Privacy Policy
Effective 24 August 2026
1. Scope
This Policy explains how Ninvo collects, uses, shares, and retains personal data when you use our website, dashboard, API, and related services.
2. Data we collect
- Account data: name, email address, authentication records, workspace details, and account settings.
- Billing data: purchase, credit, invoice, and transaction records. When payments are enabled, payment card details are handled by our payment processor rather than stored by Ninvo.
- Operational metadata: request time, model and provider, token counts, cost, latency, cache status, error status, API-key identifier, and similar service telemetry.
- Technical data: IP address, browser and device information, security logs, and session cookies needed to operate and protect the service.
3. Prompt and response content
Ninvo does not store raw prompt content. Content is transmitted to the selected third-party model provider so it can generate a response, and that provider processes it under its own terms and privacy practices. When exact caching is enabled for a workspace, Ninvo stores the generated response against a one-way hash of the request for the configured cache period, currently up to one hour. Streaming requests and requests that are not eligible for exact caching are not stored in this cache.
4. Why we use data
We use personal data to provide accounts and API access, route and bill requests, prevent abuse, secure and troubleshoot the service, show usage and savings, communicate service information, comply with law, and improve reliability. Depending on applicable law, our basis is performance of our contract, legitimate interests in operating and securing Ninvo, legal obligations, or consent where required.
5. How we share data
We share data only as needed with infrastructure, authentication, database, monitoring, payment, and AI model providers; professional advisers; authorities when legally required; or a successor in a corporate transaction. We do not sell personal data.
6. International processing
Our service providers may process data in different countries. Where required, we use contractual and organisational safeguards intended to maintain a level of protection comparable to applicable data-protection law.
7. Retention
Operational metadata is retained according to your workspace setting and may be kept longer where reasonably necessary for security, fraud prevention, dispute resolution, or legal obligations. Account and transaction records are retained while your account is active and as required for legitimate business or legal purposes. We delete or anonymise data when it is no longer needed.
8. Security
We use access controls, encryption in transit, secret-management practices, monitoring, and other reasonable safeguards. No online service can guarantee absolute security, so you should also protect your credentials and promptly revoke exposed API keys.
9. Your choices and rights
Depending on where you live, you may request access, correction, deletion, restriction, objection, portability, or withdrawal of consent. You may also complain to your local data-protection authority. Some requests may be limited by security, contractual, or legal requirements.
10. Cookies
Ninvo uses essential cookies and similar storage for authentication, security, and session continuity. We do not use those essential technologies for third-party advertising.
11. Children
Ninvo is intended for business users and is not directed to children. Do not create an account if you are not legally able to agree to these terms in your jurisdiction.
12. Changes and contact
We may update this Policy as the service or law changes. We will update the effective date and provide reasonable notice of material changes. Privacy questions and requests may be sent to legal@getninvo.com.
Back to log in