NOVA by Bridgeye
Privacy Policy

Your data, plainly.

What NOVA collects, what it stores and what it doesn't, where your code goes when an AI model works on it, who else is involved, how long anything is kept, and how to see, fix or delete it.

Last updated 2 October 2026 · Effective 30 September 2026

What we do

  • Send the code and instructions a task needs to the AI model doing the work — and only for that request.
  • Store your NOVA projects, files, chat history and published sites so you can come back to them.
  • Keep a record of each request's model, size and credits, so you can see exactly what you used.
  • For work done in NOVA, keep a short, clipped excerpt of each model request and reply, to investigate problems and costs.
  • Keep billing records and tax invoices, as Indian law requires.

What we don't

  • Sell your data, or share it for advertising. NOVA and this website carry no ad or analytics trackers.
  • Use your code or content to train AI models.
  • Keep the content of NOVA CLI requests on our servers. The NOVA API logs counts, never prompts or replies.
  • See your password or card number. Sign-in is through GitHub or Google; payments through Razorpay.

1.Who is responsible for your data

NOVA is provided by Bridgeye Private Limited, Ponda, Goa, India (Bridgeye, we). We decide how and why your personal data is processed for the Services, which makes us the Data Fiduciary under India’s Digital Personal Data Protection Act, 2023 (and the “controller” in the language of other privacy laws).

This policy covers NOVA, NOVA CLI, NOVA Web, the NOVA API and this website. It forms part of our Terms of Service. Questions about it go to our Chief Information Security Officer, Wallace DSouza, at ciso@bridgeye.com.

For data that users of an app you publish store in it, you decide what is collected and why, and we process it on your behalf. See section 12.

2.What we collect

DataWhat it includesWhere it comes from
AccountName, email address, profile picture, and your GitHub or Google account identifier. Your onboarding answers, such as your role, and preferences such as theme.The sign-in provider you choose, and you
What you create in NOVAProjects and their files, version history and snapshots, chat messages with NOVA, files and images you attach, published sites and apps, and collaborators you invite. Secrets you store for a project are kept encrypted.You
What the CLI sendsFor each request: your instruction and the code or file context NOVA selected for it. We pass it to the AI model and do not keep it (section 3).The CLI on your computer
Usage recordsFor each request or charge: time, feature, model used, request size in tokens, and credits charged. Not the prompt or reply.Generated as you use NOVA
Model call log (NOVA)For each model request NOVA makes for you: the model, timing, cost, whether it succeeded, and the first part of the prompt and of the reply — clipped, never the whole text. Requests from NOVA CLI are not logged this way.Generated as you use NOVA
BillingBilling name and address, GST number if you give one, what you bought, invoices, and payment references from Razorpay.You, at checkout, and Razorpay
Connected servicesIf you connect GitHub repositories or a connector (for example Google Sheets, Gmail, Figma or Shopify): the access token that service issues, stored encrypted, and the data you ask NOVA to read from it.You, when you connect
DomainsIf you buy a domain: the registrant contact details you enter.You
TechnicalIP address, browser and device type, operating system, CLI version, error reports and security logs.Your browser, the CLI and our servers
MessagesEmails you send us, and delivery status of emails we send you.You, and our email provider

3.How AI requests are handled

This is the part most people want to understand, so here it is step by step.

  1. You ask. In the CLI, NOVA reads your project on your computer and selects only the context the task needs. In Play, it uses your project’s files and the conversation so far.
  2. We route. The NOVA API checks your plan and credits and sends the request over an encrypted connection to the model that will do the work — the one you picked, or NOVA’s default for that task.
  3. The model provider processes it. Most models are reached through OpenRouter, which forwards the request to the model’s provider (for example Anthropic, OpenAI, Google, Moonshot AI or DeepSeek). Some are called directly, including Groq, NVIDIA and OpenAI.
  4. The answer comes back. In the CLI, changes are applied to your files on your machine. In Play, results are saved to your project.
  5. We record the charge, not the content. The NOVA API keeps the model, size and credits used, never the prompt or reply. For requests made from NOVA, we also keep a clipped excerpt of the prompt and reply (section 2) to investigate problems and costs.

