Privacy
This page explains what personal information nuvekta collects, why, and which service providers process it. It covers this website and the account service that issues trials and licences. The desktop application is not released yet; see the last section.
The short version, which the rest of this page supports rather than replaces: we collect the minimum needed to answer you, to give you a trial, and to keep that offer from being abused. We do not sell personal information and we run no advertising trackers.
What we collect
This website
| What | When | Why |
|---|---|---|
| Email address | You join the early-access list | To contact you about early access |
| Email address, name (optional), message content | You submit the contact form | To answer you |
| Email address | You request a trial | To evaluate the request and send you a setup link |
| A Cloudflare Turnstile token | You submit the trial form | Anti-abuse; to confirm the submission is not automated |
| Aggregate page-view counts | Every page view | To see which pages are useful |
Page-view measurement uses Cloudflare Web Analytics, which sets no cookies, does not fingerprint your browser, and cannot follow you to other sites. We also process standard request metadata, including IP address and user agent, for security, rate limiting, and abuse prevention.
The account service
If your trial request is approved and you set up an account, we hold:
- your email address, a hashed password, whether the address is confirmed, and account creation and sign-in timestamps;
- your organisation membership and role, and any invitation records;
- your entitlement — plan, seat count, enabled features, and expiry;
- a one-way hash of a normalised form of your email address, which is how we enforce one trial per person. It is a hash, not a stored address, and it is kept after the trial ends because it is the thing that prevents repeat trials;
- a pseudonymous, append-only audit log of security- and licence-relevant events: what type of event occurred, when, the outcome, and internal identifiers. It does not contain your email address or message content;
- IP address and request metadata for rate limiting and abuse detection.
No payment processor is live and we hold no billing information. When that changes, this page will say so before it does.
Cookies and browser storage
This site sets no cookies of its own and writes nothing to your browser's local storage. There is nothing to accept or decline, which is why there is no cookie banner. Four things come close, so here they are:
- Page-view counts. Cloudflare Web Analytics, described above, works without cookies or local storage.
- The trial form. The anti-abuse check, Cloudflare Turnstile, runs from
Cloudflare's own domain under Cloudflare's
Turnstile privacy terms. It
reads signals such as IP address, user agent, and TLS fingerprint to tell people from bots, and
Cloudflare describes those signals as strictly necessary for that purpose. Inside its own frame,
on Cloudflare's domain rather than ours, it also keeps an identifier in your browser's storage
(
cf.turnstile.u) as part of that check. - Cloudflare's network. This site is delivered through Cloudflare. If
Cloudflare needs to challenge a suspicious request, it can set a short-lived security cookie,
such as
cf_clearanceor__cf_bm. These are strictly necessary for that check and are not used to track you; Cloudflare lists them in its cookie reference. - Account setup links. The page that opens from an invitation or password-reset email reads a one-time token from the link, removes it from the address bar, and holds it in memory only until you set a password. It is not saved to a cookie or to storage.
If we add a cookie that is not strictly necessary, it will be listed here, with who sets it, why, and how long it lasts, before it goes live.
Do Not Track
Some browsers send a Do Not Track signal. We do not track you across other sites, so there is nothing for the signal to switch off, and the site behaves the same whether or not your browser sends it.
Why we collect it
To answer your enquiries; to issue and administer trials, accounts, and licences; to enforce one trial per person; and to keep the service secure. Early-access and product emails are sent on the basis of your consent, which you may withdraw at any time. We will not sell your details, rent them, or share them for unrelated marketing.
Who processes it
We use the following service providers. Each processes personal information on our behalf, under its own terms.
| Provider | What it processes | Purpose |
|---|---|---|
| Supabase | Trial requests; account, organisation, entitlement, and audit data; authentication | Database, authentication, and serverless functions for the account service |
| Cloudflare | Website requests; Turnstile challenge tokens; aggregate page-view counts | Website delivery, bot mitigation, privacy-preserving analytics |
| Google (Workspace SMTP relay) | Email addresses and message content | Delivery of transactional email, such as confirmation and invitation messages |
| Kit (formerly ConvertKit) | Email address | Early-access mailing list |
| Formspree | Contact-form submissions | Delivery of contact-form messages to our inbox |
We may also disclose personal information to comply with law or a valid legal request; to enforce our agreements or protect our rights; to investigate fraud, abuse, or a security incident; or in connection with a merger, acquisition, or sale of assets, in which case we will give notice before your information becomes subject to a different privacy policy.
How long we keep it
- Account, organisation, and entitlement records — while your account is active, and for a short wind-down period afterwards.
- Trial de-duplication hashes — kept after the trial ends, because they are what prevents repeat trials.
- Rate-limiting records — pruned automatically on a recurring schedule.
- Contact-form messages — while we need them to answer you and to keep a record of the exchange.
- Early-access list entries — until you unsubscribe, ask us to remove you, or the programme ends.
Your choices
You can ask us to access, correct, or delete the personal information we hold about you, and to opt out of any message we send. Email the address below and we will take care of it.
Two honest limitations, so they are not a surprise later:
- Organisation ownership. If you own an organisation in which other people hold seats, we cannot delete your account until those seats are removed or ownership is transferred — doing so would destroy other people's access.
- The audit log. It is append-only by design and cannot be edited, deleted, or truncated, because a log that can be edited is not evidence. It is pseudonymous: it records event types, outcomes, timestamps, and internal identifiers, not your email address. Deleting your account severs the link between those identifiers and you.
Security
We protect the account service with tenant isolation enforced at the database layer, certificate-verified database connections, an append-only audit log, rate limiting, and server-side bot mitigation on public forms. No system is perfectly secure and we do not claim otherwise. If we become aware of a breach affecting your personal information, we will notify you and the relevant authorities as required by law.
Children
The service is not directed to children under 16 and we do not knowingly collect their personal information. If you believe a child has provided us information, contact us and we will delete it.
The desktop application
The desktop application has not been released, so nothing in it is collecting anything from anyone today. It is built to compute locally — your sequences, structures, input files, and results stay on your machine — and to transmit only what licensing requires. Before it ships, this page will state exactly what it sends, verified against the released build rather than the design intent.
Changes and contact
We will update this page as the product changes, and will update the date at the top. Questions about privacy, or anything else? Email hello@nuvektascientific.com.