Privacy Policy
Last updated: Aug 20, 2026
Nectvia is built on the idea that your professional history belongs to you. That only means something if we are precise about what we hold, so this policy describes what the software does.
Who we are
Nectvia is operated by:
Lance Haig, Faehlmannweg 12A, 14089 Berlin, Germany
For anything in this policy, including a request about your own data or about data we hold on someone else, write to us at privacy@nectvia.work.
What we collect
When you create an account
- Your username, email address, full name and chosen interface language.
- Your password, stored only as a bcrypt hash. We never hold the password itself and cannot recover it for you.
On your profile
Your headline, summary, location, industry, profile picture and LinkedIn address, as far as you choose to fill them in. If you connect an AT Protocol identity, we also store its DID (a permanent identifier) and its handle.
What you write
Posts, articles, comments, likes and direct messages.
Verifying a work email address
To confirm where you work, we email a code to your work address. We store the address, its domain, and a hash of the code. The code itself is never stored.
Feedback you send us
A feedback report carries your user identifier, never your email address, along with the page you were on, the app version, your interface language and your browser window size.
If an administrator forwards a report to our public issue tracker, the text you wrote is copied across word for word. Please do not put anything in a report that you would not want to appear in a public bug report.
Technical data
Every request to Nectvia is written to a server log recording the time, the page, the response status and your IP address. Administrator actions are logged the same way.
Our rate limiters, which are what stops someone guessing passwords, also key on your IP address, held as it is for up to an hour. Where a rate limiter keys on an email address instead, it stores only a hash of it.
Server logs roll over: we keep roughly the last 30 MB and older entries are discarded automatically. How long that covers depends on how busy the site is, so we cannot honestly give you a figure in days.
If you join the waitlist
We store your email address, the language you were reading the site in, whether you have been let in yet, and a hash of your invitation token. Storing only the hash means that reading our database is not enough to let someone in.
If an existing member gave you an invite code, that code records nothing about you until you actually register. We never built a feature to email an invitation, because it would have meant holding your address and your relationship to someone else before you had agreed to anything.
Data about other people
If you import your LinkedIn data export, that file contains information about other people. For each of your connections we store:
- their name
- their LinkedIn profile address
- their email address, where LinkedIn included one
We do not store their headline, their employer or their job title, even though those columns are in the file.
From the same export we also store your LinkedIn invitations, your LinkedIn message history, which includes both parties' names and profile addresses and the full text of the messages, and endorsements.
What we do with it
We use those email addresses and profile addresses to match people to accounts. If someone imported a file containing your email address, and you later register with that address, Nectvia will automatically create a connection between you and them. This works in both directions, and it happens without either of you choosing it.
If you are one of those people
If you have never signed up for Nectvia, someone else's import may still mean we hold your name, your profile address and your email address. You did not agree to that.
You can ask us what we hold about you, and ask us to delete it, by writing to privacy@nectvia.work. We will do it. You do not need an account, and you do not need to explain why.
When a member deletes their Nectvia account, every contact record from their import is deleted with it.
What we never collect
- We do not track who looks at your profile. There is no such record anywhere in the system.
- We hold no salary information about you. Where a salary range appears on Nectvia, it is a range an employer advertised on a job listing.
- We run no analytics, no advertising and no third-party trackers. Nectvia's content security policy permits scripts from our own servers and nowhere else. There is no analytics service, no advertising pixel, no session recorder and no tracking cookie.
- We do not sell your data, and we do not share it for advertising.
Where your data goes
- Our database runs on a server in Germany, hosted by Hetzner.
- Images you upload are stored in Hetzner Object Storage in Nuremberg, Germany, and served through Nectvia.
- Email we send you goes out through our email provider.
- Payments, where you make one, are handled by Mollie. We send Mollie your name and email address so that it can process the payment. We never see or store your card details.
- Our issue tracker, if an administrator forwards your feedback there, as described above.
- Your own AT Protocol repository, described below.
- If you link an AT Protocol identity, resolving it involves a lookup against the public PLC directory and against your own provider.
Publishing to your own AT Protocol repository
Nectvia can copy some of your data into a personal data server that you control, so that it is yours independently of us.
- It is off by default. Nothing is ever written to your repository until you switch it on.
- It is per type. You choose separately whether to publish your profile, your posts, your positions, your education, and so on.
- Your repository is public. Anything published there can be read by anyone who has the address, including people who do not use Nectvia.
- Some things can never be published, by design. Your direct messages, pending connection requests and job applications have no route to your repository at all. This is not a setting you could switch on by accident: the capability does not exist, and an automated test fails if anyone adds it.
Why we are allowed to hold this
We process your data to run the service you asked us to run: your account, your profile, your content and your connections.
We process technical data, meaning IP addresses in logs and in rate limiters, to keep the service available and to defend it against abuse.
We process data about people who are not members, arriving through members' imports, to provide the connection features described above. Where that concerns someone who never signed up, that section explains how to have it removed.
Your rights
You can:
- See your data. Most of it is visible in the app.
- Take a copy of it, from your settings. We prepare an archive of everything we hold about you and email you a link.
- Correct it, by editing your profile and your content.
- Delete it, by deleting your account.
- Ask us anything about it, at privacy@nectvia.work.
The export arrives as CSV and JSON, with a plain-text file explaining what each part contains and which parts include information about other people. The download link works only while you are signed in to your account, and both the link and our copy of the archive expire after 72 hours. Ask for another whenever you like.
Deleting your account
Deleting your account is permanent and immediate. There is no grace period and no recovery. Your profile, posts, articles, comments, messages, connections, imported history and uploaded images are erased from our database in a single operation, not merely hidden.
Two things are kept in a deliberately anonymised form, because they are not only about you:
- If you posted a job and reviewed someone's application, the application stays, because it is the applicant's data rather than yours, with your name removed from it.
- If you joined using someone's invite code, that code stays marked as used, with the link to you removed. Otherwise deleting your account would bring a spent code back to life.
What deletion does not touch
Anything already published to your own AT Protocol repository stays there. That repository belongs to you, not to us, and emptying it is not ours to do. If you want those records gone, remove them through your provider or through another AT Protocol application.
Leaving Nectvia does not un-publish what you chose to publish.
How long we keep things
- Account data: until you delete your account.
- Server logs: a rolling window of roughly the last 30 MB.
- Rate-limit records: between one minute and 24 hours, depending on the limit.
- Verification codes: they expire, and only ever existed as hashes.
- Waitlist entries: until you register or ask us to remove you. If you register, the entry is deleted along with your account when you delete it.
Content we show but do not host
A company can connect its own AT Protocol account to its Nectvia page. When it does, we read what that account publishes and show it on the company's page and in the feeds of people who follow it. We do not copy it: we store only the address of each record and fetch the content from the company's own server each time it is shown.
That content belongs to the company and lives on infrastructure we do not run. We cannot edit or delete it. If the company deletes a record, it stops appearing here; if the company disconnects its account, everything from it stops appearing here.
We can stop showing an individual record on Nectvia, and we will do so where it breaks our terms or the law. That only hides it from Nectvia. The record itself stays where its author published it, and anyone reading that account directly can still see it. To have something removed at the source, you need to contact whoever published it or the provider hosting their account.
Changes to this policy
If we change what we collect or what we do with it, we will change this policy and update the date at the top. That date reflects when the document changed, not when you loaded the page.
Contact
Write to us at privacy@nectvia.work.
This document is published in several languages. Where a translation and the English version differ, the English version is the one that applies.