Draft
Privacy Policy
Last updated 11 September 2026
1. Who we are
[Legal entity name], of [Registered address], operates Nitrah and is the controller of the personal data described here. This policy explains what we collect, why, who it goes to, and what you can do about it.
2. What we collect
Account data. Your email address, the name you give us, and a hashed form of your password. We never store the password itself.
Content you create. Conversations, uploaded files and the text we extract from them, projects and their instructions, agent goals and results, generated images and audio, and — if you turn the feature on — memory notes about you.
Usage records. For every request: which model handled it, how many tokens it used, what it cost, how long it took, and whether it succeeded. This is how credits are metered and how we know what we are spending.
Security records. Your IP address and browser identifier when something looks wrong — a failed sign-in, an attempt to reach data in another workspace, an unusual volume of requests. Request bodies and passwords are never written to these records.
Billing data. Your plan, subscription status and billing period. Card details go directly to Stripe and never reach our servers.
Public assistant. If you use the assistant on our marketing site without an account, we keep the cost of each exchange and your IP address for rate limiting. We do not keep the conversation.
3. What we do with it
We use your data to provide the Service, meter and bill it, keep it secure, answer your support requests, and meet legal obligations. We do not sell it, and we do not use your content to train our own models or anyone else’s.
Memory is off unless you turn it on. When on, your saved notes are included with your requests so you need not repeat yourself. A separate switch controls whether Nitrah may add notes on its own from what you write; when that is on, notes it adds are marked as automatic and can be deleted. Notes about health, religion, politics, sexuality, ethnicity, immigration status, criminal history and financial accounts are never captured automatically, whatever you write.
4. Who it goes to
AI model providers. To answer a request, its content — your message, relevant excerpts from attached files, project instructions and active memory notes — is sent to the provider whose model handles it: Anthropic, OpenAI or Google. They process it under their API terms, which for all three exclude using API traffic to train their models. Which provider handled a request is shown to you with the answer.
Web search. When you use research mode, your query is sent to Tavily to retrieve results.
Payments. Stripe processes subscriptions and holds your payment details.
Email. Resend delivers transactional email such as password resets.
Hosting. Our servers, database and file storage are operated by [hosting providers], in [region].
We share data with authorities when the law requires it. We do not share it with advertisers.
5. How long we keep it
Content stays until you delete it or your account. A deleted chat, project or file can be restored for one hour in case the click was a mistake, and is removed from our systems within a day. Password reset links expire after one hour and are cleared after a day. Security records are kept for 90 days. Usage records are kept for as long as we need them for billing and fraud prevention; after you delete your account they are stripped of anything identifying you and kept only in aggregate.
6. Your rights
You can see and delete your conversations, files, projects and memory notes inside the Service at any time, and you can delete your whole account from the account settings page. Deletion is permanent. You can also download a copy of everything we hold about you, as a single file, from the same page — no request needed.
Depending on where you live you may also have the right to access, correct or restrict processing of your personal data, to object to processing, and to complain to a supervisory authority. To exercise any of these, email us from the address on your account. We will respond within 30 days.
7. Cookies
We set one cookie: the session that keeps you signed in. It is strictly necessary for the Service to work and is removed when you sign out. We do not use advertising or cross-site tracking cookies.
8. Security
Connections are encrypted in transit. Passwords are hashed with bcrypt. Every request re-checks that you belong to the workspace whose data it touches. Model provider API keys stay on our servers and are never sent to your browser. Repeated suspicious activity from an address is automatically and temporarily blocked.
No system is perfectly secure. If we learn of a breach affecting you, we will tell you.
9. Children
The Service is not for anyone under 18, and we do not knowingly collect data from them.
10. Changes
If we change this policy in a way that matters, we will email the address on your account before the change takes effect.
Questions about this document: support@nitrah.com. See also our Terms and Privacy Policy.