Privacy Policy
This policy describes what Nyxwatch stores, why, where it goes, and what you can ask us to do about it. It is written against what the software actually does. Where a statement here and the product disagree, treat it as a defect and tell us.
1. Who we are
Nyxwatch LLC (“we”), is the controller of the personal data described below. Contact: support@nyxwatch.com.
We have not appointed a Data Protection Officer. At our scale we do not carry out large-scale systematic monitoring or process special categories of data as a core activity, so one is not required; the address above reaches a person who can act on any request in this policy.
2. Two very different kinds of data
Nyxwatch holds two things that a privacy policy usually treats as one, and the distinction matters more here than in most products.
Your account data is about you: the name you asked us to address you by, your email address, and records of your sessions.
Your case material is whatever you capture into an investigation — web pages, pasted text, uploaded files, the entities and relationships you record. We do not choose it, review it, or use it. It may contain personal data about people who are not our users and who have not agreed to anything.
For case material, you decide the purpose and the means; we only store it. In data-protection terms you are the controller of that material and we are your processor. If you need a written data processing agreement — for example because you are investigating on behalf of a client or an employer — write to us and we will sign one. The obligations that follow from collecting information about other people — having a lawful basis, honouring their rights, deleting it when you no longer need it — are yours. Section 7 of the Terms says the same thing from the other side.
3. What we store about you
| Data | Why | Kept |
|---|---|---|
| Display name | So messages can address you. Free text, not unique, not verified. | Until the account is deleted |
| Email address | Your only sign-in identifier; confirmation and password reset. Stored lowercased. | Until the account is deleted |
| Password | Sign-in. Stored only as a bcrypt hash — we cannot read it or recover it for you. | Until changed or the account is deleted |
| One-time codes | Confirming your address and resetting your password. Stored hashed, never in the clear. | 15 minutes live; swept within 72 hours |
| Session records: sign-in time, IP address, browser user-agent | Showing you where your account has been used, and security investigation. | Until you sign out, reset your password, or the account is deleted. We do not currently expire idle sessions automatically. |
| Activity log: who did what, when, in which case, and the display name at the time | An investigation report has to be able to say who made each claim. This log is append-only by design. | For the life of the case |
| Preferences: report language, proposal engine, theme | Keeping the product the way you set it. | Until the account is deleted |
| Server logs | Diagnosing faults. These include email addresses on failed sign-in and registration attempts. | 30 days |
We do not use advertising or analytics trackers, and we do not sell anything to anyone. The only browser storage we use is the one holding your session so you stay signed in.
4. What we store for your cases
When you capture a source, Nyxwatch keeps a sealed copy — the bytes as they were at the moment of capture, plus a SHA-256 fingerprint and a timestamp. That is the point of the product: a report is only worth something if the evidence behind it can be shown not to have changed since.
Text and link captures are stored in our database. Uploaded files are stored in Cloudflare R2 object storage. Both are kept for the life of the case.
5. Automated relationship suggestions
Nyxwatch can suggest possible relationships between entities. You choose which engine runs, and the choice is shown in every report.
- Heuristic — runs entirely on our servers. Nothing leaves.
- Language model — sends a request to Anthropic’s API containing the labels, types and attributes of the entities in your case, and the titles of the sources they were cited from. The captured content itself — page text, pasted text, uploaded files — is never sent. This is a transfer to a processor in the United States, made under the European Commission’s Standard Contractual Clauses as incorporated in Anthropic’s commercial terms. If you would rather nothing left our servers at all, leave the engine set to Heuristic — it is the default.
Suggestions are proposals. Nothing enters a report until you accept it. No decision with legal or similar significance is made about anyone by automated means.
6. Who else processes data for us
| Provider | What for | Where |
|---|---|---|
| Render | Application hosting and the database disk | European Union (Frankfurt) |
| Cloudflare R2 | Uploaded files and database backups | European Union |
| Titan / GoDaddy | Sending confirmation and password reset email | United States |
| Anthropic | Relationship suggestions — only if you choose that engine | United States |
7. Backups
The database is copied daily to object storage and the copies are kept for fourteen days. Deleted data therefore persists in backups for up to fourteen days after deletion, and we do not edit backups to remove individual records — doing so would destroy the property that makes a backup worth having.
8. Your rights
You can ask us to give you a copy of your data, correct it, or delete it. Write to support@nyxwatch.com. We answer within 30 days. If you think we have handled your data badly, you can complain to the Ukrainian Parliament Commissioner for Human Rights, and — if you are in the EU or the UK — to the data protection authority where you live.
These requests are handled by hand right now. There is no export button and no delete-my-account button in the product yet; both are being built. In the meantime the email address above is the mechanism, and 30 days is the commitment.
Two limits worth stating plainly. Account deletion does not retroactively empty the activity log of cases, because a report that cannot say who recorded a finding is not a report. And it does not reach into backups, which age out on their own schedule.
9. Accounts that are never confirmed
If you register and never confirm your address, the account is deleted automatically after 72 hours, and the address becomes available again. If someone else registers with the same unconfirmed address before then, the pending registration is replaced — an unconfirmed address belongs to whoever can receive mail at it, not to whoever typed it first.
10. Security
Passwords and one-time codes are hashed. Traffic is served over TLS. Sign-in, registration and password reset are rate limited. Confirmation of your address is required before the product can be used.
One limitation we would rather state than hide: changing your password does not immediately sign out sessions that are already open. An existing sign-in remains valid until its token expires, which is one hour from sign-in. If you believe someone else has access to your account, change the password and then contact us so we can end the remaining sessions immediately.
11. Changes
If we change this policy in a way that matters, we will email every account holder at least 14 days before the change takes effect, and the date at the top of this page will change. Minor corrections — a clearer sentence, a fixed typo — we make without notice.