Privacy Policy
Last updated: 21 September 2026
Nabbly helps freelancers find work by gathering job postings from public boards and putting them in one place. This policy explains what we collect, why, and what we never do with it. It is written to be read, not to be survived.
Summary
We collect the little we need to show you relevant gigs and let you sign back in. We do not sell your data, we do not run advertising trackers, and we do not share your information with advertisers. Usage is counted on our own server, and a copy of those counts goes to PostHog, the service we use to read them.
Information We Collect
When you sign in. Your email address. If you use Google sign-in, Google tells us your verified email address and your name, and nothing else. We only accept an address Google has confirmed as verified. If you sign in by email instead, we store the address you type.
Your profile, if you fill it in. Your name, what you do, your skills, the rate you will not work below, keywords to prioritise, words to mute, a portfolio link, a short bio, and your country and city. All of it is optional, and it is used to sort the board around you.
Your resume, if you upload one (Pro). You can upload a resume so drafted replies can cite your real, specific experience instead of a generic bio line. It is stored with your account — the extracted text, kept alongside your profile — so it is still there the next time you sign in, and you can delete it at any moment from your settings, which removes it immediately and everywhere. It is read for exactly one purpose: when you ask for a drafted reply, the resume text is sent to Anthropic to write that reply, the same as the rest of your profile. It is never shown to anyone else, never used for anything but your own drafts, and never sent anywhere except to write a reply you asked for.
Your alert settings, if you set them up. Only the channels you choose to configure: a phone number for SMS, a notification topic, a Telegram bot token and chat ID, or a Slack or Discord webhook address. We need these to send the alerts you asked for.
Newsletters you forward, if you use that feature. You can forward mailing lists and newsletters to a private Nabbly address. We read those messages to pull the individual opportunities out of them. Gigs extracted this way are private to your account. They are never added to the public board and no other user can see them.
Feedback you send us, and the message you wrote.
Basic usage analytics. Page views, clicks, which site referred you, and whether you are on a desktop or a phone. These are counted on our own server, and a copy is sent to PostHog, a product analytics service, so we can see which parts of Nabbly are used and make it better.
PostHog receives a rotating session identifier and nothing that identifies you: not your email, not your name, and nothing you have written into Nabbly — your profile, your resume and anything you forward are never sent. The counts are sent from our server, so there is no analytics script running in your browser, and we set no advertising cookies and no tracking pixels.
A sign-in token. A random token identifies you between visits. It is held in your browser session and appears in your address bar. Anyone who obtains that link can access your account, so treat it like a password and do not share it.
Information We Do Not Collect
We never ask for and never store passwords, government identification, or your contacts. If you subscribe to a paid plan, Stripe handles the payment: your card details go to Stripe and never touch our servers. We keep only Stripe's reference for your subscription, so we can show you what you are on and let you cancel.
How We Share Information
We do not sell your data or share it with advertisers, ever. We use a small number of service providers to run Nabbly, and they only handle what they need to:
- Render hosts the application.
- Supabase stores the database, so your account and profile survive a
redeploy.
- Google handles sign-in, if you choose that option.
- Stripe processes payments for paid plans.
- Resend delivers our email: sign-in codes, the weekly email, and any
alerts you set to email.
- Freelancer.com, only if you connect your Freelancer account: your bid
is sent to Freelancer under your own account, and the access token they give us is stored encrypted. You can disconnect at any time.
- ip-api.com is queried only if you press "Detect my location", to guess a
country and city from an IP address.
- Anthropic powers drafted replies where that feature is switched on. When
you ask for a draft, the text of that job posting, the relevant parts of your profile, and your uploaded resume (if you added one) are sent to generate it.
- The alert channel you choose (your SMS provider, Telegram, Slack, Discord,
or your notification service) receives the alerts you asked us to send.
We will also disclose information if the law genuinely requires it.
Where Your Data Is Stored
Nabbly is operated from the United States, and the services we rely on store data there. If you use Nabbly from elsewhere, including the UK or the EU, your information is transferred to and processed in the United States.
Data Retention
We keep your account and profile for as long as your account exists, so you can sign back in and keep your settings. Ask us to delete your account and we will remove your account record, your profile, your alert settings, and any gigs you forwarded in.
Your Rights and Choices
You can edit or clear your profile at any time from the Profile page, turn off any alert channel by removing it, stop forwarding newsletters at any time, and ask us to delete your account entirely. Email hello@nabbly.co and we will action it.
Depending on where you live you may have additional rights over your data, such as requesting a copy of it or asking us to correct it. Email us and we will help.
Children's Privacy
Nabbly is meant for working adults and is not directed at children under 16. We do not knowingly collect their information.
Security
We take reasonable care with your data, but Nabbly is an early product built by a very small team. Sign-in works through a link-based token rather than a password, which is convenient and less secure than a full password system. Please do not store anything sensitive in your profile.
Changes to This Policy
If we change this policy we will update the date at the top. If a change meaningfully affects how we handle your data, we will say so clearly in the app.
Contact
Questions, corrections, or deletion requests: hello@nabbly.co
← Back to Nabbly