read your contacts.
Why we hold it
To run the workspace: to show your work to the colleagues who are meant to see it, to record who did what, and to let people reach you inside the product.
To deliver the notifications you asked for, on the channels you have left switched on.
To decide what you may open. Your membership and your role are the basis of every access check Nasaq makes.
Who can see it
Your name and picture are visible to the other members of your organization. Work you create is visible to the members who have access to the space it lives in — a team, a project — and to no one else.
Access is enforced in the database itself, by row-level security. A request that is not permitted comes back empty, whatever the interface asks for; hiding a button is not how Nasaq decides who sees what.
Your organization’s administrators decide who joins, which teams they belong to, and what each role may see or change. They can see the membership and role of every member.
The people who operate and maintain Nasaq can reach the database when the service has to be fixed or supported. They use that access for nothing else.
One exception is worth knowing: profile pictures and organization logos are kept in a public file store, so anyone holding the exact link to an image can open it. Those links are not published anywhere outside your workspace.
The channels you can turn off
Every notification arrives in your inbox inside Nasaq. That channel is always on — it is the product itself.
Push notifications. If you allow them in the mobile app, Nasaq sends a short line of text to Expo’s push service, which delivers it to your device. Expo receives your device’s push token and that short line, nothing more. Turn push off in your notification settings and nothing further is sent.
WhatsApp messages. If your organization switches the WhatsApp channel on, notifications also reach you as a direct message. That necessarily means your phone number and the text of the message are handed to the WhatsApp provider Nasaq uses (WasenderAPI) so it can deliver them. Turn the WhatsApp channel off in your notification settings and your number is no longer used this way.
You can also mute any space — a team, a project — and its notifications stop reaching you on every channel at once.
Documents and Dropbox
Documents are optional. If your organization connects its own Dropbox account, the files stay in that Dropbox; Nasaq keeps no copy of them on its servers.
What Nasaq stores is the connection itself — an access token, encrypted in a vault only the app can read — so it can list, open, and upload files on your organization’s behalf. Only members with access to documents can use it.
What happens to a file inside Dropbox is governed by Dropbox’s own terms and by your organization’s Dropbox settings.
Where it is stored
Your workspace lives in a Supabase Postgres database hosted in the European Union (Frankfurt). Profile pictures and organization logos are kept in the file storage of that same Supabase project.
The web app is hosted on CranL and served from isnasaq.com.
These are the only outside services that receive any of your information: Supabase (database, sign-in, files), CranL (hosting), Expo (push delivery), WasenderAPI (WhatsApp delivery, only if your organization enables it), Dropbox (documents, only if connected), and Google (only if you sign in with Google).
Cookies and browser storage
Nasaq sets a cookie to keep you signed in and one to remember your language. Connecting Dropbox sets a short-lived cookie that protects that connection while it is being made.
Your browser also remembers small preferences on its own: the theme, the state of the sidebar, how you last arranged a table. None of this is an advertising or tracking cookie.
What Nasaq does not do
There is no advertising in Nasaq and no ad network inside it. Your information is not sold, not rented, and not handed to a data broker.
There is no third-party analytics and no tracking pixel. Nasaq does not follow you around other websites.
How long it is kept
Work content stays in your organization’s workspace for as long as the organization keeps it. When someone deletes a task, a project, or a comment, the record is really deleted — Nasaq holds no hidden copy.
Your profile stays for as long as your account exists. If the account is deleted, what belongs to you alone goes with it: your profile, your notification settings, the items you follow, your inbox, and your device tokens. Work you created stays with the organization, and the activity record keeps the event while forgetting who did it.
A device’s push token is dropped when the push service reports that the device is gone, and it is reassigned if a different person signs in on that device.
Your rights
You can see and correct most of your information yourself, from your account page: your name, your phone number, your picture, and your language. Your email address comes from the account you sign in with.
To receive a copy of your information, to correct something you cannot edit yourself, or to have your account deleted, ask an administrator of your organization.
Deleting your account ends your access and removes the records that belong to you. It does not delete the work you created, because that belongs to the organization’s record.
How to reach us
Questions about this policy, or about your own information, go first to an administrator of your organization — the workspace is theirs, and they decide what it holds.
Changes to this policy
If this policy changes, the date at the top of the page changes with it, and the version in force is always the one at this address.