Legal
Privacy Policy
This policy explains what data Novix handles, why, who we share it with, and how you control it. It describes what the product actually does today rather than promising more than we do. We wrote it ourselves and a lawyer has not reviewed it.
Scope and roles
This policy covers Novix (“Novix,” “we,” “us”): the application, dashboard, and APIs. It covers two kinds of data: information about the people who administer an Novix workspace (our customers), and the content those customers connect so Novix can do its job (tickets, code context, and credentials).
For the content you connect, you are the controller and Novix acts as a processor on your behalf: we handle that data to provide the Service to you, under your instructions. You are responsible for having the right to share it with us and for your own privacy obligations to your end customers.
What we collect
Account information
When you sign up, we store your name, email address, and workspace membership and role. Passwords are never stored in plain text. We keep only a salted scrypt hash, which cannot be reversed back into your password.
Support tickets, including end-customer messages
Novix reads support tickets from the tools you connect. A ticket can include the message text your end customer wrote, a subject and description, the requester’s email address, error logs, code snippets attached to the ticket, and metadata about its source. It can also include internal notes and tags your team adds. This content often contains personal data belonging to your end customers, which you have chosen to route through Novix.
Connected-integration credentials
To read from and write to the tools you connect, we store the API keys, tokens, and secrets you provide. These credentials are encrypted at rest using authenticated encryption, and their values are never returned by our API. The dashboard shows only which credential fields are set, not the secrets themselves.
Code context pulled for diagnosis
When diagnosing a ticket, Novix pulls live evidence from the systems you connect (for example, matching files and recent commits from a connected repository, and error, log, or incident data from observability tools). The relevant excerpts are stored on the ticket so the diagnosis, the drafted fix, and your dashboard can use them.
Audit logs and product data
We keep an append-only audit log of significant actions in a workspace (for example, a ticket being analyzed, a fix being drafted, approved, or rejected, an integration being connected, and membership changes). The audit log records who did what and when; it does not store secrets, tokens, or password data. We also process ordinary operational data such as basic logs and usage counts needed to run and secure the Service.
If you contact us before you are a customer
If you fill in a form on our marketing site or email us about Novix, we store what you sent: typically your name, email address, your role, and which tools your team uses. We use it to reply to you and to decide what to build next, and for nothing else. It is not sold, and it is not passed to an advertising network. Ask us at support@getnovix.ai and we delete it.
Data about other people
Two things you do in Novix hand us somebody else’s details. Inviting a colleague stores the address you typed and the invitation until it is accepted or revoked, and you can revoke it from the dashboard. A ticket usually carries the email address of whoever reported it. In both cases you are the one choosing to give us the address, and you are responsible for being allowed to.
How we contact you
Every email Novix sends is about your account or your work: a verification or sign-in code, a password reset, an invitation, a billing notice, and the ticket alerts and digest you turn on in settings. There is no marketing list, and we do not send campaigns. You control the alerts from the notifications section of settings; the account and billing mail we have to be able to send you.
Product analytics
We measure how workspaces get started with Novix: how many reach milestones like connecting a repository or approving a first fix, how long that takes, and which workspaces have been active recently. There is no analytics or tracking script anywhere in Novix, and no cookie is set for this. Nothing separate is captured about you. These are counts calculated, when a member of our team opens the page, from records the Service already keeps to work at all: your workspace, its members, its integrations, its ticket counts, and its audit log.
We took this approach deliberately. A third-party analytics script would load on the pages that display your end customers’ support tickets, and we are not willing to put their messages in front of another company. The trade is that we cannot see session replays, heatmaps, or page views, and we would rather not see them.
This view shows your workspace name, the name, email address and role of each member, counts of tickets and fixes, your integration and billing status, and what happened in your workspace: that a ticket arrived, was diagnosed, had a fix drafted, approved or rejected.
