Privacy Policy

Effective: September 15, 2026 (previously August 24, 2026)

1. Introduction

Nimvox ("we," "us," or "our") operates the nimvox.dev website and provides Kubevox, Buildvox, Jobvox, Markvox, and Scoutvox (collectively, the "Services"). This Privacy Policy describes how we collect, use, store, and protect your information when you use our Services.

We are committed to protecting your privacy. We collect only the data necessary to provide our Services, we never sell your data, and we never use it for advertising.

2. Information We Collect

2.1 Account Information

When you create an account or make a purchase, we collect your email address and, for purchases, your name. For OAuth sign-in (Google or GitHub), we receive your email address and basic profile information from the provider.

2.2 Payment Information

Payments are processed by Stripe and PayPal. Nimvox never receives, stores, or has access to your credit card numbers or bank account details. We receive only transaction confirmations (amount, date, status) from these processors.

2.3 Product-Specific Data

Product Data Collected
Buildvox Purchase email, GitHub username (for repository access delivery)
Kubevox Kubernetes cluster configuration (encrypted at rest), workload metrics, scaling policies
Jobvox Resume content (encrypted at rest), tracked company URLs, discovered job listings, workflow/pipeline data
Markvox Brand projects, name candidates, uploaded and generated logo and brand assets, organisation membership, and review scores
Scoutvox Job listings submitted for scoring, the analyses and rewrite suggestions produced from them, and employer organisation details

2.4 Automatically Collected Information

When you visit nimvox.dev, our hosting provider records your IP address, browser type and the pages you visited, through Cloudflare Web Analytics. It sets no cookies and does not track you across sites. It is inserted at the edge and runs on every page, so it is not something we ask you to accept — what it does and does not see is described in Section 7.

3. How We Use Your Information

We use the information we collect to:

We do not:

4. Third-Party Services

We use a small number of third-party services (“sub-processors”) to operate. The complete, current list — each one’s name, purpose, the data it receives and where it processes it — is maintained at nimvox.dev/sub-processors.

That page is the single authoritative list, kept separately so it stays current: a sub-processor list that lives inside a policy document tends to go stale the moment it is inconvenient to amend one. Each sub-processor has its own privacy policy, and we encourage you to review them.

Changes. By using Nimvox you provide general authorisation for us to engage the sub-processors listed on that page. We will publish any addition to it at least 30 days before the new sub-processor begins processing your data, so that you have an opportunity to object. If you object and we cannot offer a reasonable alternative, you may terminate the affected service.

AI features. Some Nimvox products use third-party AI providers to generate content you ask for — for example brand name suggestions and logo drafts in Markvox. When you use such a feature, the input you supply for it is sent to that provider so it can produce the result. We contract with these providers so that your content is not used to train their models. Providers may retain input briefly for their own abuse monitoring; the retention period, where a provider applies one, is noted on the sub-processors page. AI features are only invoked when you use them — we do not send your content to an AI provider in the background.

5. Data Storage and Security

We implement industry-standard security measures to protect your data:

6. Data Retention

Data Type Retention Period
User accounts Until you request deletion
Jobvox job listings 120 days
Jobvox discovery cache 45 days
Post-cancellation account data 30 days, then permanently deleted

You may request complete deletion of your data at any time by contacting us at contact@nimvox.dev.

7. Cookies and Analytics

What Purpose Sets a cookie?
Session cookie Keeps you signed in Yes — strictly necessary, so no consent is asked
Cloudflare Web Analytics Counts page views and measures loading speed No
This site’s and each product’s own page counting Which parts of a site or product people reach No — a session number your browser discards when you close the tab

We use no advertising, marketing or cross-site tracking cookies of any kind, and we sell nothing to anyone.

Cloudflare Web Analytics runs on every page our hosting provider serves for us. It is inserted at the edge rather than by our own code, it sets no cookies, it builds no profile across websites, and it starts before any page of ours has run — so there is nothing to consent to and we ask you nothing. It does see the network address the request came from, as any provider serving a page must.

