Privacy policy
Effective August 21, 2026
Our privacy promise
NIMVEIL is designed to help organizations reduce accidental exposure when employees use supported browser-based AI services. By default, supported prompt detection happens locally in the browser. We do not design the product to store complete employee prompts, detected secret values, or general browsing histories.
Information we collect
Account and organization information
We may collect name, business email, organization name, role, industry, employee-count range, timezone, subscription status, and support communications.
Privacy-safe protection events
For supported interactions, the service may receive organization, user or installation identifiers, AI service, time, source type, detection category, severity, confidence class, policy, action, and count. It is not intended to receive the full prompt, uploaded document, or detected sensitive value.
Product operations
We may collect authentication records, audit events, device policy/version health, billing identifiers, transactional email delivery state, and limited product analytics needed to operate and secure the service.
Information the default product does not collect
- Full raw prompts or general prompt histories
- Detected passwords, API keys, SSNs, card numbers, or bank values
- General browsing history outside supported and granted AI sites
- Unsupported binary file contents claimed as inspected
How information is used
We use information to provide protection, synchronize organization policy, show reports, manage accounts and subscriptions, deliver requested transactional messages, prevent abuse, investigate security issues, and improve product reliability. AI personalization for founder outreach uses only supplied or public lead information and cannot send messages autonomously.
Service providers and subprocessors
The planned production stack may use Supabase for authentication and PostgreSQL hosting, Stripe for billing, Resend for transactional product email, approved hosting infrastructure, and OpenAI only for administrator-controlled features that do not receive raw employee prompts by default. The final production policy must name actual vendors, locations, and data-processing terms before launch.
Retention and deletion
Retention must be configurable and limited to business need. Production launch requires verified deletion workflows, backup-retention behavior, legal-hold handling, and account-deletion procedures. Contact privacy@nimveil.com for a privacy request once that mailbox and process are operational.
Security and limitations
We use reasonable technical and organizational measures, but no system prevents every incident. A browser extension on an unmanaged device can be disabled or removed. Local detection can miss sensitive content or produce false positives. NIMVEIL is not a substitute for training, access controls, contracts, incident response, or professional legal and security advice.
Children, international use, and changes
NIMVEIL is a business service and is not directed to children. International transfers and region-specific rights require review before broad availability. Material policy changes should be dated and communicated through the product or account contact.