Privacy Policy
Last Updated: March 9, 2026
At Nebula, we believe your data is yours alone. We built this project with a “local-first, paranoid-level security” mindset.
Zero Data Collection
We do not own servers, we do not collect telemetry, and we do not track your usage. Nebula does not transmit any personal data, analytics, or crash reports to us or any third-party marketing services.
Local-Only Encryption
All sensitive data, including your cryptographic keys, session tokens, and cached files, are stored exclusively on your device. We use SQLCipher and AES-256-GCM encryption. The decryption keys are protected by your operating system's native secure enclave (e.g., Keychain, Keystore) and never leave your hardware.
Telegram Infrastructure
- When you use Nebula, your encrypted data is relayed through Telegram's cloud infrastructure.
- We do not have access to your Telegram account, messages, or files.
For information on how Telegram handles data on their servers, please refer to the Telegram Privacy Policy.
Open Source Verification
Nebula is completely open-source. You do not have to take our word for it — our entire codebase, including the C++ core and Flutter UI, is available on GitHub for independent auditing.
Contact
If you have any questions about our security practices or this policy, please open an issue on our GitHub Repository or email kaabdulaal@gmail.com.