Novix staff can read a task in full, including what was reported, the diagnosis, and the run log showing what the engine did at each stage. We do this to support you and to understand how the product is used so we can make it better. It is read only: there is no path by which we can change a task, approve a fix, or act in your workspace.
Every time a member of Novix staff opens one of your tasks or one of its files, we write a record of it: who looked, at what, and when. That log is internal rather than shown in your workspace, and you can ask us for your part of it at any time by writing to support@getnovix.ai. Browsing a list of task titles is not recorded, because a row for every scroll would bury the records that matter.
That includes files and screenshots attached to a task. A screenshot is often the whole bug report, so a run log without it explains half of what happened. Each file you have attached is opened one at a time and each one is recorded separately, because opening a file is a different thing from reading the task it is attached to.
We do this for two reasons and no others: to help you when something has gone wrong, and to understand how the product is actually used so we can improve it. Your tasks, your code and your files are never used to train a model, not ours and not anybody else’s. See below for what our AI provider does and does not do with what it is sent.
How we use it
We use the data described above to:
- Provide the Service: classify and diagnose tickets, gather code context, and draft candidate fixes and customer replies for your review.
- Open pull requests and send the notifications you configure (for example a Slack alert when a diagnosis is ready), and maintain the audit trail.
- Operate, secure, debug, and improve the Service, and enforce our Terms.
- Communicate with you about your account and the Service.
We do not sell your data. We do not use the content of your tickets or code to train our own models.
Why we are allowed to use it
If you are in the UK or the EEA, the law wants us to name a legal basis for each thing we do with your personal data. Two different answers apply, because we hold two different kinds of data.
For the content you connect, tickets, code context, attachments and everything in them, we are your processor. We handle it on your instructions to give you the Service, and the legal basis for that data is yours to hold as the controller, not ours. Our DPA is where that is written down.
For the people who hold a Novix account, we are the controller and these are our bases:
- Performing our contract with you. Creating and running your account and workspace, signing you in, sending the account email in it, taking payment, and providing support.
- Our legitimate interests. Keeping the Service secure and available: rate limits, abuse and fraud prevention, the audit log, spend caps, debugging, and the first-party product analytics described above, which is how we work out what to build next. We also rely on this to reply to you if you contact us before you are a customer. In each case our interest is running a service people can trust, and we use the least data that does the job.
- Complying with the law. Tax and accounting records, and responding to a lawful request from an authority.
- Your consent, where we ask for it. That is rare, because the Service does not run on optional data, and where we do ask you can withdraw it at any time without affecting anything we did before you did.
If you want to object to something we do on the legitimate-interests basis, email support@getnovix.ai and say which part. See deletion and your choices.
AI processing
Novix uses a large language model to classify, diagnose, and draft fixes. To do this, the relevant ticket content and the code and context pulled for that ticket are sent to our AI provider, Anthropic, and processed by its Claude models. This is the core of how the Service works.
Anthropic processes this data to return a result to us; per Anthropic’s commercial terms, it does not use data submitted through its API to train its models. When no AI provider key is configured, Novix runs in an offline demo mode and this data is not sent anywhere.
If you bring your own inference key
A workspace can point Novix at its own inference account instead of ours. Today that can be Anthropic, OpenAI, Google Gemini, DeepSeek, OpenRouter, or Kimi, and an enterprise agreement can point it at an endpoint you host. When you configure one, the ticket content and code context described above go to that provider instead of to Anthropic, on your own account and under your agreement with them. We validate the key when you save it, which sends a short test request to that provider.
This is your choice to make and your contract to hold: we are not a party to it, that provider’s terms govern what it does with the data, and we cannot make its training, retention, or data-location commitments on its behalf. Some of the providers on that list operate outside the United States and the EEA. If your own privacy obligations turn on where data goes or on a vendor’s training practices, check the provider before you point us at it. Novix’s own key runs on Anthropic, as described above, and that is the default.
