Skip to content

Privacy Policy

Last updated: August 23, 2026

1. Who We Are

This Privacy Policy describes how Nabu ("we," "our," or "us") collects, uses, discloses, and protects personal information when you use our research opportunity matching platform (the "Service").

Legal Entity: Sole proprietorship
Jurisdiction: Massachusetts, United States
Contact: projectnabu.support@gmail.com
Definitions: "Personal Information" means any data that identifies, relates to, describes, or could reasonably be linked to an identifiable individual.

This Policy applies to all users of our Service, including undergraduate and graduate students, postdoctoral researchers, and other academic professionals. By using the Service, you acknowledge you have read and understood this Policy.

2. What We Collect

Most of Nabu works without an account. Browsing the lab directory, viewing a lab or university page, looking up a principal investigator’s public contact address, and using our outreach email templates all work while signed out, and none of them require you to give us any personal information. An account is only needed to save labs and to manage your own account settings.

2.1 Information You Provide Directly

CategoryExamplesPurpose
Account DataName, email address, profile pictureAccount creation, authentication
Saved LabsThe labs you bookmark from the directoryShowing your saved list back to you
CommunicationsMessages sent via support channelsCustomer support

2.2 Information Collected Automatically

CategoryExamplesPurpose
Usage DataPages visited, time on page, feature interactionsService improvement, analytics
Device DataIP address, browser type, operating systemSecurity, diagnostics
Log DataAPI calls, error events, request timestampsInfrastructure monitoring

2.3 Information from Third Parties

SourceExample DataPurpose
Google / GitHub OAuthName, email, profile picture (upon login)Social authentication
Public research databasesLab directory listings, faculty profilesAggregating research opportunity data

2.4 Sensitive Data

We do not collect sensitive personal information (race, religion, health data, biometrics, or political opinions). Nabu has no document upload, no free-text profile fields, and no questionnaire — the only personal data you can give us is what your sign-in provider passes us and which labs you save, so there is no route by which sensitive data would reach us.

2.5 Children's Data

Our Service is not directed at individuals under the age of 13. We do not knowingly collect personal information from children under 13. If we discover such data was collected inadvertently, we will delete it promptly. Users aged 13–17 may use the Service only with parental or guardian consent where required by applicable law.

2.6 Academic Records & FERPA

Nabu does not collect academic records. There is no transcript upload, no CV upload, and no GPA, coursework, or test score field anywhere in the Service. We never request records from your educational institution, and the Family Educational Rights and Privacy Act (FERPA) — which governs how institutions handle student records — is therefore not engaged by anything we do.

Earlier versions of Nabu offered a research fit report built from an uploaded CV and transcript. That feature has been discontinued along with the personalized reports, target lists, and AI-drafted emails that depended on it. Any academic data collected under those earlier versions has been deleted.

3. How We Collect Information

We collect information through three channels:

  • Voluntary Provision: You provide information when you create an account, save a lab, submit a support request, or communicate with us.
  • Automatic Collection: Our servers and analytics tools automatically record interactions when you access or use the Service. This includes log files, Vercel Analytics (privacy-preserving, no cookies), and JavaScript tracking.
  • Third-Party Sources: We receive information from authentication providers (Google, GitHub) and public research databases used to populate our lab directory.

4. Purposes & Lawful Basis (GDPR)

For users in the European Economic Area (EEA) and the United Kingdom, we process personal data under the following lawful bases (Article 6 GDPR):

Processing PurposeData CategoriesLawful Basis
Account creation & managementAccount DataContract necessity (Art. 6(1)(b))
Saving labs to your accountAccount Data, Saved LabsContract necessity (Art. 6(1)(b))
Analytics & product improvementUsage Data (aggregate, no identifiers)Legitimate interest (Art. 6(1)(f)) — to be assessed via LIA prior to EEA processing
Error diagnostics & service reliabilityLog Data, Device Data, account identifierLegitimate interest (Art. 6(1)(f))
Security & abuse preventionLog Data, Device DataLegitimate interest (Art. 6(1)(f))
Marketing communicationsEmail addressConsent (Art. 6(1)(a))

Right to Object (Article 21 GDPR): You have the right to object to any processing based on legitimate interests at any time by contacting projectnabu.support@gmail.com. If we cannot demonstrate compelling legitimate grounds for the processing, we will cease it upon your objection.

