Legal
Privacy Policy
Effective April 10, 2026
NoxSoft Inc ("NoxSoft", "we", "us") operates the ANIMA, Nox, BYND, VEIL, Veritas, Mail, SVRN, and related products under the noxsoft.net domain. This policy explains what personal data we collect, how we use it, who we share it with, and the choices you have.
If you only read one thing: we collect the minimum we need to run the product and bill you. We don't sell your data. Where practical, we design for end-to-end encryption (VEIL) and data sovereignty (CNTX) so that not even we can read your content.
1. What we collect
Account data
- Display name, username, email address (or passkey identifier)
- Hashed passwords or WebAuthn credentials (never plaintext)
- Organization memberships and roles
Usage data
- Agent job history and token usage (model, input/output token counts, latency) for billing and abuse prevention
- Per-platform content you create: ANIMA soul/memory/journal entries, BYND posts, Mail messages, Nox tasks, Veritas preferences
- Mailbox metadata (sender, recipient, timestamps, thread IDs) for NoxSoft Mail
- Server logs (IP, user-agent, request path) retained 30 days for security and debugging
Payment data
- Card details are collected and processed by Stripe. NoxSoft never sees raw card numbers — we only receive a customer/subscription ID and the last four digits.
- Your email address and billing address are stored to generate invoices.
AI prompts and responses
When you talk to your ANIMA, ask Nox to run a job, or use Veritas, the prompts and generated responses pass through Anthropic's API. If you're on Bring-Your-Own-Key (BYOK), they go directly through your own Anthropic account under your own billing. If you're on a paid platform integration (e.g. your school/employer uses NoxSoft), they route through NoxSoft's Anthropic account.
VEIL is different. VEIL sessions are end-to-end encrypted with keys held by you. We can see metadata (session count, timestamps, storage size) but cannot read the contents of any conversation, even as administrators.
2. How we use it
- Operating the product — authenticating you, running agent jobs, delivering mail, showing you your own data
- Billing — calculating usage, charging your card via Stripe, sending invoices
- Abuse prevention — rate-limiting, detecting automated scraping, reviewing spam/abuse reports
- Product improvement — aggregated, anonymized metrics only. We do not train models on your content unless you explicitly opt in.
- Support — responding to you when you email us or file a report
3. Who we share it with
We share data only with sub-processors we need to run the service. Each is bound by a data processing agreement:
- Supabase — Postgres database, authentication, file storage
- Anthropic — Claude API for AI inference (managed-key paths only)
- Stripe — payments and subscription management
- Resend — transactional email (welcome, receipts)
- Cloudflare — DNS, CDN, email routing
- Railway & Vercel — application hosting
We do not sell personal data. We do not share it with advertisers. We only disclose data to law enforcement in response to a valid legal process and, where lawful, we will tell you first.
4. Your rights
You can exercise any of these by emailing privacy@noxsoft.net:
- Access — a copy of the personal data we hold about you
- Correction — fix inaccurate data
- Deletion — remove your account and associated data
- Portability — export your content in an open format
- Objection — opt out of specific processing activities
We aim to respond within 30 days. Deletion is honored even where retention would be legally permitted, except where we must retain records for tax, fraud prevention, or billing purposes.
5. Retention
- Account data is kept while your account is active.
- Agent job history is kept 12 months by default; you can delete individual jobs sooner.
- Billing records are retained 7 years for tax compliance.
- Server logs are rotated after 30 days.
- When you delete your account, we remove personal data within 30 days except where legal retention rules require otherwise.
6. Security
We use TLS for all network traffic, encrypt data at rest in Postgres, hash passwords with argon2 (via Supabase Auth), and follow principle-of-least-privilege for internal access. We run bug bounty and security review on critical paths. No system is perfectly secure — if you believe you've found a vulnerability, email security@noxsoft.net and we'll respond within two business days.
7. Children
NoxSoft is not directed at children under 13. Platforms used in K-12 education (such as ASCEND or the Aedura LMS integration) operate under a distinct data processing agreement with the school as the data controller — teachers and administrators, not NoxSoft, manage student accounts and consent.
8. International users
NoxSoft is a Delaware corporation with operating presence in Sydney, Australia. Data is processed on servers in the United States and the EU (Supabase). We rely on Standard Contractual Clauses for data transfers out of the EEA/UK. If you are in the EU/UK, the UK/EU GDPR applies and we act as the data controller for account data; if you are in California, CCPA rights apply.
9. Changes to this policy
When we make material changes we will notify signed-in users via in-app banner and email at least 14 days before the changes take effect. The effective date at the top of this page always reflects the current version.
10. Contact
NoxSoft Inc
30 N Gould St, Sheridan, WY 82801, USA
Privacy questions: privacy@noxsoft.net
General: hello@noxsoft.net
See also our Terms of Service.