What model providers do with it

  • Each provider processes the request under its own terms and privacy policy, and may keep it for a limited time for abuse monitoring or as its policy states.
  • We use settings and providers that do not allow your data to be used for model training wherever that choice exists. We do not allow training on your data ourselves. We cannot control every provider’s practices, so avoid sending anything you are not allowed to share with a third party.
  • Providers may process requests outside India, including in the United States, Europe and China, depending on the model.

Using NOVA means your Input is sent to an AI model provider — there is no way to use an AI model without it. If you work with sensitive or regulated code or data, choose what you share accordingly, or ask us about it first.

4.What we don't collect or keep

  • Your GitHub or Google password. We never see it.
  • Card numbers, CVVs or bank credentials. Razorpay handles those under PCI-DSS.
  • The content of CLI requests. It passes through to the model provider and is not stored on our servers.
  • Your whole repository. The CLI sends only the context a task needs, when you run it.
  • Anything from your computer when NOVA isn’t running, your clipboard, screen or browsing, or files outside the project you point NOVA at.
  • Advertising data. We don’t run ads, and NOVA and this website load no third-party analytics or ad trackers (section 11 covers the sign-in page on NOVA Web).

The CLI keeps its sign-in and settings on your own computer, in a .nova folder in your home directory.

5.How we use your data, and why we're allowed to

PurposeBasis
Sign you in, run your requests, store and publish your projects, and show your usage and invoicesTo provide the Services you asked for, and your consent when you sign up
Charge credits, take payments, issue tax invoices and keep financial recordsLegal obligation (tax and accounting law) and the contract with you
Keep the Services secure: prevent fraud, abuse and account misuse, and fix errorsLegitimate use for the safety and integrity of the Services, and legal obligation
Send service emails: receipts, security alerts, changes to these policies, and notices about your accountTo provide the Services; you cannot opt out of these while you have an account
Send product news and offersYour consent; unsubscribe from any such email at any time
Understand how NOVA is used, in aggregate, to improve itLegitimate use, using counts and usage records rather than your content
Respond to lawful requests from authoritiesLegal obligation

We do not use your content to train AI models, and we do not make decisions about you that have legal or similarly significant effects based solely on automated processing.

6.Who we share it with

We do not sell your personal data. We share it only with the service providers that help us run NOVA, only what each one needs, under contracts that limit their use of it:

RecipientWhyWhat they receive
AI model providers, directly or through OpenRouterTo process your requestsThe prompt, code, files and attachments for each request
Google Cloud (Firebase)Account, plan, credit and billing recordsAccount details, usage and billing records
Our hosting providers (Boston, USA)To run the Services and store NOVA projectsEverything stored in NOVA
GitHub, GoogleSign-in, and repositories or connectors you connectWhat is needed to authenticate you and act on your behalf
RazorpayPayments and refundsAmount, currency, billing details and payment references
ResendSending emailsYour email address and the email
Domain registrars (ResellerClub, Spaceship) and registriesRegistering domains you buyRegistrant contact details you enter
Pexels, Pixabay, UnsplashFinding stock photos for pages you buildShort image descriptions, not personal data
Google (Tag Manager)Measuring visits to NOVA Web, including the sign-in pageIP address, browser details and pages visited on that site
Connected services you choose (for example Shopify, Figma)Doing what you ask with themWhat the task requires

We may also disclose data when Indian or other applicable law requires it, to protect people’s safety, or to defend our legal rights — and will tell you where we lawfully can. If Bridgeye is part of a merger or acquisition, data may pass to the new owner under this policy, and we will tell you.

7.Where your data is stored

  • NOVA — including your projects, files, chat history and published sites — and this website run on servers in Boston, USA.
  • The NOVA API and NOVA Web run on servers in Boston, USA.
  • Account, plan and billing records are stored with Google Cloud (Firebase).
  • AI requests are processed by model providers in the countries where they operate, including the United States, Europe and China.

Where data leaves India, we rely on the protections of our contracts with these providers and on encryption in transit, and we follow any restriction the Indian government places on transfers to particular countries.

8.How long we keep it, and deleting your account

When you delete your account, your data is deleted at the same time. The only exceptions are listed below.

