Skip to content

Privacy Policy

Last revised: February 2026

This Privacy Policy describes how and when Nilum Tech AB ("Nilum", "us", "we", "our") collects, uses, shares, and protects the personal information ("information") of our users ("you" or "User(s)") when you use our mobile application and related services (collectively, the "Services" or "Nilum").

Nilum is a second-hand marketplace aggregator. We collect and present second-hand product listings from various online sources in our iOS application, allowing you to discover and access listings across multiple platforms. When you click on a listing, you are redirected to the original source where the listing is hosted.

By using our Services, you acknowledge the collection, transfer, storage, disclosure, and other uses of your information as described in this Privacy Policy. The legal bases for our processing of your personal data are set out in Section 6 below. If you do not agree with this Policy, please do not use our Services.

1. What This Privacy Policy Covers

This Policy covers the handling of personal data that Nilum gathers when you access and use our Services. We explain what information we gather, why we gather it, the legal basis for processing, and the choices you have regarding your personal information.

2. Information We Collect

We may collect and process the following types of information when you use our Services:

2.1 Personal Information

Personal information is data that can identify you as an individual. This includes information you provide to us directly, such as:

  • Your name and email address when you create an account
  • Profile information you choose to add to your account
  • Communications you send to us (e.g., support requests or feedback)
  • Any other information you voluntarily provide to us

2.2 Automatically Collected Information

When you use our Services, we automatically collect certain technical and usage information, including:

  • Device information (device type, operating system, unique device identifiers)
  • App usage data (features used, listings viewed, clicks on external listings)
  • IP address
  • Log data (access times, pages viewed, referring URLs, crash reports)
  • Information collected through cookies, pixels, and similar technologies

3. How We Collect Information

3.1 Information You Provide

We collect personal information when you register for an account, update your profile, contact our support team, or otherwise interact with our Services. You may choose not to provide certain information, but this may limit your ability to use some features of our Services.

3.2 Information Collected Automatically

Our Services automatically collect usage and technical information when you interact with the app. This data helps us understand how Users engage with our Services, identify popular listings and features, and improve the overall experience. We use this data primarily in aggregated or anonymised form.

3.3 Information from Third Parties

We receive product listing data from third-party platforms whose listings we aggregate. This data relates to the products and listings themselves and does not include personal data about our Users.

4. Cookies and Similar Technologies

We use cookies and similar technologies in connection with our Services. A cookie is a small text file placed on your device that helps us recognise you and remember your preferences.

We only use strictly necessary cookies. These are essential cookies required to keep you logged in and for the Services to function properly. We do not use analytics, advertising, or any other non-essential cookies.

Because these cookies are strictly necessary for the operation of our Services, they cannot be disabled. If you block these cookies through your browser or device settings, some features of our Services may not function correctly. Since we do not use any non-essential cookies, no cookie consent banner is required or displayed.

5. How We Use the Information We Collect

We use the information we collect for the following purposes:

  • To provide, operate, and maintain our Services
  • To personalise your experience, including showing relevant second-hand listings
  • To process your account registration and manage your account
  • To communicate with you, including responding to inquiries and sending service-related notices
  • To send you promotional communications (with your consent, where required)
  • To analyse usage trends and improve our Services, features, and content
  • To detect, prevent, and address fraud, security issues, and technical problems
  • To comply with legal obligations and enforce our terms and policies
  • To facilitate affiliate referrals when you click through to external listings

6. Legal Basis for Processing (GDPR)

Under the General Data Protection Regulation (GDPR), we process your personal information based on one or more of the following legal grounds:

  • Contractual necessity: Processing is necessary to perform our contract with you (e.g., providing the Services you requested).
  • Consent: You have given us explicit consent to process your personal information for specific purposes (e.g., marketing communications).
  • Legitimate interests: Processing is necessary for our legitimate interests (e.g., improving our Services, fraud prevention), provided these interests are not overridden by your rights and freedoms.
  • Legal obligation: Processing is necessary to comply with applicable laws and regulations.

7. Information We Share With Third Parties

We share your personal information only as described in this Policy and in the following circumstances:

7.1 Affiliate and Marketplace Partners

When you click on a listing in our app, you are redirected to the external marketplace where the listing is hosted. These marketplace partners may collect information about your visit in accordance with their own privacy policies. We do not share any personal data with our affiliate or marketplace partners.

7.2 Service Providers

We use third-party service providers for hosting and infrastructure to operate our Services. These providers process data on our behalf under contractual obligations that restrict them from using it for any other purpose. We do not share personal data with third parties for their own independent use.

