Legal

Privacy Policy

Effective Date: June 10, 2026 · Previous version: April 21, 2026

This Privacy Policy describes how Nourva, a product of Tokra, LLC ("we", "our", or "us"), collects, uses, and protects your personal information when you use our desktop application and associated web services. Tokra, LLC is the data controller for this data.

1. Information We Collect

We collect the following types of information when you use Nourva: Account Information: When you register, we collect your email address and a hashed password. We do not store plaintext passwords. Usage Data: We collect anonymized telemetry about feature usage (e.g., which tools are activated) to improve the product. This data cannot be linked back to specific actions on your device. Payment Information: All payment processing is handled by Stripe. Nourva does not store your credit card number, CVV, or billing address. We receive only a payment confirmation and customer identifier from Stripe. Local Data: Your conversation history, memory entries, generated documents, and desktop automation logs are stored in an encrypted local database on your device — not on our servers. To generate a response, only the content needed for that request is sent transiently to a cloud AI provider (see "Local Storage & Cloud AI Processing" below); it is not retained by us, and your memory is never automatically uploaded. Consent Records: When you make a cookie choice or create an account, we record the consent event (what was agreed, the document version, and a timestamp) together with a salted one-way hash of your IP address — the raw IP is never stored — so that we can demonstrate compliance.

2. How We Use Your Information

We use the information we collect to: - Provide, maintain, and improve the Nourva service - Process transactions and send billing-related communications - Send service updates, security notices, and support responses - Analyze usage patterns (in anonymized form) to improve product features - Comply with legal obligations We do not sell your personal data to third parties. We do not share it with advertisers. We do not use it to train AI models. We do not "sell" or "share" personal information as those terms are defined under the California Consumer Privacy Act (CCPA, as amended by the CPRA), and we have not done so in the preceding 12 months.

3. Legal Bases for Processing (GDPR Art. 6)

Where the GDPR or equivalent law applies, we process your personal data on the following legal bases: Performance of a contract (Art. 6(1)(b)) — creating and maintaining your account, authenticating you, providing the subscription you purchased, processing payments, and answering support requests. Legitimate interests (Art. 6(1)(f)) — securing the Service, preventing fraud and abuse, measuring aggregate site traffic without cookies (see the Cookies section), and establishing or defending legal claims. We balance these interests against your rights, and you may object at any time (see Your Rights). Consent (Art. 6(1)(a)) — optional analytics cookies, any future marketing cookies, and marketing email. You can withdraw consent at any time, with effect for the future, without affecting the lawfulness of past processing. Legal obligation (Art. 6(1)(c)) — retaining records required for tax, accounting, and responding to lawful requests by public authorities.

4. Local Storage & Cloud AI Processing

Nourva is designed with local-first privacy for your data: your memory and files live on your device, and we keep no copy of your memory on our servers. AI processing itself runs on cloud AI providers. Nourva requires an internet connection and does not perform model inference on your device. To answer you, only the content needed for a given request — your prompt and the relevant context — is sent over an encrypted connection to a trusted AI provider, used solely to generate that response, and is not retained by us or used to train any model. Your memory and personality profile are never automatically uploaded to our servers. If you choose, you may explicitly share a memory slice with our cloud agent (Arachne) for a limited, self-expiring window, and you can wipe it at any time.

5. Data Sharing

We share data only with the following categories of third parties: Infrastructure Providers: We use infrastructure and service providers to run our web application and API. These providers process data under strict confidentiality agreements. Payment Processor: Stripe processes all payments. Their privacy policy governs how they handle your payment data: https://stripe.com/privacy AI Inference Providers: When your tasks require cloud AI inference for advanced capabilities, prompts are sent to our trusted cloud AI providers. These providers process your prompts under their respective data handling terms and strict confidentiality agreements. We do not share your data with advertisers or data brokers. A current list of our service providers (sub-processors) is published at https://nourva.ai/legal/sub-processors.

Google API Services — Limited Use

Nourva's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements. When you connect your Google account, Nourva may access your Gmail messages and send mail on your behalf, only to provide features you explicitly request (for example reading, searching, summarizing, and triaging your inbox, and composing or sending email you dictate). • No advertising. We never use Google user data for advertising. • No sale or unauthorized transfer. We do not sell Google user data and do not transfer it to third parties except (a) as needed to provide the feature on our own infrastructure, (b) for security or legal compliance, or (c) in connection with a merger or acquisition in which the successor remains bound by these Limited Use commitments (with prior notice). • No AI/ML training. We do not retain or use your Gmail or Google Workspace data to develop, improve, or train generalized or non-personalized AI/ML models. Data is used transiently to fulfill your immediate request. • Limited human access. No human reads your Google data except with your explicit consent, for security, abuse, or legal reasons, or on anonymized and aggregated data for operations. • Encryption and control. Connection tokens are stored encrypted (AES-256-GCM); you can disconnect at any time, which deletes the stored credentials.

6. International Data Transfers

Your personal data may be processed by us and our service providers on cloud infrastructure located in multiple regions around the world; the specific region can vary by service and over time. Wherever your data is processed, and whenever it is transferred across a border, we apply appropriate safeguards: Standard Contractual Clauses (and the UK International Data Transfer Agreement / Addendum), reliance on adequacy decisions where applicable, participation in recognized transfer frameworks where our providers are certified, and equivalent contractual, organizational, and technical measures — including TLS encryption in transit and least-privilege access controls. For users in the EU, our designated representative under GDPR Art. 27 is listed at https://nourva.ai/legal/eu-representative. You can contact the representative or us directly ([email protected]) on any transfer-related question.

