This policy explains what data NepAI collects, why we collect it, and the rights you have over it.
1. What we collect
Account data
- Name and email you provide at signup.
- Hashed password (we never store passwords in plaintext).
- Email verification status.
Usage data
- Prompts you submit, model selected, parameters, and generation outputs.
- Credit transactions and payment records (gateway, amount, NPR-only, no card numbers).
- IP address and user-agent for security audit logging.
What we do NOT collect
- We never see your Khalti or eSewa credentials. Payment authentication happens on the gateway's own site.
- We do not collect biometrics, location, or contacts.
- We do not load third-party advertising trackers.
2. Why we collect it
- Run the service: we need your account info to authenticate you and your prompts to generate outputs.
- Bill and refund: payment records are used to issue receipts, prove transactions, and refund failed generations.
- Moderate abuse: we review prompts and outputs flagged by our filters or by user reports.
- Improve reliability: we aggregate failure rates and latencies; aggregates contain no personally identifying information.
3. Who we share it with
- Replicate (model provider) — receives only your prompt and selected parameters at generation time. Replicate's privacy policy applies.
- Cloudflare R2 — stores generated assets. Access is limited to URLs we generate.
- Khalti / eSewa — receive the payment amount and order ID. They do not receive your prompts or outputs.
- Resend (email provider) — receives your email address and receipt content.
- We do not sell or rent personal data. We disclose to authorities only under valid Nepali legal process.
4. Where it lives, how long
- Servers in regions chosen for proximity to Nepal (currently Cloudflare R2 auto-region; database on a major cloud provider).
- Account data: kept while your account exists.
- Generation outputs: kept until you delete them or for 12 months after account deletion, whichever is sooner.
- Payment records: kept for 7 years per Nepali tax requirements.
- Server logs: 30 days unless under active security investigation.
5. Your rights
You can: download all your data, correct your name/email, delete your account (which removes account data and generations within 30 days), and object to specific processing. Reach us at the address below to exercise these rights — we'll respond within 14 days.
6. Security
- All requests use HTTPS in production.
- Passwords are hashed with bcrypt.
- API access uses bearer tokens that can be revoked from your account or by us in response to a breach.
- We perform routine dependency updates and follow secure-by-default Laravel + Next.js conventions.
7. Children
NepAI is not directed at children under 16. We delete accounts on discovery that the holder is under 16.
8. Changes
Material changes will be notified by email at least 14 days before they take effect. Minor edits (typos, clarifications) may be made silently with the "Last updated" date refreshed.
9. Contact
Data protection questions: [email protected], or call +977 9818810378.