DataKept
Account and profileUntil you delete your account
NOVA projects, files, history and chatUntil you delete them, or your account
Published sites and apps, and their users’ dataUntil you unpublish or delete them, or your account
Content of CLI requestsNot stored by us
Usage and credit recordsUntil you delete your account
Model call log excerpts (NOVA)Until you delete your account
Connected-service tokensUntil you disconnect the service, or delete your account
Invoices and payment recordsFor the period Indian tax and accounting law requires, even after your account is deleted
Security logsFor a short period, then deleted
BackupsOur database backups are a small rolling set that is continually overwritten, so deleted data disappears from them as they roll over

To delete your account, email support@bridgeye.com from the email address on your account with “Delete my account”. Data already sent to a model provider is subject to that provider’s retention.

9.How we protect it

  • Encryption in transit (TLS) for every connection to NOVA and to model providers.
  • Project secrets, connected-service tokens and GitHub tokens are encrypted at rest.
  • Sign-in cookies are HTTP-only, so page scripts cannot read them, and session tokens are rotated.
  • Access to production systems is restricted to people who need it, and is logged.
  • Published sites run on separate domains from your NOVA session, so a site cannot act as you.
  • Rate limits protect sign-in against abuse.

No system is perfectly secure. If we become aware of a breach affecting your personal data, we will notify you and the Data Protection Board of India as the law requires. To report a security issue, email ciso@bridgeye.com.

10.Your rights

Under the Digital Personal Data Protection Act, 2023 and other laws that may apply to you, you can:

  • Access a summary of the personal data we hold about you and how we use it.
  • Correct, complete or update it. Much of it you can see and change in your account at your account page.
  • Erase it, by deleting your account (section 8).
  • Withdraw consent at any time. This does not affect what was done before, and may mean we cannot keep providing the Services.
  • Get a copy of your data in a portable format.
  • Nominate someone to exercise your rights if you die or become unable to.
  • Complain to us (section 15) and, if you are not satisfied, to the Data Protection Board of India or your local authority.

Email ciso@bridgeye.com from the address on your account. We will confirm who you are before acting and respond within the time the law requires.

11.Cookies and local storage

  • Sign-in cookies. Two first-party cookies keep you signed in (an access token and a refresh token). They are strictly necessary and are cleared when you sign out.
  • Preferences. Your browser stores small settings on your device, such as light or dark theme.
  • No third-party tracking on NOVA or this website. We don’t use advertising cookies or third-party analytics there.
  • NOVA Web, including the sign-in page, uses Google Tag Manager to measure visits. It can set Google cookies and send Google your IP address and browser details. Blocking it with your browser’s tracking protection or a content blocker does not affect signing in.

Your region for showing prices (rupees or dollars) is worked out from your browser’s time zone, on your device. It is not stored.

12.Apps you build and their users

If an app you publish with NOVA lets its own users sign up, submit forms or upload files, that data belongs to your app. You decide what it collects and why, and you are responsible to those users for it, including giving them a privacy notice. We store and process that data only on your instructions, to run your app, and keep it secure as described here. We do not use it for anything else.

If one of your app’s users contacts us, we will refer them to you. Contact ciso@bridgeye.com if you need our help responding to a request.

13.Children

NOVA is not for children under 13. Users between 13 and 18 may use it only with the verifiable consent and supervision of a parent or legal guardian. We do not track or target advertising at children. If you believe a child has given us data without that consent, email ciso@bridgeye.com and we will delete it.

14.Changes to this policy

We will update this policy when our practices or the law change. For material changes we will email you or tell you in the product at least 30 days before they take effect. The date at the top shows the latest version.

15.Contact and grievances

Our Chief Information Security Officer handles privacy questions, data requests and grievances:

NameWallace DSouza, Chief Information Security Officer
Emailciso@bridgeye.com
PostBridgeye Private Limited, Ponda, Goa, India
General supportsupport@bridgeye.com

Include your name, the email on your account, what happened, and what you would like us to do. We acknowledge grievances within 24 hours and aim to resolve them within 15 days. If you are not satisfied, you may complain to the Data Protection Board of India.