Privacy Policy
Effective 14 August 2026 · Version 3.0
This policy explains what personal data NovaBuild collects when you use novabuild.dev, why we process it, who we share it with, how long we keep it, and the rights you can exercise. It covers the platform itself. It does not cover applications you build and deploy with NovaBuild, where you are the controller and you must publish your own notice.
Plain language summary
- We collect account details, workspace and project data, prompts and generated files, credential metadata, billing records and technical logs.
- We do not sell personal data, and we do not use your prompts or code to train foundation models.
- Prompts and file context are sent to the model provider needed to answer them, and to sandbox infrastructure to run your code.
- You can export or delete your data at any time, and you can ask us for a copy of what we hold.
- Full credential values are never returned to a browser. Only a label, provider and last four characters are shown.
The summary is for orientation only. The numbered sections below are the operative text.
1. Scope and roles
For the NovaBuild platform, we are the controller of personal data about account holders, workspace members, prospects and visitors. For content you put into projects, including personal data about your own end users, you are the controller and NovaBuild is your processor. That relationship is governed by the Data Processing Addendum.
If you are a member of a workspace created by someone else, that workspace owner can see the projects, chat history and usage in that workspace. Talk to them about their own retention choices.
2. Categories of data we collect
| Category | Examples | Notes |
|---|---|---|
| Identity and account | Email address, display name, avatar URL, authentication provider, hashed password material held by the managed auth service | We never see raw passwords |
| Workspace and membership | Workspace name, role, invitations, plan, ownership transfers | Visible to workspace admins |
| Project content | Prompts, chat messages, generated files, diffs, agent run logs, build and typecheck output, preview screenshots | May contain personal data you choose to include |
| Credential metadata | Provider, label, last four characters, created and last used timestamps, verification status | The secret itself is encrypted and never displayed again |
| Usage and metering | Credit ledger entries, token counts per run, model selected, sandbox minutes, deploy events, rate limit counters | Needed for accurate billing |
| Billing | Plan, invoices, payment status, billing address, tax identifier, partial card details supplied by the processor | We do not store full card numbers |
| Technical | IP address, user agent, timestamps, request paths, error traces, performance timings | Retained for security and debugging |
| Communications | Support emails, in app messages, transactional email delivery status | Includes anti abuse signals |
| Referrals | Referral code, signup attribution, reward status | Referred user details are not shown to the referrer |
3. Sources of data
- Directly from you when you register, create projects, type prompts, upload files or contact support.
- Automatically from your device and browser when you use the app, including cookies described in the Cookie Policy.
- From services you connect, such as an identity provider returning your email and name, or a source host returning repository metadata.
- From our payment processor, which returns billing status and limited card metadata.
- From security tooling, which produces abuse and fraud signals about requests.
4. Why we use data and our legal bases
| Purpose | Data used | Legal basis |
|---|---|---|
| Provide the platform, run agents, sandboxes, previews and deploys | Account, project, technical | Performance of a contract |
| Meter usage and bill accurately | Usage, billing | Performance of a contract |
| Authenticate you and secure accounts | Identity, technical | Contract and legitimate interests |
| Prevent abuse, fraud and platform harm | Technical, usage, communications | Legitimate interests |
| Provide support | Communications, project, technical | Contract and legitimate interests |
| Improve reliability and product quality using aggregate data | Aggregated usage and error data | Legitimate interests |
| Send service and security notices | Identity, communications | Contract and legal obligation |
| Send product marketing | Identity, communications | Consent, withdrawable at any time |
| Meet tax, accounting and legal duties | Billing, communications | Legal obligation |
| Defend legal claims | Any relevant category | Legitimate interests |
Where we rely on legitimate interests we have balanced them against your rights, and you can object using the contact details below.
5. Prompts, code and model providers
To answer a prompt we send the prompt, the relevant slices of your project file tree, tool results and conversation history to the model provider selected for the run. Providers currently in use are listed on the Subprocessors page. If you supply your own provider key, the request goes to that provider under your own account and their terms.
To build and preview your project we send your project files to the sandbox provider, which runs dependency installs, typechecks, dev servers and production builds inside an isolated container.
Keep secrets out of prompts
Anything typed into a prompt becomes part of the conversation and may be sent to a model provider. Store credentials in the workspace key vault instead, where they are encrypted and injected only inside the sandbox at run time.
6. Model training
We do not use your prompts, project files, generated code or chat history to train or fine tune foundation models, and our provider agreements are configured to exclude platform traffic from provider training where the provider offers that setting. We may use aggregated and de identified metrics, such as error rates, tool call success rates and latency, to improve routing and prompts. Those metrics do not contain your code or your customers' data.
7. Sharing and disclosure
We share personal data only in these cases:
- Subprocessors that operate parts of the service on our behalf, under contract, listed on the Subprocessors page.
- Other members of your workspace, according to their role.
- Anyone with the link, for projects you set to public, limited to the file tree and preview.
- Payment and tax providers, to take payment and issue invoices.
- Professional advisers, auditors and insurers, under confidentiality.
- Authorities, where a valid legal request applies. We check the request, resist overbroad demands, and tell you unless prohibited.
- An acquirer, in a merger or sale of assets, with notice to you and no reduction in protection.
We do not sell personal data and we do not share it for cross context behavioural advertising.
