Who is behind this
Nirvaana is a small, early product built and run by Benicio Padilla. There is no company privacy department to route you through; questions come to beniciopadilla8@gmail.com and are answered by a person.
What we collect
- Who you are. You sign in either with an emailed link or through one of the identity providers the sign-in page offers — Google, GitHub, Microsoft or Apple, whichever are switched on when you get there. We receive your email address and, if the provider sends one, your name; the sign-in system also keeps what the provider hands back alongside them, such as an avatar address and that provider’s own account id. In our own tables we keep your email address and a display name. We never receive or store your password.
- What you say and what you save. Your conversations, and the facts, promises and notes you choose to keep, are stored so your agent can pick up where you left off. That is the point of the product: a world that remembers.
- Ordinary operational records. A log of actions taken on your behalf, a record of what each request cost to run, and server logs. Those logs include your IP address, as any web server’s do; where we store one ourselves to slow down repeated failures, we keep only a one-way hash of it. Error reports carry the type of error and where it happened, never the text of your conversation.
We do not ask for, and you should not send, payment card numbers, government identifiers or anyone else’s sensitive records.
Who else processes it
Running the service means handing parts of it to a few companies. These are all of them:
- Supabase — the database and the sign-in system. Your account and everything you save live here.
- Resend — email delivery. When you ask for a sign-in link, your email address and that link pass through Resend on the way to your inbox. It is used for sign-in mail and service alerts, never for marketing.
- Vercel — hosting. Your requests pass through it and appear in its server logs.
- Anthropic — the model provider. The text of a conversation is sent to it to produce a reply, under API terms that do not permit training on it.
- Voyage AI — when enabled, the text of a fact you save, and the phrases used to search your facts later, are sent to be turned into a numeric index so your agent can find them again.
- PostHog — product analytics. It is set up to carry no content: no page text, no form contents, addresses with their query strings stripped, and you identified by an internal account id rather than by your email. Where session replay is switched on, every piece of text and every input is masked, so a recording shows the shape of a session and never its contents. Your browser loads analytics only once you are signed in; the sign-in page itself loads none. If a sign-in fails, the server alone records which provider it was and which error code came back — never your address, and your IP address only as a one-way hash, used to stop the same failure being reported over and over.
What stays private to you
This is the promise the rest of the product is built around. Your principles, your private facts and your conversations are yours. They are never shown to another person, never proposed to a group, never repeated to another user.
A world you share with other people is separate from your private one, and nothing crosses from private into shared without you saying yes to that specific thing first. The agent is not permitted to publish on your behalf, and the database enforces the same boundary underneath, so a mistake in one layer does not open the other.
What we do not do
- We do not sell your data, and we do not share it for advertising.
- We do not train models on your conversations, or let anyone else do so.
- We run no ad networks and no cross-site tracking.
- Nobody reads your conversations for interest. The operator can be required to look at stored data to fix a failure or to answer a legal demand, and that is the only reason it would happen.
Cookies
Few, and all of them first-party. The sign-in system sets a session cookie, which is what keeps you signed in — it may arrive split across more than one cookie, because it is larger than a cookie is allowed to be. A second cookie holds whether you chose the light or the dark theme, so the page is already correct before it paints. One cookie remembers whether you have seen the welcome page and which version, so the front door sends you straight to sign-in after the first time, until a month passes or the page changes. It holds a version number and a day and no identifier, so everyone who saw the same version on the same day carries the same value. Signed in, the version and when you saw it are kept on your profile, so another browser does not show you the page again. While a sign-in is in flight, a short-lived cookie records which provider you picked, so a failure can be reported as “Google failed” rather than nothing at all; it expires within the hour. Analytics sets one of its own on signed-in pages, to tell one visit from the next.
No advertising cookies, no cross-site trackers, and nothing that follows you off this site.
Seeing, exporting and deleting your data
Write to beniciopadilla8@gmail.com from the address on your account and ask for a copy of what is stored about you, a correction, or deletion. We aim to answer within thirty days.
Deletion means removing your sign-in record — your email address and the identity your provider handed us — and everything hanging from it: your profile, your conversations, your private facts, and anything sent to your agent’s door. We take your address off the invite list at the same time, so no part of it sits waiting for you to come back.
Some things outlast that, and we would rather say so now than surprise you later. What you deliberately put into a world you share — a fact you promoted, a rule you wrote, a lesson the world recorded — stays with that world, because it belongs to it now; ask before you go and we will tell you which those are. And the ledgers of what was spent and what the agent did keep their rows, because they are built so that nothing can quietly rewrite them. As your account goes, the column that pointed at you is set to nothing: the rows are cut loose from you, and what remains is amounts, timestamps and hashes — never the text of anything you wrote, in those or in the counters we use to slow down abuse.
Self-service export and deletion are not built yet. Until they are, the email above is the way, and it is a real one.
Where it is held
Data is stored and processed in the United States by the providers named above. If you are writing from elsewhere, your information travels there.
Changes
When this changes, the date at the top changes. The attorney-reviewed version will replace this one before Nirvaana is open to the public, and anyone with an account will be told when that happens.
Contact
beniciopadilla8@gmail.com. Say what you need plainly; you will get a plain answer.