Platform
The ProblemThe Neivan ApproachHow it WorksAgent TemplatesMobile AppFAQs
Resources
SecurityDocumentationAPI Reference
AboutPricing
Sign inRequest Access
The ProblemThe Neivan ApproachHow it WorksAgent TemplatesMobile AppFAQs
SecurityDocumentationAPI Reference
AboutPricingContact SalesSign in
Legal

Privacy Policy

Effective June 9, 2026.

Version 2.0 · Last updated June 9, 2026

On this page
  • Summary
  • The two roles we play
  • Personal information we collect
  • How we use personal information
  • Legal bases (EEA/UK/Switzerland)
  • AI, automated processing, and model training
  • Cookies and similar technologies
  • How we disclose personal information
  • Third-party services and connected accounts
  • International data transfers
  • Data retention
  • Information security
  • Your privacy rights
  • United States state privacy disclosures
  • Children’s privacy
  • Do Not Track and Global Privacy Control
  • Changes to this Policy
  • Contact

Summary

Neivan, Inc. ("Neivan", "we", "us") operates an AI orchestration platform that lets organizations build, deploy, supervise, and govern AI agents, together with related websites, applications, and APIs (the "Services"). This Privacy Policy explains what personal information we collect, how we use and disclose it, and the rights and choices you have.

In short: we collect the minimum needed to operate the Services; we never sell or "share" personal information for cross-context behavioral advertising; and we process the content you put into the platform only to deliver, secure, and support the Services. This summary is not a substitute for the full policy. Read it together with our Terms of Service, Data Processing Addendum (DPA), Cookie Policy, Sub-processor list, and Acceptable Use Policy, each incorporated by reference.

The two roles we play

Controller. We act as a controller (or "business") when we determine the purposes and means of processing for account registration and administration, billing and payments, marketing and our website, support, security and fraud prevention, and product analytics and improvement. This Policy governs that processing.

Processor. When customers and their authorized users submit content to the Services — prompts, documents, knowledge sources, integration data, agent instructions, and agent outputs ("Customer Content") — we process that content on behalf of, and under the instructions of, the customer (the controller), under our DPA. If your personal information appears in Customer Content, please direct your privacy requests to the relevant organization; we will assist them as required.

Personal information we collect

Information you provide. Identifiers and account data (name, work email, username, organization, role, profile photo, credential hashes); billing and commercial data (billing contact and address, plan and transaction history, tax identifiers — we do not store full payment-card numbers, which are handled by our payment processor, Stripe); and support, communications, and marketing/event data.

Customer Content (processed as a processor). Prompts and chat messages, uploaded or connected documents and knowledge sources, agent and workflow configurations, standard operating procedures, records pulled from connected systems, and agent outputs.

Information collected automatically. Device and technical data (IP address, browser, OS, device identifiers, language); usage and log data (pages and features used, run metadata, timestamps, diagnostics, crash/error reports); cookies and similar technologies (see Cookie Policy); and metered-usage data (volume of AI operations, tokens consumed, model and feature used, and cost attribution) used for billing, quotas, and reporting.

Information from third parties. Single sign-on / identity providers (e.g., Google, Microsoft), connected integrations you authorize, service providers and partners (e.g., our payment processor and security vendors), and publicly available sources.

Sensitive information. We do not seek sensitive information for our own purposes beyond what is necessary to operate the Services (e.g., authentication credentials). We do not use or disclose sensitive personal information to infer characteristics or for cross-context behavioral advertising.

How we use personal information

As a controller, we use personal information to: provide and operate the Services; process billing and payments and prevent payment fraud; provide support and send administrative/service messages (security advisories, incident and billing notices, changes to terms); secure the Services and detect, investigate, and prevent abuse, fraud, and prohibited activity; analyze usage, debug, and improve and develop the Services; market to prospects (with consent where required); and comply with law and establish, exercise, or defend legal claims.

We will not process personal information for materially different, unrelated, or incompatible purposes without notice or consent where required.

