Privacy policy
What data Nabiora processes and why the current platform needs it.
Last updated: July 25, 2026
Document status
This document is a product working draft and is not final legal advice.
Nabiora is operating as a beta platform; the operator and official legal details will be published separately when the service is ready for public release.
Current product behavior
Nabiora uses Supabase Auth for sign-in and sessions, PostgreSQL with RLS for data, and Supabase Storage for listing photos.
The project includes profiles, listings, photos, favorites, buyer-seller messages, notifications, reports, manual moderation, and audit logs for administrative actions.
Automatic listing translation runs only when the feature flag and external DeepL provider are configured; quotas and fallback behavior exist, and translations may be unavailable.
A production email provider, analytics, and advertising trackers are not currently wired in the codebase.
Data processed
Supabase Auth account data, profile, language, phone or WhatsApp when provided, avatar, listings, prices, city/district location, photos, messages, favorites, notifications, and reports are processed.
Server logs, security/audit data, and administrative actions are used for protection, diagnostics, and moderation.
Listing text may be sent to an external translation provider when translation is enabled.
What is not currently used
The codebase currently has no production email provider, analytics SDK, or advertising tracking pixels.
If those services are added later, these documents and cookie controls must be updated before non-essential scripts load.
Retention and access
Data is stored in Supabase PostgreSQL and Storage with RLS policies separating public, user, and staff access.
A separate privacy email is not published yet; privacy requests are handled through the available platform support channels.