Automated decisions
Novix is an automated system, so it is worth being exact about what it decides on its own. It reads tickets and code and makes judgments about software: whether a report is a defect, what the root cause is, and what a patch should say. It does not profile people, score them, or make a decision about anybody that produces a legal or similarly significant effect on them. There is nothing in Novix that rates your end customers.
No code change is automated. Novix opens a pull request and stops. A person on your team reviews it and decides. That boundary is the product, not a setting, and there is no path that merges without somebody choosing to.
Three automated calls do affect a ticket, and you can undo all three:
- A first-pass triage model can mark an incoming ticket as junk. A junk ticket that nobody on your team has touched is deleted after 7 days. One assignment, note, reply, snooze, rating, or state change takes it out of that sweep permanently.
- If you set up an auto-summon for a monitoring alert, Novix drops an alert that carries a clear not-a-defect signal before opening a task at all, and deletes a task the engine then concludes was not a bug. A task that needs more information is always kept, because a question is waiting on a person.
- Limits can stop work in a workspace: a spend cap that has been reached, a rate limit, or a suspension for abuse. The end of a trial is no longer one of them, because a trial that runs out moves the workspace to the free plan and it keeps working. Those are decisions about an account rather than about a person, and a human of ours will look at any of them if you email support@getnovix.ai.
Building and testing fixes
When Novix drafts a fix, it builds and tests that fix before asking you to approve it. This is a step of the analysis and runs on every drafted fix; it is skipped only when there is no patch to build, or when our own safety review has already refused the patch.
To do it, Novix starts an isolated, single-use container at our provider E2B and clones the repository you connected into it, using the access token you granted. The token is removed from the container before any command runs, and the run is abandoned if that removal cannot be confirmed. The drafted patch is applied to that clone, and your repository’s own build and test commands are run against it. Nothing is written back to your repository from the container.
The container is destroyed as soon as the result is recorded. If you turn on the optional live preview, it instead stays running for a short period, stated on the ticket, so you can click through the fixed app, and then stops. What we keep afterwards is the pass or fail result and the command output, stored on the ticket and scrubbed of credentials before it is saved or shown.
Your build and test commands are your code, and they run with the network access the container provides. Only connect a repository you are willing to have built this way, and see our terms for the permission this relies on.
Subprocessors
We use a small number of third parties to run the Service. Each acts on our instructions and receives only what it needs.
- Anthropic: AI analysis. Receives ticket content and the code and context pulled for a ticket, in order to classify, diagnose, and draft fixes and replies.
- Supabase: managed Postgres database. Stores the Service’s data at rest; connections are made over TLS.
- Render and Vercel: hosting. Render runs the backend that processes every request; Vercel serves the dashboard and site and proxies traffic to the backend.
- Resend: account and notification email. Receives the recipient address and the message. That covers verification and sign-in codes, password resets, workspace invitations, billing notices, and the ticket alerts and digest you turn on. Those carry a title, a count and a link; the diagnosis, the patch, the attachments and your customer’s own words stay in the product.
- Stripe: billing. Receives your billing email and payment details, entered on Stripe’s own pages, to process a subscription. We never see or store card numbers.
- E2B: the isolated container each drafted fix is built and tested in. Receives a clone of the repository you connected, the drafted patch, and briefly the token used to clone it. See Building and testing fixes below.
- Your own inference provider, if you configure one: receives what Anthropic would otherwise receive. See AI processing above.
The tools you connect, such as Slack, a help desk, or a code host, are not subprocessors. You hold those accounts, and data moves to and from them under your agreement with each provider.
The current list, with what each vendor receives, is maintained at Subprocessors and services.
How we protect it
- Encrypted credentials. Integration API keys, tokens, and secrets are encrypted at rest with authenticated encryption, and their values are never returned through the API.
- Hashed passwords. Passwords are stored only as a salted
scrypthash, never in plain text. - Encryption in transit. Connections to the managed database are made over TLS.