This site and each product also count their own page views. When you open a page, it records that the page was opened, which page it was, and the address of the page that sent you. On this site it also records which product or pricing card you clicked — the name we gave that card, never the words printed on it and never anything you typed. To count one visit rather than many, your browser keeps a random session number for as long as the tab is open; closing the tab discards it. Nothing counted here is linked to a person or an account, because this site has no accounts. Records are deleted after 90 days. Products that link their own records to a signed-in account say so on their own privacy page.

You can switch that counting off, and the switch for this site is just below. Each product carries its own switch on its own privacy page — reachable from that product’s footer — because a browser stores such a preference separately for every website, so the switch below cannot reach markvox.dev and a switch there could not reach this site. A single control claiming to cover all of them would be telling you it worked when it had not. We also honour your browser’s Do Not Track and Global Privacy Control settings without being asked.

8. Your Privacy Rights

8.1 All Users

Regardless of your location, you have the right to:

8.2 European Economic Area (GDPR)

If you are located in the EU or EEA, you have additional rights under the General Data Protection Regulation:

8.3 California Residents (CCPA/CPRA)

If you are a California resident, you have the right to:

To exercise any of these rights, contact us at contact@nimvox.dev. We will respond within 30 days.

9. International Data Transfers

Your data is stored and processed on infrastructure located in the United States (Virginia) and Finland (Helsinki). If you are located outside these regions, your data will be transferred to one or both locations for processing. For transfers from the EU/EEA, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission to provide appropriate safeguards for your data.

10. Children's Privacy

Our Services are not directed at children under the age of 13 (or 16 in the EEA). We do not knowingly collect personal information from children. If we discover that we have inadvertently collected data from a child, we will promptly delete it. If you believe a child has provided us with personal information, please contact us.

11. Changes to This Policy

We may update this Privacy Policy from time to time. For material changes, we will provide at least 30 days' notice by posting the updated policy on our website and updating the effective date at the top of this page. Your continued use of our Services after the effective date constitutes acceptance of the updated policy.

September 2026 (third update). Markvox and Scoutvox are now named as Services, and Section 2.3 lists what each of them collects. They were missing: this policy’s definition of “the Services” had named only Kubevox, Buildvox and Jobvox since it was first written in March 2026, and was never revisited as the other two launched. Because each product’s own privacy page defers to this one for what is collected, a Markvox or Scoutvox customer was pointed at a policy that did not list their product. Nothing about what we collect has changed — this corrects a document that had fallen behind the products it governs.

September 2026 (second update). This site now counts its own page views, and which product or pricing card was clicked, in the same cookieless and account-free way Section 7 already describes for the products. Section 7 previously said this counting was switched off here. That was accurate until today, and rather than leave the sentence standing we have rewritten it and put the switch on this page. This widens what we process rather than narrowing it, so the reasoning in the entry below does not carry over to it. It takes effect immediately for three reasons: the measurement is anonymous and sets no cookie, it is the same measurement every Nimvox product already discloses and performs, and the control that turns it off is on this page and takes effect from the moment you use it. Your browser’s Do Not Track and Global Privacy Control settings are honoured here without being asked, exactly as they already were on the products. If you would rather not be counted, the switch is in Section 7.

September 2026. This site used to show a banner asking you to accept “analytics cookies”, and Section 7 used to say analytics were loaded only if you accepted. Neither was accurate. The analytics described in Section 7 set no cookies, and the measurement that runs on every page is inserted by our hosting provider before any code of ours runs — so declining never stopped it, and accepting was consent to something that did not need it. The banner is gone and Section 7 now describes what actually happens. Nothing new is collected as a result; the switch that does work moved to each product’s own privacy page, where a browser will honour it. It takes effect immediately rather than after the 30 days’ notice above: that notice protects you from processing being widened, and this change only narrows it — waiting would have meant knowingly leaving an inaccurate statement on the page for another month.

12. Contact

If you have questions about this Privacy Policy or how we handle your data, please contact us at contact@nimvox.dev.

Nimvox LLC, 4037 Via Marina, H-203, Marina Del Rey, CA 90292