Legal bases (EEA/UK/Switzerland)

Where the GDPR or UK GDPR applies and we act as a controller, our legal bases are: performance of a contract (to provide the Services, billing, support); legitimate interests (security, fraud prevention, product improvement, analytics, business operations, legal claims); consent (prospect marketing and non-essential cookies, where required); and legal obligation (compliance and responding to legal process).

Where we rely on legitimate interests you may object; where we rely on consent you may withdraw it at any time without affecting prior processing.

AI, automated processing, and model training

AI inference. When you run an agent, chat, or use another AI feature, the relevant prompt and context (which may include Customer Content) are transmitted to one or more large-language-model providers — which, depending on configuration, may include OpenAI, Anthropic, and Google Cloud (Vertex AI) — each engaged as a sub-processor and listed on our Sub-processors page.

No training of shared models without instruction. We do not use Customer Content to train, fine-tune, or improve any model made available to other customers, except where the customer has expressly instructed or agreed in writing. We contractually require our model providers not to use Customer Content transmitted through the Services to train their general-purpose models, to the extent such commitments are offered through their enterprise/API terms.

AI outputs are probabilistic. Output may be inaccurate or unsuitable and should be reviewed by a human before being relied upon for consequential decisions. See our Terms of Service and Acceptable Use Policy.

Automated decisions. As a controller, we do not make decisions producing legal or similarly significant effects about you based solely on automated processing without human involvement. Where a customer configures agents that process personal data automatically, the customer is the controller and is responsible for human oversight, notices, and honoring rights (including human review) owed to affected individuals.

Cookies and similar technologies

We and our service providers use cookies, pixels, local storage, and similar technologies to operate and secure the Services, remember preferences, and — where permitted — measure usage. Some are strictly necessary; others are optional and used only with your consent where required. You can manage non-essential cookies through our cookie banner/preference center and your browser settings, and we honor recognized opt-out preference signals (e.g., Global Privacy Control). For details, see our Cookie Policy.

How we disclose personal information

We do not sell personal information, and we do not "share" it for cross-context behavioral advertising. Since our founding we have never sold or shared personal information within the meaning of those laws.

We disclose personal information: within your organization (to administrators and authorized users per your access controls); to service providers and sub-processors (cloud hosting and storage, database and authentication, payment processing, email delivery, error monitoring, product analytics, observability, incident paging, CDN/security, and AI model inference — each bound by contract and a DPA where applicable); to connected integrations you authorize; for legal, safety, and compliance (when required by law or legal process, to enforce our agreements, or to protect rights and safety — we notify the affected customer of legal demands for its Customer Content where permitted); in a business transfer (merger, acquisition, financing, or sale of assets, subject to confidentiality protections); and with your direction or consent.

Our current sub-processors are listed on our Sub-processors page.

Third-party services and connected accounts

The Services let you connect third-party applications, data sources, and APIs and authorize agents to read from or act within them. We process credentials, tokens, and data from a connected service only as necessary to provide the integration and according to the scopes you grant. The connected third party’s own policies govern its handling of your data. You can review and revoke connections and agent access within the Services at any time, and you are responsible for having the rights and consents needed to connect a service and permit agent actions.

International data transfers

Neivan is based in the United States and uses sub-processors in the United States and other countries. When we transfer personal information across borders (including from the EEA, UK, or Switzerland), we use an appropriate transfer mechanism — the European Commission Standard Contractual Clauses (SCCs), the UK International Data Transfer Addendum, the Swiss addendum, and/or reliance on an adequacy decision where available. These mechanisms are incorporated into our DPA. EU/UK data residency options are on the Enterprise roadmap.

Data retention

We retain personal information only as long as necessary for the purposes described here. Active accounts: account and Customer Content retained for the life of the account. After closure/termination: Customer Content returned or deleted within 30 days at the customer’s choice (except routine backups and data we must retain by law); account/profile data deleted or anonymized within 90 days. Billing and financial records: 7 years. Audit logs: 7 years in immutable (write-once-read-many) storage. When information is no longer needed, we delete or de-identify it.

Information security

We maintain administrative, technical, and physical safeguards including encryption in transit (TLS 1.3) and at rest (AES-256), role-based access control and least-privilege access, MFA for privileged access, network protections (firewall, WAF, DDoS mitigation) and key management, immutable audit logging, vulnerability management with static analysis and dependency scanning in CI, a documented incident-response process, and controls aligned to SOC 2 Type II (internally audited; an independent audit is planned but not yet engaged).

