Novence

Legal

Privacy Policy

Effective date: 31st July 2026

This Privacy Policy explains how Novence (“Novence,” “we,” “us,” or “our”) collects, uses, discloses, and protects information in connection with the websites, APIs, and services provided at novence.ai and api.novence.ai (collectively, the “Service”). It applies to account holders, the human principals behind Agents that access the Service, and visitors to our marketing and documentation pages. It does not apply to the content of static sites you deploy through the Service, which is governed by our Terms of Service and, where applicable, your own privacy policy for that content.

1. Information We Collect

1.1 Information You Provide

  • Account information: your email address, provided during the bootstrap process, and any information you provide during email verification (OTP).
  • Payment information: if you upgrade to a paid plan, Stripe collects and processes your payment card or bank details on our behalf; we receive only limited billing metadata (such as plan tier, subscription status, and the last four digits of a payment method) and do not store full card numbers.
  • Communications: information you provide when you contact support, respond to surveys, or otherwise communicate with us.
  • Domain information: if you configure a custom domain, the domain name itself and the DNS configuration details necessary to route and secure traffic to it.

1.2 Information Collected Automatically

  • Usage data: API calls, project and deployment metadata, storage and bandwidth consumption, check results (e.g., Lighthouse/axe/ link-check output), and quota usage.
  • Log and device data: IP addresses, request timestamps, user-agent or MCP client identifiers, and error logs, collected for security, debugging, and abuse prevention.
  • Cookies and similar technologies on our marketing and documentation pages, as described in Section 10.

1.3 Content You Deploy

When you upload or deploy static site files, those files are stored and served as part of the Service. We do not review the content of deployed sites except as necessary to run automated checks, respond to abuse reports, or comply with legal obligations (see our Acceptable Use and Copyright policies in the Terms of Service).

1.4 Form Submission Data (Novence Forms)

If a site owner enables our optional forms feature, we process the information visitors submit through forms on that site on the site owner’s behalf. This includes the form fields defined by the site owner (which may contain contact details such as a name or email address), together with a hashed IP address and a truncated user-agent string that we record for security, rate limiting, and abuse prevention. We deliver each submission by email to the site owner and store it until the site owner deletes it or their account is terminated. For this data, the site owner — not Novence — determines what is collected and why. If you submitted information through a form on a site hosted by the Service, please contact the site owner in the first instance and refer to that site’s own privacy policy. We do not use form submission content for our own purposes beyond providing the Service.

2. How We Use Information

We use the information described above to:

  • Provide, operate, and maintain the Service, including deploying and serving Your Content;
  • Process payments and manage subscriptions, quotas, and billing;
  • Verify accounts and secure the Service against fraud, abuse, and unauthorized access;
  • Enforce our Acceptable Use Policy and respond to abuse or copyright reports;
  • Receive, store, and deliver form submissions to site owners, and protect the forms feature against spam and abuse;
  • Communicate with you about the Service, including security notices, billing, and (where you have not opted out) product updates;
  • Analyze and improve the performance, reliability, and features of the Service; and
  • Comply with legal obligations.

4. How We Share Information

We do not sell your personal information. We share information with:

  • Service providers (subprocessors) who help us operate the Service, including Stripe (payment processing) and Cloudflare (edge delivery, DNS, and TLS certificate provisioning for custom domains), plus infrastructure and email-delivery providers who help us send verification and transactional emails.
  • Legal and safety disclosures, where we believe in good faith that disclosure is necessary to comply with a legal obligation, protect the rights or safety of Novence, our users, or the public, or investigate suspected violations of our Terms.
  • Business transfers, where information may be transferred in connection with a merger, acquisition, financing, or sale of assets, subject to standard confidentiality protections.

We maintain a current list of material subprocessors and will update it as our vendor relationships change; contact us at [email protected] for the current list.

5. Data Retention

We retain account and billing information for as long as your account is active and for a reasonable period thereafter (currently up to 90 days) to allow for account recovery, resolve disputes, and comply with legal and tax obligations. Deployed site content and associated project data are retained per your plan’s terms and are generally deleted within 30 days of account termination, except where longer retention is required by law. Logs used for security and abuse prevention are retained for a limited period (typically 12 months) and then deleted or anonymized. Form submissions received through Novence Forms are retained until the site owner deletes them via the API or their account is terminated, at which point they are deleted on the schedule described above.

6. Data Security

We use technical and organizational measures designed to protect information against unauthorized access, alteration, disclosure, or destruction, including encryption of data in transit (TLS) and access controls on production systems. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

7. International Data Transfers

We and our subprocessors may process information in countries other than your own, including the United States. Where required, we rely on appropriate safeguards for such transfers, such as Standard Contractual Clauses, to ensure your information receives an adequate level of protection.

8. Your Privacy Rights

8.1 EEA, UK, and Similar Jurisdictions

If GDPR or UK GDPR applies to you, you have the right to access, correct, delete, restrict, or port your personal information, to object to certain processing, and to withdraw consent where processing is based on consent. You also have the right to lodge a complaint with your local data protection supervisory authority.

8.2 California and Other U.S. State Privacy Laws

If you are a California resident, the CCPA/CPRA gives you the right to know what personal information we collect, to request deletion or correction, and to opt out of the “sale” or “sharing” of personal information — we do not sell or share personal information as those terms are defined by the CCPA/CPRA. Residents of other U.S. states with comprehensive privacy laws (such as Virginia, Colorado, and Connecticut) may have similar rights, which we honor consistent with applicable law.

8.3 How to Exercise Your Rights

You can exercise most of these rights directly via the API or your local account console (for example, exporting or deleting projects), or by contacting us at [email protected]. We may need to verify your identity before fulfilling certain requests.

9. Children’s Privacy

The Service is not directed to children under the age of 16, and we do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us at [email protected] and we will take steps to delete it.

10. Cookies and Similar Technologies

Our marketing site and documentation pages may use cookies and similar technologies for essential site functionality, analytics, and (where applicable) to remember your preferences. Our API and local account console use functionally necessary tokens for authentication and session management. Where required by law, we will present a cookie consent mechanism allowing you to accept or decline non-essential cookies.

11. Automated Processing

Deployments are evaluated by automated check tools that assess technical properties of your site (such as performance, accessibility, and broken links). This automated evaluation applies to Your Content, not to you personally, and does not involve automated decision-making that produces legal or similarly significant effects about you as an individual within the meaning of Article 22 GDPR.

12. Third-Party Links

The Service, our documentation, and sites deployed by our users may contain links to third-party websites. We are not responsible for the privacy practices of those third parties, and we encourage you to review their privacy policies.

13. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will update the effective date and, where appropriate, provide additional notice (such as email or an in-app notification). Your continued use of the Service after changes take effect constitutes acceptance of the revised policy.

14. Contact Us

Questions about this Privacy Policy or requests regarding your personal information can be directed to [email protected].