- Tenant scoping. Data is scoped to your workspace, and access is limited to the members you invite and their roles.
No method of storage or transmission is perfectly secure. We keep strengthening our controls, and we describe what is in place today rather than what we hope to add later.
If you think you have found a hole, our disclosure policy says how to tell us and what we do about it.
If there is a security incident
We have a written procedure for this and we read it before we need it, because the thing that goes wrong in a real incident is deciding what to say while the clock runs.
- If it touches data we hold for you, your tickets, code excerpts, attachments, or connected-tool data, we tell you without undue delay, with what you need to meet your own notification duties, and we help you work out the scope. You notify your own regulator and your own end customers, because for that data you are the controller. See our DPA.
- If it touches Novix account data, names, email addresses, password material, or sessions, we are the controller and it is ours to report. We tell the people affected, and where the law requires it we notify a supervisory authority within 72 hours of becoming aware.
We will tell you what we know when we know it rather than waiting for a complete picture, and we will say plainly which parts we are still working out.
Data retention
We keep data only as long as it is useful, and delete the rest automatically on a schedule:
- Resolved tickets are deleted after two years. Before a ticket is deleted, its diagnosis is distilled into a short, anonymized learning (root cause, category, affected areas, outcome), so Novix keeps what it learned without keeping your customer’s message, email, logs, or attachments. Open and recently resolved tickets are kept while your account is active.
- Junk is deleted after 7 days. A ticket the triage model called junk, that nobody on your team has touched, goes at a week. Anything a person has assigned, replied to, snoozed, rated, or moved is out of that sweep for good, whatever the model said about it. Nothing else can delete a ticket nobody resolved.
- Short-lived security tokens are deleted within about a week. Password-reset links, email-verification codes, and two-factor codes expire within minutes; the spent records are then cleared.
- Internal deduplication markers are deleted after about 30 days. These only stop the same incoming webhook being processed twice, so they do not need to be kept.
- Cost records are kept for about 400 days. One row per model call, holding a workspace id, a date, a model name and a token count, so we can answer a billing question and see what the Service costs us to run. There is no ticket content and no personal data in them, and they outlive the ticket they refer to on purpose.
- Audit logs are kept for the life of your workspace. The record of who did what is append-only and is never edited or deleted while your account is active.
- Everything else is kept while your account is active: your account, workspace settings, connected integrations, and active tickets.
We also retain data as needed to provide the Service, comply with our legal obligations, resolve disputes, and enforce our agreements. These windows are the defaults; an enterprise agreement may set different ones.
Deletion and your choices
Disconnecting an integration deletes the stored credentials for that integration right away. You can do this at any time from the dashboard.
Deleting your workspace or account. You can ask us to delete your workspace and its data by emailing support@getnovix.ai. We will delete it within 30 days, subject only to anything we must keep for legal reasons, and we cancel any active subscription as part of closing the account. Email is the way to do this, and it is deliberate rather than a gap: a request goes to a person, who confirms the workspace and cancels the billing before anything is erased, and deletion cannot be undone.
Your rights. Depending on where you live, you can ask to access, correct, delete, export (in a portable form), restrict, or object to the processing of the personal data we hold about you. Email support@getnovix.ai and we will respond within the timeframe the law allows, normally 30 days. We will not charge you for a request or treat you differently for making one. You can also withdraw any consent you have given us, and object to anything we do on the legitimate-interests basis described in why we are allowed to use it.
How we check it is you. We confirm a request comes from the address on the account. If we cannot, we may ask for a little more, and we ask for the least that settles it. We will not ask you for a government identity document unless there is genuinely no other way, and we do not keep what you send once the request is answered.
Someone acting for you. An agent can make a request on your behalf if you have given them written permission. We may still check with you directly before we act on it.
