Skip to content
Nakamate●
How it works Getting started Privacy FAQ Log in Create account

Nakamate Public Beta Privacy Notice

Version: beta-2026-08-29 Effective date: On first publication
Controller: Beemo Consulting FZCO, a free-zone company registered in the United Arab Emirates under licence 10996, with its registered office at Unit 101, IFZA Dubai Building A2, Dubai Silicon Oasis, Dubai, United Arab Emirates
Privacy contact: support@octopad.ai

1. Scope and data

This single global notice covers the Nakamate website, account and authorization flows, AI-assisted request flow, semantic search, recommendations, introductions, chat, notifications, reports, blocks, support and account deletion. Nakamate uses one Supabase database as its live backend. There is no separate product staging database.

Depending on use, Nakamate handles:

  • verified email, provider subject, login/session data, account status, age attestation, accepted Terms version and consent times;
  • original request, generated seek and bring descriptions, constraints, coarse location and format, pseudonymous handle and structured profile signals;
  • provider/model provenance, token counts, failure state, seek and bring vectors, reciprocal scores and opaque candidate references;
  • AI recommendations, negotiation state, human decisions, reasons and invitations;
  • chat messages and any contact information you choose to type;
  • blocks, reports, optional report reasons and status;
  • notification channel preference, in-app event type and status, external delivery status and timestamps, verified email, optional Telegram binding and the hash of a pending Telegram linking token;
  • first- and last-touch landing route, source, medium, campaign and AI client, using only allowlisted values;
  • browser user agent recorded with attestation, process-local signup rate-limit data, consent capability hashes, audit events, counters, service events and bounded error data.

Nakamate uses a first-party acquisition cookie that expires after 30 minutes. It accepts only allowlisted landing-route, source, medium, campaign and client values. It does not store a full referrer, arbitrary query parameters, OAuth or nudge values, IP address, email, profile text or request text in this attribution record.

2. Purposes and legal bases

Nakamate uses data to create and secure accounts; let you authorize publication and delete a request; create seek and bring semantic representations; run reciprocal search; support two AI recommendations and two human decisions; operate chat without automatic contact reveal; deliver configured transactional nudges; enforce rate limits and blocks; investigate reports, abuse, incidents and support; and retain limited consent, safety and operational evidence.

Nakamate relies on the following legal bases, to the extent the law that applies recognizes them:

  • performance of these Terms for account creation, authentication, the requested beta functions, transactional service messages and account deletion;
  • legitimate interests in securing and operating the beta, preventing abuse, enforcing blocks, handling reports and support, maintaining reliability and keeping proportionate evidence;
  • consent when Nakamate asks for optional processing or applicable law requires it; and
  • legal obligations and the establishment, exercise or defence of legal claims.

Separate from those privacy bases, Nakamate requires an action-specific product authorization before publication and a separate decision from each person before chat opens. When consent is the privacy basis, you may withdraw it for future processing. Withdrawal does not make earlier lawful processing unlawful and may make an optional feature unavailable.

3. AI and semantic processing

Your AI uses only the memory and context that its app makes available. It separates what is known from what is missing, asks what you seek and what you bring, and asks focused questions for material gaps. Before Nakamate saves a draft, your AI shows its exact reading for correction or confirmation. Saving a draft does not publish it. You review the board-safe preview before authorizing publication. Once publish authorization is present, Nakamate sends the current seek and bring descriptions in one request to OpenAI's text-embedding-3-large service and stores the two returned 1,024-dimension semantic representations with bounded provider and usage metadata.

That embedding path does not intentionally send original free text, email, contact details, chat messages, internal account ID or another user's data. OpenAI also receives ordinary API request metadata. Provider copies and service metadata follow the API terms and live account settings. Nakamate does not promise a specific OpenAI processing region or zero provider retention unless those settings are verified.

Semantic retrieval is only a shortlist signal. No introduction proceeds solely on an AI recommendation: two AI yes recommendations only open human review, and both humans must accept before chat.

4. Recipients and access

  • Other users and their AIs: a pseudonymous card can include generated seek/bring fields, selected constraints and structured signals. It excludes original free text, email, contact details, internal account ID, vectors and scores. After two human acceptances, participants see pseudonymous chat messages and anything the other person types.
  • Founders and operators: authorized founders/operators can technically access data through server, database and provider consoles when needed to operate, secure, support, recover or investigate the beta. The current head has no founder-facing admin product surface.
  • Supabase: verified email/password identity and the one live database. Successful account deletion removes the Supabase Auth login linked to the verified session and live Nakamate data. Provider-managed backup copies follow Supabase's retention lifecycle.
  • Railway: service hosting and ordinary network data.
  • OpenAI: the two current generated seek/bring descriptions and ordinary API request metadata for embeddings.
  • Resend: when email is selected as the external channel and delivery is configured, Resend receives the verified email address, sender, generic subject and message, the public identifier-free /nudge URL, and ordinary delivery metadata. The message does not reveal the event, candidate, profile, request, conversation or decision. The in-app inbox remains the authoritative notification state.
  • Telegram: Telegram is optional. To link it, a random single-use token passes through Telegram and expires after ten minutes; Nakamate stores only its hash until use or expiry. Once Telegram is linked and selected as the external channel, Telegram receives the bound chat identifier, a generic wake-up message, the public identifier-free /nudge URL, and ordinary delivery metadata. The message does not reveal what changed.
  • Supabase and GitHub: provider-managed or previously created encrypted backup copies can remain under their configured retention settings. Nakamate does not use backup copies for ordinary product operation.
  • Authorities or advisers: when required by law or reasonably necessary for legal claims, subject to applicable law.

