Back to home
N22

Privacy Policy

What we collect, why we collect it and what we do with it.

This document is a working draft and does not yet constitute the final legal terms of the service.

What we collect

When you create an N22 account we store your name, your email address and a hash of your password. We never store your password itself. If you connect an AI provider, we store the credential you supply in encrypted form, plus its last four characters so you can recognise it.

Provider credentials

Credentials are encrypted at rest with AES-256-GCM. The encryption key lives outside the database, so a database dump alone does not expose them. A stored credential is never returned to your browser and is decrypted only on the server, at the moment a request to that provider is made.

Usage data

To show you costs and consumption, we store aggregated usage records: provider, model, day, request counts, token counts and cost. We do not store the content of your prompts or the responses you receive.

Logs

Server logs record request identifiers, timing and errors. Passwords, tokens, API keys and other secrets are redacted before anything is written.

Deleting your account

Deleting your account removes your user record and everything linked to it, including sessions, provider connections and usage records.

Contact

For any question about this policy, contact us through the channels listed on our contact page.

Last updated: 2026-08-10