Privacy Statement

Nyx Backup and nyxbackup.com Version: 1 Last updated: 2026-07-31 Effective: 2026-07-31 Nyx Software, LLC, 16523 NE 48th St, Redmond, WA 98052, USA privacy@nyxbackup.com - +1 (480) 442-8063 Documentation and support: https://nyxbackup.com/support

The short version: your backup data never reaches us, telemetry is off unless you turn it on, and the only personal data we hold is what it takes to issue and support your license.

We are the data controller. There is no separate privacy team; privacy@nyxbackup.com reaches the owner of the business directly.

1. Your backups: we never see them

The Software is end-to-end encrypted. File contents, names, paths, and manifests are encrypted on your machine using a key derived from a passphrase you choose. The encrypted bytes go straight from your machine to the storage provider you pick - object storage, a cloud drive, network storage, or local disk.

We do not receive, store, proxy, or have any access to your backup data, file names, or encryption keys. If you lose your passphrase, your data is permanently unrecoverable and we cannot help.

Your storage provider’s privacy policy covers the encrypted blobs you upload to them. For Google Drive, OneDrive, and Dropbox, the Software keeps the OAuth refresh token on your machine and we never see it.

Google user data. Nyx Backup’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

The Software requests only these Google scopes:

ScopeWhat it allows
drive.appdataAccess to a hidden, per-application folder in your Drive
that only Nyx Backup can see. It cannot read, list, or
modify any other file in your Google Drive, including
files you can see yourself.
openid, emailYour Google account email address, shown in the app so
you can confirm which account is connected

We request no broader Drive access of any kind. Your encrypted backup data is written only to that hidden application folder, the authorization happens directly between your machine and Google, the refresh token stays in your OS keyring, and none of it, including your Google email address, is transmitted to Nyx Software.

2. What we actually hold

DataWhyKept
Your email, edition, transaction referenceIssue and re-send your7 years
(from Paddle)license; tax records
License identifier, hashed machine IDsEnforce the machineLife of
limit, honour refundslicense
and revocations+ 2 years
Support emails you send usAnswer you2 years
Website server logs, including IPSecurity, debugging30 days
Update-check server logs, including IPSecurity, debugging30 days
Telemetry, unless you switch it offUnderstand usage,2 years
find and fix defects

Purchases go through Paddle, our Merchant of Record. Paddle handles the payment and gives us the order details above; its own privacy policy covers your payment data. We never see your full card details.

We do not sell your data, do not share it for advertising, and do not use it to train machine-learning models.

3. License verification and the machine check

Your license is a digitally signed file the Software verifies on your own machine, offline. Verifying it never contacts us and never needs an Internet connection. We do not send your license key, hostname, version, or a timestamp to validate it.

When your machine is online, the Software performs a limited machine check against our license service, to enforce the machine limit and honour refunds and fraud revocations. It sends only:

  • your license identifier;
  • a one-way hash derived from your machine identifier (not your machine name, and deliberately unrelated to the telemetry identifier below so the two cannot be linked); and
  • the licensed email address in your license file, to confirm the request is authorized.

A machine with no Internet connection performs no check and keeps working on its signed license file. Restore is never blocked.

4. Update check

By default, once every 24 hours the Software asks https://downloads.nyxbackup.com/latest.json whether a newer version exists.

  • It is a plain request for a static file. It sends no license key, no machine identifier, no version number, and no account information. The comparison against your installed version happens entirely on your machine.
  • As with any web request, our server necessarily sees your IP address, the time, and a generic client identifier. We keep those access logs for 30 days for security and debugging and do not use them to build a picture of your installation.
  • You can turn it off. Set the update interval to “Never” in Settings and the Software makes no update requests at all. A manual “Check for updates” button remains available.
  • Downloading and installing an update is never automatic unless you switch that on separately. The default is off.