If we say no. We tell you why, and you can ask us to look again. Reply to us and say you want the decision reconsidered; a person who was not the one who refused it will read it, and we will write back with the outcome and the reason. If you are still unhappy, you can complain to your data protection regulator: in the UK that is the Information Commissioner’s Office, and in the EEA it is the supervisory authority for the country you live or work in. In the United States it is your state attorney general. We would rather you came to us first, but you do not have to.
Opting out of product analytics. Email support@getnovix.ai from an address on your workspace and we will exclude your workspace from the product analytics described above. We handle this by hand rather than with a switch in the dashboard, so allow a few working days. Opting out does not change anything about how the Service works for you, and we will not treat you differently for asking. What it cannot remove is the underlying records, since your workspace, its members, its integrations and its audit log are what make the Service run.
Because much of the content in Novix belongs to your end customers, requests from those end customers should generally go through you as the controller; we will support you in responding to them.
United States state privacy rights
If you live in a state with its own privacy law, California, Colorado, Connecticut, Virginia, Texas and a growing list of others, this section is the part written for you. It sits on top of everything above rather than replacing it.
We do not sell personal information and we never have. Not for money, not for anything else of value, and not in the last twelve months. We do not share it for cross-context behavioural advertising, because we run no advertising at all. There is no data broker, no ad network and no analytics vendor anywhere in Novix.
We do not ask you for sensitive personal information, and we do not use anything that happens to arrive in a ticket to infer characteristics about anybody. We do not knowingly collect personal information from anyone under 18, so there is nothing to opt in about.
What you can ask for. To know what we collect, where it came from, why we have it and who we give it to; a copy of it; a correction; deletion; and a portable copy. The opt-out rights those laws give you cover selling, sharing for targeted advertising, and profiling in service of decisions with legal effects. None of those happen here, so there is nothing for an opt-out to switch off. The same is true of limiting the use of sensitive personal information.
How. Email support@getnovix.ai. It is one address and a person reads it. How we verify you, how an agent can act for you, and how to appeal if we refuse are all in deletion and your choices above.
We will not treat you worse for asking. No price change, no lower service, no different product. You are entitled to exercise these rights free from discrimination, and it costs you nothing.
Where the detail lives. The categories we collect and where they come from are in what we collect, why we have them is in how we use it, who receives them is in subprocessors, and how long we keep them is in data retention. We would rather point you at the real sections than restate them in a table that drifts.
For the tickets, code and attachments inside a workspace, we act as a service provider to the business that owns it. A request about that content goes to that business, and we help them answer it.
End-customer data
Support tickets routed through Novix often contain personal data about your end customers: their messages, email addresses, and whatever they included when they reached out. You decide what to connect and route to Novix. You are responsible for having a lawful basis and any notices or consents required to share that data with us and, in turn, with our subprocessors for the purpose of diagnosing and resolving the ticket.
Our data processing addendum (DPA) covers this relationship: our role as your processor, the subprocessors we use, international transfers, security, and how we help you answer requests from your end customers. It applies to your use of the Service, and we will send a countersigned copy on request.
Where data is processed
The Service and our subprocessors, including our AI provider, may process and store data in the United States and other countries. If you are located elsewhere, using the Service means your data may be transferred to and processed in those countries. Where we transfer personal data out of the EEA, the UK, or Switzerland to a country without an adequacy decision, we rely on the Standard Contractual Clauses (SCCs), with the UK and Swiss variants as applicable. See our DPA for the details.
Children
Novix is a business tool and is not directed to children. You must be at least 18 to hold an account, and we do not knowingly collect personal data from anyone under 18 through the account-holder side of the Service. If we learn that we have, we delete it. If you think a child has given us something, email support@getnovix.ai and we will deal with it.
Changes to this policy
We will update this policy as the product and our practices evolve. When we make a material change, we will update the effective date above and, where appropriate, give notice. Continuing to use the Service after a change takes effect means you accept the updated policy.
Contact
Privacy questions or requests?
Email support@getnovix.ai. See also our Terms of Service.