Cloud Cmds LLC d/b/a Deep Noodle AI operates Nvoken (“Nvoken,” “we,” “us,” or “our”). This Privacy Policy explains how we collect, use, share, retain, and protect information when you use the Nvoken website, console, HTTP API, client SDKs, agent execution service, and related services (collectively, the “Services”).
Nvoken is built for organizations putting agents inside their own products. The Services therefore process both information about the people and organizations that use Nvoken and Customer Data those organizations submit or cause us to process for their own end users.
Our role
“Customer Data” includes agent instructions and configuration, messages, prompts, memories, Conversation content, turn records, tool definitions, tool calls and results, metadata, usage records, and integration payloads submitted to or generated by the Services for a customer organization.
For personal data in Customer Data, Nvoken generally acts as a processor or service provider for the customer organization. The customer decides why the data is processed, which people may interact with its agents, which tools and providers are connected, and how results are used. The customer is responsible for its own privacy notices, permissions, and lawful basis.
Nvoken acts as a controller for information it uses to manage accounts, operate and secure the Services, communicate with customers, administer billing, understand product use, and meet legal obligations.
Information we collect
Information you provide
- Account and organization information. Name, email address, profile information, authentication records, organization membership, and role assignments. Our authentication provider handles sign-in credentials.
- App and agent configuration. App settings, Agent Agent revisions, model and routing choices, tools, webhooks, signing keys, API-key metadata, and provider-key metadata. Reusable provider secrets are encrypted when stored.
- Conversation and execution data. Conversation messages, prompts, selected memories, application context, turn events, model responses, tool calls and results, status, diagnostics, and related metadata.
- Usage and credit information. Token and model usage, estimated and settled cost, customer attribution, budgets, tenant credit counters and allocations, purchased-credit balance, and purchase records where applicable.
- Communications. Information you send us about support, security, billing, sales, or feedback.
Information collected automatically
- Technical information. IP address, browser and device type, operating system, request metadata, and network and authentication events.
- Usage information. Pages and features accessed, actions taken, API requests, rate-limit usage, model and tool activity, and configuration changes.
- Logs and diagnostics. Service logs, errors, performance data, traces, security events, audit records, and incident-response information.
AI, model-provider, and tool processing
To run a turn, Nvoken may send relevant agent instructions, conversation context, application context, prompts, and tool results to the model provider selected by the customer. Supported providers currently include Anthropic, OpenAI, Google, and xAI. The provider returns model output that Nvoken uses to continue or complete the turn.
When an agent calls a host tool, callback, webhook, MCP server, or provider tool, Nvoken sends the information required by that tool to the customer-controlled or third-party endpoint configured for it. Tool results may then become part of the conversation context sent to the selected model provider.
Nvoken does not use Customer Data to train foundation or generative AI models. Model providers and customer-configured integrations process data according to the customer’s configuration, the applicable provider terms, and any agreement between the customer and that provider.
How we use information
We use information to:
- Provide and operate accounts, organizations, Apps, agents, Conversations, turns, tools, streaming, model routing, usage records, budgets, and credits.
- Authenticate requests, apply permissions and service limits, protect credentials, prevent abuse, and investigate security events.
- Monitor reliability and performance, diagnose failures, support customers, and improve the Services.
- Attribute model usage and cost, administer purchased credits and fees, and maintain business and accounting records.
- Communicate about the Services, including operational, security, support, billing, and material legal notices.
- Comply with legal obligations and enforce our Terms of Service.
Data security
We use reasonable technical and organizational measures designed to protect information, including encryption in transit, encryption at rest through our cloud providers, logical isolation by organization and App, encrypted storage for reusable provider secrets, scoped credentials, and least-privilege operator access.
No Internet service can guarantee absolute security. You are responsible for protecting credentials and configuring appropriate permissions for your agents and tools. Report a suspected vulnerability or incident to support@nvoken.com.
Data retention and deletion
Nvoken retains account, configuration, conversation, execution, and usage information for as long as reasonably necessary to provide the Services and maintain the durable, inspectable records customers use to operate agents. Runtime records are retained by default unless a supported retention setting, deletion operation, customer agreement, or operational process provides otherwise.
Customers may configure an idle retention window for eligible Conversations. Some transient transport and diagnostic information is pruned on a shorter schedule. Billing, usage, audit, security, and incident records may be kept longer for legal, accounting, fraud prevention, dispute, and legitimate operational needs.
A deletion request may require coordination with the customer organization that controls the data. Deletion from active systems and backups may take time, and some information may remain where law or a legitimate business need requires it.
Your rights and choices
Depending on where you live and your relationship to a customer organization, you may have rights to access, correct, delete, restrict, object to processing of, or receive a portable copy of personal data. You may also control organization membership, credentials, provider keys, and other settings through the console where those controls are available.
To make a request, contact support@nvoken.com. We may need to verify your identity and authority. If a customer organization controls the data, we may direct the request to that organization or assist it in responding.
Browser settings can control cookies, and you may opt out of non-essential communications by using the instructions in the message or contacting us. We do not discriminate against people for exercising applicable privacy rights.
Age limitations
The Services are business tools for people who are at least 18 years old. They are not directed to children under 13, and we do not knowingly collect personal information from them. Contact us if you believe a child has provided personal information.
International data transfers
We and our providers may process information in the United States and other countries where they operate. Where applicable law requires it, we use appropriate safeguards for international transfers.
Changes to this policy
We may update this Privacy Policy from time to time. We will post the updated version here and change the “last updated” date. For material changes, we may provide additional notice by email or in the product.
Contact
Questions or requests about this policy and our privacy practices go to support@nvoken.com.