7. Data Retention & Deletion

Account data is retained for as long as your account is active. You may permanently delete your account at any time from the in-app Privacy Settings page (/settings/privacy) — the deletion is self-service, GDPR-compliant, and requires only an email confirmation. When you delete your account: - Your profile, conversations, settings, paired devices, billing/credit history, and Stripe subscription are erased immediately from our primary databases. - Encrypted database backups containing your data are purged on a rolling 30-day cycle. We retain backups for that window for disaster-recovery purposes only — they are not accessible to staff for any other reason. - Tamper-evident audit log entries (which we are required to keep for fraud and security forensics) are anonymized: your name and email are replaced with a synthetic identifier such as [deleted-user-N]. - A confirmation email is sent at the start (with a 1-hour single-use link) and at the end of the deletion process. Local agent data (stored on your device) is under your full control. You may delete it at any time by removing the Nourva application data folder. Anonymized usage telemetry may be retained for up to 24 months.

8. Security

We implement industry-standard security practices including: - TLS encryption for all data in transit - Encrypted password storage (bcrypt) - Principle of least privilege for all internal data access - Regular security reviews No method of transmission over the internet or electronic storage is 100% secure. We strive to use commercially acceptable means to protect your data but cannot guarantee absolute security.

9. Your Rights (GDPR, CCPA & Equivalent Laws)

If you are in the European Economic Area, the United Kingdom, Switzerland, or another jurisdiction with similar privacy laws (CCPA/CPRA, LGPD, PIPEDA, etc.), you have the following rights: Right of access (GDPR Art. 15) — see what we hold. Use the in-app data export at /settings/privacy to download a JSON+CSV bundle of your profile, conversations, ledger, audit log, and more. The link arrives by email and is valid for one hour, single download. Right to rectification (GDPR Art. 16) — correct inaccurate personal data. Edit your profile in dashboard settings, or contact [email protected]. Right to erasure / "right to be forgotten" (GDPR Art. 17) — permanently delete your account and personal data. Self-service from /settings/privacy: type the localized confirmation phrase, click the email link we send, and your data is wiped within seconds. Backups are purged within 30 days. Right to data portability (GDPR Art. 20) — download a structured, machine-readable copy of your data. Same export endpoint as right of access. Right to restrict processing (GDPR Art. 18) — temporarily pause our use of your data while you contest accuracy or legality. Contact [email protected]. Right to object (GDPR Art. 21) — object to processing for direct marketing or profiling. You can disable marketing email any time from notification preferences in dashboard settings. Right to withdraw consent — wherever our processing is based on consent (e.g. marketing email), you can withdraw it at any time without affecting the lawfulness of past processing. Right to lodge a complaint — with your local data protection authority. For EEA users, see https://edpb.europa.eu/about-edpb/about-edpb/members_en. To exercise any right that's not covered by self-service, email [email protected]. We respond within 30 days. US State Privacy Rights (California CCPA/CPRA, Virginia, Colorado, Connecticut, Utah, and similar): you have the right to know what personal information we collect, to access and correct it, to delete it, to opt out of "sale" or "sharing" of personal information and of targeted advertising (we do neither), and to not be discriminated against for exercising any of these rights. You may use an authorized agent to submit a request. If we decline a request, you may appeal by replying to our decision email or writing to [email protected]. Automated decision-making: We do not use your personal data for automated decisions that produce legal or similarly significant effects on you, and we do not perform profiling.

10. Cookies & Similar Technologies

Our website uses three categories, governed by a granular consent banner shown on your first visit: Essential cookies — authentication/session, locale preference, CSRF protection, and the consent record itself. Always active; the site cannot function without them. Optional analytics (consent only) — Google Analytics and our first-party measurement cookie (nv_sid) are loaded or set ONLY after you opt in via the cookie banner. IP anonymization is enabled and cookie lifetimes are capped at 12 months. If you do not opt in, no analytics cookie is ever set. Cookieless measurement — without analytics consent, we still count page views server-side under an anonymized identifier derived from a one-way hash that rotates daily. Nothing is stored on your device, and visits cannot be linked across days or sites. This is done under our legitimate interest in aggregate traffic measurement. We do not use advertising cookies, social-media trackers, or any third-party tracking cookies. You can change or withdraw your cookie consent at any time on the Cookie Policy page (https://nourva.ai/cookies), which also lists every cookie, its purpose, and its retention.

11. Children's Privacy

Nourva is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from anyone under 18. If we discover that we have inadvertently collected such information, we will delete it promptly.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes via email or a notice within the application. Your continued use of Nourva after changes take effect constitutes acceptance of the updated policy. This version is effective June 10, 2026 and replaces the version dated April 21, 2026.

13. Contact & Data Controller

Tokra, LLC is the data controller for the personal data described in this policy. Tokra, LLC (a Delaware limited liability company) 131 Continental Dr, Suite 305, Newark, DE 19713, USA Privacy inquiries and rights requests: [email protected] General support: [email protected] Legal: [email protected] Company information: https://nourva.ai/legal/company EU representative (GDPR Art. 27): https://nourva.ai/legal/eu-representative Sub-processor list: https://nourva.ai/legal/sub-processors

© 2026 Nourva. All rights reserved.