Privacy Policy
The short version. We collect what we need to run your account, build and operate your apps, and bill you. Your code and data are yours; we do not sell personal information and we do not use your code or data to train AI models. AI agents do the building, so your briefs, code and some telemetry are sent to the AI provider you connect, or to ours for included builds. Our own analytics on nanza.com are cookieless. The details, including every provider we use, are below.
- Who this covers
- Information we collect
- How we use it
- AI processing
- Cookies and similar technologies
- How we share information
- How long we keep it
- Security
- Your rights and choices
- Where data is stored
- Children
- If you build an app on Nanza
- Changes to this policy
- Contact
1. Who this covers
This policy describes how Nanza LLC ("Nanza", "we", "us") handles information when you visit nanza.com, create an account, use the Nanza platform, or communicate with us. It applies to our customers, the members they invite, and visitors to our website.
It does not describe what the apps our customers build do with their own users' information. Each customer operates their app and is responsible for its privacy notice; we process that information only on the customer's instructions, as explained in section 12.
2. Information we collect
2.1 Account and profile
Your name, email address, password (stored only as a hash), preferred language, account and team names, the roles you assign to members, and the notification preferences you set. If you sign in with Google, we receive your name, email address and Google account identifier from Google.
2.2 Billing
Payments are processed by Stripe. We never see or store your full card number. From Stripe we keep your customer and subscription identifiers, the status of your subscription, invoice records (amount, tax, status, invoice number and a link to Stripe's invoice page), and a display summary of your payment method (card brand and last four digits). Your billing address and tax identification number are collected by Stripe during checkout and used to calculate tax and issue invoices.
2.3 The content you create on the platform
The briefs and descriptions you write, the tasks on your project boards, your conversations with your Manager and with the agents, files and screenshots you upload, project documentation, settings, and the application secrets you store for your app (which are encrypted and never shown back in full).
2.4 Your app's source code
The code of each app, held in a source repository that we manage for you or that you connect, together with its history of changes, whether made by you or by the agents.
2.5 Connected accounts and credentials
When you connect an AI provider, GitHub, a cloud provider, a domain registrar, an email, messaging or telephony provider, or similar, we store the token or key needed to act on your behalf. These are encrypted at rest and used only for the purpose you connected them for.
2.6 Telemetry from your apps
Apps built on Nanza report errors, logs, performance metrics, request traces and deployment markers to our monitoring service so that we can detect and fix problems. Depending on what your app does, that telemetry can include information about your app's users (for example an email address in an error message or a request path). Section 12 explains your responsibilities for that.
2.7 Your app's production data
Your app's own database and files live on hosting we manage for you. We do not read them in the ordinary course. Your Manager and agents can read production data when you or your team ask them to, through a brokered path that uses a read-only database role by default; changes require a separate permission and take a backup first. Every such action is recorded.
2.8 Usage and technical information
- Website analytics. Our own analytics on nanza.com are cookieless. For each page view we record the page path, the referring site's hostname, campaign parameters from the link you arrived by, your screen size and language, and a short-lived session identifier kept in your browser's session storage. We use your IP address at the moment of the request to derive a coarse location (country, region and city) and to make a visitor identifier that rotates every day; the IP address itself is not stored with the analytics record.
- Product events. Key actions in your account (signing up, creating a project, running a build, publishing, changing a plan) are recorded with your user identifier so we can understand how the Service is used and support you.
- Server logs. Requests to our systems are logged with the IP address, browser or client identifier, request identifiers and timing, and kept for a short period for security and troubleshooting.
- Error reports. If the Nanza web application itself has an error in your browser, a report with the error, the page and your browser type is sent to us.
2.9 Communications
Emails you send us, feedback you submit from inside the app (including screenshots you attach), and support conversations. If you use voice or messaging features on an Enterprise plan, the call and message content those features handle.
