Privacy policy
What is collected, who else sees it, and how to get it deleted. Short, because not much is collected.
Last updated 26 July 2026
Who is responsible
Nuxavel is built and maintained by a small team based in Brazil. Personal data described in this policy is controlled by Nuxavel's operator, who is reachable at support@nuxavel.com — including for requests to access or delete your data.
This website
This site uses Vercel Web Analytics, which counts page views and referrers in aggregate. It sets no cookies, does not fingerprint visitors and does not build a profile across sites — which is why there is no cookie banner here. Vercel also hosts the site and, like any web host, processes the IP address your browser sends in order to serve the page.
There are no advertising trackers, no social media pixels and no third-party scripts other than the analytics endpoint described above.
Buying a licence
Checkout is handled by Paddle as merchant of record. They are the seller on your receipt and the party that collects your payment details — we never see or store your card number. Their privacy policy governs that part of the transaction.
From a completed order we receive and keep:
- your name and email address;
- the licence purchased, the amount and the date;
- the country Paddle determined for tax purposes;
- the GitHub username you supply at checkout.
That data is used to grant your repository access, to email you about the code you bought, and to answer support questions. It is kept as long as your licence exists, because a licence with no record of who holds it is not a licence. It is never sold, rented or shared for marketing.
GitHub
The GitHub username you provide is sent to GitHub in order to invite you to the private repository. That is the entire purpose it is collected for. Your use of GitHub is governed by GitHub's own terms and privacy policy.
While you are typing it at checkout, your browser also asks GitHub's public API whether that account exists, so that a typo is caught before you pay rather than after. That request goes from your browser straight to GitHub and carries only the username — we never see it, and nothing is stored unless you complete the purchase.
Buyers receive email about the product they purchased — release notes and anything affecting the code they hold. There is no marketing list and nothing is sold to one. If you email support, that thread is kept so the conversation makes sense next time.
The live demo
The demo runs on shared, published accounts that anyone can sign into, and its database is wiped and reseeded every night. Treat everything you enter there as public and temporary — it is a sandbox, not a place to put real data.
The demo's AI assistant is switched off deliberately, and prompts typed into it are not sent to a model or stored. Its email is written to a log rather than delivered, and its payment keys are test keys, so no real message or charge can leave the demo.
Who else processes your data
- Paddle — payment, invoicing and tax.
- Vercel — hosting and analytics for this site.
- GitHub — private repository access.
- Railway — hosting for the demo.
Each of these is a company acting on our behalf under its own privacy terms. There is no other recipient.
Your rights
You may ask for a copy of the data held about you, ask for it to be corrected, or ask for it to be deleted. Write to support@nuxavel.com and you will get a reply within 30 days.
One limit worth stating plainly: deleting your purchase record ends the licence attached to it, because the record is the licence. Repository access ends with it. Order data may also need to be retained where tax law requires it — in that case Paddle holds it as merchant of record, not us.
Changes
If this policy changes materially, the date at the top of this page changes with it, and buyers are told by email.