Privacy Policy
Your privacy is protected by mathematical guarantees and 5,000 years of wisdom.
Last updated: January 21, 2025
🔒 Privacy-First Architecture
Nuru AI is built on zero-knowledge architecture where your data never leaves your control. We implement mathematical privacy guarantees that make data sharing technically impossible, not just contractually prohibited.
1. Information We Collect
1.1 Data You Provide
- Account Information: Email, name, and organization details for Enterprise accounts
- AI Interactions: Conversations and queries processed locally on your infrastructure
- Payment Information: Processed securely through third-party payment providers
1.2 Automatically Collected Data
- Technical Logs: System performance metrics for service optimization
- Usage Analytics: Feature usage patterns to improve platform capabilities
- Security Logs: Authentication and access logs for security monitoring
2. Zero-Knowledge Architecture
Mathematical Privacy Guarantees
Local Processing
AI computations run on your infrastructure. Nuru AI never accesses your conversation data.
Encrypted Transmission
All data in transit uses end-to-end encryption with keys you control.
Zero-Knowledge Proofs
Platform improvements use cryptographic proofs without exposing your data.
Data Sovereignty
You maintain complete ownership and control of all AI-generated content.
3. How We Use Information
3.1 Service Provision
- Platform authentication and access control
- Technical support and customer service
- System monitoring and performance optimization
- Security threat detection and prevention
3.2 Platform Improvement
- Aggregated usage analytics (anonymized and encrypted)
- AI model performance optimization
- New feature development based on usage patterns
- Heritage-tech algorithm enhancement
4. Data Sharing and Third Parties
🛡️ No Data Sharing
We never sell, rent, or share your personal data with third parties.
Our zero-knowledge architecture makes data sharing technically impossible, even if legally requested. Your data remains under your exclusive control.
Limited Service Providers
- Payment Processing: Stripe (financial transactions only)
- Infrastructure: Cloud providers for platform hosting (encrypted data only)
- Communication: Email service providers for account notifications
5. Data Retention and Deletion
5.1 Retention Periods
- Account Data: Retained until account deletion or service termination
- Technical Logs: 90 days for security and performance monitoring
- AI Interactions: Processed locally and not stored on Nuru servers
- Billing Records: 7 years for tax and compliance requirements
5.2 Right to Deletion
You can request complete data deletion at any time by contacting privacy@nuru.network. We will permanently delete all associated data within 30 days.
6. Enterprise Privacy Features
SOC 2 Type II
Independently audited security controls and privacy safeguards
GDPR & CCPA
Full compliance with global privacy regulations
Custom DPAs
Data Processing Agreements for enterprise deployments
Audit Logs
Complete transparency with detailed access logging
7. International Data Transfers
For Enterprise deployments, data processing occurs within your specified geographic regions. Personal account data may be processed in the US and EU under appropriate safeguards including Standard Contractual Clauses and adequacy decisions.
8. Security Measures
Technical Safeguards
- AES-256 encryption for data at rest
- TLS 1.3 for all data transmission
- Multi-factor authentication requirements
- Regular security audits and penetration testing
- Zero-trust architecture principles
Heritage-Tech Security
Our security approach combines modern cryptography with time-tested Mesopotamian administrative principles of access control and data stewardship, creating multilayered protection that has withstood both ancient and modern threats.
9. Your Rights
Privacy Rights
- Access: Request copies of your personal data
- Rectification: Correct inaccurate personal data
- Erasure: Request deletion of personal data
- Portability: Export data in machine-readable format
- Restriction: Limit processing of personal data
- Objection: Opt out of certain data processing
Contact privacy@nuru.network to exercise these rights.
10. Contact Information
Data Protection Officer
Email: dpo@nuru.network
Response time: 72 hours
Privacy Inquiries
Email: privacy@nuru.network
Response time: 5 business days
11. Policy Updates
We may update this Privacy Policy to reflect changes in our practices or legal requirements. Material changes will be communicated 30 days in advance via email and platform notifications. Continued use of our services constitutes acceptance of updated terms.
Heritage-Tech Privacy Commitment
Like the ancient guardians who protected sacred knowledge for millennia, we safeguard your data with both mathematical precision and time-tested wisdom. Your privacy is not just a policy—it's our foundational principle.