Note on Vercel Analytics: Vercel Analytics operates without cookies and collects only aggregate, anonymized data (page views, referrers, device type). No personal identifiers are tracked. For GDPR purposes, this processing falls under legitimate interest with minimal privacy impact.

5. Data Sharing & Third Parties

5.1 Subprocessors

SubprocessorServiceData SharedLocation
Supabase Inc.Database and authenticationAccount Data, Saved LabsUS
Vercel Inc.Hosting, deployment, analyticsUsage Data, Log Data (aggregate, no identifiers)US
Functional Software, Inc. (Sentry)Error monitoring and diagnosticsError reports: message and stack trace, page URL, browser and operating system version, and — if you are signed in — your account identifier. See Section 5.2.US

This is the complete list. Nabu uses no advertising networks, no marketing or attribution trackers, no data brokers, and no third-party AI or language model providers.

5.2 Error Monitoring (Sentry)

When something breaks, Nabu sends a diagnostic report to Sentry so we can find and fix it. We have configured Sentry to minimise what those reports contain:

  • No IP addresses. Collection of visitor IP addresses is switched off.
  • No request or response bodies, and no database query values.
  • Account identifier only. If you are signed in, we attach your internal account ID — not your name and not your email address. That ID is meaningless to anyone without access to our database, and it exists so we can tell whether a fault affected one person or a thousand.
  • Session credentials are stripped before transmission, so your login session cannot be captured in an error report.

Session Replay: When an error occurs, Sentry may also record a reconstruction of the moments leading up to it — which pages you were on and where you clicked — so we can reproduce the fault. Text content is masked by default, and recordings are made only when an error actually occurs; we do not record ordinary browsing sessions. These recordings are held on Sentry’s US infrastructure and are deleted on Sentry’s standard retention schedule (90 days). This processing rests on our legitimate interest in keeping the Service working, and you may object to it under Section 6.

5.3 Other Disclosure Circumstances

  • Legal Obligations: We may disclose data to law enforcement, regulators, or courts where required by applicable law.
  • Corporate Transactions: In the event of a merger, acquisition, or sale of assets, your data may be transferred. We will notify you of any change in ownership.
  • With Your Consent: We may share data for other purposes with your explicit consent.

5.4 Sale or Sharing of Personal Information

We do not sell personal information for monetary consideration. We do not share personal information for cross-context behavioral advertising. If this practice changes, we will update this Policy and provide a "Do Not Sell or Share My Personal Information" mechanism.

6. GDPR Rights (EEA & UK Users)

If you are located in the EEA or the UK, you have the following rights under the GDPR (Articles 15–22):

RightDescriptionHow to Exercise
Right of Access (Art. 15)Obtain confirmation of whether we process your data and a copy of that dataSubmit DSAR via projectnabu.support@gmail.com
Right to Rectification (Art. 16)Correct inaccurate or incomplete personal dataEdit in account settings or email us
Right to Erasure (Art. 17)Request deletion of your personal data ("right to be forgotten")Submit request via account settings or email. Exceptions: legal obligations, establishment of legal claims
Right to Restriction (Art. 18)Limit processing of your data (storage allowed, use restricted)Submit request via email
Right to Data Portability (Art. 20)Receive your data in a structured, commonly used, machine-readable format (JSON/CSV)Submit request via email
Right to Object (Art. 21)Object to processing based on legitimate interests or direct marketingVia account settings (marketing) or email (other objections)
Rights re: Automated Decisions (Art. 22)Not to be subject to solely automated decisions with legal/significant effectsNot applicable — we make no automated decisions about you (Section 13)

Response Time: We respond to all requests within 30 calendar days (Article 12(3)). We may extend by up to 60 additional days where necessary due to complexity or volume — we will inform you of any extension.

Identity Verification: We may request additional information to verify your identity before fulfilling a request. This is a security measure to ensure personal data is not disclosed to unauthorized persons.

Complaint to Regulator: You have the right to lodge a complaint with your local data protection authority (DPA). Contact details for European DPAs are available at edpb.europa.eu.

