PRIVACY

What Nesso holds about you

Nesso is a record of what you checked at a viewing. Almost everything it holds is that record. Analytics and advertising are not live yet — this notice is rewritten before either is, and nothing it learns about you is sold to anybody.

Last updated: 8 September 2026

1. Who is responsible for your data

The data controller is the operator of Nesso, identified at the end of this page. Write to the address given there about anything in this notice, including any of the requests described in section 11.

No Data Protection Officer has been appointed. GDPR art. 37(1) asks for one where the core activity is large-scale regular and systematic monitoring of people, or large-scale processing of the special categories in art. 9. Nesso does neither — see section 6 — so an appointment is not required. If that changes, this section changes with it.

2. What this notice covers

The Nesso web application and the native shells built from it. Nesso is a beta service, currently covering Torino, offered to people considering renting or buying a home for themselves.

Nesso holds no property listings and has no relationship with any estate agent, agency or portal. Nothing you record is offered to one.

3. What we hold

Your account
Your e-mail address, a password hash (scrypt — the password itself is never stored and cannot be recovered from the hash), when the account was created, when you last signed in, and whether the address has been confirmed.
Your signed-in browsers
One row per browser you sign in from: a truncated user-agent string, when it was created, when it was last seen, and whether it has been revoked. This is what lets you end a session on a phone you no longer have.
What you record about a property
The address you enter, anything you paste or type from an advertisement, the verdicts you tap against each check, the notes and readings from a property check, the priorities you set, and the decision you record at the end.
Readings your phone takes
Numbers only: a noise level in decibels, a tilt angle in degrees, a compass bearing, a distance. See section 5 for what happens to the microphone and camera themselves.
Photographs you choose to send
A photograph is kept only if you press send on it. What is then held is the image itself, its size, four measurements of the picture as a file — how bright and how sharp it is — which check it belongs to, and the date it stops being kept. The file is named so that it identifies nobody. A photograph you do not send is never stored, because no copy of it is ever made.
Photographs from advertisements
A fingerprint of images that appear on adverts, so the app can tell you an image has been used on other adverts too. The count is all that is ever shown: which other properties, and whose, is never disclosed to anybody.
Product events
A small first-party log of which steps were reached — a property check started, a comparison opened — keyed to your session identifier. It records that a step happened, never what you found there. There is no third-party analytics service involved.
Security records
Sign-in, sign-up and password-reset attempts, kept briefly so that repeated attempts can be slowed down. One-time links sent to you are stored only as a SHA-256 digest, so a copy of our database contains no usable link.
Server logs
Our hosting provider keeps ordinary request logs, which include IP addresses, for a short period. We do not use them to build a picture of anybody.

4. What runs today, and what does not yet

  • Not live yet: advertising, an advertising network, a pixel for it, or a third-party cookie set on its behalf.
  • Not live yet: an analytics vendor, a tag manager or session recording. The product log we keep today is our own, in our own database, and reaches nobody outside it.
  • No sale of personal data, and no sharing of it with estate agents or agencies.
  • No profile is built about you across other websites, because nothing of ours runs on any.
  • The web fonts are served from our own domain, so loading a page contacts no font provider.
  • The map tiles are served from our own domain, so panning the map contacts no map vendor.

5. The microphone, the camera and the motion sensors

A property check asks your phone for the microphone, the camera and the motion sensors. Your browser asks your permission first, and you can refuse each one; the walk continues without the step that needed it.

The camera is different, and the difference is a second tap. Taking a photograph holds a still frame on your screen and nothing more — the shutter reaches no network. A separate control sends that frame to us, and until you press it the picture has not left the device. Sending is never automatic, never a side effect of taking the picture, and never remembered as a preference for the next one.

A photograph you send was created by the camera at the moment you took it, so it carries no location, no device model and no timestamp of its own — and there is no way to attach one from your gallery instead. It is stored under a name that identifies nobody: not you, not your session, not the address. You can remove it from the same screen you sent it from, and it is deleted on its own after the period in section 11.

