Last updated September 26, 2026
Privacy Policy
01What we collect
Account data. Your name and email address, and your password, which is stored only in hashed form by our authentication provider. If you sign in with Google, we receive your name, email address and profile picture from Google.
Workspace data. What you and your team put into a workspace: agents, their written purpose and spending authority, workspace policy, webhook endpoints, reviews and labels.
Decision data. What your agents send with each decision request — for example the agent, its task, the steps that led to the spend, and the spend itself (merchant, amount, currency, description and any attributes you include) — together with Neltava’s decision, its step-by-step trace, and any outcomes you report.
Operational data. A log of API calls made with your workspace’s keys (time, endpoint, status code, error code, which key, duration — never the request or response body), and standard server logs used to run and secure the Service.
API keys. We store keys only as a one-way hash plus a short prefix so you can recognise them; the full key is shown to you once.
Website analytics. On neltava.com (not in the console), if you accept analytics, Google Analytics records how the site is used — pages viewed, how you arrived, approximate location, device and browser, and clicks on the sign-up button. Until you accept, no analytics cookies are set. We do not enable Google’s advertising or personalisation features.
Emails you send us. If you write to us, we keep the correspondence.
02How we use it
- To provide the Service: authenticate you, evaluate your agents’ spend requests, record decisions and show them to you.
- To send you the emails the Service needs, such as verification codes and password resets.
- To keep the Service secure and reliable: rate limiting, abuse prevention, debugging and incident response.
- To answer your questions and, if you ask us, help you set up.
We do not sell your data. We do not use your workspace or decision data to train AI models. We use no advertising trackers anywhere, and no analytics in the console. On neltava.com we use Google Analytics only if you accept it, to understand which pages are useful.
03Purpose assessments
To check whether a spend serves an agent’s purpose, the Service sends the agent’s written purpose and the relevant parts of the decision request (task, steps and spend) to a third-party AI model provider. The result is recorded as evidence in the decision. A model’s assessment can send a spend to a person for review; it never blocks a spend on its own.
04Service providers
We use a small number of carefully chosen service providers to run the Service — for hosting, our database and authentication, email delivery, AI model access for purpose assessments, and — on neltava.com, with your consent — website analytics. They process data only on our behalf and only as needed to provide those services. If you sign in with a third-party account such as Google, that provider also receives the information needed to sign you in.
We may disclose information if the law requires it, or to protect the rights, property or safety of our users, the public or Neltava.
05Cookies
The console uses only cookies it needs to work: your sign-in session, the workspace you are viewing, and a short-lived cookie that holds your email address while you enter a verification or reset code. On neltava.com, Google Analytics cookies are set only after you accept them in the banner; your choice is remembered in your browser. You can change it by clearing this site’s data, which shows the banner again.
06Retention and deletion
Decision records, reviews, labels and outcomes are append-only and hash-chained so they are tamper-evident: individual records cannot be edited or removed through the Service, and they are kept for as long as your workspace exists. The API request log is kept for 7 days.
You can ask us to delete your account or an entire workspace at any time by writing to us from your account’s email address. We will then delete it, except for information we must keep to comply with the law or to resolve disputes.
07Where data is processed
The Service is operated from the United States, and our providers process data primarily there. Some processing, such as email delivery, may take place in other countries.
08Security
Traffic to the Service is encrypted in transit. API keys are stored as hashes, and access to workspace data requires a valid session or key scoped to that workspace. No system is perfectly secure; if we learn of a breach affecting your data, we will notify you as required by law.
09Your choices and rights
You can view and export your decision data from the console, and you can ask us to access, correct, export or delete personal information we hold about you. We will respond within a reasonable time and as required by applicable law.
10Children
The Service is for businesses and is not directed to children. We do not knowingly collect information from anyone under 16.
11Changes
If we change this policy, we will update the date above, and for material changes we will let account holders know by email before the change takes effect.
Questions: hello@neltava.com