no frontFor men with ADHD & burnout

Privacy

Privacy

Who we are

no front is based in Lisbon, Portugal and is the contact for privacy matters. Contact: hey@nofront.app.

What we collect, why, and on what legal basis

  • Application answers: your chosen pseudonym, email, country and time zone, which place you are asking for (Outta Orbit or Inna Orbit), the time you confirmed you are 18 or over, the time you acknowledged this notice, and two short answers about you and why you are here. Used so the founder can review your application. Basis: steps needed before a contract. The two confirmations are records that you ticked those boxes; they are not consent to marketing or to processing health information. Asking for a place is not an allocation, a charge or an approval. Deliberately minimal - no diagnosis proof, no clinical history.
  • International waitlist: your email, country, and the time you asked us to keep them. Used only to tell you when applications open where you live. Basis: your consent. It is not an application, membership approval, place allocation or marketing subscription, and you can ask us to remove it at any time.
  • Account data: email, pseudonym, settings, notification choices. Used to run your membership. Basis: the membership contract.
  • Community content: your posts, replies, saves and reports. Used to run and moderate the community. Basis: the contract, plus your explicit consent where content touches on health (see below).
  • Private check-ins and your saved list: for you only. These are private - the founder and admins cannot read them. Basis: the contract.
  • Payment: handled entirely by Stripe. We never see or store your card number. Basis: the contract; billing records are then kept as long as Portuguese tax law requires.
  • Technical data: server logs and strictly necessary cookies only - the ones the site needs to function. No analytics or advertising trackers. Basis: legitimate interest in a working, secure service. Under ePrivacy rules, strictly necessary cookies need no banner; if we ever add anything non-essential, a consent banner comes first.

Content that touches on health

no front is a peer support community, not a health service. But what you choose to write may mention health - a diagnosis, medication, a rough stretch. Under GDPR that is special-category data, and we treat it with the highest level of protection the law requires.

  • We process it only with your explicit consent, which you give when you join and which covers only what you yourself choose to post or record.
  • You can withdraw that consent at any time, and you can delete any post or check-in at any time. Deleting is immediate and permanent.
  • We do not treat the closed community as “public”. Your special-category content is never processed on the basis that you made it public.
  • Consents stay separate: community content, any future AI features, and any marketing each get their own consent. One yes never covers the others.

Pseudonymity - what we promise and what we do not

  • Inside the community you are known only by your pseudonym. So is the founder.
  • We do not promise absolute anonymity or end-to-end encryption. The operator can link your pseudonym to your account email, and legal obligations can require disclosure.
  • Other members are bound by the same rule: sharing your material or identity outside the community is a boundary breach.

What we never do

  • Sell your data.
  • Run advertising trackers.
  • Train AI models on member discussions or private check-ins without a specific, informed design and your explicit permission.

AI features

The optional AI companion is not active. Before any activation we will publish the exact model provider, where data goes, how long it is kept and how deletion works, and ask for separate consent. We prefer EU storage and processing where feasible, and we verify each supplier rather than assuming EU location from their branding.

The post builder and Mistral

  • “Shape this into a post” is optional. Nothing is sent unless you tick the notice and press the button, every single time.
  • When you do, your rough draft and the response type you picked are sent to Mistral AI (Paris, France) through its EU inference endpoint, api.eu.mistral.ai, so it can tidy the wording. Mistral is the AI processor for this feature.
  • Mistral does not train its models on API data. Some of our Mistral account and billing metadata is handled outside the EU. We make no zero-retention claim: Mistral may keep API requests for a limited period under its own terms, for abuse monitoring.
  • We do not store your rough draft. We keep only a count of how many times you used the builder each day (to cap it at 10) and basic technical logs - request ID, model, latency, token counts, status - never the text.
  • Nothing is posted until you press Post yourself. Other members' posts and profiles are never sent to Mistral.
  • Don't put names or details in a draft that you don't want to share.

Where your data lives

EU data locality where feasible. Verified 25 Sep: the application and its built-in backend are hosted by Lovable AB (Stockholm, Sweden; lead supervisory authority IMY) on Lovable Cloud, which is built on Supabase infrastructure; Lovable publishes a Data Processing Agreement (version dated 17 November 2025) as part of its terms, and processing can involve countries outside the EU, including the US. Lovable assigns each project one of three hosting regions (Europe, Americas, Asia-Pacific) at creation; the dashboard does not display this project's region, so we are confirming it with Lovable before launch. Stripe will handle payments when billing activates (EU-US transfers under the EU-US Data Privacy Framework). A transactional email provider is still to be chosen. A data-processing agreement will be in place with every supplier that touches member data before launch.

Retention and deletion

  • Account and community data is kept while you are a member. When you leave, your posts, check-ins and profile are deleted or irreversibly pseudonymised within 30 days.
  • Billing records are kept as long as Portuguese tax law requires.
  • Declined or expired applications are deleted within 90 days.
  • International waitlist details are kept until applications open where you live, or until you ask us to remove them.
  • You can request an export or deletion at any time by emailing hey@nofront.app. Backups are protected and restricted.

Your rights

Under GDPR you can access, correct, delete, export and restrict or object to processing of your data, and withdraw any consent at any time - withdrawing never makes earlier processing unlawful. We answer within one month. You can complain to the Portuguese supervisory authority, the CNPD (Comissao Nacional de Protecao de Dados, cnpd.pt), at any time.

Security

Access rules are enforced on the server for posts, reports, files, search and exports. Admin access is restricted and auditable. Notifications use neutral previews. If we ever have a breach that affects you, we will tell you straight.

Adults only

no front is for adults (18+). We do not knowingly collect data from minors.

Changes

If this policy changes, we will tell members before the change takes effect.

Zaffar Khan
Avenida da Liberdade, n.º 67B, 3.º B, CX-132
1250-140 Lisboa
Portugal