A photograph you send is read by an automated model. Section 8 says what it may report and what it may never report; the short version is that it can tell you something is visible and can never tell you that nothing is wrong.

Nesso does not read your device location. An address is one you type; it is turned into coordinates on our server, so the lookup carries our address and not yours.

6. Why we hold it, and on what legal basis

PurposeLegal basis (GDPR art. 6)
Keeping the record you make, and showing it back to youPerformance of a contract — art. 6(1)(b)
Creating and running your account, confirming your address, resetting a passwordPerformance of a contract — art. 6(1)(b)
Keeping the session that holds an anonymous record togetherPerformance of a contract — art. 6(1)(b), and art. 122(1) of D.lgs. 196/2003 for the cookie itself
Slowing down repeated sign-in attempts, and limiting outbound requestsLegitimate interest in protecting the service and its users — art. 6(1)(f)
Counting which steps of the product are reachedLegitimate interest in knowing whether the product works — art. 6(1)(f)
Detecting that a photograph is reused across advertisementsLegitimate interest in telling users something about an advert — art. 6(1)(f)
Answering a request you make under section 11, and keeping a record that we didLegal obligation — art. 6(1)(c)

Where we rely on a legitimate interest, we have weighed it against your interests and rights. The two that matter: the product log records that a step was reached and never what you found there, and the photograph count is a fact about an advertisement rather than about any person. You can object to either at any time under art. 21 — see section 11.

Providing an e-mail address is necessary to have an account, because it is what lets you sign in again and recover access. Everything else you enter is your choice, and a property check works with any part of it left blank.

7. No special-category data, and nothing about health

Nesso is not a health product and holds none of the special categories in GDPR art. 9. It asks nothing about your health, your origin, your beliefs, your politics, your union membership, your sex life or your orientation, and it holds no biometric or genetic data.

A noise level in decibels is a measurement of a room. A tilt angle is a measurement of a floor. Neither is a measurement of a person, and neither is used as one.

Nesso holds no criminal-offence data under art. 10. Where the app shows a crime index, it is a published statistic covering an entire province and is not about any individual.

8. Scores, bands, and automated decisions

Nesso computes a score and a band — good, conditional, avoid — for a property and for an area. The score is derived every time it is shown, is never stored, and always prints where each part of it came from, how confident it is, and what could not be checked.

The weights the score uses are the ones you set yourself on the priorities screen. Change them and the score changes, with nothing written to the database.

Separately, a photograph you choose to send is read by an automated model, which returns a short list of things that are visibly present in the frame — a patched area, a stain, a lifted edge, a line in a surface — each one beside a question to ask about that part of the room. It is given the image and its instruction, and nothing else: no address, no account, no session identifier, and nothing you have recorded elsewhere.

Nothing the model returns is stored. It is shown once, beside the frame, and the record of the check remains the verdict you tap yourself. Like the score, this is processing about a property and not about you: it produces no legal effect on you, GDPR art. 22 does not apply, and nobody is profiled by it.

9. Who else touches it

A small number of suppliers process data on our instructions, under a contract required by GDPR art. 28. They are not permitted to use it for anything of their own.

Hosting and delivery
Our hosting provider runs the application and its request logs, and serves the static files. Data is stored in the European Union.
Database
A managed PostgreSQL service holds the records described in section 3, in the European Union.
E-mail delivery
Resend delivers the confirmation and password-reset messages. It receives your e-mail address and the text of the message, which contains a one-time link and nothing else about your account.
OpenStreetMap
The Nominatim service is used as a fallback when our own address gazetteer cannot resolve an address. The request is made by our server, so it carries our address and not yours, and it contains the property address only.
Photograph storage
Cloudflare holds the photographs you choose to send, in a bucket pinned to the European Union jurisdiction, under file names that identify nobody.
The model that reads a photograph
Anthropic receives a photograph you send, and its model returns the list described in section 8. It is sent the image and our instruction and nothing else about you or the property. It processes on our instructions and not for any purpose of its own.

