← Back to nuvrail.com

Privacy Policy

Nuvrail, Inc.

Effective date: May 1, 2026 · Last updated: 2026-06-03

1. Who We Are

Nuvrail, Inc. (“Nuvrail,” “we,” “us,” or “our”) operates the Nuvrail approval gateway — a proxy layer between AI agents and email servers. By default it stages every AI-proposed email action for human review before execution. You may also configure auto-approval rules that automatically approve, reject, defer, or flag matching actions — including sending email — without per-action human review (see Sections 3.2, 4, and 8).

Contact: hello@nuvrail.com


2. What This Policy Covers

This policy describes how we collect, use, store, and share personal information when you use:

  • The Nuvrail web application (app.nuvrail.com or test.nuvrail.com)
  • The nuvrail.com marketing website
  • The Nuvrail proxy service (IMAP/SMTP gateway)

3. Information We Collect

3.1 Information You Provide

  • Account information: email address, name, company name (at signup)
  • Email credentials: IMAP/SMTP server address, port, username, and password or, for Gmail, an OAuth 2.0 refresh token. On our hosted service these credentials are stored in Google Cloud Secret Manager — our application database holds only a reference to the secret, never the secret itself. They are fetched on demand, held briefly in memory, and used solely to operate the proxy on your behalf. Short-lived OAuth access tokens are kept in memory only and are never written to disk. (Self-hosted deployments of the open-source core may instead encrypt credentials at rest with AES-256-GCM.)
  • Configuration: rules, approval settings, and preferences you set in the application.
  • Waitlist: if you join the waitlist on nuvrail.com, we collect the email address (and any details) you submit. Waitlist email is processed by our email provider, Loops (see Section 7).

3.2 Information Generated by the Service

  • Pending operations: when an AI agent proposes an email action through the proxy, we record the proposed operation (e.g., “send email to X with subject Y”) along with its status (pending, scheduled, approved, rejected, executed, or expired). If you have configured auto-approval rules, an operation may reach its status automatically — decided by a rule — rather than by your manual review.
  • Audit log: every operation that passes through the proxy is written to an immutable append-only log. This includes the timestamp, the action type, the proposing agent identifier, the decision (e.g., approved, rejected, scheduled, held, or executed), and who or what made it — either the approving human’s identifier or, for an automated decision, an indication that an auto-approval rule decided it together with that rule’s identifier and description. If you run a rule in “shadow” mode, the log also records the decision the rule would have made, without acting on it.Audit log entries are not deleted — this is a core feature of the service.
  • Email metadata: subject lines, sender and recipient addresses, folders, and timestamps of messages your agent acts on, plus a local mirror of message metadata (folders, message IDs, flags) the proxy needs to present a consistent mailbox. For outbound sends and message uploads (IMAP APPEND)staged for review, we store the full message body in the staged-operation record so it can be delivered if you approve. A background process scrubs the body (and any short preview) 7 daysafter the operation reaches a terminal state; only the envelope metadata (subject, sender, recipient) is retained thereafter. We do not store the contents of messages your agent merely reads.

3.3 Technical Information

  • Server logs: IP address, browser type, referring URL, pages visited, timestamps. Retained for up to 90 days for security and debugging purposes.
  • Authentication tokens: the web application stores your session token in browser localStorage (not a browser cookie). No analytics cookies are used; we use Plausible Analytics (no cookies) — see Section 9.

4. How We Use Your Information

We use the information we collect to:

  • Operate the Nuvrail proxy and web application
  • Stage AI-proposed email operations for your review
  • Evaluate proposed operations against the auto-approval rules you configure — matching on attributes such as operation type, sender, recipient, subject, source and destination folder, message flags, and the number of messages affected — to automatically approve, reject, defer (with a cool-down window before sending), or flag them. This evaluation runs only within your own account; we do not use it to build cross-customer profiles, and it is not used to train AI models.
  • Maintain the audit log (integrity is a core service property; audit log entries are cryptographically hash-chained — each row's SHA-256 hash covers all its fields plus the previous row's hash, making any tampering detectable)
  • Authenticate you and keep your account secure
  • Send transactional emails (account confirmations, alerts for pending operations)
  • Respond to support requests
  • Improve the service (aggregate analytics only — we do not use your email content for training AI models)
  • Comply with legal obligations

We do not:

  • Sell your personal information or email credentials to third parties
  • Use your email content to train AI models (ours or anyone else’s)
  • Share your credentials with the AI agents that connect through the proxy (agents see only the proxy interface, not your underlying credentials)

5. How We Store and Protect Your Information

  • Email credentials are stored in Google Cloud Secret Manager, isolated from our application database (which holds only a reference to each secret). Access is restricted to the gateway’s service identity; credentials are never logged and are held in memory only transiently. Short-lived OAuth access tokens are never persisted. (Self-hosted deployments of the open-source core may instead encrypt credentials at rest with AES-256-GCM.)
  • Audit log entries are append-only — the application never issues DELETE or UPDATE against the audit log table. Once an event is written it stays in the record. Each entry is cryptographically chained to the previous one (SHA-256 hash linkage), making any retrospective modification detectable.
  • Data is stored on fly.io infrastructure in the United States: regions iad (Northern Virginia) and ord (Chicago, Illinois); email credentials reside in Google Cloud Secret Manager (United States).
  • We use TLS for all data in transit.
  • For outbound sends and IMAP APPEND operations, the full message body is stored in the staged-operation record (required for delivery on approval). A background process scrubs both the full body and the short preview 7 days after a terminal decision. Only the envelope metadata (subject, sender, recipient) is retained thereafter.

