LEGAL

Privacy Policy

Last updated

What information Nearwire processes, why we need it, and the choices available to you.

01About this policy

This policy describes how Nearwire handles information when you use our website, dashboard, and news search API. It covers information processed by Nearwire; publishers and third-party services have their own privacy policies.

02Information we collect

  • Account information. Your email address, optional name, account creation date, email verification status, and a password hash.
  • Authentication information. Session records, hashed session tokens, and API key hashes, names, prefixes, permissions, expiration dates, creation dates, and usage or revocation timestamps.
  • Usage information. Your account and API key identifiers, requested endpoint, request timestamp, whether a request came from the API or playground, and monthly usage totals.
  • Rate-limit information. Request counters and hashed identifiers derived from your account, email, or client IP to enforce request limits and protect against abuse.
  • Search inputs. Query text, vectors, and filters you submit to perform a search.
  • Monitoring information. Saved query text, embeddings, source filters, webhook URLs, encrypted signing secrets, matched articles, inbox read-state records, delivery payloads and attempt records. We send matching articles and saved query details to the receiver you configure. Inbox matches and delivery history are retained for up to 30 days and is removed when you delete the associated query, endpoint or account.
  • Billing information. Your plan, Stripe customer and subscription identifiers, subscription status, and billing period information. Payment details are collected by Stripe rather than stored in the Nearwire application database.
  • Technical information. Hosting and service providers may process IP addresses, browser details, and diagnostic logs when handling requests.

03How we use information

We use information to create and authenticate accounts, return search results, manage API keys, enforce plan limits, display usage, process subscriptions, diagnose failures, protect the Service, and meet legal obligations. Where applicable data protection law requires a legal basis, processing is based on performing our agreement with you, legitimate interests in operating and securing the Service, compliance with legal obligations, or consent where required.

04Search queries and embeddings

Text queries that need a new embedding are sent to OpenAI to convert the text into a numerical vector. Repeated queries may use a cached embedding. Queries supplied as vectors do not require sending query text to OpenAI. Avoid including sensitive personal information or confidential material in search inputs.

The query cache stores a hash and an embedding, rather than the original query text, and is shared across searches. Request usage records store endpoint and timing information rather than query text. Saved monitoring queries retain their original text and filters until you delete them. These descriptions apply to Nearwire’s application records; third-party processing is subject to the provider’s applicable terms and privacy practices.

05Cookies and external resources

Nearwire uses an essential cookie named nv_session to keep you signed in. It expires after 30 days unless replaced or cleared earlier. Signing out clears the cookie and removes the corresponding session. Blocking cookies may prevent account features from working. The application does not currently include advertising trackers or third-party analytics scripts.

The site loads fonts from Google Fonts, so your browser sends Google a request that includes technical information such as your IP address. Stripe-hosted checkout and billing pages may use their own cookies and process information under Stripe’s privacy policy.

06Sharing and service providers

We share information with service providers as needed to operate the Service, including hosting and database providers, Stripe for billing, OpenAI for embedding generation, and Resend for account emails. Resend receives your email address, optional name, and the reset or verification message to deliver it. Stripe receives account details such as your email, name when provided, and an account identifier to manage subscriptions. We may also disclose information when required by law, to protect rights or security, or in connection with a business transfer subject to applicable privacy requirements.

Provider details are available in the Stripe Privacy Policy, the OpenAI Privacy Policy, the Resend Privacy Policy, and the Google Privacy Policy. Providers may process information in countries other than your own, where privacy laws may differ.

07Retention and security

Account, billing, and usage records are retained to operate your account and meet applicable legal, accounting, and security needs. Session access expires after 30 days. Cached query embeddings are periodically pruned according to the configured retention period. Provider logs and backups may follow separate retention schedules. Expired rate-limit counters are scheduled for daily deletion after they have been expired for at least one day.

Passwords are stored as salted hashes, and session tokens and secret API keys are stored as hashes. These measures reduce risk, but no storage system or transmission method guarantees absolute security. Keep credentials private and revoke keys you no longer need.

08Your choices and rights

You can revoke API keys in your dashboard, change your password or delete your account on the Account page, and manage or cancel billing through the Stripe billing portal. Changing your password ends all sessions. Account deletion removes your account, sessions, API keys, request history, and monthly usage records from the application database and closes your Stripe customer account to stop subscriptions. Billing providers may retain transaction records to meet legal obligations, and backups and security counters may remain until their retention periods expire. Depending on your location, you may have rights to request access to, correction of, deletion of, or a copy of your personal information, and to object to or restrict certain processing. You may also have the right to withdraw consent where processing relies on it and complain to your local data protection authority. Contact the Nearwire operator to make a privacy request. We may need to verify your identity, and some records may need to be retained where permitted or required by law.

09Children’s privacy

The Service is intended for adults and is not directed to children under 18. If you believe a child has provided personal information, notify the Nearwire operator so the information can be investigated and removed as appropriate.

10Changes to this policy

We may update this policy as the Service or our practices change. The date above reflects the latest revision. Material changes will be communicated through the Service or your account email where required by law, and consent will be requested when required.