On macOS, the graphical application uses Sparkle, a standard macOS updater, which checks https://downloads.nyxbackup.com/appcast.xml on the same 24-hour schedule. It is disabled by the same “Never” setting, so switching updates off stops all update traffic on macOS as well. Sparkle is configured not to send a system profile (SUSendProfileInfo is set to false), though its request header does identify the application and its version, unlike the check described above.

5. Telemetry

Once a month the Software sends an anonymous usage-and-error summary. We use it for one purpose only: to understand how Nyx Backup is actually used, and to find and fix defects. It is not used for advertising, profiling, scoring, resale, or any commercial purpose, and it is never combined with your license or contact details.

This is on by default, and you can switch it off at any time in Settings. Turning it off stops collection immediately and nothing further is sent.

The summary contains only:

  • a random, one-way install identifier;
  • the software version, operating-system family, and CPU architecture;
  • your license state (trial, active, or expired);
  • counts: backup sets, storage-backend types, snapshots, bytes stored, and how many backups and restores succeeded or failed;
  • the category of the most common error, for example “network_transient”; and
  • which high-level features are enabled.

It never includes your files, file or folder names, paths, backup destinations, hostnames, IP address, account, email, or credentials. It is best-effort, fails silently, and never affects a backup.

The install identifier is stable, so we describe this data as pseudonymous rather than anonymous. We hold no key linking it to your license, email, or IP, so we cannot connect it to you or retrieve one person’s records.

6. Crash reports

The Software does not send crash or error reports. Logs stay on your machine. Sending us a log is always something you choose to do.

7. What stays on your machine

Backup contents, file names, paths, and manifests; your master encryption key (OS keyring, optionally TPM-sealed on Linux); storage provider credentials and OAuth tokens (OS keyring, never in config files); backup history, deduplication index, and file-state cache; and application logs.

These live in %ProgramData%/NyxBackup/ on Windows, /var/lib/nyxbackup/ on Linux, and /Library/Application Support/NyxBackup/ on macOS.

8. The website

nyxbackup.com runs no analytics. No Google Analytics, no Plausible, no Fathom, no tracking pixels, no advertising or social-media trackers, and no third-party scripts that profile you. We do not know how many pages you looked at or where you came from.

Cookies. The Site sets only strictly necessary cookies - the ones needed to make the checkout work and to keep the Site secure. It sets no analytics, advertising, or preference-tracking cookies. Because strictly necessary cookies are the only kind we use, no consent banner is required and you will not see one.

Checkout runs through Paddle, which is the data controller for it and sets its own cookies under its own privacy policy while you are completing a purchase.

Server logs. Our web server keeps access logs including IP address and user agent for 30 days, for security and debugging. These are not used to build a profile of you, and are not shared.

Mailing list. We do not operate one. We email you about your license, your purchase, and your support requests, and nothing else. We do not send marketing email and we will not add you to a list.

9. Who else sees this data

We process data in the United States. Our service providers are Paddle (payments), plus our hosting and email providers. We do not share your data with anyone else except where the law requires it.

10. Your rights

You can ask us to access, correct, delete, or export your data, to restrict or object to what we do with it, or to withdraw consent. Email privacy@nyxbackup.com from the address on your license. We reply within 30 days, free of charge, and we extend these rights to everyone regardless of where you live.

Deleting your license record deactivates the license, and you would need a new purchase to keep using the Software after the trial. It does not touch your backups, which we never held.

We cannot find or retrieve your specific telemetry records, because no link to your identity exists. Turning telemetry off in Settings stops collection immediately.

If you are unhappy with how we handled a request, tell us at privacy@nyxbackup.com. You may also complain to your local data protection authority.

11. Age

The Software and Site are for people 18 and over. We do not knowingly collect data from children.

12. Changes

We announce material changes on https://nyxbackup.com and in the in-app About screen, and they take effect at least 30 days later. The version and date above are updated each time.

Questions: privacy@nyxbackup.com