Legal
Privacy Policy
Last updated: September 14, 2026
01General information and data controller
This Privacy Policy explains how the operator of Nymrio ("we", "us", or "our") handles personal information collected through the public website, the application, account services, support channels, APIs, and widgets. It applies to the Nymrio platform and the related services made available through it.
The data controller is BRINDUSOIU EDUARD-NICOLAE PFA, a sole proprietorship registered in Romania, with fiscal identification code (CUI) RO44875202.
We process personal information in accordance with applicable data-protection law. If you use Nymrio for an organization, that organization may also act as a controller for information it submits to the Service. Questions about this policy or a privacy request can be submitted through the contact channel available on the website or through the application.
02Data we collect and infrastructure storage
We limit collection to information needed to provide, secure, improve, and bill for the Service. The categories of information may include:
- Account and identity data: name, email address, account settings, authentication events, two-factor verification data, and recovery information.
- Workspace and Customer Content: agent instructions, workflow configurations, RAG documents and extracted media, conversations, prompts, retrieved context, tool inputs and outputs, execution traces, widget settings, and MCP metadata.
- Usage and operational data: selected models, API requests, token and credit consumption, performance metrics, security events, error reports, and diagnostic logs.
- Billing data: plan, billing period, invoices, tax or billing details, and payment-provider identifiers. Payment card details are handled by the payment provider rather than stored directly by Nymrio.
- Messages and support data: name, email address, subject, and message content when you contact us or request assistance.
Application data is stored in the Nymrio backend infrastructure, including PostgreSQL and vector search storage used to support RAG retrieval. Credentials, tokens, and secrets required for integrations are processed to perform the actions you request and should be limited to the minimum access necessary.
03Purpose and legal basis of processing
We use personal information to create and maintain accounts, authenticate users, deliver AI agents and workflows, process documents, provide RAG retrieval, connect MCP tools, serve APIs and widgets, record usage, manage plans and credits, prevent abuse, troubleshoot failures, and communicate about the Service.
Depending on the context and applicable law, our legal bases include performance of a contract, compliance with legal obligations, legitimate interests such as security and service improvement, and consent for optional processing. You may withdraw consent where processing is based on consent, without affecting processing that took place before withdrawal.
04Data recipients and third-party sub-processors
We do not sell personal information. To operate Nymrio, selected data may be shared with service providers that host, secure, monitor, support, and bill for the platform. Model requests may be sent to Google, OpenAI, Anthropic, or another provider selected for the relevant model. The content and metadata required to complete a request may therefore be processed under that provider's terms and privacy notice.
When you connect an MCP server, invoke an external tool, or use an API integration, the relevant request, credentials, metadata, and result may be transmitted to the endpoint you selected. You are responsible for reviewing the provider's practices and for obtaining any permissions required for the data you send. Billing and checkout information may be processed by Paddle or another payment provider shown at the time of purchase.
We may also disclose information when required by law, to enforce our agreements, prevent fraud or abuse, protect rights and safety, or in connection with a corporate transaction. Where a transfer is subject to GDPR restrictions, we use a legally recognized transfer mechanism where required.
05Data retention period
We retain account, workspace, and operational data for as long as your account or subscription remains active and for the additional period needed to provide the Service, resolve disputes, enforce agreements, maintain security, or comply with legal, tax, and accounting obligations.
You can delete an account or request deletion through the available account settings or support channel. Deletion may be subject to legal retention requirements, backup cycles, fraud-prevention records, and information that must be retained to establish or defend legal claims. Connected credentials and API keys can be revoked or removed through the relevant application settings, subject to operational and legal requirements.
06Your rights under applicable privacy law
Depending on your location, you may have the right to:
- Request access to and a copy of personal information we hold about you.
- Request correction of inaccurate or incomplete information.
- Request deletion, restriction, or portability of information where the law allows.
- Object to processing based on legitimate interests and withdraw consent for consent-based processing.
- Lodge a complaint with the data-protection orchestratory authority in your place of residence or work.
To exercise a right or ask a privacy question, contact us through the channel made available on the website or in the application. We may need to verify your identity before completing a request.
07Information security
We use technical and organizational measures intended to protect personal information against unauthorized access, disclosure, alteration, and loss. These measures include authenticated access, access controls, encrypted transport where supported, environment separation, security monitoring, and controlled handling of credentials and integration tokens.
No internet transmission or storage system can guarantee absolute security. You are responsible for protecting your credentials, API keys, documents, and connected endpoints, and for notifying us promptly if you believe an account or integration has been compromised.