7.3 Legal Requirements

We may disclose your personal information if we believe in good faith that such disclosure is necessary to:

  • Comply with applicable law, regulation, legal process, or governmental request
  • Enforce our Terms and Conditions and this Privacy Policy
  • Detect, prevent, or address fraud, security, or technical issues
  • Protect the rights, property, or safety of Nilum, our Users, and the public

7.4 Business Transfers

If Nilum is involved in a merger, acquisition, reorganisation, or sale of assets, your personal information may be transferred as part of that transaction. We will notify you of any such change and any choices you may have regarding your information.

8. Data Storage and Security

Your information is stored on secure servers within the European Economic Area (EEA). We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction.

While we take reasonable precautions, no method of transmission over the internet or electronic storage is completely secure. We cannot guarantee the absolute security of your information.

9. Data Retention

We retain your personal information only for as long as is necessary to fulfil the purposes described in this Policy, unless a longer retention period is required or permitted by law. Specifically:

  • Account data: Retained for the duration of your account. When you delete your account, your personal data is deleted immediately from our active systems.
  • Log data: Retained for 90 days, after which it is automatically deleted.
  • Essential cookies: Session cookies expire when you close the app or log out.

When your information is no longer needed, we will securely delete or anonymise it.

10. Your Rights Under the GDPR

As a data subject under the GDPR, you have the following rights regarding your personal information:

  • Right of access: You have the right to request a copy of the personal information we hold about you.
  • Right to rectification: You have the right to request correction of inaccurate or incomplete personal information.
  • Right to erasure: You have the right to request deletion of your personal information, subject to certain legal exceptions.
  • Right to restrict processing: You have the right to request that we limit the processing of your personal information in certain circumstances.
  • Right to data portability: You have the right to receive your personal information in a structured, commonly used, machine-readable format.
  • Right to object: You have the right to object to the processing of your personal information based on legitimate interests or for direct marketing purposes.
  • Right to withdraw consent: Where processing is based on your consent, you have the right to withdraw that consent at any time without affecting the lawfulness of prior processing.

To exercise any of these rights, please contact us at legal@nilum.ai with the subject line "GDPR Request". We will respond to your request within 30 days.

You also have the right to lodge a complaint with a supervisory authority. In Sweden, the relevant authority is Integritetsskyddsmyndigheten (IMY).

11. Account Deletion

You may delete your account at any time directly from the Settings page in the Nilum iOS app, or by emailing us at support@nilum.ai. Upon deletion, we will remove your personal information from our active systems. Please note that some information may be retained in archived or backup systems for a limited period as required by law or for legitimate business purposes. Any public activity associated with your account prior to deletion may remain visible.

12. Marketing Communications

With your consent, we may send you promotional communications about products, features, and events that may interest you. You can opt out of marketing communications at any time by:

  • Clicking the "unsubscribe" link in any marketing email
  • Adjusting your notification preferences in the app settings
  • Contacting us at legal@nilum.ai

Please note that even after opting out of marketing communications, you will continue to receive transactional and service-related messages related to your account.

13. Children's Privacy

Our Services are not directed at children under the age of 16. We do not knowingly collect personal information from children under 16. If we become aware that we have collected personal information from a child under 16, we will take steps to delete that information as promptly as possible. If you believe we may have collected information from a child under 16, please contact us at legal@nilum.ai.

14. Third-Party Links and Services

Our Services contain links to external marketplaces and other third-party websites. When you click on a listing or external link, you leave our Services and are subject to the privacy policies of those third parties. We are not responsible for the privacy practices of external sites and encourage you to review their policies before providing any personal information.

15. Automated Decision-Making

We do not use automated decision-making or profiling that produces legal effects or similarly significant effects on you. All decisions that may affect your use of our Services are made with human involvement.

16. Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority (IMY) within 72 hours of becoming aware of the breach, as required by GDPR. If the breach is likely to result in a high risk to you, we will also notify you without undue delay and provide information about the nature of the breach and the steps we are taking to address it.

17. International Data Transfers

Nilum Tech AB is based in Sweden. Your personal information is primarily processed and stored within the EEA. If we transfer your data outside the EEA, we will ensure appropriate safeguards are in place, such as Standard Contractual Clauses approved by the European Commission, to protect your information in accordance with applicable data protection laws.

18. Changes to This Policy

Nilum reserves the right to update this Privacy Policy from time to time. If we make material changes to how we handle your personal data, we will notify you through the app or by email. All other changes are effective as of the "Last Revised" date stated at the top of this Policy, and your continued use of the Services after that date constitutes acceptance of the updated Policy.

19. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:

Nilum Tech AB Org. nr: 559552-5907 Tulegatan 28, 113 53 Stockholm, Sweden Email: legal@nilum.ai

We will make every effort to address your concerns promptly.