← Back to NiyoGen

Privacy Policy

Last updated: 2026-06-11

1. Who we are (the data controller)

NiyoGen Pte. Ltd. is a Singapore-registered software development and AI consultancy. We operate app.niyogen.com (“the Service”), which lets you generate web apps from natural-language prompts. NiyoGen is the data controller for the personal data described in this policy.

Contact for data-protection matters: api@niyogen.com

2. What personal data we process

We process the minimum personal data needed to run the Service:

  • Account identity: email address (required), bcrypt hash of your password (never the password itself), optional display name.
  • Authentication state: session cookies and verification/reset tokens (auto-expire; single-use for reset tokens).
  • Your prompts & generated apps: the prompts you submit to the architect, the resulting JSON schemas, and any multi-page app manifests.
  • Form submissions to your apps: when end-users fill out a form widget you built, the submission is stored against your app so you can view it.
  • Usage analytics: counters like prompts_sent, apps_published, time-to-first-render. Tied to your user_id while you have an account; anonymised when you delete your account.
  • Operational logs: IP address and User-Agent for request logs, retained ≤ 30 days for abuse / debugging.

We do not use third-party analytics (no Google Analytics, no Facebook Pixel), ad networks, or cross-site trackers.

3. Legal bases for processing

  • Contract performance (Singapore PDPA s.13(1)(a), Sri Lanka PDPA s.12(1)(b), GDPR Art. 6(1)(b)) — we need your email + password hash to give you an account, and your prompts/schemas to run the Service.
  • Consent (SG PDPA s.13(1)(b), LK PDPA s.12(1)(a), GDPR Art. 6(1)(a)) — for optional things like marketing emails (none today; we’ll re-prompt if that changes).
  • Legitimate interests (LK PDPA s.12(1)(f), GDPR Art. 6(1)(f)) — for fraud prevention, abuse rate-limits, and debugging via short-retention logs.

4. Third-party processors

We use the following processors to operate the Service. Each is bound by a data processing agreement (DPA) and processes data only on our documented instructions:

  • Anthropic (US) — receives your prompts in order to generate the schema. Prompts are not used to train Anthropic models per their commercial API terms.
  • Cloud infrastructure providers (currently a US-based hosting provider; the specific provider may change with notice via an update to this Privacy Policy) — host our servers, database, and supporting services. Each is bound by their standard data-processing addendum and GDPR-equivalent commitments.
  • Stripe (US) — billing for paid plans (when introduced). Stripe is the controller for payment-card data; we never see your card number.
  • Google LLC (US) — when you choose “Sign in with Google”, Google authenticates you and returns a signed token to us containing your email address, name, and a stable Google account identifier. We store these to create or look up your NiyoGen account and never receive your Google password. Use is optional; email + password sign-in remains available. Google’s handling of your data is governed by the Google Privacy Policy.
  • Let’s Encrypt (US, ISRG) — issues our TLS certificate. No personal data shared.

5. Cross-border transfers

Our servers are currently in the United States. This means personal data leaves Singapore and Sri Lanka. We may change the country or specific provider with notice via an update to this Privacy Policy.

  • Singapore PDPA s.26: we ensure recipient organisations are bound to a comparable standard of protection via written contracts (data-processing addenda with our infrastructure provider, Anthropic, and Stripe).
  • Sri Lanka PDPA s.18: same DPA approach. We rely on standard contractual safeguards rather than country adequacy determinations.
  • GDPR Art. 46: we rely on Standard Contractual Clauses (SCCs) with US-based processors.

6. Retention

  • Account & content: until you delete your account or 24 months of inactivity (whichever comes first).
  • Verification / reset tokens: 24h / 1h respectively; deleted on use.
  • Form submissions to your apps: until you delete the app or your account.
  • Request logs: ≤ 30 days.
  • Anonymised analytics: retained indefinitely; cannot be re-tied to you.
  • Stripe billing records: 7 years (Singapore tax-record requirement under the Income Tax Act).

7. Your rights

Whether you are in Singapore, Sri Lanka, the EU/EEA, or elsewhere, you have:

  • Access to the personal data we hold about you.
  • Correction of inaccurate data (you can change your display name yourself; email changes via support).
  • Erasure (“right to be forgotten” under GDPR Art. 17, LK PDPA s.19; cessation of use under SG PDPA s.16/s.25). The Account Settings page has a self-service Delete account button — it hard-deletes your user record, every app/page/manifest you own, every form submission to those apps, every session, and every token. Anonymised analytics are kept; everything else is gone.
  • Restriction of processing (GDPR Art. 18).
  • Data portability (GDPR Art. 20) — email us, we’ll send your data as JSON within 30 days.
  • Object to processing based on legitimate interests (GDPR Art. 21).
  • Withdraw consent at any time where we rely on consent.

To exercise any right not covered by the self-service button, email api@niyogen.com. We respond within 30 days (sooner where required by law).

Complaints: if we get this wrong, you can complain to your local supervisory authority — the Personal Data Protection Commission of Singapore (PDPC), the Data Protection Authority of Sri Lanka, or your EU/EEA member-state authority.

8. Cookies & local storage

We use only essential cookies and storage:

  • cleanai_session — HttpOnly session cookie. Required to keep you logged in.
  • csrf_token — CSRF protection token. Required for any state-changing request.
  • cleanai_anon — anonymous client identifier for abuse rate-limits.
  • sessionStorage entries like cleanai_verify_banner_dismissed — UI state only; never leaves your browser.

We do not set tracking, advertising, or analytics cookies. Because all cookies we set are strictly necessary for the Service to function, no consent banner is required under SG PDPA, LK PDPA, or the EU ePrivacy Directive. If we ever add non-essential cookies, we’ll add a banner first.

9. Security

Passwords are bcrypt-hashed. Sessions and CSRF tokens are HttpOnly and Secure under HTTPS. The whole runtime is verified-schema-only — the AI is never in the execution path — which limits the impact of a malicious or buggy prompt. Transit is TLS 1.2+ via Let’s Encrypt. We’ll notify you within 72 hours of becoming aware of a personal-data breach affecting your account (SG PDPA s.26D notification window, LK PDPA s.23, GDPR Art. 33).

10. Children

The Service is not directed to children under 13. We do not knowingly collect personal information from children. If you believe we have, email api@niyogen.com and we will delete the account.

11. Changes

We’ll update the “Last updated” date and email account holders if we materially change this policy.

12. Contact

Data protection: api@niyogen.com
General: api@niyogen.com