1. Information collected
I collect information you provide directly, such as your name, email address, organization details, subscription details, support messages, and content entered into the platform.
Most API request payloads are processed transiently and are not permanently stored. Some features intentionally retain data, such as saved variables, connection records, account records, billing records, and files stored in R2.
If you send personal data through requests, variables, files, or templates, that data may be processed as part of providing the service.
2. How information is used
Information is used to provide, operate, secure, and improve the service.
It is also used to process billing, subscription changes, refunds, receipts, account notices, product communication, usage tracking, and support requests.
Information may be used to comply with legal obligations, enforce agreements, and prevent fraud, abuse, or other misuse of the service.
3. Service providers
The service uses third-party providers to operate certain parts of the product:
- Railway for hosting and infrastructure, with production data hosted in EU West where configured.
- Resend for sending transactional and product emails.
- Stripe for billing, subscriptions, invoicing, and payment processing.
- Cloudflare R2 for storing files created by supported APIs.
- Google Analytics for website traffic analysis and product measurement where enabled.
Information may also be shared if required by law, to respond to lawful requests, to protect rights and safety, or to help prevent fraud and abuse. Personal information is not sold.
4. Retention and security
Customer payloads are processed through the infrastructure and discarded unless a feature explicitly stores them.
Files created by supported APIs are deleted according to the API settings you choose, including any expiration you set on the file or the configured retention period for that tool.
Data that must be retained for account management, billing, support, security, or legal reasons may be stored for that purpose. Secrets are encrypted at rest where supported by the product. Transport security, access controls, and operational safeguards are used, but no system is perfectly secure.
You are responsible for the content you send to the service and for ensuring you have the right to process it.
5. Your choices
You may access, update, export, or delete data through the app or by contacting support.
Cookies can be managed through your browser, and analytics may be limited by browser or consent settings.
If account deletion is requested, it will be handled subject to legal and business retention requirements.
6. Contact
Privacy requests can be sent to support[ AT] nisastack [DOT] com.
This policy may be updated from time to time. The version on this page is the current one.