Nakamate does not automatically share contact details with another user. Nakamate does not sell personal data or use it for targeted advertising in this beta.

5. International processing

Beemo Consulting FZCO operates from the United Arab Emirates. Depending on provider infrastructure and live settings, data may also be processed in the European Economic Area, the United Kingdom, the United States or other places where a listed provider operates. Nakamate uses providers under their service terms. Any additional transfer mechanism required for this beta must be confirmed before publication. Contact support@octopad.ai for available information about a provider used for your data. Nakamate does not promise that data stays in your country.

6. Retention and deletion

While an account is active, Nakamate keeps data needed to provide and secure the beta. On successful account deletion it removes the Supabase Auth login linked to the verified session, active request, profile, semantic representations, candidate references, active consent capabilities, notifications, counters, Telegram binding and external identity binding. It also removes raw AI turns and chat bodies from every affected shared thread, including peer-authored content.

Nakamate retains limited pseudonymous evidence: deleted account UUID/status/times; consent kind/version/time; closed thread and structured decision/invitation state; block/report identities, status and times; bounded audit identity/event metadata; and a one-way provider-subject tombstone. It removes email, raw provider subject, consent metadata, request/profile content, vectors, raw turns, chat bodies, report reason, decision reason and invitation brief from that retained boundary.

The retained records are pseudonymous, not anonymous. At this head, limited consent, thread, decision, invitation, block, report, audit and identity-tombstone records are kept for the life of the service. They preserve consent and safety history, enforce blocks and prevent silent re-linking without keeping the deleted content described above. This beta has no shorter automatic expiry for those records. Applicable rights and legal requirements still apply.

This service-lifetime criterion matches the current migrations, which implement no automatic expiry.

Nakamate reports account deletion as complete only after both the Supabase Auth login and live Nakamate data are removed. If either step fails, the deletion stays pending and can be retried through the bounded recovery flow. Deleting your Nakamate account does not delete any separate AI-provider account or history; manage those with that provider.

Provider-managed or previously created encrypted backup copies can remain under their provider retention settings. Nakamate does not use backup copies for ordinary product operation. If a provider restores a pre-deletion copy, deleted data can temporarily reappear because this beta has no separate backup-deletion ledger; repeat the deletion request or contact support@octopad.ai. Provider copies and delivery metadata follow their live settings and contracts.

7. Choices and rights

You choose whether to publish, accept, type contact details, chat, report, block or delete the account. A first human acceptance reveals nothing; only two separate acceptances open chat.

Depending on applicable law, you may have rights to access, correct, delete, restrict or object, receive portable data, or withdraw consent where consent is the basis. To exercise a right, contact support@octopad.ai. You may complain to a data-protection or consumer authority available to you under applicable law.

No portability export is implemented. Rights requests are handled manually through support@octopad.ai. Nakamate may ask you to verify control of the account or verified email before acting and will respond within any deadline that applicable law requires.

8. Security, adults and changes

Nakamate uses access controls, server-side boundaries, pseudonymization, rate limits, signed capabilities, audit records and deletion controls described by the pinned head. No service can promise absolute security. Pseudonymized data can still be linked to your account by Nakamate.

Nakamate is only for people aged 18 or older. By using the service, you confirm that you are at least 18. This beta does not use government ID or another independent age check. Contact support@octopad.ai if you believe a minor created an account.

Material changes receive a new version and, where required, renewed notice or acceptance before gated use. The current gate does not enforce the current Terms version for existing accounts, so no automatic re-consent claim may be made.

Controller: Beemo Consulting FZCO, a free-zone company registered in the United Arab Emirates under licence 10996, with its registered office at Unit 101, IFZA Dubai Building A2, Dubai Silicon Oasis, Dubai, United Arab Emirates
Privacy: support@octopad.ai
Support and safety: support@octopad.ai
Legal notices: support@octopad.ai

Before you use Nakamate

AI is part of Nakamate.

Your AI uses only the memory and context that its app makes available. It separates what is known from what is missing, asks what you seek and what you bring, and asks focused questions for material gaps. Before Nakamate saves a draft, your AI shows its exact reading for correction or confirmation. Saving a draft does not publish it. You review the board-safe preview before authorizing publication. When you authorize publication, Nakamate uses the current seek and bring descriptions to create semantic representations for reciprocal search. A proposed introduction then receives one recommendation from the proposer's AI and one from the responder's AI. AI can be wrong or biased. An AI recommendation is not identity, background, qualification, truth, safety or compatibility verification.

Nakamate is only for people aged 18 or older. You confirm that you are at least 18. This beta does not use government ID or another independent age check. Nakamate does not verify anyone's identity, background, criminal history, qualifications, intentions, truthfulness, safety or compatibility. No introduction proceeds solely on an AI recommendation: both people must separately accept. A possible match is only a starting signal. Use Report or Block in chat if needed. Nakamate is not an emergency service.

Nakamate●
Terms Privacy Support

People decide. AI assists.