← Back to pricing

Privacy Policy

Last updated: July 2026

This page explains what NeverMessy collects, why, how long we keep it, and what you can do about it. We've tried to write it the way we'd want to read it — short, plain, no legal wall.

Who we are

NeverMessy (nevermessy.com) is operated by NeverMessy, 4 Ul Vit, Simeonovo, Bulgaria. Contact: hello@nevermessy.com. We are the data controller for the information described below.

What we collect

Account information: your email address, a hashed password (we never store or see your actual password), your display name, and your language preference.

Zones and tasks: the names you give your zones (e.g. "Kitchen", "The garage") and your daily task completion history, so the app can track your streak and assign tomorrow's task.

Before/after photos: if you choose to take them. Photos are private by default and stored outside our public website folder — nobody can view them without either being you (signed in) or you explicitly choosing to share that specific pair to the public gallery. Sharing is opt-in, per photo, and reversible any time from "My transformations" in the app. A shared pair appears in the public gallery and may also be included in a weekly email to other NeverMessy users.

The quiz: nothing. The quiz runs entirely in your browser — your answers are never sent to us, never stored, and disappear when you close the tab. You don't need an account or an email address to take it or to see your result.

Payment information: handled directly by Stripe. We never see or store your card number. Stripe tells us only whether a subscription is active, which plan it is, and when it renews.

Sign-in security data: if you set up fingerprint/Face ID sign-in, your device creates a security credential and we store the public part of it — we never receive or store your actual fingerprint or face data, that never leaves your device.

Push notification data: if you enable reminders, your browser gives us a subscription endpoint so we can send that one notification. We don't use this for anything else.

Basic technical data: your IP address is used momentarily for spam prevention on signup forms and is not stored longer than necessary for that purpose.

Why we're allowed to process it

Under the GDPR we have to tell you the legal basis for each thing we do with your data. Ours are:

WhatWhy we may process it
Account, zones, tasks, streaksPerformance of our contract with you — this is the service you signed up for.
Subscription and payment statusPerformance of our contract, and our legal obligation to keep accounting records.
Before/after photos (private)Performance of our contract — an optional feature of the app you chose to use.
Sharing a photo to the public galleryYour consent, given per photo, withdrawable at any time.
Push remindersYour consent, given when you enable them, withdrawable at any time.
Fingerprint/Face ID credentialYour consent, given when you set it up.
IP address for signup spam preventionOur legitimate interest in keeping the service usable and free of automated abuse.
Account and service emailsPerformance of our contract.

Where we rely on your consent, you can withdraw it at any time, and doing so doesn't affect anything we did before you withdrew it.

How we use it

To run the app: show you your tasks, remember your streak, serve your photos back to you, and send the emails you'd expect (password resets, an occasional weekly digest of shared before/afters, account-related notices). We do not sell, rent, or share your personal data with third parties for their own marketing purposes.

Who else touches your data

We keep this list as short as we can:

Data outside the EU

Your account data, zones, tasks and photos are stored on our own server in the EU and stay there.

Two things do leave the EU. Stripe and the browser push services named above are US-headquartered and may process data in the United States. Those transfers rely on the safeguards those providers put in place — standard contractual clauses and, where applicable, the EU–US Data Privacy Framework. If you'd rather not have push data leave the EU, simply don't enable reminders; everything else in the app works without them.

How long we keep it

Cookies

We use a small number of functional cookies only: one to keep you signed in, and (on nevermessy.eu) one to remember your language choice. No advertising cookies, no third-party tracking or analytics cookies. Because these are strictly necessary to provide a service you asked for, we don't show a consent banner — there's nothing to consent to.

Your rights

Under the GDPR you have the right to access your data, correct it, have it deleted, restrict or object to how we process it, receive a copy in a portable format, and withdraw any consent you've given. In practice:

Complaints

If you think we've handled your data badly, please tell us first at hello@nevermessy.com — we'd rather fix it. You also have the right to complain to a data protection supervisory authority. Ours is the Bulgarian Commission for Personal Data Protection (Комисия за защита на личните данни), 2 Prof. Tsvetan Lazarov Blvd., Sofia 1592, Bulgaria — cpdp.bg. If you live in another EU country, you can complain to your own national authority instead.

Changes to this policy

If this policy changes in a way that matters, we'll update the date at the top and, for significant changes, let you know by email.

Contact

Questions about this policy or your data: hello@nevermessy.com.