Privacy

Privacy Policy

Last updated: August 18, 2026

The short version

  • We do not sell personal data.
  • We do not use customer API payloads or submitted source code to train AI models.
  • PII-processing payloads and API Security source-code payloads are processed for the operation you request and are not intentionally persisted as customer content by the PrivoNest application routes.
  • API Security source scans run in the PrivoNest security engine and are not forwarded to Qwen or another external AI model.
  • With the AI Privacy Guard, a protected/aliased textual prompt is sent only to the third-party AI provider selected by your application.

Information we collect

We collect limited service data needed to operate accounts: name, email, authentication provider, API key/account quota metadata, plan and usage counters. Contact and paid-access forms store the details you submit so we can respond.

PII-processing API content

Text, documents and other content sent to PII-processing endpoints are processed to return the requested protected output. The application is designed not to intentionally persist those payloads as customer content in the account database.

API Security source-code scans

When you use API Security Preflight, supported project source files and dependency manifests/lockfiles are submitted to the PrivoNest API for analysis. The v1.0.5 scan route is designed not to log or intentionally persist submitted source content and does not include source code in JSON/SARIF reports. Source analysis is performed by the PrivoNest API Security Engine rather than an external AI provider.

Dependency intelligence used during a customer scan reads a PrivoNest-owned snapshot. The customer scan path is designed not to query npm or PyPI live with customer package names.

AI Privacy Guard

PrivoNest performs PII detection/protection; your application selects the AI provider. Protected aliases/placeholders may be sent to that provider, whose own privacy terms apply. Automatic Guard interception is focused on textual LLM inputs.

Service providers

Infrastructure and transactional providers are used to operate the service. Verification emails use an email-delivery provider, and Google/GitHub receive information when you choose their OAuth sign-in. Hosting and network providers necessarily process traffic needed to deliver the PrivoNest service.

Security and data minimization

Do not submit secrets, credentials or source files that are unnecessary for the requested operation. PrivoNest applies server-side API authentication and bounded scan inputs, but you remain responsible for determining what data/code you are authorized to submit.

Abuse prevention

One-way hashes derived from IP addresses may be used for rate limiting, OTP abuse prevention and form protection instead of storing raw addresses in those controls.

Contact

Use the private Contact Us form for privacy questions.

This is a product privacy notice, not a claim of SOC 2, ISO 27001, HIPAA or other certification. Obtain legal review as jurisdictions and customers grow.