Back to Nyvlo
Legal

Privacy Policy

Last updated July 2026

This explains what Nyvlo collects, why we collect it, and the control you have over it. We collect the minimum we need to run the product, we do not sell your data, and we do not use third-party ad trackers. This policy is written to meet the GDPR for people in the UK and the European Economic Area, and the CCPA for California residents, and it applies to everyone who uses Nyvlo.

Who we are

Nyvlo is operated by Nyvlo Technologies, based in California. For the personal data described here, we are the data controller. If you have any question about this policy or want to exercise a right, email us at hello@nyvloai.com, and our registered address is available on request.

What we collect

  • Account data: your email address, your sign-in identity, and your plan and credit balance. If you sign in with Google, we receive your basic profile and email from Google rather than a password.
  • Prompts and tools you build: the plain-language prompts and edits you send, the tools we generate from them, their version history, and any data you attach or paste to build a tool around your real columns.
  • Usage and build events: first-party records of actions like builds, refines, publishes, and errors, so we can run, debug, and improve the product.
  • Billing data: your plan, credit records, and payment status. Payments run through Stripe and we never see or store your full card number.
  • Coarse visitor location: an approximate city and country derived from edge geo headers, with a geolocation lookup as a fallback. The raw IP address is used only for that lookup and is not persisted.
  • Support messages: the content of emails and requests you send us so we can help you and keep a record of what was asked.

How we use what we collect

We use your data to build and serve the tools you ask for, to run your account and process payments, to send account and receipt emails, to keep the service secure and prevent abuse, to understand product usage in aggregate, to fix errors, and to respond to your support requests. We do not use your private prompts, tools, or attached data to train public AI models.

Legal bases under GDPR

If the GDPR applies to you, we rely on these bases. To perform our contract with you, we process your account data, prompts, tools, builds, and billing so we can deliver the service you signed up for. For our legitimate interests, we process usage events, error monitoring, and coarse visitor location to keep Nyvlo secure, working, and improving, balanced against your rights. To meet a legal obligation, we keep the billing records that tax and accounting rules require. Where we ask for consent, such as any optional cookies, you can withdraw it at any time.

Analytics and no selling of data

Our analytics are first party, recorded in our own events table. We do not embed third-party advertising or cross-site tracking pixels. We do not sell your personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined under the CCPA. We have not done so in the past twelve months. Because there is no sale or share, there is nothing for you to opt out of, and you can still exercise every other right described below.

Who processes data for us

We use a small set of vetted providers to run Nyvlo, and share with each only what it needs to do its one job: authentication and database, web hosting, build-engine hosting, payment processing, the AI processing that generates your tools, account and receipt email, error monitoring, optional single-sign-on, and coarse IP geolocation where the raw IP address is never persisted. Each provider is bound by a data-processing agreement; see our data-processing page, and the current named list is available to customers on request.

International transfers

Nyvlo and several of our providers operate in the United States and other countries, so your data may be processed outside the country where you live. When we move personal data out of the UK or the European Economic Area, we rely on appropriate safeguards such as the European Commission Standard Contractual Clauses and the UK addendum, so your protections travel with your data.

How long we keep data

We keep your account, prompts, and tools while your account is active. Usage and error events are retained for a limited period for security and product analysis. When you delete your account, we remove your data promptly, except for the minimal billing records we are legally required to hold.

How we protect your data

Row-Level Security isolates each account so one customer cannot read another customer data. Data is encrypted in transit using TLS. Access to production systems is scoped and limited to what is needed to run the service. No system is perfectly secure, so we also keep monitoring in place to catch and respond to problems quickly.

Your privacy rights

Wherever you live, you can ask us to act on your data. Depending on your region, these rights include the right to access a copy of your data, to export it, to correct it, to delete it, to object to or restrict certain processing, and to withdraw consent you gave earlier. California residents have the rights to know, delete, correct, and opt out, and we will not treat you differently for exercising them.

  • Access and export: download all of your tools and prompts from Settings at any time.
  • Correct: update your account details in Settings, or email us for anything you cannot change yourself.
  • Delete: remove your account and its data from Settings, or ask us to do it by hand.
  • Object or restrict: email us to limit or object to a specific use of your data.

To exercise a right that is not a self-serve control, email hello@nyvloai.com. We will verify your request against your account and respond within the time the law allows. You may use an authorized agent where the law permits.

Cookies

We use only the cookies needed to sign you in and keep the product working, plus our own first-party analytics. We do not use advertising cookies. You can read the details on our cookies page.

Children

Nyvlo is not for children. You must be at least 13 to use it, and at least 16 where the GDPR sets that as the age of digital consent. We do not knowingly collect data from anyone below these ages. If you believe a child has given us data, email us and we will delete it.

Deleting your data

When you delete your account from Settings, we remove your account, tools, prompts, published links, and connected sign-in. Deletion also cancels any live subscription. We keep only the minimal records we are legally required to hold, such as billing history for tax and accounting. Once complete, published links stop resolving and your data is gone from our active systems.

Contact and complaints

Questions, or want us to action a request by hand? Email hello@nyvloai.com. If you are in the UK or the European Economic Area and you believe we have not handled your data properly, you also have the right to lodge a complaint with your local data protection supervisory authority. We would appreciate the chance to resolve it with you first.