Privacy Policy

Last updated: September 29, 2026

TL;DR
  • βœ“ We do not store the content of conversations sent to the API
  • βœ“ We use AI models configured with zero data retention
  • βœ“ Payments are handled by Stripe β€” we never touch your card data
  • βœ“ You can request account deletion at any time

1. What we collect

Account data (when you sign up):

  • Name and email address (via Google, GitHub or Microsoft OAuth)
  • Profile picture provided by the OAuth provider
  • Current plan and credit usage history

Technical usage data:

  • Number of API calls per key and per period
  • Credits consumed per validator
  • IP address for rate limiting and abuse prevention
  • Error logs (without conversation content)

2. What we do not collect

❌ We do not store the text of agent_input, user_input or any other dialogue field sent in validation calls.

❌ We do not log the content of your end-users' conversations.

❌ We do not use submitted data to train models or improve services beyond immediate call processing.

Dialogues sent to the API are processed in memory and discarded immediately after the response is returned.

3. AI models and infrastructure

NaLU AI uses third-party language model providers for semantic processing. All providers are contracted with data retention disabled β€” data sent is not stored, used for training, or shared by the provider.

Data sent to these providers is exclusively the dialogue content required for validation. No identifying information about your end users is transmitted.

4. Payments

Payments are processed by Stripe, PCI DSS Level 1 certified. NaLU AI does not store, process or transmit credit card data. When subscribing, you are redirected to Stripe's secure environment.

5. Social login (OAuth)

Login via Google, GitHub or Microsoft provides only your name and email. We do not request additional permissions such as access to emails, calendar or other account data.

6. Cookies and local storage

  • Session cookie β€” required to keep you logged in. Expires when the browser is closed or after inactivity.
  • No tracking cookies β€” we do not use Google Analytics, Meta Pixel or any behavioral tracking tools.

7. Data retention and deletion

Account data is retained while the account is active. To request deletion:

  • Dashboard β†’ Settings β†’ Delete account
  • Or email

After the request, all account data is removed within 30 days. Anonymized technical logs may be retained for up to 90 days for security requirements.

8. Data sharing

We do not sell or share your data with third parties for commercial purposes. Data is shared only with the service providers described in this policy (Stripe, AI providers) strictly for service execution.

9. Contact

Privacy questions: