Privacy Policy
Last updated: July 25, 2026
Our principle
Nyvor is built so that you own your software, your data, and your infrastructure. We host nothing on your behalf, we do not sell your data, and we collect the minimum needed to run the service. This policy explains what we handle and how.
What we collect
- Account information. When you sign in with GitHub, we receive your basic profile (name, email, avatar, GitHub login) to create your account.
- Repositories you point us at. We read the code of repositories you explicitly provide, to analyze how your software is built. We store the resulting understanding (architecture, services, database, dependencies, health) as your engineering knowledge graph — not a copy of your source code.
- Infrastructure connections. Tokens for your own services (Coolify, Neon, Hetzner) are encrypted with AES-256-GCM before they are stored, and are decrypted in memory only at the moment we act on your behalf.
- Operational data. Basic logs and events (e.g. a deploy started/completed) to operate the service and show you your activity.
What we do NOT do
- We do not sell or rent your data to anyone.
- We do not use your private code to train models.
- We do not host your application or database — those live on infrastructure you own, and keep running independently of Nyvor.
- We never return your secrets or connection strings to the browser.
How we use what we collect
We use your information solely to provide the service: to authenticate you, to analyze and deploy the software you ask us to, to keep your knowledge graph and recommendations current, and to secure and improve the platform.
Third-party services
Nyvor connects to services you choose — GitHub (sign-in and repositories), and your own Hetzner, Coolify, and Neon accounts. Data you share with those services is governed by their respective privacy policies.
Security
Secrets and infrastructure tokens are encrypted at rest, transmitted over HTTPS, and never logged in the clear. Access is scoped to your account. No system is perfectly secure, but we design around least privilege and encryption by default.
Data retention and your rights
You can disconnect an infrastructure connection or delete your account at any time, which removes your stored connections and knowledge graph. Because your applications run on your own infrastructure, deleting your Nyvor account does not affect them. To request deletion or a copy of your data, contact us.
Changes
We may update this policy; material changes are reflected by the “Last updated” date above.
Contact
Questions about your privacy? Contact us at hello@nyvor.dev.