Data protection
Privacy Policy
Effective 2026-09-26
The controller is Heiko Trenkle, Rosenthaler Straße 43–45, 10178 Berlin, Germany, email hello@nyxia.ai. This policy describes Nyxialith OS under the EU General Data Protection Regulation (GDPR).
What we process
- Account identifiers from Google or Telegram, such as provider ID, username, verified email where supplied, and sign-in timestamps.
- Prompts, conversations, voice recordings and transcripts, uploaded files, generated images and music, workspace names, and technical generation records.
- Catnip balances and ledger entries; connected Solana wallet addresses, invoice details, public transaction signatures, asset and exchange-rate data.
- Security and operations data such as session IDs, IP address, user agent, request timing, errors, model usage, token counts, and estimated provider cost. We do not intentionally place prompt or response content in operational telemetry.
- A necessary signed session cookie and local device preferences. We do not use advertising cookies.
Google sign-in
If you sign in with Google, we request only the openid and email scopes. We receive your Google account ID, your email address, and whether Google has verified it. We use this only to create and secure your account and to sign you in. We do not request access to your Gmail, Drive, contacts, or any other Google data.
We do not sell this data, use it for advertising, or share it with anyone except our hosting provider. Deleting your account removes it. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Why and on what basis
- To provide your account, creative tools, storage, and purchases: performance of the contract (Article 6(1)(b) GDPR).
- To keep invoices and accounting records: compliance with legal obligations (Article 6(1)(c)).
- To secure, debug, rate-limit, and improve the service: our legitimate interests in a reliable and abuse-resistant service (Article 6(1)(f)).
- Where we specifically ask permission: consent (Article 6(1)(a)), which you may withdraw prospectively.
We do not use your content to train AI models.
Recipients and international transfers
We host the service, database, and file storage with Railway (USA). Identity providers: Google and Telegram. AI providers, depending on the feature you use: Google (Gemini), OpenAI, Microsoft (Azure speech), Meta, Black Forest Labs, Replicate, Runware, Z.ai, Tempolor, Comfy, and the model routers OpenRouter and TypeSafe. Your prompts, uploads, and voice recordings are sent to the provider that handles the request. Solana payments are checked through Alchemy, and exchange rates come from DexScreener. These providers receive only the data needed for their role.
Some providers may process data outside the EEA. Where required, transfers rely on an adequacy decision or appropriate safeguards such as the European Commission’s Standard Contractual Clauses. Public Solana payment data is also written to a globally replicated public blockchain and cannot be erased by us.
Retention
Workspace content remains until you delete it or your account. Active sessions expire or are revoked on sign-out. Short-lived authentication and security records are kept only as needed for their purpose. On account deletion, we erase identities, sessions, conversations, uploads, and generated media. Pseudonymous invoice and ledger records are retained only for applicable German tax/commercial retention periods and legal claims, then deleted.
When you submit a bug report, you choose whether to include a technical snapshot, screenshot, or selected text. The recent action history stays in memory on your device until you submit it. Reports are available only to authorized administrators. Report content is retained for 30 days and basic report records for 90 days; account deletion also removes your reports. Existing automatic crash reporting is separate.
Your rights
Subject to the GDPR, you may request access, correction, deletion, restriction, portability, and objection, and may withdraw consent. You may complain to a competent data-protection supervisory authority. There is no solely automated decision-making that produces legal or similarly significant effects.
Account deletion
Open the account menu and choose “Delete account,” then type DELETE. This permanently removes your account access and workspace content. You may also request deletion by emailing hello@nyxia.ai. Backups and failed object-storage cleanup may take a limited additional period to age out or complete.
Contact
Privacy requests: hello@nyxia.ai. We may need to verify that you control the relevant account before acting.