Privacy Policy
Last updated: July 21, 2026
This policy describes what data Nyvel ("we", "us") collects when your organization uses the Service, why we collect it, and the choices you have. Questions or requests: support@nyvel.io.
1. Data we collect
- Account data. Your name and email address, provided through our sign-in provider (WorkOS) when you authenticate with Google or GitHub, and your organization's name.
- Device inventory and security posture. When you connect an MDM, we read the device information your MDM exposes for the devices you choose to observe: serial number, device name, model, OS version, tags and device-group membership, enrollment state, and the state of security settings (for example FileVault, firewall, Gatekeeper, System Integrity Protection, screen lock, and update status). We do not collect the contents of files, messages, browsing history, or location from your devices.
- MDM API credentials. Stored encrypted at rest and used only to read from your MDM. You can rotate or revoke them at any time.
- Billing data. Payments are processed by Stripe. We store your subscription state and invoicing identifiers; we never see or store full card numbers.
- Service logs. Standard operational logs (such as API requests and sync outcomes) used to run and secure the Service.
2. How we use data
Solely to provide, secure, support, and improve the Service: rendering your compliance evidence, generating exports you request, sending alerts you subscribe to, billing, and responding to support requests. We do not sell personal data, and we do not use your fleet data for advertising.
3. Subprocessors
We rely on a small set of service providers to operate the Service: WorkOS (authentication), Stripe (payments), Fly.io and Cloudflare (hosting and delivery), Neon (database hosting), Resend (transactional email), and the MDM platforms you choose to connect. Each processes only what its role requires. Data may be processed in the European Union and the United States.
4. Retention and deletion
Fleet and evidence data is retained while your organization's account is active — retaining history is the point of a compliance-evidence service. When you delete your account or ask us to, we delete your organization's data within a reasonable period, except where law requires longer retention (for example invoicing records). Disconnecting an MDM stops collection from it immediately.
5. Security
MDM credentials are encrypted at rest, access to production systems is restricted, and connections use TLS. No system is perfectly secure; if we learn of a breach affecting your data we will notify you without undue delay.
6. Your rights
Depending on where you are, you may have rights to access, correct, export, or delete personal data, and to object to or restrict processing. Contact support@nyvel.io and we will respond. If you are in the EU/EEA you may also lodge a complaint with your supervisory authority.
7. Cookies
The application uses cookies only to keep you signed in. We do not use advertising or cross-site tracking cookies.
8. Changes
We may update this policy as the Service evolves. For material changes we will give notice before they take effect. The "last updated" date above always reflects the current version.