3. How we use it
We use the information above to:
- provide the Service: build, preview, publish, host, monitor and repair your apps, and run your Manager and agents;
- bill you, collect the right taxes, and send you receipts, invoices and payment notices;
- keep the Service secure, prevent abuse and fraud, enforce our Terms of Service, and investigate incidents;
- support you when you ask, and tell you about changes to your account, your apps, your plan or the Service;
- understand how the Service is used and improve it;
- comply with the law and protect our rights and those of others.
We send transactional email about your account and apps. We do not currently send marketing email; if we start, you will be able to opt out from each message.
4. AI processing
Building and operating your app is done by AI agents. To do that work, your briefs, instructions, conversations, the relevant parts of your code, and excerpts of telemetry (such as an error and the code around it) are sent to an AI model provider:
- Your connected provider. Once you connect your own AI provider account (for example Anthropic or OpenAI), the agents run on that account. The provider's terms and privacy policy apply to that processing, and the provider bills you directly.
- Nanza's provider account. Builds included with the Starter plan, and your Manager while you have not yet connected a provider, run on Nanza's account with Anthropic under Anthropic's commercial terms, which do not permit training on that data.
Nanza does not use your content, code or telemetry to train AI models, and we do not permit the providers we use to do so where their terms give us that choice. The agents work inside an isolated environment for your account, and their actions on your production systems follow the brokered, audited path described in section 2.7.
5. Cookies and similar technologies
nanza.com uses a small number of strictly necessary cookies: a session cookie that keeps you signed in and a cookie that protects forms against forgery. We store some preferences (such as which panels you collapsed or a message draft) in your browser's local storage. We do not use advertising cookies or third-party tracking, and our analytics do not set cookies. When you pay or manage billing, you are on pages hosted by Stripe, which sets its own cookies under its policy.
6. How we share information
We share information only as described here. We do not sell personal information and we do not share it with advertisers.
6.1 Providers that work for us
These providers process information on our behalf, only for the purposes below and under contracts that require them to protect it:
| Provider | Purpose | What they receive |
|---|---|---|
| Stripe | Payments, invoicing, tax calculation, the customer portal | Your name, email, billing address, tax ID, payment details (entered directly with Stripe), subscription and invoice records |
| DigitalOcean | Servers, storage, networking and DNS for the platform and for hosted apps | Your apps, their data and telemetry, and the platform's own data |
| GitHub | Source code repositories and container image storage | Your apps' code and build images, and the names of your projects |
| Anthropic | AI models for the agents and the Manager (Nanza's account for included builds; your own if you connect one) | Briefs, instructions, conversations, code and telemetry excerpts needed for the work |
| OpenAI | AI models, only when you connect an OpenAI account | The same categories as above, under your account |
| Resend | Sending our email | Your email address and the content of the emails we send you |
| Sign in with Google, and Google Docs, Sheets and Drive features when you connect them | Your Google account identity; documents you ask the agents to create or read | |
| Twilio and Telnyx | Voice calls and text messages for Enterprise voice and messaging features | Phone numbers, call audio and transcripts, message content, when you use those features |
| Namecheap | Domain registration and DNS when you buy or manage a domain through Nanza | Domain registrant details you provide |
| Slack | Internal operational alerts to the Nanza team | Account name, owner email and plan or billing status in the alert text |
Celerbrake, the monitoring service your apps report to, is operated by Nanza. We will update this table when the providers change, and the date at the top of this policy will move.
6.2 On your instruction
When you connect a service to your account or ask the agents to use one (send an email, create a document, publish to a domain), we share what is needed with that service on your behalf.
6.3 Legal and safety
We may disclose information if we believe in good faith that it is required by law, a court order or a government request; to enforce our Terms; to detect or prevent fraud, abuse or security problems; or to protect the rights, property or safety of Nanza, our customers or others. Where the law allows, we will tell you before disclosing your information in response to a legal request.
6.4 Business transfers
If Nanza is involved in a merger, acquisition, financing or sale of assets, information may be transferred as part of that transaction. We will tell you before your information becomes subject to a different privacy policy.
