Privacy
Privacy Policy
How Nowly handles your data, what stays on your device, and what depends on your consent.
Last updated: 17 September 2026.
This policy describes how Anthony Lejeune (“we”), as data controller, processes personal data in connection with Nowly. Rich Presence activity is sent from your browser to the Discord client on your machine. It does not pass through our servers. Optional usage statistics and a few website features do involve our API or processors, as described below.
Controller
The controller is Anthony Lejeune, sole trader (micro-enterprise), SIREN 105 793 194, 7 rue d'Arras, 62450 Bapaume, France. Email: contact@qkimi.fr. Full identification is in the legal notice. No data protection officer has been appointed.
What Nowly is
Nowly includes a browser extension (Chrome and Firefox), a desktop app that talks to Discord locally, a website (nowly.me), documentation (docs.nowly.me), a public API, and optional Canary test builds. The extension detects supported sites in your browser and, with the desktop app, updates Discord Rich Presence over a local IPC channel.
Data processed on your device (extension)
The extension stores data in the browser’s local storage API (Chrome
chrome.storage.local / Firefox equivalent). It stays on that device unless you enable optional analytics or use a custom API URL:- Installed presences (metadata, signed bundles, activation state).
- Current activity (title, platform, duration, thumbnail URL).
- A debug log (timestamps, actions, visited URLs of supported sites).
- Onboarding state and a local snapshot of your Discord profile (ID, username, avatar) used only to display the extension UI, taken from the local Discord client.
- Display preferences, shortcuts, and per-presence settings.
- A locally generated device identifier (UUID) used if you opt into analytics.
Browser extension permissions
The extension needs certain permissions to work:
- Access to websites (including a broad host permission): a lightweight content script can run on pages you visit so Nowly can detect supported platforms. It is not used to send your browsing history to our servers.
- User Scripts (Chromium): presence scripts run on matching sites. Official catalogue scripts are cryptographically signed (ECDSA P-256) and verified locally before they run. Canary and sideloaded packages may not carry the same production signature guarantees; treat them as experimental.
Data processed on your device (desktop app)
The desktop app may write a local log named
nowly-host.log under the NowlyClient cache directory, for example:- Windows:
%LOCALAPPDATA%\NowlyClient\ - macOS:
~/Library/Caches/NowlyClient/ - Linux:
~/.cache/NowlyClient/
Usage statistics (opt-in)
Analytics are off by default. If you enable them during onboarding or later in extension settings, our API may receive:
- Your device UUID (pseudonymous: it is not your Discord or Google account, but it is still personal data under the GDPR because it can identify your installation).
- Browser, OS, language, extension version, and desktop app version.
- Installed presence slugs/versions and usage events (for example installs, heartbeats, ratings) with a limited payload.
Discord
Nowly talks to the Discord desktop/browser client through local IPC. Typical Rich Presence fields include platform name, title, channel or author, play/pause state, and timestamps. Anyone who can see your Discord profile may see that status. Once Discord receives it, Discord’s own processing applies. See Discord’s privacy policy.
The API can also issue a session token (JWT, typically 30 days) after optional Discord OAuth for account features (for example reviews). The public marketing site does not require an account. If you never log in, we do not create that token for you.
The API can also issue a session token (JWT, typically 30 days) after optional Discord OAuth for account features (for example reviews). The public marketing site does not require an account. If you never log in, we do not create that token for you.
Legal bases (GDPR Art. 6)
- Opt-in usage statistics: consent (Art. 6(1)(a)). You may withdraw it in the extension at any time, without affecting the lawfulness of processing before withdrawal.
- Language cookie and documentation cookie: necessary for the service you request and/or legitimate interest in remembering your language (Art. 6(1)(b) and/or (f)).
- Theme and cookie-notice flags (local storage): legitimate interest in a usable interface (Art. 6(1)(f)).
- Image proxy: legitimate interest in displaying catalogue and activity artwork without loading every third-party CDN in your browser (Art. 6(1)(f)).
- Optional Discord login: performance of the account feature you request (Art. 6(1)(b)) and, where needed, our legitimate interest in securing the API (Art. 6(1)(f)).
- GitHub, Discord community, Ko-fi, GitHub Sponsors: data you choose to send to those services is processed under their policies; we read public issues or messages you address to us in order to reply (Art. 6(1)(b) or (f)).
Retention
- Local extension and desktop logs: until you delete them, reset, or uninstall.
- Language cookie: 1 year, refreshed when you change language.
- Usage statistics: kept only as long as needed to produce aggregated metrics. There is no automatic 12-month purge implemented today. You may request erasure as described above.
- JWT (if you log in): about 30 days unless you log out or we revoke it.
Processors and transfers
We use:
- Contabo GmbH (Germany) as hosting provider of the VPS on which we run the website, API, and PostgreSQL. The publisher administers the server. Processing takes place in the European Union (VPS provided by Contabo GmbH, Germany). This is an intra-EU hosting arrangement, not a transfer to the United States. Contabo privacy policy.
- Cloudflare to deliver static files (thumbnails, desktop installers, Canary zips) and to protect the sites. Transfers may rely on SCCs and, where applicable, the EU-US Data Privacy Framework.
- Google (Chrome Web Store) and Mozilla (Firefox Add-ons) to distribute the extension; their stores process installer and account data under their own terms.
- Google AdSense only if advertising is enabled on the website (it is off unless we turn it on). Google then acts as an independent controller or joint controller for its advertising cookies, according to Google’s terms.
Image proxy
Our API can fetch public thumbnail URLs (YouTube, Twitch, and similar CDNs) so the UI can display artwork. We do not use the proxy to sell advertising profiles. The requested URL can still relate to a title you were viewing. Logs of those requests are kept only as technically needed to operate and secure the service.
Cookies
nowly.me and docs.nowly.me each set a
locale cookie for language. Theme and the cookie notice use local storage, not cookies. See the cookie policy.Security
Official presence packages are signed (ECDSA P-256). The production extension verifies signatures before running catalogue presences. Canary builds distributed as zip files are test software and may be unsigned. Do not install packages from untrusted sources.
Your rights
If the GDPR applies, you may request access, rectification, erasure, restriction, objection, and portability, and you may withdraw consent for analytics. Developer diagnostics in the extension may show events still queued on your device; they are not a complete export of our servers. To exercise rights, email contact@qkimi.fr or use the GitHub repository. You may also lodge a complaint with the CNIL (France) or your local supervisory authority.
Contact
Email: contact@qkimi.fr. Publisher details: legal notice.