Privacy Policy

Last updated: 16.09.2026

1. Introduction

At Nimbus, we take your privacy seriously. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.

2. Information We Collect

Personal Information

We collect information that you provide directly to us, including:

  • Name and email address
  • Account credentials
  • Payment information (processed securely through our payment provider)
  • Profile information
  • Communications with us

Payment Card Data Protection

Important: We do NOT store your payment card data on our servers. All payment card information is processed and stored securely by our PCI-DSS Level 1 compliant payment processor. We receive only the last 4 digits of your card number for display and reference purposes. Your complete card details never touch our servers and are never accessible to us.

  • Card numbers are encrypted and tokenized by our payment processor
  • We receive only the last 4 digits for your records
  • CVV/CVC codes are never stored anywhere
  • All payment transactions use industry-standard SSL/TLS encryption
  • Our payment processor is PCI-DSS Level 1 certified (highest security level)

Usage Information

We automatically collect certain information about your use of the Service:

  • Device information (IP address, browser type, operating system)
  • Usage data (features used, time spent, interactions)
  • Cookies and similar tracking technologies

Code and Project Data

When you use our Service to generate or modify code:

  • Project descriptions and requirements
  • Generated code and configurations
  • Task descriptions and history
  • Information about a code repository you choose to connect

3. How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve our Service
  • Process transactions and manage your account
  • Send you technical notices and support messages
  • Respond to your comments and questions
  • Develop new features and services
  • Monitor and analyze usage patterns
  • Detect and prevent fraud and abuse
  • Comply with legal obligations

4. Data Sharing and Disclosure

We may share your information in the following circumstances:

  • Service Providers: With third-party vendors who perform services on our behalf
  • Legal Requirements: When required by law or to protect our rights
  • Business Transfers: In connection with a merger, acquisition, or sale of assets
  • With Your Consent: When you explicitly consent to sharing

We do not sell your personal information to third parties.

5. Data Security

We implement appropriate technical and organizational measures to protect your information, including:

  • Encryption in transit and at rest
  • Regular security assessments
  • Access controls and authentication
  • Secure infrastructure and monitoring

However, no method of transmission over the Internet is 100% secure, and we cannot guarantee absolute security.

6. Data Retention

We retain your information only for as long as necessary to provide the Service and fulfill the purposes outlined in this Privacy Policy, and no longer. Our retention periods by category are:

  • Account and profile data: for the life of your account, plus 30 days after deletion to allow recovery of an accidental deletion
  • Transaction and payment records: 6 years, to meet UK statutory bookkeeping and tax record-keeping obligations
  • Generated code, project, and task data: for the life of your account, or until you delete the associated project
  • Usage and log data: up to 12 months, then aggregated or deleted
  • Support communications: up to 24 months after the ticket is closed

When you delete your account, we delete or anonymize your personal information within the periods above, except where we are required to retain it for legal, tax, or legitimate business purposes (such as fraud prevention or dispute resolution).

Where your data is stored: our primary database and application infrastructure are hosted in the United States. If you are located in the United Kingdom or the European Economic Area, using the Service means your personal data is transferred to and processed in the United States. Where required, we rely on appropriate safeguards for that transfer, such as the UK International Data Transfer Addendum or EU Standard Contractual Clauses, incorporated into our agreements with our infrastructure providers.

7. Your Rights

Depending on your location, you may have certain rights regarding your personal information:

  • Access and receive a copy of your data
  • Correct inaccurate information
  • Request deletion of your data
  • Object to or restrict processing
  • Data portability
  • Withdraw consent

To exercise these rights, please contact us at support@nimbus.expert

8. Cookies and Tracking

We use cookies and similar technologies to collect usage information and improve your experience. You can control cookies through your browser settings, but disabling cookies may affect your ability to use certain features of the Service.

9. Children's Privacy

Our Service is not intended for anyone under 18 years of age, matching the age requirement in our Terms of Service. We do not knowingly collect personal information from children.

10. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the "Last updated" date.

11. Data Controller

Iron Cortex LTD
Registration Number: 16889774
Academy House 11 Dunraven Place,
Bridgend, Mid Glamorgan, CF31 1JF,
United Kingdom

12. Contact Us

If you have any questions about this Privacy Policy, please contact us:

Email: support@nimbus.expert