Privacy Policy

What we collect, what we do with it, how long we keep it, and who else touches it.

Version 0.1-draftUpdated September 17, 2026

Draft, pending legal review. This describes how the service behaves today and has not yet been reviewed by counsel. It is published so the behaviour is documented; it is not yet a finished legal instrument. Questions to [email protected].

Who this covers

Nvisy operates a hosted redaction service at app.nvisy.com and this website. If you run the engine on your own infrastructure, this policy does not apply to the documents you process: they never reach us.

What we collect

Account data. An email address, a display name, and the workspaces you belong to. If you sign in through Google or Microsoft, we receive the identity those providers return and store the identifier, not the password.

Documents you upload. Files you send for redaction, the entities detected inside them, the redacted output, and the audit record of what was changed. This is the sensitive material, and it is treated as such below.

Connection credentials. If you connect an object store or a cloud file service, we store the credentials or OAuth tokens needed to read and write it, encrypted at rest.

Operational data. Request logs, error reports, and usage measurements, including IP address and browser. On this website we record page views and session replays only if you accept analytics in the consent banner.

We do not buy personal data, and we do not track you across other sites.

What we do with it

We use account data to run your workspace and contact you about the service. We use documents solely to perform the redaction you asked for and to produce its audit trail. We use operational data to keep the service running and to find faults.

We do not train models on your documents. Neither our own models nor any third party’s.

How long we keep it

Retention is configurable per workspace, set separately for four classes of data: original documents, redacted output, audit records, and processing intermediates such as OCR layout or transcripts.

The default for all four is deletion as soon as processing finishes. A workspace can instead keep data for a fixed number of days, or indefinitely, and that choice is yours to make.

Deleting a file purges it from storage rather than hiding it. Account data is kept while the account exists.

How it is protected

Files are encrypted at rest with XChaCha20-Poly1305 under keys derived per workspace, so the storage layer only ever holds ciphertext. Traffic is encrypted in transit with TLS 1.3.

Access inside a workspace is governed by roles. A reviewer sees redacted output and the audit trail but not the originals, so review work can be delegated without widening access to the sensitive material.

Who else touches it

We use subprocessors to run the service. The current list, what each one does, and where it operates is published at /legal/subprocessors.

We do not sell personal data or share it for advertising.

Your rights

You can export your data at any time, ask us to correct it, or ask us to delete it. Where the GDPR applies you also have the right to object to processing, to restrict it, and to lodge a complaint with a supervisory authority.

Write to [email protected] and we will respond.

Changes

We will note the date at the top when this changes. If a change materially affects how we handle your documents, we will tell account holders directly rather than relying on you to re-read the page.