EU Representative (GDPR Article 27): As a sole proprietor based outside the EEA, we may be required under Article 27 GDPR to designate a representative in the EU for data protection matters. We believe we qualify for the small-scale exception under Article 27(2) given the current scope of our processing activities. As our user base in the EEA grows, we will appoint an EU representative and update this Policy accordingly.

7. CCPA/CPRA Rights (California Residents)

If you are a California resident, the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) grant you the following rights:

RightDescriptionDetails
Right to KnowRequest disclosure of categories and specific pieces of personal information collected, sources, purposes, and third partiesCovers the 12 months preceding your request
Right to DeleteRequest deletion of personal information held by us and our service providersSubject to exceptions (complete transactions, detect security incidents, legal compliance)
Right to CorrectRequest correction of inaccurate personal informationWe will use commercially reasonable efforts
Right to Opt OutOpt out of the sale or sharing of personal information for cross-context behavioral advertisingWe do not sell or share PI. If this changes, we will provide a "Do Not Sell or Share My Personal Information" link
Right to Limit Use of Sensitive PILimit use of sensitive personal information to purposes authorized by regulationWe do not collect sensitive PI for purposes beyond those authorized (see Section 2.4)
Right to Non-DiscriminationNo denial of services, price differences, or different quality for exercising rightsWe will not discriminate against you for exercising your CCPA/CPRA rights

Categories of Personal Information Collected in the Last 12 Months: Identifiers (name, email, account identifier), internet/electronic activity (usage data, saved labs, error diagnostics).

Categories of Personal Information Disclosed for a Business Purpose: Identifiers (to Supabase for account storage and authentication; account identifier only to Sentry for error diagnostics).

Response Time: 45 calendar days (extendable by an additional 45 days with notice).

Do Not Track / Global Privacy Control (GPC): We honor Global Privacy Control (GPC) signals transmitted by your browser as an opt-out request. Our Service currently does not respond to traditional Do Not Track (DNT) signals because no uniform standard exists. If a DNT standard is established, we will update our practices.

Authorized Agent: You may designate an authorized agent to submit requests on your behalf. We require proof of authorization (signed permission) and identity verification of both you and the agent.

8. PIPEDA Rights (Canadian Users)

If you are located in Canada, the Personal Information Protection and Electronic Documents Act (PIPEDA) governs our handling of your data through its 10 Fair Information Principles:

#PrincipleOur Commitment
1AccountabilityWe designate a Privacy Officer responsible for PIPEDA compliance. We are responsible for personal data under our control, including data transferred to third parties.
2Identifying PurposesWe identify the purposes of collection before or at the time of collection (see Section 4 above).
3ConsentWe obtain meaningful consent for collection, use, and disclosure. Express consent is required for sensitive data; implied consent may be used for routine operational data.
4Limiting CollectionWe collect only the personal information necessary for the identified purposes.
5Limiting Use, Disclosure, and RetentionWe use and disclose data only for the purposes for which it was collected, unless you provide new consent. We retain data only as long as necessary (see Section 11).
6AccuracyWe keep personal data as accurate, complete, and up-to-date as necessary for its intended purposes.
7SafeguardsWe implement security safeguards appropriate to the sensitivity of the data (see Section 10).
8OpennessThis Privacy Policy and related practices are readily available for your review.
9Individual AccessYou may access and challenge the accuracy of your personal information upon request.
10Challenging ComplianceYou may challenge our compliance with PIPEDA principles. Complaints are investigated and responded to in writing.

Breach Notification: If a data breach poses a real risk of significant harm to an individual, we will notify the Office of the Privacy Commissioner of Canada (OPC) and affected individuals as soon as feasible. We maintain records of all breaches, regardless of severity.

Privacy Officer: Nabu / projectnabu.support@gmail.com

9. International Transfers

Your personal information may be transferred to and processed in countries other than your country of residence. These countries may have data protection laws different from those of your jurisdiction.

