Privacy policy draft

Privacy should be clear before the app asks for trust.

Last updated: August 23, 2026. This page mirrors the repository’s release-draft privacy policy for Nyralux — the EmployeeOS desktop app, plus the companion apps that follow it. Nyralux is the public brand name; this draft remains subject to the blockers below.

Publication blocker: this is not the final public privacy policy until the policy owner confirms the legal and operational items below.

Publication blockers

  • Legal entity / controller identity
  • Verified privacy contact and mailing address where required
  • Final subprocessors and production data regions
  • Retention periods for backend records, function logs, backups, and provider data
  • Verified account-deletion timing and deployed cascade behavior
  • Region-specific disclosures and App Store privacy nutrition labels

1. Data stored on the device

Nyralux stores conversation history, drafts, app settings, and other working data locally. Provider API keys and tokens entered by the user are stored using the system Keychain. Provider-key account sync, iCloud settings, and session handoff are disabled for v1 pending final production provisioning.

2. Account and profile data

Nyralux uses Supabase for account authentication and account-backed features. Depending on the features used, the backend can process email address, account identifier, sign-in/session tokens, profile fields, preferences, last-active time, local-conversation count, and subscription identifiers used to associate an Apple transaction with the signed-in account.

3. AI messages and model providers

Conversation history is persisted locally, but cloud inference requires transmitting the prompt and relevant conversation context. Included hosted requests go through a Nyralux-hosted Supabase Edge Function before being forwarded to the configured provider; bring-your-own-key requests go from the app to the provider or compatible endpoint selected by the user; local endpoints remain local only if the configured endpoint does.

4. Device permissions and integrations

Nyralux may request access to Calendar, Reminders, Contacts, Photos, camera, microphone, speech recognition, local-network devices, and notifications. The app uses a permission only after the user or operating system allows it. Information passed to an AI model through these features follows the inference path selected by the user.

5. Purchases

Apple processes App Store purchases. Nyralux receives StoreKit transaction and entitlement information, and Apple server notifications can update the signed-in account subscription record so included-model access can be enforced. Nyralux does not receive full payment-card details.

6. Analytics, diagnostics, and tracking

The app does not include a third-party advertising or cross-app tracking SDK. Apple may provide crash or diagnostic information through App Store Connect according to the user's Apple settings. Local analytics and diagnostics can run in the app, account profile sync can send limited activity metadata to the backend, and hosted-model usage metering records token counts for entitlement and quota enforcement.

7. Retention and deletion

Users can request account deletion in the app. The backend deletion function is intended to delete the authentication account and associated profile, subscription, and usage records. Locally stored conversations and settings can be removed through app controls or by uninstalling the app. Data already sent to an AI provider is subject to that provider's retention and deletion terms.

8. Children's privacy

Nyralux is not intended for anyone below the minimum age established for the published service. The policy owner still needs to select and document the supported minimum age and any parental-consent requirements for every launch region.

9. Changes

Nyralux may update this policy as the service changes. The published version must show its effective date, and material changes should be communicated through an appropriate in-app or account notice.

10. Contact

Publication blocker: replace this section with a verified privacy contact, legal entity/controller name, and mailing address where required.