8. International transfers
NovaBuild and its providers operate globally, so data may be processed outside your country, including in the United States and the European Economic Area. Where we transfer personal data out of the EEA, the United Kingdom or Switzerland, we rely on an adequacy decision where one exists, and otherwise on the Standard Contractual Clauses with the UK Addendum, combined with technical measures such as encryption in transit and at rest and strict access control. A copy of the transfer mechanism used for a given provider is available on request.
9. Retention schedule
| Data | Retention | Trigger |
|---|---|---|
| Account and workspace records | Life of the account plus 30 days | Workspace deletion |
| Project files, chat history, agent logs | Until you delete the project or workspace | Your action |
| Credential secrets | Until you remove the credential | Your action, immediate purge from live systems |
| Credit ledger and invoices | 7 years | Tax and accounting law |
| Security and audit logs | 12 months | Rolling window |
| Rate limit counters | Up to 24 hours | Rolling window |
| Sandbox contents | Ephemeral, cleared when the machine stops | Idle reaper or session end |
| Encrypted backups | Up to 35 days | Rolling window, then automatic expiry |
| Support correspondence | 24 months | Last message |
| Marketing contact records | Until you unsubscribe plus 12 months | Your action |
Deletion from live systems is immediate or same day. Copies inside encrypted backups roll off on the schedule above, and we do not restore deleted content from backup except to recover from an incident affecting the whole platform.
10. Security of processing
Measures include encryption in transit with modern TLS, encryption at rest for databases and backups, row level security on every tenant table, credential encryption with server side only decryption, least privilege access for staff with logging, isolated per project sandboxes, tamper resistant audit logging, rate limiting and quota enforcement, dependency scanning, and code review before release. Full detail is in the Security page.
11. Your rights
Depending on where you live, you can ask us to:
- confirm what we hold and give you a copy, in a portable format where applicable;
- correct data that is wrong or incomplete;
- delete data, subject to legal retention such as invoices;
- restrict or object to processing, including profiling for abuse prevention;
- withdraw consent for marketing at any time, without affecting other processing;
- not be discriminated against for exercising a privacy right;
- appeal a decision we make about your request.
Many of these can be done yourself in the app: export a project, delete a project, delete a workspace, change your email, or unsubscribe from marketing.
12. How to make a request
Email privacy@novabuild.dev from the address on your account, and tell us what you want. We verify identity before acting, respond within 30 days, and may extend once by a further 60 days for complex requests, telling you why. There is no charge unless a request is excessive or repetitive. An authorised agent may act for you with written proof.
14. Automated decision making
We use automated checks to score requests for abuse and fraud, to enforce rate limits, and to route prompts to a model. These decisions can slow or block a request, but they do not have legal effects on you within the meaning of data protection law. If an automated control blocks you incorrectly, email support@novabuild.dev and a human will review it.
15. Children
NovaBuild is not intended for children under 16, we do not knowingly collect their data, and we will delete an account promptly if we learn the holder is under age. Contact privacy@novabuild.dev if you believe a child has registered.
16. Public projects and what they expose
On the free plan projects are public by default. A public share page exposes the generated file tree, the rendered preview, the project name and description, and aggregate view counts.
Never exposed on a public page
- Chat history and agent reasoning logs
- Credential values, environment variable values and key vault metadata
- Credit balances, ledger entries and invoices
- Workspace member identities and roles
- Anything stored in a connected database rather than in project files
Anyone can request removal of personal data that appears in a public project by emailing privacy@novabuild.dev with the share link and the detail concerned.
17. Regional disclosures
European Economic Area, United Kingdom and Switzerland
You have the rights in section 11 and can complain to your supervisory authority. We do not currently require a Data Protection Officer, and privacy@novabuild.dev is the contact point for all data protection matters.
California
We collect the categories in section 2, for the purposes in section 4, from the sources in section 3, and disclose them for business purposes to the recipients in section 7. We do not sell personal information and do not share it for cross context behavioural advertising. You can exercise access, deletion, correction and opt out rights as described above, and we will not discriminate against you for doing so.
Other United States states
Residents of states with comprehensive privacy laws, including Colorado, Connecticut, Virginia, Utah, Texas and Oregon, have access, correction, deletion, portability and opt out rights, plus an appeal right if we deny a request. Use the same contact address.
Australia
We handle personal information in line with the Australian Privacy Principles, including notification of eligible data breaches to affected individuals and the regulator.
18. Data breach handling
We maintain an incident response process with defined severities, on call escalation, containment steps and post incident review. If a breach affects your personal data and is likely to create risk, we notify you without undue delay, and we notify supervisory authorities within 72 hours where the law requires it. Where we act as your processor we notify you promptly so you can meet your own notification duties.
19. Changes to this policy
We update this policy as the product changes. The effective date and version at the top reflect the current text. Material changes are announced in the app or by email before they take effect, and we keep prior versions available on request.
20. Contact and complaints
Privacy requests and questions: privacy@novabuild.dev. Security reports: security@novabuild.dev. If you are unhappy with our response you can complain to your local data protection authority, and we ask that you give us the chance to fix the issue first.
This document is published by the NovaBuild team as general information about the service. It is not legal advice, and it is not a certification or an independent audit of NovaBuild or of any third party. If anything here is unclear, or you need a countersigned copy for procurement, email legal@novabuild.dev.