How Nabad handles session and participant data — written for the questions procurement teams ask.
Last updated: 7 September 2026
Application data — accounts, sessions, questions, and participant responses — is stored in a managed PostgreSQL database (Neon). Live vote tallies during a session are held in a managed Redis cache (Upstash). The application runs on DigitalOcean. Our current data region is the United States (AWS US-East). Customers with a regional data-residency requirement can contact us to discuss options.
Participants do not create accounts. For each participant we process:
We do not ask participants for an email, phone number, or login, and we use no advertising cookies anywhere. No analytics or tracking script runs on the pages a participant sees — the join page, the voting page and the presenter screen carry none. Our public marketing pages use Cloudflare Web Analytics, which counts visits without cookies. Browser local storage is used only to remember a participant’s chosen reading language and which questions they have already answered.
| Data | Retention |
|---|---|
| Session results & participant responses | Kept until the host deletes them. Closing a room does not delete it, so a host can reopen the results sheet later, on any plan. We do not run an automatic deletion schedule today; if your organisation needs a fixed retention period, contact us and we will agree one in writing. |
| Account data | Kept while the account is active; deleted within 30 days of account deletion, except where retention is legally required. |
| Live vote cache (Redis) | Cleared when the session ends. |
We share data with these providers only to deliver the service. We do not sell data.
| Provider | Purpose | Data |
|---|---|---|
| Neon | Primary database | Accounts, sessions, responses |
| Upstash | Live vote cache (Redis) | Transient vote tallies |
| Google (Gemini API) | AI room insights and recap (Pro sessions); translation of answers when a host requests it (any plan) | Participant open-text, Q&A and word-cloud answers (see section 5) |
| Stripe | Payments | Host billing details — card data never touches our servers |
| Google (Analytics) | Marketing-site analytics | Page views on our public pages. Not loaded on the join page, the voting page or the presenter screen. |
| Resend | Transactional email | Host email address |
| Sentry | Error monitoring | Stack traces and request context from server errors, which can include a session identifier |
| DigitalOcean | Application hosting | Application traffic |
Participant text reaches Google’s Gemini API in exactly two situations, and no others:
Text is sent for that processing only. It is not used to build a profile of any participant, and display names are not sent. Institutional customers can request our current data-processing and retention terms for this provider.
For host account data, Nabad is the data controller. For participant responses, the host running the session is the controller and Nabad is the processor acting on their behalf. Our lawful basis is the legitimate interest of the host in running their session and the performance of our contract with the host. A data processing agreement is available to institutional customers on request.
A host can delete any session — and all of its responses — from their dashboard at any time, and can delete their entire account from their profile. For any other deletion request, including a participant asking to remove a response, email info@nabad.live. We action verified deletion requests within 30 days.
If we become aware of a personal-data breach affecting your data, we will notify affected customers without undue delay and, where required, within 72 hours of becoming aware — describing what happened, what data was involved, and the steps we are taking.