Legal

Privacy policy

Last updated 9 September 2026

Who we are

NaVi (navi.how) is a cross-border work information service operated from the Netherlands. For anything in this policy, contact us at spartan.int@gmail.com. We answer privacy questions ourselves, not through a form that goes nowhere.

What we collect, and why

Your assessment answers. The country, date and work questions you fill in exist to compute your report. They are the product. Anonymous assessments are stored under a random claim token, not under your name.

Account data. If you create an account: your email address, a display name, and a password hash (we never store the password itself) or a link to your Google account if you sign in with Google. Signing in lets you keep reports and claim anonymous ones you made earlier.

Beta and contact data. If you join the beta list or send an enterprise inquiry: the name and email you give us, used to contact you about exactly that and nothing else.

Purchase data. Payments run entirely through Stripe. We receive a confirmation, the amount and your email for the receipt and unlock codes. Your card number never touches our servers.

Copilot questions. If you ask the report copilot a question, that question and your report's findings are processed by our AI provider to produce the answer. Ask it nothing you would not put in the report itself.

Technical logs. Standard server logs (IP address, time, requested page) for security and abuse prevention, rotated, not mined.

What we do not do

We do not sell or rent your data. We run no advertising trackers. We do not read your assessments for anything except showing them to you and improving the rules engine in aggregate. Product analytics, when enabled, measure which pages and steps are used, not who you are.

Where your data lives

Our servers run in Frankfurt, Germany (Hostinger), inside the EU. Some processors below may process data outside the EU under their own EU-approved safeguards.

Processors we use

Each of these touches only what its job requires:

  • Hostinger - hosting and databases (Frankfurt, EU).
  • Stripe - payment processing and receipts.
  • Anthropic - the AI layer that turns your computed findings into the written summary and answers copilot questions.
  • Google - only if you choose to sign in with Google, for that sign-in alone.
  • Resend - transactional email (magic links, reminders), when email features are active.

Cookies and storage

We set what the product needs and nothing more: a session cookie when you log in, a beta-access cookie when you enter the access code, a language preference, and a short-lived state cookie during Google sign-in. Your browser's local storage may hold conveniences like a draft assessment or which report steps you ticked off. No third-party advertising cookies, no cross-site tracking.

How long we keep things

Anonymous reports expire with their claim link. Account data stays until you delete your account or ask us to. Purchase records are kept as long as tax law requires (seven years in the Netherlands). Beta list entries are deleted when the beta ends or on request.

Your rights

Under the GDPR you can ask for access, correction, deletion, a portable copy, or restriction of your data. Mail spartan.int@gmail.com and we act on it, no forms, no friction. You can also complain to the Dutch data protection authority, the Autoriteit Persoonsgegevens.

Changes

When this policy changes materially we update the date above and, for account holders, say so in the product. We never quietly widen what we collect.

See also our Terms of Service.