Privacy policy

NAS Reborn is designed to keep your information private. It does this by collecting very little information, using as few third-party services as possible and keeping your data on your own device.

On the device

Your files, the accounts and access keys you create, camera video and clips, and the readings from your home's accessories and the device's own sensors are stored on the device and go only where you send them: to the clients you let in and onto the pages you choose to serve. Clients connect straight to the device, without an account with me or a relay in the middle, and on your local network the server announces its name so the Finder, the Files app and Windows can find it.

The app asks for Local Network access so other devices can find the server. It asks for the camera, the microphone, your home's accessories and motion data only when you set up something that needs them, and Face ID confirms it is you before a secret is shown. Video is captured while somebody watches a camera feed or while the feed watches for movement, and it stays on the device. The microphone is reduced to a loudness number, and the audio itself is discarded.

The server keeps a log of failed requests and a diagnostics log on the device, both readable in the app. The error log records the address a failed request came from. Neither leaves the device unless you export the diagnostics log yourself, for instance to attach it to a support email. The diagnostics log holds hostnames, addresses and errors and never a password or the secret half of an access key.

Usage statistics

The app collects usage data to know how many servers are running and on what hardware, which features are used and what kinds of problems they run into. Signals count that the app launched, that it was installed for the first time, that a feature was used, such as a backup running, and the kind of error a feature ran into, such as a connection failing. An error is recorded as its kind only, never with its message, the address, the file name or anything else that would identify the server or the person. Each signal carries the app version, the operating system version, the device model, the language and region, and an identifier hashed on the device from Apple's per-app vendor identifier so an install is counted once without being identified. No file, share, hostname, address or account is included.

Usage data is recorded using TelemetryDeck and can be disabled with the Anonymous usage statistics switch in Settings. While the switch is off nothing is collected and nothing is queued for later.

Security advisories

At most every six hours the app fetches a signed file from nasreborn.com listing known security problems for its version. The address of that file contains the app version, and like any web request it arrives from your internet address. Nothing else is sent, and the file is the same for everyone running that version. An advisory can show you a notice and, for a version that can no longer be updated, turn sharing off once until you turn it back on. The check can be disabled with the Check security advisories switch in Settings.

Hostname and certificate

A server used only as a network drive never contacts my backend. When you opt into serving on the web, the app registers with the backend and is assigned a random hostname under nas2.dk, and from then on keeps the DNS records for that name pointed at the current addresses of the device. DNS is public: anyone who knows the hostname can look up the address of your internet connection, which is also what a visitor learns by opening any page you serve. The backend keeps no database. The address lives in the DNS record itself, and the token that lets a device edit its own name is derived on the fly rather than stored. It runs on DigitalOcean, which also hosts the nas2.dk DNS, so DigitalOcean handles those requests and any logs of them.

The reachability check asks the backend to connect to your public address from outside, carrying a one-time token that only your device can answer, and tells you which addresses work.

The certificate is requested by the device itself from Let's Encrypt, with no email address on the account. My backend only relays the DNS record that proves you control the hostname. Every certificate Let's Encrypt issues is published in public Certificate Transparency logs, so the hostname, and a domain of your own when you add one, becomes public along with the dates each certificate was issued. A domain of your own is validated by Let's Encrypt connecting to the server directly, and my backend plays no part in it.

Notifications

When you let a browser receive notifications from a camera, the device sends them through the push service of that browser, run by Apple, Google or Mozilla. Each notification is encrypted for your browser and carries a line of text and a link, never a picture or video. The subscriptions live on the device.

Backups

A backup to another person's device or to an S3 bucket is encrypted on your device before it leaves. Whoever hosts it sees encrypted blocks, their size, when they arrive and the address they come from, and never a file name or a byte of content. By default the key that encrypts a backup is kept in your iCloud Keychain, which Apple end-to-end encrypts, so a new device signed into your Apple account can find and restore the backup. The Keep key in iCloud switch on each destination turns that off, leaving the recovery phrase as the only way back in.

A backup invitation travels in the part of a link after the # sign, which your browser never sends anywhere, this site included.

Purchases and crash reports

Pro is a one-time purchase through the App Store. Apple handles the payment and I receive no name, address or payment details. The app keeps the purchase state on the device. Crash reports reach me only through Apple, when you have allowed sharing them with developers in your device's settings, or through TestFlight along with the feedback you send from there.

Support

Writing to support@nasreborn.com puts your email address and whatever you send in my mailbox. I use it only to help you and keep it for as long as that takes.

This website

nasreborn.com is a static site served by Netlify, which handles each request and keeps its own logs of it. The site has no analytics, sets no cookies and loads nothing from anywhere else.

The newsletter form sends the address you enter to EmailOctopus, which sends the confirmation mail and, once you have confirmed, one or two emails a year. I use the address for the newsletter only, every mail ends with an unsubscribe link, and an address that is never confirmed is dropped.

NAS Reborn and this site are made by Anders Borum. This page changes when the app does and was last updated on 8 September 2026.