Legal

Privacy Policy

This policy explains how Niralabs LLC collects, uses, shares, retains, and protects information across the Niralabs website and Nira Local AI service.

Effective May 11, 2026 · Last updated August 11, 2026

1. Information we collect

Information you provide

We collect account email, business identity and contact information, connected business URLs, content you upload, support correspondence, and subscription details. Stripe processes card information directly; Niralabs does not store full card numbers.

Public and connected-source information

To operate Nira Local AI, we may collect public reviews, ratings, publicly displayed reviewer names, business profiles, listings, search visibility observations, website information, and other public business metadata. When you authorize a connected account, we process data allowed by that authorization.

Technical information

Servers may record IP address, browser and device information, requested pages, timestamps, and referrer URLs for operation, security, and troubleshooting. The public website can load Google Analytics 4 and Google Ads measurement after a visitor grants optional analytics and advertising consent. These tools receive page and interaction data, device information, and campaign identifiers; Niralabs does not intentionally send contact-form fields to Google.

2. How we use information

  • Provide accounts, onboarding, dashboards, monitoring, analyses, recommendations, and AI-assisted outputs.
  • Send transactional, security, product, billing, and support communications.
  • Operate, debug, secure, and improve the service.
  • Prevent fraud, abuse, and unauthorized access.
  • Comply with law and enforce agreements.

3. How we share information

We do not sell personal information or share it for cross-context behavioral advertising. We use service providers for functions such as application hosting and storage, payments, email delivery, AI inference, public-data collection, maps or geocoding, visibility data, and authorized Google integrations. Providers may process information only for contracted services and applicable legal requirements.

Niralabs uses service providers only as needed to operate the service, and reviews that provider inventory as infrastructure changes.

We may also disclose information to comply with valid legal process, protect rights and safety, investigate abuse, or complete a corporate transaction where the recipient must honor this policy.

4. Google API Services user data

Niralabs’ use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including Limited Use requirements.

When a customer connects Google Business Profile, Niralabs may request the business.manage scope to identify authorized locations and support review-reply functionality the customer authorizes. Niralabs does not use Google user data for advertising, does not sell it, and does not transfer it except as necessary for user-facing service features, security, legal compliance, or a corporate transaction with notice where required.

Google OAuth refresh tokens are encrypted at rest and are not intentionally logged in plaintext. Customers can disconnect through available application settings or revoke access through their Google account permissions.

5. Cookies and analytics

We use essential storage for site operation and first-touch campaign attribution. With your consent, the public website loads Google Analytics 4 and Google Ads measurement to understand visits and conversion actions. Optional measurement is denied by default until you choose Accept. You can clear site storage to reset your choice. We do not include contact-form values in analytics events.

6. Retention

We retain information only as needed to provide the service, meet legal obligations, resolve disputes, and prevent fraud. The existing operational policy states these general windows:

  • Reviews and product data: while the subscription is active.
  • Reviews after cancellation: 90 days, then purged or anonymized.
  • Account and user data after cancellation: 90 days, then deleted, subject to required records.
  • Billing records: up to seven years for tax and accounting requirements.
  • Server and email-delivery logs: up to 12 months.

Records may be retained longer where required for billing, tax, fraud prevention, security, or legal obligations.

7. Security

We use safeguards designed to protect information, including TLS in transit, access restrictions, and encryption for sensitive stored credentials. No system can be guaranteed completely secure.

8. Privacy rights

Depending on location, you may have rights to access, correct, delete, restrict, object to, or receive a portable copy of personal information. We do not discriminate for exercising applicable rights. Email nira@niralabs.ai from the address associated with your account. We may verify identity before fulfilling a request.

9. Children and international transfers

The service is intended for businesses and is not directed to people under 18. We do not knowingly collect personal information from children. Information may be processed in the United States; where required, we use appropriate safeguards for international transfers.

10. Incidents and policy changes

If a security incident affects personal information, we will provide notice consistent with applicable law. We may update this policy and will update the date above. Material changes will be communicated by email or in-product notice where feasible.

11. Contact

Privacy questions or rights requests: nira@niralabs.ai.