Legal
Last updated: 25 July 2026
This policy covers app.nurilabs.io and this website. It is written to be read, not to be survived. If something here is unclear, write to us and we will fix the wording.
There is no password, because sign-in is by email link, so there is no password of yours for us to leak.
The keys you enter are encrypted at rest (AES-256-GCM) under a master key held only on the server, and are decrypted solely at the moment a run needs to call that provider. Once saved, a key is never sent back to the browser, not even partially masked. The interface shows you its last four characters and the date you set it, taken from a note made at the moment you typed it, and nothing else.
Our servers keep short-lived request logs (IP address, page, timestamp) to operate the service and defend it against abuse. Errors are sent to Sentry so we can fix what breaks before you have to report it. We use no advertising or analytics trackers, and this website sets no cookies of its own.
We do not sell personal data, and we do not use your content to train models, ours or anyone else’s.
Every provider involved, named. Providers reached with your own keys (model providers such as Anthropic, and the stock photo services) receive what a run sends them under your own account with them, governed by their terms.
| Provider | Location | Purpose |
|---|---|---|
| Hetzner Online GmbH | Germany | Application and database hosting |
| Cloudflare, Inc. | EU (WEUR) / global | DNS, static site, object storage for images and backups |
| Resend | EU | Sign-in emails |
| Functional Software, Inc. (Sentry) | EU (Germany) | Error monitoring |
| DataForSEO | EU (Estonia) | Search results and keyword metrics |
| Firecrawl | United States | Reading competitor pages |
| Apify | EU (Czechia) | Image search and video transcripts |
| Unsplash · Pexels · Pixabay | United States / EU | Stock photography, on your own keys |
Where a provider is outside the EU, transfers rely on the European Commission’s standard contractual clauses.
Under the GDPR you can ask to access, correct, delete or export your data, to restrict or object to a processing, and to withdraw a consent you gave. Write to hello@nurilabs.io; we answer within a month.
If our answer does not satisfy you, you can complain to your national supervisory authority: in France, the CNIL.
Traffic is encrypted in transit (HTTPS); provider keys are encrypted at rest; access to your data is scoped to your organisation and enforced on the server, not merely hidden in the interface. Backups are taken daily and stored off the application server. No system is perfect: if a breach ever affects your data, we will tell you and the supervisory authority, as the law requires.
If this policy changes in a way that matters, we will email account holders before it takes effect. The date at the top always reflects the version in force.