nyvor
Back to Nyvor

Privacy Policy

Last updated: July 25, 2026

Our principle

Nyvor is built so that you own your software, your data, and your infrastructure. We host nothing on your behalf, we do not sell your data, and we collect the minimum needed to run the service. This policy explains what we handle and how.

What we collect

  • Account information. When you sign in with GitHub, we receive your basic profile (name, email, avatar, GitHub login) to create your account.
  • Repositories you point us at. We read the code of repositories you explicitly provide, to analyze how your software is built. We store the resulting understanding (architecture, services, database, dependencies, health) as your engineering knowledge graph — not a copy of your source code.
  • Infrastructure connections. Tokens for your own services (Coolify, Neon, Hetzner) are encrypted with AES-256-GCM before they are stored, and are decrypted in memory only at the moment we act on your behalf.
  • Operational data. Basic logs and events (e.g. a deploy started/completed) to operate the service and show you your activity.

What we do NOT do

  • We do not sell or rent your data to anyone.
  • We do not use your private code to train models.
  • We do not host your application or database — those live on infrastructure you own, and keep running independently of Nyvor.
  • We never return your secrets or connection strings to the browser.

How we use what we collect

We use your information solely to provide the service: to authenticate you, to analyze and deploy the software you ask us to, to keep your knowledge graph and recommendations current, and to secure and improve the platform.

Third-party services

Nyvor connects to services you choose — GitHub (sign-in and repositories), and your own Hetzner, Coolify, and Neon accounts. Data you share with those services is governed by their respective privacy policies.

Security

Secrets and infrastructure tokens are encrypted at rest, transmitted over HTTPS, and never logged in the clear. Access is scoped to your account. No system is perfectly secure, but we design around least privilege and encryption by default.

Data retention and your rights

You can disconnect an infrastructure connection or delete your account at any time, which removes your stored connections and knowledge graph. Because your applications run on your own infrastructure, deleting your Nyvor account does not affect them. To request deletion or a copy of your data, contact us.

Changes

We may update this policy; material changes are reflected by the “Last updated” date above.

Contact

Questions about your privacy? Contact us at hello@nyvor.dev.