Privacy Policy
Privacy Policy
How the website and research workspace handle personal data.
Effective and last updated: 8 October 2026. Version: privacy-v2-2026-10-08.
This policy explains how the Noexis AI website and research workspace handle personal data. Piyush Verma, based in Delhi, India and trading as Noexis AI, is the operator and contact for data questions and complaints. Noexis AI is currently unincorporated. Email founder@noexis.tech.
Information and purposes
| Information | How it is used |
|---|---|
| Account email, sign-in identity, session information and profile details supplied by your chosen sign-in provider | Create and secure your account, sign you in and maintain sessions. |
| Affirmative 18+ self-confirmation, Terms acceptance, Privacy notice acknowledgement, server timestamp and document versions linked to your account | Record eligibility and the agreement and notice presented before workspace access. The confirmation does not ask for your date of birth or independently verify age. |
| Questions, graph titles, summaries, nodes, connections, source material and metadata | Save, display and organise your research workspace. |
| Prompts, selected research context, requested and returned model identifiers, provider request identifiers, AI responses, contribution decisions and operation or run history | Provide requested AI assistance, record the work and support inspection, recovery and troubleshooting. |
| Uploaded PDFs, filenames, extracted text, document sections and storage metadata | Import and display evidence and use relevant excerpts in requested research. Stored-file upload can retain the original PDF. |
| Source URLs, search queries and retrieved page material when you use source features | Obtain and organise the source material you request. |
| Usage counts, limits and any billing customer, payment or subscription identifiers, statuses, dates and provider event records | Apply service limits and handle available billing, reconciliation and required records. |
| Access or walkthrough requests: email, optional name, organisation and research notes, request kind, 18+ declaration with timestamp and version, receipt time and duplicate-submission identifiers | Let the founder review your enquiry, follow up and prevent duplicate submissions. |
| Daily coded rate-limit keys derived from requester IP address and email | Limit abusive or repeated form submissions. These are keyed identifiers, not a promise that the processing is anonymous. |
| Contact messages and relevant support information | Respond to enquiries, data requests and complaints. |
| Session cookies and browser preferences for models, context, search and layout | Keep you signed in and remember workspace settings. |
| Technical request and error information handled by hosting and infrastructure providers | Deliver the service, protect it against abuse and diagnose failures. |
Authentication information is processed when you sign in, before you complete the workspace eligibility and agreement confirmations. The account-confirmation handler does not store a date of birth, raw IP address or user-agent string in the acceptance record.
Private website enquiry and rate records do not store raw IP addresses, user-agent strings, dates of birth or referrers. The request handler uses the IP address transiently to derive the rate key. Separately, Sites and Cloudflare process IP address, user-agent, referrer, request URL, timestamp and response status for website delivery and troubleshooting. The form handler also records failure statuses or error names to diagnose failed submissions. Providers manage their infrastructure logs separately from the private enquiry records.
Only submit content you are authorised to process. Do not put passwords, payment credentials or unnecessary sensitive or confidential material in an access, walkthrough or support request.
AI and source processing
When you request AI assistance, the relevant prompt and research context are sent to the provider for the model you choose. This may include selected graph content, source text and document excerpts. When you choose Claude, this information is sent to Anthropic; when you choose an OpenAI model, it is sent to OpenAI. A provider's processing is necessary even if it does not use the data for model training.
OpenAI describes its API default as not using API data to train or improve models unless the customer explicitly opts in. Its processing, sharing options and retention depend on the API feature and account settings. OpenAI may retain data for abuse monitoring and feature-specific operation under its policy. Contact us if your workflow needs a particular provider setting or retention arrangement.
Anthropic describes its commercial API policy as not using customer inputs and outputs for model training unless the customer opts in or explicitly provides material such as feedback. Anthropic may retain inputs and outputs under its API data-retention policy. Handling and retention depend on the model, feature, account arrangement, usage-policy enforcement and legal obligations.
Source features may process queries, URLs and retrieved content. Visiting or fetching a source can disclose request information to its website. Check the provider information, or ask us, before using a workflow that requires a particular supplier or handling arrangement. Context selection changes what later requests use; it cannot recall information already sent to a provider.
An access or walkthrough submission is stored for founder review. It is not automatically sent for model inference and does not automatically send an email or create a calendar booking.
