Privacy Policy

Last updated: March 2026

1. Introduction

Nirixa ("we", "us", "our") operates an LLM observability platform accessible at nirixa.in and app.nirixa.in. This Privacy Policy explains what data we collect, how we use it, and your rights regarding that data.

2. Data We Collect

Account information — when you sign in via Google or GitHub OAuth, we receive your email address, display name, and OAuth provider ID. We do not receive or store your OAuth password.

LLM call logs — when your application sends data via the Nirixa SDK, we store the following fields per call:

  • Provider and model name (e.g. openai / gpt-4o)
  • Feature label you assign in your code
  • Prompt tokens, completion tokens, total tokens
  • Estimated cost in USD
  • Latency in milliseconds
  • Hallucination risk score and risk tier (LOW / MEDIUM / HIGH)
  • Error flag and timestamp
  • Deduplicated call ID you provide

We do not store the actual prompt or response text from your LLM calls.

SDK API keys — keys you create in the dashboard are stored (hashed) in our database and linked to your account.

Usage & billing — token consumption counters and subscription status are stored to enforce plan limits and process payments.

3. How We Use Your Data

  • Render your dashboard (cost, performance, hallucination risk charts)
  • Send alert emails when cost spikes, hallucination risk rises, or prompt drift is detected
  • Enforce subscription token limits and trial periods
  • Debug service issues and improve the platform

We do not sell your data or use it to train AI models.

4. Third-Party Services

  • Supabase — database and authentication (data stored in EU region). Privacy policy: supabase.com/privacy
  • Dodo Payments — payment processing for paid subscriptions. We never store card numbers.
  • SendGrid — transactional alert emails. Only your email address is shared.
  • Google / GitHub — OAuth providers for sign-in. Subject to their respective privacy policies.

5. Data Retention & Deletion

Your call logs and account data are retained while your account is active. You can request deletion of all your data at any time by emailing hi@nirixa.in. We will process deletion requests within 30 days.

6. Security

All data is encrypted in transit (TLS) and at rest via Supabase's storage layer. SDK API keys are stored hashed and cannot be recovered — only replaced.

7. Cookies & Local Storage

We use localStorage in the dashboard to persist your session token, theme preference, and selected API URL. No third-party tracking cookies are set on app.nirixa.in.

8. Changes to This Policy

We may update this policy. Material changes will be communicated via email or an in-dashboard banner. Continued use after the effective date constitutes acceptance.

9. Contact

Questions or requests? Email us at hi@nirixa.in.