Legal
Privacy Policy
This policy explains what data Neuvix handles, why it is used, who may process it, and the controls available to you.
Effective date:
1. Scope and operator
This policy applies when Shakar Ali provides the Neuvix website, applications, APIs, and related services.
It covers information handled through account, creation, collaboration, community, billing, automation, advertising, connected-app, and support features. A third-party service you choose to connect also applies its own privacy terms.
2. Information we handle
- Account and profile information, such as email address, display name, profile image, public handle, biography, verification state, language, and account-security settings.
- Prompts, chats, uploaded source files, generated media, projects, documents, brand assets, voice or character material, community posts, comments, reports, and the metadata needed to process them.
- Service activity and technical data, including feature events, IP address, device or browser information, request identifiers, security events, error records, and approximate usage timing.
- Plan, credit, subscription, invoice, payment-status, refund, and advertising-spend records. Payment providers handle payment credentials; Neuvix stores the transaction and reconciliation data returned to the service.
- Identifiers, permissions, encrypted access credentials, posts, messages, campaigns, and performance data for social networks, AI providers, MCP clients, or other services you choose to connect.
- Information you send in support, privacy, moderation, abuse, or legal requests.
Passwords are stored only as password hashes. API keys, recovery codes, verification links, provider tokens, and MFA secrets are stored as hashes or encrypted values where the feature requires them; they are not included as usable secrets in account exports.
3. Why we use information
- Provide, personalize, operate, and troubleshoot the features you request, including generating, storing, publishing, and exporting content.
- Authenticate users, enforce access controls and limits, prevent fraud or abuse, moderate content, investigate incidents, and protect the service.
- Send transactional messages, respond to requests, and provide service or account notices.
- Measure reliability and product use and improve features. Optional analytics or error-monitoring services receive data only when the deployment configures them.
- Process payments, maintain accounting records, resolve disputes, enforce terms, and meet applicable legal obligations.
4. Processors, providers, and disclosure
Information is disclosed only as needed to operate a requested feature, administer the service, protect users, or comply with law. Depending on the enabled feature, recipients may include:
- Hosting, database, email, storage, queueing, monitoring, and content-delivery providers.
- AI generation, transcription, voice, media-processing, search, or asset-management providers that process the prompt, source material, or output needed for your request.
- Payment gateways, fraud-prevention services, and accounting or reconciliation providers.
- Social networks and advertising platforms you direct Neuvix to connect to, publish to, read from, or purchase advertising through.
- Analytics and error-monitoring providers when their deployment keys are configured.
- Professional advisers, authorities, or counterparties where reasonably necessary for law, safety, a dispute, or a business transaction subject to appropriate safeguards.
Neuvix does not represent that personal information is sold for money. The operator must separately assess whether any configured advertising or analytics integration is treated as a sale or sharing under the laws that apply to the deployment.
5. Cookies and local storage
Neuvix uses essential cookies or browser storage to keep you signed in, rotate sessions, complete MFA and OAuth flows, remember language and theme choices, protect sensitive actions, and preserve in-progress work. Blocking these may prevent the service from working.
Analytics or error-monitoring tools are active only when configured by the deployment. The operator must implement any consent banner or opt-out required by applicable law before enabling non-essential tracking.
6. Security
The service uses access controls, short-lived sessions, revocation, encryption or hashing for sensitive credentials, private object storage, input validation, rate limits, audit records, and provider-scoped credentials. No system is perfectly secure; use a unique password, enable MFA when available, and report suspected compromise promptly.
7. Retention and deletion
Personal profile, authentication, projects, generations, messages, uploads, and similar live-service data remain while the account or feature needs them. Self-service account deletion removes these rows or disconnects them from your identity.
Payment, credit, subscription, advertising-spend, security, moderation, and audit records may remain in pseudonymous or anonymized form for reconciliation, disputes, fraud prevention, integrity, and legal compliance. The operator must set and document exact statutory retention periods for its jurisdiction.
Private and public stored objects and supported provider assets are placed in durable cleanup tasks and retried when a provider is temporarily unavailable. Deletion therefore may complete asynchronously. Content already published to an external platform is controlled by that platform and may need to be deleted there separately.
Application deletion does not rewrite immutable backups. Deleted data may remain until the configured backup lifecycle expires and must not be restored into active service except for a legitimate recovery, after which deletion controls must be reapplied.
8. Your choices and rights
Depending on where you live, you may have rights to access, correct, export, delete, restrict, or object to processing, withdraw consent, or complain to a regulator. Some rights have legal exceptions, including records that must be retained.
Authenticated users can download a machine-readable export or request account deletion from Account data settings. For another privacy request, use the contact details below.
9. International processing
Infrastructure and providers may process information in countries other than yours. The operator is responsible for confirming the locations used by its configured providers and putting required transfer safeguards in place.
10. Age requirement
Neuvix is intended for people aged 18 or older. Do not create an account if you are under 18. If the operator learns that an ineligible child supplied personal information, it should disable the account and delete the information subject to legal retention duties.
11. Changes to this policy
The policy may change as the service, providers, or law change. Material changes should be announced through the service or an account communication when required, and the effective date above must be updated.
12. Contact
Send privacy questions or rights requests to the verified operator contact below. The operator may need to confirm your identity before acting on a request.
- Service operator
- Shakar Ali
- Privacy contact
- developer@neuvix.io
- Notice address
- Sulaymaniyah, Iraq