Providers and other disclosures
We use providers for the functions below. Their own infrastructure, security records and applicable retention policies can also involve processing of data.
| Provider | Function and relevant information |
|---|---|
| Supabase | Account authentication, database, realtime workspace features, private document storage, eligibility and agreement records, and private website enquiry records. |
| OpenAI | Model inference when an OpenAI model is chosen, with relevant prompts and research context. OpenAI Sites is also part of the public website hosting path, which is separate from model inference. |
| Anthropic | Claude model inference when chosen, using the relevant prompt and research context. |
| Vercel | Hosting and request processing for app.noexis.tech. |
| Cloudflare | Public website delivery and request handling through Sites, including infrastructure request logs. |
| Inngest | Background workflows and durable execution. Intermediate step state can contain research content, not only account or graph identifiers. |
| Google sign-in when chosen, communications through the founder's business Gmail account, and Google Fonts delivery for the public website. Your browser requests the font stylesheet and font files from Google, which receives request metadata such as IP address and browser information. | |
| Razorpay | The configured payment integration, used when available billing is enabled. Relevant payment and subscription records may return to Noexis AI for reconciliation. |
Noexis AI participates in the Sarvam Startup Program. Sarvam is not an active research-inference provider.
We may also disclose relevant information where law requires it, to respond to a valid legal request, or as necessary to investigate abuse, protect the service and address legal claims. Authorised support, administration and provider operations may require access to relevant records for those functions.
Processing locations and safeguards
The Supabase project holding private website requests is in the Tokyo region, ap-northeast-1. Providers may process information, logs and backups in other locations, including outside India and outside your country. This database region covers the private request store rather than every service or copy of data.
We use sign-in checks, ownership controls, private document storage and signed access links to restrict access. Privileged administration and provider operations remain part of service handling. See Security. Report a suspected vulnerability to founder@noexis.tech.
Retention and deletion
We retain account and saved research records to maintain your workspace and its history. They currently have no automatic expiry. Archiving retains the graph. Undoing an operation or deleting a supported node can leave operation history and original uploads. The account confirmation record remains linked to your account and is removed when your sign-in account is deleted.
Access and walkthrough requests remain available for founder review and follow-up until manually removed; there is currently no automatic request-expiry schedule. You can ask us to remove your submission. Daily rate records older than two days are removed on the next admitted submission or an administrator's cleanup action, so they can remain longer when neither occurs.
Contact and support records are kept as needed to resolve the enquiry, provide support and handle related follow-up or disputes. Billing and other records may need to remain for applicable legal obligations, security investigations or legal claims. Providers operate their own logs, backups and recovery copies with separate retention and deletion processes.
Account closure and broader deletion requests are handled manually. We will verify the request, identify the records concerned and explain material limits or required retention. Signing out or closing the browser does not delete saved account data. A request-record deletion does not by itself erase infrastructure logs and backups.
Your choices and requests
Email founder@noexis.tech to ask what personal data we hold and how it is used, request access or correction, ask for deletion or account closure, withdraw a permission you previously gave, or raise a complaint. Identify your account email and the information or action concerned. For a website enquiry, provide the email used and any request identifier available. Do not send a password. We may need proportionate information to confirm that a request relates to you.
Some processing is necessary to provide a requested feature or maintain an account. If you stop authorising that processing, the affected feature or account may no longer be usable. We will explain relevant consequences rather than treating acknowledgement of this policy as blanket consent for every future purpose.
The workspace includes available graph export, sign-out, editable content and research-context controls. Graph export is not necessarily a complete personal-data export. Your browser settings let you clear cookies and local preferences; this can sign you out or reset settings.
Piyush Verma is the contact for privacy questions and complaints at founder@noexis.tech. If a concern is unresolved, you may pursue any regulator, court or other remedy available under law applicable to you. This policy does not restrict those rights.
Age and policy changes
The workspace is for people aged 18 or older. We require an affirmative self-confirmation before workspace access; this does not independently verify age. The enquiry form has its own 18+ declaration. Contact us if you believe an under-18 person has supplied personal data so we can assess and address it, including closing access and deleting relevant records where appropriate.
We will publish changes with an effective date and version and bring material changes to your attention in the app or by email. Where a new permission is needed, we will request it separately. Acknowledging this notice is not an unrestricted permission to use your research for unrelated purposes.