90 AI Technologies
SV

Privacy Policy

How Nitti AI AB handles information collected through Nitti.

Effective date: 21 September 2026

Protecting your privacy is important to us. Accordingly, we're providing this Privacy Policy to explain how Nitti AI AB (“Nitti AI,” “we,” “us,” or “our”) collects, uses, shares, and protects information when you use Nitti, our platform for reading and analysing the public record, including our website, workspace, API, agents, and related services, collectively referred to as the “Services.”

Nitti is a product provided by Nitti AI AB. This Privacy Policy applies to Nitti and does not apply to third-party websites, services, or applications that we do not control, even if they are accessible through our Services.

If you use Nitti through an organisation, such as your employer, client, or team, that organisation may control certain data associated with your account and workspace.

Information We Collect

We collect information that you provide directly to us, information generated when you use the Services, and information processed through our service providers.

This may include your name, email address, profile information, organisation, login information, workspace membership, the briefs and instructions you give to agents, assignment and agent-run activity, comments, uploaded documents, notification preferences, technical logs, IP address, device information, browser information, support requests, and other information you choose to provide through the Services.

If you join the waitlist on our website, we collect the email address you enter, the permission you gave, the exact wording of that permission in the language it was shown to you, the language of the page, and whether you told us you are a Reform Society customer. We keep the wording so that what you agreed to is on the record alongside the agreement itself.

If you purchase a paid plan, we and our payment processor also collect billing information needed to complete and manage the transaction. This may include billing name, billing address, country, tax identifiers where required, the last four digits and brand of the card used, subscription status, plan history, and invoices. Full card numbers and security codes are handled directly by our payment processor and are not stored by Nitti.

When you or your organisation use AI features or run an agent, we record metadata about each call, such as the model used, token counts, the AI credits charged, the documents read, and the workspace the run was made on behalf of. This usage data is used to operate the features, calculate billing, and prevent abuse.

Information From the Public Record

The material Nitti reads is drawn from the public record. It contains personal data about identifiable people, most often in their public capacity: elected representatives, candidates, officials, and the named authors and signatories of published documents. It may include names, party and organisational affiliation, roles and offices held, dates, and the positions those people have taken in public.

We did not collect this data from the people it concerns. We obtain it from published sources, including the Riksdag and other public bodies, and we structure it so that it can be searched and read.

Where this processing is subject to data protection law, we rely on legitimate interests: making the public record readable and searchable, so that people and organisations can follow and take part in public decision-making. We consider this proportionate because the material has already been published by a public body, and it concerns the public conduct of people acting in a public role.

Assessments produced by our agents are assessments against a customer's brief. They are not statements of fact about any person, and they are not judgements about anyone's character, motives, or private life. Customers are told this in the Services and are responsible for their own use of the results.

If you appear in the public record and have questions about how your data is processed in Nitti, you can contact us using the details below. Where the source document itself is inaccurate, the correction has to be made by the body that published it, and we will update our copy accordingly.

How We Use Information

We use information to provide, operate, maintain, secure, and improve the Services. This includes creating and managing accounts, authenticating users, running agents and assignments, storing and displaying customer content, delivering reports and notifications, providing support, communicating with users, analysing product performance, preventing abuse, and complying with legal obligations.

We may also use information to send administrative messages, product updates, security notices, and other communications related to the Services.

If you joined the waitlist, we use your email address to tell you about Nitti and related products, in the terms you agreed to. You can withdraw that permission at any time by replying to any email we send you.

Where required by law, we rely on appropriate legal bases for processing personal data, including performance of contract, legitimate interests, legal obligations, and consent.

Customer Content

You and your organisation retain ownership of the content you upload, create, or store in Nitti, including briefs, instructions, uploaded documents, and the reports agents produce for you. We do not claim ownership over your customer content.

We access customer content only as necessary to provide, secure, support, troubleshoot, improve, or maintain the Services, comply with applicable law, enforce our terms, or follow the instructions of the relevant customer organisation.

Sharing of Information

We do not sell personal data.

We may share information with service providers that help us deliver the Services, including hosting, authentication, database infrastructure, job execution, notifications, payment processing, AI model providers, security, analytics, support, and related operational functions.