When we transfer personal data from the EEA, UK, or Canada to the United States, we rely on the following measures:

  • Standard Contractual Clauses (SCCs): We commit to entering into the European Commission's Standard Contractual Clauses (Decision 2021/914) with our subprocessors (Supabase, Vercel, Sentry), all of whom offer DPA/SCC adoption through their dashboards. These agreements will be executed before processing EEA/UK user data at scale.
  • UK Safeguards: For UK-originating transfers, we will use the UK International Data Transfer Agreement (IDTA) or UK Addendum to the EU SCCs.
  • Canadian Transfers: Transfers from Canada rely on contractual protections and the comparable-level-of-protection framework under PIPEDA.

Key Locations: Our cloud infrastructure is hosted primarily in the United States (via Supabase on AWS and Vercel on Google Cloud). Error diagnostics are transmitted to Sentry’s US infrastructure.

Questions about transfers? Contact projectnabu.support@gmail.com.

10. Data Security

We implement technical and organizational measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction:

CategoryMeasures
Encryption at RestAES-256 encryption for all stored data (databases, file storage, backups)
Encryption in TransitTLS 1.2+ for all network communications; HTTPS enforced site-wide
Access ControlRole-based access control (RBAC), multi-factor authentication (MFA) for all administrative access, least-privilege principle
InfrastructureSOC 2-compliant hosting providers (Supabase, Vercel); automatic security patching; network segmentation
MonitoringIntrusion detection; automated anomaly alerting; regular log review
Incident ResponseIncident response procedures; notification within 72 hours where required by law (GDPR Art. 33)
PersonnelLimited data access on a need-to-know basis; documented access logging

Security Reporting: If you discover a security vulnerability, please report it to projectnabu.support@gmail.com.

11. Data Retention

We retain personal information only as long as necessary to fulfill the purposes described in this Policy, or as required by law.

Data CategoryRetention PeriodRationale
Account Data (name, email, profile)Duration of account + 90 daysService delivery; recovery grace period
Saved LabsDuration of accountCore service functionality
Usage Data (aggregate analytics)26 monthsIndustry standard
Error Reports & Session Replays (Sentry)90 daysDiagnosing and fixing faults; Sentry’s standard retention
Support Tickets & Resolution History2 years after resolutionQuality assurance; dispute resolution
Server Logs (IP, timestamps, endpoints)90 days (rolling)Security monitoring; incident investigation
Marketing Preferences & Consent RecordsDuration of account + 2 yearsAudit trail for consent

Deletion Commitment: Upon account deletion, we commit to deleting your personal data within 90 days. Backup copies will be purged within the next backup cycle (maximum 30 additional days). We are actively implementing automated deletion workflows to meet this commitment.

Anonymization: Analytics data (Vercel Analytics) is aggregated and anonymized by design. It is no longer considered personal information and may be retained indefinitely.

12. Cookies & Tracking

12.1 How We Use Tracking

Nabu uses Vercel Analytics, which operates without cookies. It collects only anonymized, aggregate data (page views, referrer URLs, device type, browser, and geographic region at the city/country level). No individual identifiers, session IDs, or persistent tracking mechanisms are used.

No cookies are set by the Nabu platform for analytics, advertising, or tracking purposes. Cookies are used strictly for authentication and platform security, and only once you sign in. Sentry, our error monitoring provider, sets no cookies.

Browser storage: Two things are stored in your browser rather than as cookies. Your light/dark theme choice is kept in local storage so the site does not flash the wrong colours on your next visit. If an error occurs while you are using the Service, Sentry writes a short-lived session-storage entry to tie the diagnostic recording together. Both stay on your device; neither is used to track you across sites, and clearing your browser data removes them.

12.2 Cookie Categories

CategoryExamplesPurposeConsent Required?
Strictly NecessarySession cookie, CSRF token, auth tokenAuthentication, platform security, load balancingNo (ePrivacy Art. 5(3) exception)
Functional— (theme preference uses local storage, not a cookie)Remembering your light/dark settingNo (set only at your request)
Analytics— (Vercel Analytics is cookieless)Usage measurementNot applicable (no cookies)
Marketing— (none deployed)AdvertisingN/A

12.3 Future Cookie Use

If we add any cookies beyond strictly necessary ones in the future, we will:

  • Notify you via an updated Policy
  • Deploy a cookie consent banner with granular controls
  • Obtain prior consent before placing non-essential cookies (ePrivacy Directive)
  • Provide "Accept All" and "Reject All" options with equal prominence
  • Log consent records (timestamp, consent scope)
  • Allow withdrawal of consent at any time

13. AI & Automated Decisions

Nabu does not use artificial intelligence to process your personal data. We send no personal data to any AI or large language model provider, and there is no such provider in our subprocessor list in Section 5.1.

