← Back to Noxavelle

Noxavelle · Effective 16 August 2026

Privacy Notice

1. Who is responsible for your data

Noxavelle is operated by Erik Ha Cong, Slovakia (the “Controller”). Contact: support@meetnoxavelle.com.

2. Data we process

  • Account data: email address, profile name, preferred form of address, age-confirmation timestamp, login-code records and active session records.
  • Conversation data: messages you send, AI replies, selected character and message timestamps.
  • Technical data: an essential local device identifier, security and infrastructure logs, and information needed to prevent abuse and keep the service available.
  • Support data: messages you send to our support address.

Payments are not enabled in the current private beta, so Noxavelle does not collect payment-card data.

3. Why we process it

We process account, profile and conversation data to create your account, authenticate you, remember conversations and provide requested AI replies. The legal basis is performance of our agreement with you (GDPR Article 6(1)(b)). We process limited security and abuse-prevention data for our legitimate interests in protecting Noxavelle and its users (Article 6(1)(f)), and data required by law under Article 6(1)(c).

Noxavelle is not intended for medical, legal, financial or emergency use. Please avoid including highly sensitive personal data in chats. If you choose to include it, it is used only to provide the reply you requested and remains subject to the deletion controls described below.

4. Service providers and AI processing

  • Cloudflare: website delivery, Worker execution, security, email routing and D1 database hosting.
  • Resend: one-time login emails and authenticated support-email delivery.
  • Google: the protected mailbox used to receive and answer support requests.
  • Venice AI: generation of companion replies. The selected private model receives your profile name, preferred form of address, recent conversation context and current message. Requests use private inference with storage disabled; Noxavelle stores the resulting conversation in Cloudflare D1 so that memory works.

Providers may process data outside the EEA. Where required, transfers are handled using the safeguards made available by those providers under applicable data-protection law.

5. Retention and deletion

  • Login codes become invalid after 10 minutes and expired authentication records are purged during authentication activity; active login sessions expire after 30 days.
  • Your account, profile and saved chats remain until you delete the chat history or your account.
  • Support correspondence is retained only while needed to answer the request, maintain an appropriate support record or comply with law.
  • Limited security, delivery or backup records may remain temporarily under provider retention schedules before being overwritten or deleted.

“Delete chat history” removes saved conversations. “Delete my account” removes your account, email, profile, age confirmation, sessions, login-code record and saved conversations from the live database.

6. Your rights

Subject to the GDPR, you may request access, correction, deletion, restriction, portability or object to certain processing. Contact us at the address above. You may also lodge a complaint with the Office for Personal Data Protection of the Slovak Republic.

7. Cookies and local storage

We use an essential, secure sign-in cookie and an essential local device identifier. They are required for account access and conversation continuity. The beta does not use advertising cookies or cross-site behavioural tracking.

8. Security and changes

We use proportionate technical and organisational safeguards, but no online service can guarantee absolute security. We may update this notice as Noxavelle changes and will show a new effective date for material updates.