Privacy Policy
Effective 26 July 2026
Information NabiCat handles
NabiCat stores information you provide when creating an account and using its tools, including goals and their descriptions, dates, states, progress logs, and relationships. Authentication credentials are stored in protected form.
When you connect ChatGPT, NabiCat stores OAuth access, refresh, consent, and idempotency records needed to authenticate requests and safely process retries. Server logs may include request metadata such as time, route, account identifier, and IP address. Secrets and tokens are redacted from application request logs.
How information is used
Information is used to operate NabiCat, authenticate you, return your data to authorised clients, process changes you request, prevent duplicate writes, maintain security, diagnose failures, and create recoverable backups. NabiCat does not sell personal information.
ChatGPT access
After you approve OAuth access, ChatGPT can read and modify your goals through the NabiCat Actions API on your behalf. Write actions include creating and updating goals, completing goals, and appending progress logs. Access can be revoked from your NabiCat account.
Storage and retention
Goal data is stored on the NabiCat server. Short-lived authentication and request-control records are stored in Redis and expire automatically. Account data remains until you delete it or ask the site administrator to remove it. Backup copies may remain temporarily until normal backup rotation removes them.
Sharing and external services
NabiCat shares data only as needed to provide features you request, comply with law, protect the service, or communicate with an external client you authorise. When you use ChatGPT Actions, information included in requests and responses is also handled by OpenAI under its own terms and privacy policy.
Your choices
You can review and change your goals, revoke ChatGPT access, or delete your NabiCat account using the account controls. Account deletion removes active account data and revokes associated OAuth tokens, subject to temporary backup retention.
Security and changes
NabiCat uses access controls, signed sessions, OAuth bearer tokens, encrypted transport, rate limiting, and process-safe data locking. No system can guarantee absolute security. This policy may be updated as the service changes; the effective date above will be revised when material changes are made.