Earlier versions of Nabu generated research fit reports, match scores, action steps, and outreach email drafts using a third-party language model. Those features have been withdrawn. The outreach email templates now offered on lab pages are fixed, pre-written text that we wrote ourselves; they are filled in with public information about the lab and never leave your browser.

13.1 Automated Decision-Making (GDPR Art. 22)

We do not carry out automated decision-making that produces legal effects concerning you or that similarly significantly affects you. Nothing in the Service profiles you, scores you, or decides anything about you.

The lab directory does compute figures — publication counts and citation percentiles — but these describe laboratories using public bibliometric data. They are not assessments of you, and they are identical for every visitor regardless of whether you are signed in.

14. How to Exercise Your Rights

MethodDetailsResponse Time
In-AppAccount settings page for data update, deletion, or exportImmediate for self-service actions
Emailprojectnabu.support@gmail.com — specify the right you wish to exercise and your account email30 days (GDPR) / 45 days (CCPA)

Identity Verification: We may request proof of identity (government ID, proof of address) to prevent unauthorized access to your data. We will use this only for verification and delete it afterward.

JurisdictionResponse TimelineExtensionFee Policy
GDPR (EEA/UK)30 calendar daysUp to 60 days for complexityFree, unless manifestly unfounded or excessive
CCPA/CPRA (California)45 calendar daysAdditional 45 days with noticeFree for first 2 requests in 12 months
PIPEDA (Canada)30 daysUp to 90 days with noticeFree
Other jurisdictions45 daysReasonable extensionFree

15. Children's Privacy (COPPA)

Our Service is not directed at children under 13. We comply with COPPA as follows:

  • Age Gate: We do not knowingly collect personal information from children under 13.
  • Parental Consent: If we learn we have inadvertently collected data from a child under 13 without verified parental consent, we will delete it immediately.
  • Discovery Procedure: If you are a parent or guardian and believe your child has provided us with personal information, contact projectnabu.support@gmail.com. We will investigate and delete the data within 30 days.
  • Student Users (13–17): Students aged 13–17 may use the Service with parental or guardian consent where required by applicable law. Users under 18 should review this Policy with a parent or guardian.

16. Third-Party Links

The Service may contain links to external websites, including research lab pages, university directories, and third-party tools. This Privacy Policy does not apply to those external sites. We are not responsible for the privacy practices of third-party services. We encourage you to review the privacy policies of any external site before providing personal information.

The lab directory data displayed in our Service is aggregated from publicly available sources. We do not control the accuracy or completeness of third-party directory data.

17. Policy Updates

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or operational needs.

Type of ChangeNotification MethodTiming
Material changes (new data uses, new subprocessors, new rights)Email notification + in-app bannerAt least 30 days before effective date
Minor changes (clarity improvements, formatting)In-app notice + updated "Last Updated" dateUpon publication
Regulatory changes (new law compliance)In-app banner + updated PolicyAs required by law

Re-consent: Where required by law (e.g., new processing purposes require consent under GDPR), we will obtain fresh consent before implementing the change.

Your Continued Use: Your continued use of the Service after the updated Policy takes effect constitutes your acceptance of the changes, where permitted by law.

Previous Versions: Archived versions of this Policy are available upon request at projectnabu.support@gmail.com.

18. Complaints & Regulator Contact

If you believe we have violated your privacy rights, you have the right to file a complaint with the relevant regulatory authority.

JurisdictionRegulatorContact
European UnionYour local Data Protection Authority (DPA)edpb.europa.eu
California (US)California Privacy Protection Agency (CPPA)cppa.ca.gov
CanadaOffice of the Privacy Commissioner (OPC)priv.gc.ca

Internal Complaint Process: Before filing with a regulator, we encourage you to contact us first at projectnabu.support@gmail.com. We will acknowledge receipt within 7 business days and provide a substantive response within 30 calendar days.