No method of transmission or storage is completely secure. In the event of a personal-data breach affecting your information, we will notify affected parties and authorities as required by law and our DPA (target: without undue delay and, where applicable, within 72 hours of confirmation). See our Security page for more.

Your privacy rights

Subject to applicable law and identity verification, you may have the right to access, correct, delete, restrict, and port your personal information, to object to certain processing, to withdraw consent, and to lodge a complaint with your supervisory authority. To exercise these rights, use the in-product privacy controls (Settings → Privacy) or email [email protected]. We respond within the time required by law (generally 30–45 days) and do not charge a fee unless a request is manifestly unfounded, excessive, or repetitive. You may use an authorized agent where permitted. We will not discriminate or retaliate against you for exercising your rights.

If your information is in Customer Content, please direct your request to the relevant organization (the controller); if you contact us directly, we will refer you and assist as required by our DPA.

United States state privacy disclosures

California (CCPA/CPRA). Since our founding (within the preceding 12 months) we collected these categories: identifiers; customer records; commercial information; internet/electronic network activity; approximate geolocation (via IP); professional/employment information; and inferences. We collect sensitive personal information limited to account credentials/log-in information and do not use it for purposes that would trigger the right to limit beyond those permitted by law. We do not sell or share personal information, and do not knowingly sell or share the personal information of consumers under 16. California rights: know/access, delete, correct, opt out of sale/sharing (not applicable), limit use of sensitive personal information, and non-discrimination. "Shine the Light": we do not disclose personal information to third parties for their own direct marketing. We offer no financial incentives for personal information.

Other US states (Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and others). Depending on your residence, you may have the right to confirm and access, correct, delete, obtain a portable copy, and opt out of targeted advertising, sale, and certain profiling. We do not sell personal data, conduct targeted advertising, or perform such profiling as a controller.

Appeals. If we decline to act on your request, you may appeal by emailing [email protected] with the subject "Privacy Appeal." If your appeal is denied, you may contact your state Attorney General.

Children’s privacy

The Services are intended for businesses and their authorized users and are not directed to children under 16, and we do not knowingly collect personal information from children under 16 for our own purposes. If you believe a child has provided us personal information, contact [email protected] and we will delete it. Customers that process children’s data through the Services are responsible for compliance with applicable laws, including COPPA, and for obtaining any required parental consents.

Do Not Track and Global Privacy Control

Because there is no common industry standard for "Do Not Track," we do not respond to DNT signals. We do honor recognized opt-out preference signals, including the Global Privacy Control (GPC), where required by law. Because we do not sell or share personal information, applying such a signal does not change our practices but is respected as a valid opt-out.

Changes to this Policy

We may update this Policy from time to time. For material changes, we will post the updated Policy with a new effective/last-updated date and, where appropriate, notify account owners by email or in-product at least 30 days before the change takes effect. Your continued use of the Services after the effective date constitutes acceptance, to the extent permitted by law.

Contact

Privacy inquiries and rights requests: [email protected]. Security disclosures: [email protected]. Compliance and sub-processor notices: [email protected]. Legal notices: [email protected].

Data controller: Neivan, Inc. (Delaware, USA). Mailing address available on request. If you are in the EEA, UK, or Switzerland and we have not adequately addressed your concern, you may lodge a complaint with your local supervisory authority.

See also:Privacy PolicyTerms of ServiceSecurityContact us

The intelligence layer for what's next — built for teams who want AI that remembers, coordinates, and improves.

Platform
  • Agent Network
  • Memory & Knowledge
  • Workflows
  • Decision Engine
  • Security
  • Pricing
Trust
  • Trust Center
  • Security
  • Privacy
  • DPA
  • Sub-processors
Company
  • About
  • Docs
  • Help & Support
  • Contact
  • Careers
  • Changelog
Private preview··Your privacy rights·Acceptable Use
© 2026 Neivan, Inc. — All rights reserved.
Privacy·Terms·SLA·Cookies