Privacy Policy
This policy explains what Nimra collects, why, how it’s handled, and the choices you have. We aim to collect only what we need to run the Service and to be plain about it.
1. What we collect
- Account data: your email, optional name, and a securely hashed password (we never store it in plain text).
- Documents and analyses: the RFP/RFI files (or pasted text) you submit, the text extracted from them, and the checklists and other output Nimra generates from them.
- Usage and operational data: records of analysis runs, model and token usage, and cost, which we use to operate the Service, attribute usage to your account, and detect abuse.
- Payment data: handled by Stripe. We receive confirmation of a purchase and a Stripe customer reference; we do not receive or store your full card number.
- Essential cookies: a session cookie that keeps you signed in. See “Cookies” below.
2. How we use it
- To provide the Service: parse your documents, run the analysis pipeline, and show and save your results.
- To manage your account, credits, and purchases.
- To secure the Service and prevent abuse (e.g., CAPTCHA on signup, usage monitoring, alerting on anomalous activity).
- To communicate with you about your account (e.g., email verification, important notices) and to respond to support requests.
- To improve Nimra. Any analysis we do to improve quality uses aggregated or de-identified data. We do not sell your data, and we do not use your documents to train third-party foundation models.
3. Subprocessors
We rely on a small set of vendors to run Nimra. Your document text may be transmitted to AI providers strictly to generate your results. Current subprocessors:
- Anthropic and OpenRouter: large-language-model inference (the analysis pipeline).
- Voyage AI: text embeddings for discovery search.
- Neon: managed Postgres database hosting.
- Vercel: application hosting.
- Stripe: payment processing.
- Resend: transactional email (verification, notices).
- Cloudflare: CAPTCHA (Turnstile) on signup.
These providers process data on our behalf under their own terms; the major AI APIs we use do not train their models on data submitted via their APIs by default.
4. Cookies and analytics
Nimra uses a single essential cookie: your sign-in session, required for the Service to work and never used for advertising. We do not use tracking or advertising cookies, and we never will. Our analytics are first-party and cookieless. We count visits with a daily-rotating anonymous hash that resets every 24 hours and stores no IP address or personal information, and we use no third-party or cross-site trackers.
5. Data retention
We keep your account data while your account is active. Documents and analyses are kept so you can revisit saved work; you can ask us to delete specific items or your whole account. After deletion we remove your content from active systems within a reasonable period; limited records (e.g., transaction logs) may be retained as required for legal, accounting, or security purposes.
6. Security
We use industry-standard measures: encrypted transport (HTTPS), hashed passwords, scoped access, and reputable infrastructure providers. No system is perfectly secure, but we work to protect your data and to limit what we collect in the first place.
7. Your choices and rights
- Access, correct, export, or delete your data. Email help@nimra.ai and we’ll help.
- Depending on where you live (e.g., the EEA/UK or California), you may have additional rights over your personal data; we honor valid requests under applicable law.
- You can stop using the Service and request account deletion at any time.
8. Children
Nimra isn’t directed to children and isn’t intended for anyone under 18. We don’t knowingly collect data from children.
9. International users
Nimra is operated from the United States and our providers may process data in the US and elsewhere. By using the Service you understand your data may be processed in countries with different data-protection laws than your own.
10. Changes
We may update this policy. On a material change we’ll bump the version shown above and ask signed-in users to review and re-accept. Contact us with any questions at help@nimra.ai.