7. How long we keep it
- Account, content and code for as long as your account is open. When you close your account, or an administrator deletes it, we take your hosted apps offline, delete their servers and the associated DNS records, remove your isolated build environments and previews, and archive your monitoring data. Your source repositories are kept in our managed repository organization until you download and delete them or ask us to delete them, so that nothing is lost by accident.
- Backups of hosted app databases rotate on a short schedule (seven daily restore points on the app's server) with a separate off-site copy kept for a limited period, after which they expire.
- Billing records (invoices, payments, tax records) for as long as tax and accounting law requires, generally seven years.
- Telemetry from your apps is kept on a rolling window: logs and traces for a short period, error groups until they are resolved and then for a limited time afterward.
- Payment provider webhooks we receive from Stripe are kept for 180 days for reconciliation, then pruned.
- Server logs for a short period, typically no more than 30 days.
- Website analytics are kept in aggregate; the daily-rotating visitor identifier cannot be linked back to you after the day it was made.
We may keep information longer where we need it to resolve a dispute, enforce our Terms, or meet a legal obligation.
8. Security
We protect information with measures that include encryption in transit (TLS everywhere), encryption of stored credentials and secrets, isolated per-account environments for builds and previews, least-privilege access to production systems, brokered and audited production data access, regular backups, and monitoring of our own platform. No method of storage or transmission is completely secure, so we cannot promise absolute security. If you believe you have found a vulnerability or that your account has been compromised, write to hello@nanza.com and we will respond promptly.
9. Your rights and choices
Depending on where you live, you may have rights to access, correct, delete, restrict or object to our processing of your personal information, to receive a copy of it in a portable form, and to withdraw consent where processing is based on consent. You can exercise most of these directly:
- Access and correction: your profile and account details are editable in Settings.
- Portability: on plans that include it, download your code from the project's settings; ask us for a copy of other data.
- Deletion: close your account from Settings, or write to us. Section 7 describes what happens next.
- Billing details: update your payment method and address in the customer portal, reached from Settings, Your Plan.
For anything else, or if you cannot use those tools, email hello@nanza.com. We will respond within the time the applicable law requires, and we may need to verify your identity first. If you are in the European Economic Area, the United Kingdom or Switzerland, you also have the right to complain to your local data protection authority. If you are a California resident, you have the rights described above under the CCPA; we do not sell or share personal information for cross-context behavioral advertising, and we do not discriminate against anyone for exercising their rights. Our website does not respond to browser "Do Not Track" signals, because it does not track you across sites in the first place.
10. Where data is stored
Nanza is based in the United States and our systems and providers store and process information there. If you use the Service from elsewhere, your information will be transferred to the United States. Where the law requires a legal basis for that transfer, we rely on standard contractual clauses or an equivalent mechanism, available on request.
11. Children
The Service is for businesses and adults. We do not knowingly collect personal information from anyone under 18, and accounts are not available to them. If you believe a minor has given us information, contact us and we will delete it.
12. If you build an app on Nanza
For the apps built and hosted on Nanza, our customer is the operator of the app and decides what it collects and why; Nanza processes that information as a service provider on the customer's instructions, to build, run, monitor and repair the app. That includes hosting the app's data, holding its backups, receiving its telemetry, and letting the customer's agents act on its production data when the customer directs.
If you are a customer: you must give your app's users a privacy notice that covers Nanza's role, obtain any consents your app needs, and not use the Service for regulated data without a written agreement with us. We will help you respond to your users' requests about their data where you cannot do so yourself, and we will tell you about a security incident affecting your app's data without undue delay. A data processing agreement is available on request.
If you are a user of an app built on Nanza and have a question about your information, contact the operator of that app; their notice, not this one, governs it.
13. Changes to this policy
We may update this policy as the Service and the law change. If a change is material, we will tell you by email or in the app before it takes effect. The effective date at the top always reflects the current version.
14. Contact
Nanza LLC
Email: hello@nanza.com