We may also share information with the organisation that manages your workspace, with authorities where required by law, or in connection with a merger, acquisition, financing, restructuring, or sale of assets.

Connected AI Clients

You can connect an AI client, such as ChatGPT or Claude, to Nitti's MCP server at https://api.nitti.ai/v1/mcp. The connection is approved by one person for one organisation, grants read access only, and can never create, change, or delete anything.

When the connected client calls one of the read tools, Nitti runs the query against what the person who approved the connection can read while acting in that organisation, and returns the result to the client. Results include search snippets and verbatim passages from source documents, so they can contain personal data that appears in the public record, as well as your organisation's own content.

Nitti does not record what a connected client asks for: tool arguments and tool responses are not written to our database, and neither the text of a query nor the text of a result is written to our logs. The server keeps a request identifier and timing information, and, when a lookup finds nothing or a call errors, a diagnostic line that can include the identifier of the document or the underlying error. Rate limits are counted per person and organisation, not per query.

Once a result reaches the client, that client's own privacy policy and retention rules govern it, not this one. Disconnecting stops the client from calling Nitti; an access token that was already issued remains valid until it expires, and removing the person from the organisation ends access immediately.

Subprocessors

To support delivery of the Services, Nitti AI may use third-party subprocessors that process personal data or customer content on our behalf.

Our current key subprocessors for Nitti include:

  • Vercel Inc. — application hosting, serverless compute, and content delivery.
  • Neon, Inc. — managed Postgres database hosting.
  • Clerk, Inc. — user authentication, session management, and organisation membership.
  • Inngest, Inc. — durable execution of background and agent jobs.
  • OpenRouter, Inc. — routing of requests to large language model providers. Briefs, documents, and other inputs may be transmitted through OpenRouter to the model provider selected for a run in order to generate responses.
  • Pingram — delivery of email and in-product notifications.

We may update our subprocessors from time to time. Where required by law or contract, we will provide appropriate notice of material changes.

International Transfers

Nitti AI is based in Sweden, but some service providers may process information outside Sweden, the EU, or the EEA. Where this occurs, we use appropriate safeguards, such as standard contractual clauses, adequacy decisions, or other lawful transfer mechanisms.

Data Retention

We retain information for as long as necessary to provide the Services, comply with legal obligations, resolve disputes, enforce agreements, maintain security, and support legitimate business purposes.

Customer content is generally retained for as long as the relevant account, workspace, or subscription remains active, unless deleted earlier by the customer or required to be retained by law.

Material drawn from the public record is retained as part of the corpus for as long as we offer the Services, because the value of the record is that it can be read over time.

Waitlist sign-ups are retained until you withdraw your permission or we stop maintaining the waitlist.

Security

We take reasonable technical and organisational measures to protect information against unauthorised access, loss, misuse, alteration, or disclosure.

These measures may include access controls, tenant isolation, encryption, logging, monitoring, backups, and restrictions on employee and service provider access. However, no online service can be guaranteed to be completely secure.

Your Rights

Depending on where you are located and how your personal data is processed, you may have rights to access, correct, delete, restrict, object to, or receive a copy of your personal data. You may also have the right to withdraw consent where processing is based on consent.

Where we process your data on the basis of legitimate interests, including data drawn from the public record, you have the right to object to that processing.

If you use Nitti through an organisation, certain requests may need to be handled by that organisation as the controller of your workspace data.

You may also have the right to lodge a complaint with the Swedish Authority for Privacy Protection, Integritetsskyddsmyndigheten, or another competent data protection authority.

Cookies

We may use cookies and similar technologies to operate the Services, authenticate users, remember preferences, improve performance, analyse usage, and support security.

Where required by law, we will ask for consent before using non-essential cookies.

Children

The Services are intended for professional and business use and are not directed to children. We do not knowingly collect personal data from children.

Changes to this Privacy Policy

We may update this Privacy Policy from time to time. If we make material changes, we will provide notice through the Services, by email, or by other appropriate means.

Contact

If you have questions about this Privacy Policy or how Nitti handles personal data, contact Nitti AI AB at hello@nitti.ai.

© 2026 Nitti AI TechnologiesLegalPrivacy policy