Draft. This text has not been reviewed by legal counsel yet and may change before the commercial launch.
Privacy Policy
Last updated 2026-09-26
This policy explains what personal data [NXIO legal entity name] ("NXIO") collects when you use the NXIO AI Platform, why, and how long we keep it.
1. Data we collect
We collect only what the Service needs to run and to bill correctly:
- Account data: e-mail address, display name, a salted hash of your password (never the password itself), role, and session records (browser user-agent, IP address, last seen time).
- API keys: a hash of each key, its prefix and suffix for display, name, limits, and last-used time. The full key is shown once at creation and is not stored.
- Usage records for every request: model, timestamps, latency, HTTP status, token counts (prompt, completion, cached, cache-write, reasoning), the cost charged, the client IP address, user-agent and optional application title / referer headers.
- Request content: by default, the messages you send and the responses you receive are stored to verify that no usage goes unbilled and to investigate errors. You can turn this off for your account in Settings. Stored content is deleted automatically after the retention period below.
- Ledger entries: every credit top-up, hold, release, charge and adjustment on your account.
2. Why we process it
To provide the Service and forward your requests to the model provider you selected; to bill per token and let you audit every charge; to secure accounts and detect abuse; to reconcile our records against provider invoices; and to meet legal obligations such as accounting rules.
3. Sharing
Your prompts and any files you include are sent to the third-party provider operating the model you chose (via our upstream aggregator), which processes them under its own terms. We do not sell personal data and do not share it with anyone else except service providers that host our infrastructure, or authorities where the law requires.
4. Retention
- Request content (prompts / responses): deleted after [30] days by an automated job.
- Usage and ledger records (token counts, costs, metadata): kept for as long as your account exists plus the period required by accounting law, because they are your billing history.
- Account and session data: sessions expire after [30] days; account data is deleted within 30 days of account closure, except billing history retained as above.
5. Cookies
We use a single first-party session cookie (nxio_session, HttpOnly) to keep you signed in, and browser local storage in the Playground to remember the API key and model you chose. No advertising or third-party analytics cookies are set.
6. Security
Passwords are hashed with scrypt; API keys are stored only as SHA-256 hashes; provider credentials live only in server-side configuration and are never returned to browsers or written to logs. Access to production data is limited to NXIO staff who operate the Service.
7. Your rights
You can view and export your usage and ledger in the dashboard, revoke keys, and close your account. To access, correct or delete other personal data, or to object to processing, write to [legal@nxioai.com]. We answer within 30 days. If you are in a jurisdiction with a data-protection authority you may also lodge a complaint with it.
8. Changes and contact
We will announce material changes to this policy in the dashboard or by e-mail before they take effect. Data controller: [NXIO legal entity name], [address]. Contact: [legal@nxioai.com].