1. Introduction
Nuit (“we”, “us”, “our”) operates the website nuit.archi and the Nuit web application (collectively, the “Service”). This Privacy Policy explains how we collect, use, disclose, and protect your personal data when you use our Service.
By using the Service, you agree to the collection and use of information in accordance with this policy. If you do not agree, please do not use the Service.
2. Data Controller
The data controller responsible for your personal data is Nuit. For any privacy-related inquiries, contact us at hi@nuit.archi.
3. Information We Collect
3.1 Information You Provide
- Account information: email address provided during registration.
- Project data: text prompts, project names, briefs, and reference images you upload.
- Communications: messages you send to us via email.
3.2 Information Collected Automatically
- Usage data: pages visited, features used, generation count, timestamps, and interaction patterns.
- Device data: browser type, operating system, screen resolution, and language preference.
- Log data: IP address, access times, and referring URLs.
3.3 Cookies
We use essential cookies to maintain your session and preferences. We may use analytics cookies to understand how the Service is used. You can control cookie preferences through your browser settings or our cookie consent banner.
4. How We Use Your Information
We use the collected information to:
- Provide, maintain, and improve the Service.
- Process your image generation requests.
- Manage your account and subscription.
- Send transactional communications (account verification, billing).
- Analyze usage patterns to improve features and performance.
- Detect, prevent, and address technical issues or abuse.
- Comply with legal obligations.
5. Legal Basis for Processing (GDPR)
If you are in the European Economic Area, we process your data based on:
- Contract performance: processing necessary to provide the Service you requested (account, generation, billing).
- Legitimate interests: improving the Service, analytics, security, and fraud prevention.
- Consent: where you have given explicit consent (e.g., marketing communications, non-essential cookies).
- Legal obligation: where processing is required by law.
6. Data Sharing and Disclosure
We do not sell your personal data. We may share data with:
- Service providers: third-party services that help us operate the Service, including cloud hosting (Vercel, Supabase), AI image generation providers (for processing your prompts), and payment processors. These providers are contractually obligated to protect your data.
- Legal requirements: if required by law, court order, or governmental request.
- Business transfers: in connection with a merger, acquisition, or sale of assets, your data may be transferred to the acquiring entity.
7. AI-Generated Content
When you submit prompts and reference images, these are sent to third-party AI providers to generate images. We do not use your prompts or generated images to train AI models. Generated images are stored in your account and are accessible only to you unless you choose to share them.
8. Data Retention
- Account data: retained as long as your account is active. Upon account deletion, personal data is removed within 30 days.
- Generated images: retained as long as your account is active. Deleted upon account deletion.
- Usage logs: retained for up to 12 months for analytics and security purposes.
- Billing records: retained as required by applicable tax and accounting laws.
9. Data Security
We implement appropriate technical and organizational measures to protect your data, including encryption in transit (TLS), encryption at rest, access controls, and regular security reviews. However, no method of transmission or storage is 100% secure. We cannot guarantee absolute security.
10. Your Rights
Depending on your jurisdiction, you may have the following rights:
- Access: request a copy of the personal data we hold about you.
- Rectification: request correction of inaccurate data.
- Erasure: request deletion of your personal data.
- Portability: request your data in a machine-readable format.
- Restriction: request that we limit processing of your data.
- Objection: object to processing based on legitimate interests.
- Withdraw consent: where processing is based on consent, withdraw it at any time.
To exercise any of these rights, contact us at hi@nuit.archi. We will respond within 30 days.
11. International Data Transfers
Your data may be transferred to and processed in countries outside your country of residence, including the United States. We ensure appropriate safeguards are in place, such as Standard Contractual Clauses, to protect your data in accordance with applicable law.
12. Children's Privacy
The Service is not intended for individuals under the age of 16. We do not knowingly collect personal data from children. If we become aware that a child has provided us with personal data, we will delete it promptly.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the “Last updated” date. Your continued use of the Service after changes constitutes acceptance of the updated policy.
14. Contact
For questions, concerns, or requests regarding this Privacy Policy, contact us at: hi@nuit.archi