6. Data Retention

Data TypeRetention Period
Account informationUntil you delete your account. Self-serve deletion is available in Settings → Account. On deletion: credentials scrubbed, agents revoked, push subscriptions removed, pending operations cancelled. The audit log is retained.
Email credentialsUntil you disconnect the agent or delete your account, then removed from Google Cloud Secret Manager
Message body (sends / IMAP APPEND)Scrubbed 7 days after the operation reaches a terminal state (approved, rejected, or expired). Only envelope metadata (subject, sender, recipient) is retained thereafter.
Pending operations (pre-approval)48 hours after creation if not approved — the operation is marked ‘expired’ and its optimistic local state is reverted. The operation record is retained in the database as part of the audit trail.
Audit log entriesIndefinite— by design. The audit log is append-only and is the core integrity guarantee of the service. If you need to close your account, we can provide an export; we will retain the log for compliance purposes.
Server logs90 days
Waitlist emailUntil you unsubscribe or we close the waitlist; managed in Loops.
Analytics dataAggregate, anonymised page-view data via Plausible Analytics. No personal data. Retained indefinitely by Plausible.

7. Sharing Your Information

We do not sell your information. We share it only in these circumstances:

  • Service providers (sub-processors): vendors who process data on our behalf under confidentiality obligations:
    • Fly.io — application hosting (United States).
    • Google Cloud (Secret Manager) — encrypted storage of email-account credentials.
    • Google — OAuth authorization for Gmail agents (the Gmail scope you grant).
    • Plausible Analytics — aggregate, cookieless analytics (consent-based; EU-hosted).
    • Loops — waitlist and transactional email.
  • Legal requirements: when required by law, court order, or governmental authority.
  • Business transfers: if Nuvrail is acquired or merges with another company, your information may be transferred. We will notify you before your data is transferred and becomes subject to a different privacy policy.
  • With your explicit consent: for any other purpose.

8. Your Rights

Depending on where you are located, you may have the right to:

  • Access the personal information we hold about you
  • Correct inaccurate information
  • Delete your account — available in Settings → Account. Credentials scrubbed, agents revoked immediately. The audit log is retained per Section 6.
  • Export your data in a machine-readable format — available in Settings → Account → Download My Data.
  • Object to certain processing activities
  • Withdraw consent for optional processing (e.g., analytics cookies)

For EU/EEA residents (GDPR): Our lawful basis for processing your personal data is primarily the performance of a contract (operating the service you signed up for). For analytics, we rely on your consent. Because our infrastructure is in the United States, personal data of EU/EEA and UK users is transferred to the US under appropriate safeguards (e.g., Standard Contractual Clauses). You have the right to lodge a complaint with your national data protection authority.

For California residents (CCPA/CPRA): You have the right to know what personal information we collect, the right to delete it (subject to the audit log retention noted above), and the right to opt out of any sale of personal information (we do not sell personal information).

Automated decisions: Auto-approval rules are optional and are configured and controlled by you. When enabled, they can approve, reject, defer, or flag email operations — including sending email — without a separate human review of each action. You remain in control: rules can be edited or disabled at any time, every automated decision is recorded in the audit log, deferred (cool-down) actions can be cancelled before they run, and you can run a rule in “shadow” mode to observe its effect before it acts. If you are an EU/EEA or UK resident and believe an automated decision produces legal or similarly significant effects concerning you, you may contact us at hello@nuvrail.com to request human review.

To exercise your rights, use our data subject request form or email hello@nuvrail.com with subject “Privacy Request”. We will respond within 30 days.


9. Cookies

We use:

  • Authentication tokens: the web application stores your session token in browser localStorage (not a browser cookie). This is required to stay logged in and cannot be disabled without breaking the service.
  • Analytics (optional, consent-gated): we use Plausible Analytics on nuvrail.com and app.nuvrail.com. Plausible collects no personal data, sets no cookies, and is hosted in the EU. Analytics activate only after you click “Accept all” in the cookie banner.

You can update your cookie preferences at any time by clicking “Cookie preferences” in the footer.


10. Children

The Nuvrail service is not directed at children under 16. We do not knowingly collect personal information from children. If you believe a child has provided us their information, contact us at hello@nuvrail.com.


11. Changes to This Policy

We will post changes to this policy on this page and update the “Last updated” date. For material changes, we will notify you by email or by a prominent notice in the application before the change takes effect.


12. Contact

Nuvrail, Inc.

[Legal entity name — to be confirmed]
[Registered postal address — to be confirmed]

hello@nuvrail.com

For data protection inquiries (including GDPR requests):
hello@nuvrail.com— subject line: “Privacy Request”

© 2026 Nuvrail, Inc.