Skip to content

US State Privacy Notice

What Nivaronix collects if you live in the United States, the rights your state gives you over it, and the plain fact that we do not sell it.

Last updated: 6 August 2026

Who this applies to

This notice is for residents of US states with a comprehensive privacy law — California, Virginia, Colorado, Connecticut, Utah, Texas, and the states whose laws have followed them.

Rather than publish a section per state and fall behind as more are passed, we grant every right listed here to every US resident, whichever state you live in and whether or not your state has passed a law yet. Where two states word the same right differently, you get the more generous version.

It sits alongside our Privacy Policy, which is the full account of what we collect and who receives it. Where this notice gives you more, this notice wins. Nivaronix is operated by Pravin Gyawali, based in Butwal, Nepal, and is the business responsible for the data described here.

What we collect, and why

This is our notice at collection. It covers the last 12 months and what we collect today. We collect it from you directly, and from your browser or device as you use the service.

Category

What we actually hold

Why

Identifiers

Your name, email address, organization name, and account identifiers. For scanner and abuse logs, a salted one-way hash of your IP address — never the address itself.

Creating and running your account, authenticating you, and preventing abuse of the scanner.

Commercial information

Your plan, subscription and transaction records. Payments are billed manually today — we do not use an automated payment processor, and we do not collect or store your card details.

Billing, invoicing, tax records and support.

Internet or network activity

Request logs, browser and device information, the domains you submit for scanning, monitoring results and incident history. Site analytics only if you accept analytics cookies.

Delivering the monitoring service, diagnosing faults, and understanding how the site is used.

Audio, visual, biometric, genetic or health information

None. We do not collect any of these.

Not applicable.

Precise geolocation

None. We do not collect it and have no feature that would use it.

Not applicable.

Inferences used to build a profile

None about you as a person. Our automated analysis draws conclusions about the security posture of a domain, not about its owner's characteristics or behaviour.

Not applicable.

Sensitive personal information

We do not collect sensitive personal information as California defines it — no government identifiers, no financial account numbers, no precise location, no racial, religious, health, biometric, genetic, sexual orientation or union data. Because we collect none, there is nothing for the right to limit its use to apply to. If that ever changes, this section changes with it and the change is announced.

We do not sell or share your information

We do not sell your personal information, and we have not sold any in the preceding 12 months. No money or other value changes hands for your data, in either direction.

We also do not share it for cross-context behavioural advertising, which is the separate thing California means by "sharing". We run no advertising pixels, no remarketing tags and no ad-network integrations of any kind.

The one third-party tag on this site is Google Analytics, and it deserves a straight answer rather than a reassuring one. We load it with a plain page-measurement configuration and nothing else: no advertising features, no remarketing audiences, no ad-network linkage. It also only loads at all after you accept analytics cookies — nothing fires before you say yes, and it is switched off the moment you withdraw. On that basis our position is that it is not "sharing" under California law. If we ever enable an advertising feature in it, that becomes sharing, and we would have to offer a Do Not Sell or Share link. Today there is nothing to opt out of, so there is no such link to click.

For the same reason, an opt-out preference signal such as Global Privacy Control has nothing to switch off here. We do not currently read that signal, and we would rather say so than claim a control we have not built. Non-essential cookies are off until you turn them on, which gets you to the same place.

We do not knowingly collect personal information from anyone under 16, and we have never sold or shared the personal information of a minor.

Who we disclose it to

We disclose personal information to service providers for business purposes only — running the platform, sending your email, taking your payment, and analysing incidents. Each one, what it receives, and the source file that proves it, is listed in our Privacy Policy: Groq and Google (Gemini) for incident analysis, and Resend for email. We do not use an automated payment processor today — payments are billed manually, confirmed by a person, so no payment provider receives your data as part of that process.

One point worth stating plainly, because it is the kind of thing policies usually bury: the domain name of the asset being analysed is sent to our AI providers, deliberately, because an incident analysis that cannot name the host is useless. Organization and record identifiers are stripped first.

We disclose personal information to law enforcement or a regulator only where the law requires it. We do not disclose it to third parties for their own direct marketing, so a request under California's "Shine the Light" law would return nothing.

How long we keep it

Account data is kept until you delete your account. Scanner audit logs are kept for 90 days and security event logs for 180 days, after which a scheduled job deletes them automatically — these are enforced periods, not aspirations. Internal operational logs (asset lifecycle events, AI-generated incident analyses, LLM request/response records, notification delivery records) are kept for 90 days on the same schedule; the admin and customer action audit trail is kept for 365 days.

Payment and transaction records outlive account deletion, because tax and accounting law independently requires us to keep them, and the links to your identity are removed so what remains is an amount, a currency and a date. The full table, and the itemised list of what survives deletion, is in our Privacy Policy.

Your rights

As a US resident you have the right to:

  • Know what personal information we have collected about you, where it came from, why we collected it, who we disclosed it to, and to get a copy of it.
  • Delete the personal information we hold about you, subject only to the narrow categories the law lets us keep, which are listed for you before you confirm.
  • Correct personal information that is inaccurate.
  • Take it with you — receive your data in a portable, machine-readable format.
  • Opt out of the sale or sharing of your personal information, of targeted advertising, and of profiling that produces legal or similarly significant effects about you. We do none of these, so there is nothing to opt out of — the right is stated because it is yours, not because we are relying on it.
  • Limit our use of sensitive personal information. We collect none.
  • Appeal a decision of ours that you disagree with, before you go to a regulator.

How to exercise them

If you have an account, access, portability and deletion are self-service and need no permission from us. Go to Settings → Privacy & your data, download a complete copy, or start a deletion. A deletion has a 30-day grace period during which you can cancel it; after that it is a real, irreversible delete, not a hidden row.

For anything else — correction, a copy without an account, or a question about what we hold — email [email protected]. We aim to reply within 30 days, which is the deadline our own system clocks against every request. US state law allows up to 45 days and one extension where a request is genuinely complex; we will tell you if we need it.

Verifying it is you. Email us from the address on the account, and we will match your request to our records. If we cannot confirm who you are, we will tell you rather than hand your data to someone else — and we will not use the information you give us for verification for anything other than verifying you.

Authorised agents. Someone may make a request on your behalf if they send us written permission signed by you. We may still contact you directly to confirm it, which is your protection rather than an obstacle.

If we say no

If we refuse a request, we will tell you why. You can appeal by replying to that message, or by emailing [email protected] with the word "appeal". The operator reviews it personally and responds in writing within 45 days, with reasons.

If the appeal is also refused, you can complain to your state attorney general. We will tell you how to do that in the same message, rather than leaving you to find it.

No discrimination

Using any of these rights costs you nothing and changes nothing about your service. We will not deny you the product, charge you a different price, give you a worse version of it, or treat your account differently because you asked us what we hold or told us to delete it. We run no financial incentive or loyalty programme that trades a discount for your data.

Contact

Nivaronix, operated by Pravin Gyawali, Butwal, Nepal. Privacy questions and rights requests go to [email protected]. A person reads that mailbox, not a ticket queue.

Our other policies