We will also disclose data where a law or a lawful order of an Italian or EU authority requires it. There is no other disclosure: no agent, no agency, no portal, no data broker, and no advertiser.

10. Transfers outside the European Economic Area

The records themselves are held in the European Union, photographs included. Two suppliers are established in the United States. Resend, which delivers e-mail, means that sending a confirmation or a password-reset message transfers your e-mail address outside the EEA. Anthropic, whose model reads a photograph you choose to send, means that the photograph is transferred outside the EEA for as long as that one request takes — it is not stored there by us, and nothing identifying you or the property goes with it.

That transfer is made under the European Commission Standard Contractual Clauses adopted by Decision (EU) 2021/914 (GDPR art. 46(2)(c)), together with the supplier certification under the EU–US Data Privacy Framework where it applies. You can ask us for a copy of the clauses using the address at the end of this page.

11. How long we keep it

The session cookie
180 days from when it is set, and it is renewed while you keep using Nesso.
Your account and your records
For as long as the account exists. You can delete it at any time from the account screen.
A signed-in browser
Until you sign it out, or until you use log out everywhere, or until you reset your password — which ends every session including the one that asked.
One-time links
One hour for a password reset, one day for an address confirmation, and in both cases only as a digest. A link stops working the moment it is used.
A photograph you sent
Thirty days, unless the screen says otherwise at the moment you send it. The period is fixed then and there, so a later change to it can never extend the life of a photograph you were told would be gone in a month. You can remove one yourself before then. Deleting your account does not delete them either, for the reason in the note below — but unlike the rest of your records, they do go on their own when the thirty days are up.
Sign-in attempt records
Minutes. They are pruned as they are counted.
Product events
Up to 24 months, then removed.

12. Your rights

Under GDPR arts. 15 to 22 you may ask us for any of the following, free of charge. We answer within one month, and tell you if we need longer and why.

  • A copy of what we hold about you, and confirmation of whether we hold anything (art. 15).
  • Correction of anything inaccurate, and completion of anything incomplete (art. 16).
  • Erasure of what we hold, including the records described in the notice above (art. 17).
  • Restriction of processing while a dispute about accuracy is resolved (art. 18).
  • A machine-readable copy of what you gave us, or its transfer to somebody else (art. 20).
  • Objection to any processing we base on a legitimate interest, including the product log (art. 21).
  • Withdrawal of any consent you have given, at any time, without affecting what was done before (art. 7(3)).

You can also complain to the Italian supervisory authority: Garante per la protezione dei dati personali, Piazza Venezia 11, 00187 Roma, garante@gpdp.it, protocollo@pec.gpdp.it, www.garanteprivacy.it. You may complain to the authority in the EU country where you live or work instead, and you may go to court in either case.

13. How it is protected

  • Passwords are stored as scrypt hashes with a per-password salt, never as text.
  • Both cookies are HttpOnly, so no script on the page can read them, and SameSite=Lax, so a cross-site request cannot act as you.
  • Every connection uses TLS, and the cookies are marked Secure in production.
  • A signed-in browser can be revoked one at a time or all at once, and a password reset revokes all of them.
  • One-time links are stored only as a digest, so a stolen copy of the database contains none of them.
  • Access to the database is limited to the application and to the people who operate it.

These are the measures GDPR art. 32 asks for, given what Nesso holds. No measure makes a breach impossible; if one happens and it is likely to be a risk to you, we will notify the Garante within 72 hours and tell you where art. 34 requires it.

14. Age

Nesso is for adults deciding where to live. It is not directed at children and we do not knowingly create accounts for anyone under 18. If you believe a child has made an account, write to us and we will remove it.

15. Changes to this notice

The date at the top is when this version was written. If we change how we process anything in a way that affects you, we will say so on this page before the change takes effect, and by e-mail if you have an account and the change is significant.

Yulia Sushkova · Borgata Levrette, 31, 10094 Valgioie TO, Italy · info@nesso.fit