Nok Inventory — Privacy Policy
Last updated: 25 June 2026
Nok Inventory ("the app") is an internal inventory-management tool published by Nokturnal ("we", "us") for use by authorized members of our organization. Access requires signing in with a Microsoft work account managed by our organization; the app is not intended for, and cannot be used by, the general public. This policy explains what data the app handles and why.
Who can use the app
Although the app is downloadable from the app store, it is usable only by users who have been granted access in our Microsoft Entra ID directory. Anyone else is denied at the Microsoft sign-in step and cannot reach any data.
What data we process
- Identity data — your name, work email / user principal name, and directory identifier, obtained through Microsoft sign-in (Microsoft Entra ID). Used solely to authenticate you and determine your role and permissions within the app.
- Inventory data — the inventory records, quantities, and change history you view or edit. These are read from and written to our organization's Microsoft 365 (SharePoint) environment via the Microsoft Graph API.
- Camera — used on your device only to scan inventory QR codes. The camera feed and any images are processed locally and are never transmitted to us or stored.
What we do not do
- We do not use advertising, tracking, or analytics SDKs.
- We do not sell or share your data with third parties for their own use.
- We do not collect location, contacts, photos, or audio.
Where data is stored
Identity and inventory data reside in our organization's Microsoft 365 tenant (Microsoft Entra ID and SharePoint) and are governed by Microsoft's security and compliance controls and our organization's data-retention policies. The app itself stores only a short-lived authentication token on the device, in the operating system's secure storage, to keep you signed in.
Data retention & deletion
The app does not create a separate account for you — your identity is managed entirely by our organization's Microsoft Entra ID directory. To revoke access or remove your identity, an administrator removes your assignment in Entra ID. Inventory records are retained according to our organization's internal record-keeping policies.
Security
All communication with Microsoft services uses encrypted HTTPS connections. Sign-in uses the OAuth 2.0 authorization-code flow with PKCE; the app never sees or stores your password.
Children
The app is a workplace tool and is not directed to children.
Changes to this policy
We may update this policy as the app evolves. Material changes will be reflected by the "Last updated" date above.
Contact
Questions about this policy or your data: michael.jackisch@nokturnal.ai.