Legal
Privacy
This page covers two separate things: the NerveStax product, and the nervestax.ai website. They are not the same and the answers are very different, so they are kept apart below.
Last updated: 17 September 2026
Part 1 — The product
NerveStax runs two ways: hosted by us, or self-hosted on your own infrastructure, against your own database, under your own operational control. What happens to your data depends on which you use, so each is covered separately.
Hosted service
What we process
When you use NerveStax hosted, we process the data your workspace connects, in order to run the service: metadata about your warehouse and projects, code from your repositories, logs, query results the agents retrieve, and your conversations with the agents.
Where it is processed
The hosted service runs on Google Cloud in the United States. Agent code sandboxes run on E2B. Model calls go to the LLM provider you choose, using your own key, under your agreement with that provider, so review their terms for your use case, particularly anything about training on submitted data.
Secrets in the hosted service
Credentials you store, such as warehouse credentials, repository tokens and model keys, are encrypted with AES-256-GCM using a key held in Google Cloud Secret Manager, outside the database.
Questions about hosted data
For security matters, email [email protected]. For anything else about your data, email [email protected]. How the product is secured is described at nervestax.ai/security/.
For self-hosted deployments
We do not receive your data
In a self-hosted deployment we have no access to your installation and receive no data from it. Your warehouse contents, queries, code, credentials, logs, prompts, agent conversations and generated output stay inside your infrastructure. We cannot read them, and we have no mechanism that would let us.
Under most privacy frameworks this makes you the controller of that data, and means we are not a processor of it at all — there is nothing for us to process. If your organisation requires a data processing agreement regardless, contact us and we will cover the narrow cases described below.
Self-hosted software does not phone home
The product contains no telemetry, no usage reporting, no licence check and no call-back to us of any kind. It does not need a network route to us in order to run: an installation with no path to the public internet behaves exactly like one that has it. Nothing about your usage, scale, users or data is transmitted to us, because there is no code that would do it.
The one thing we can see is your container registry pulls — when you download a release using the credentials issued to you, our registry logs record that a pull happened, when, and under which credential. That is metadata about software distribution, not about your data or how you use the product.
Where self-hosted data goes
A self-hosted deployment talks to the systems you connect it to, and nothing else. Each is your own relationship with that provider, under their terms, using credentials you supply.
AI model providers. To do its work the agent sends prompts and relevant context — which can include schema, sample rows, query text and code — to the model provider whose API key you enter. That key is added per organisation by your own administrator, stored encrypted in your database, and used from your infrastructure. We never see it and never proxy those calls. Your data reaches that provider under their terms, so review them for your use case, particularly anything about training on submitted data.
Your data warehouse, to read metadata and run the queries and transformations you ask for. Your code repository, to read projects and open pull requests. Your orchestrator, to inspect and trigger pipelines. And an observability endpoint if you configure one — tracing is off by default, and if you enable it the traces go to the collector you nominate, never to us.
Secrets in a self-hosted deployment
Credentials you store — warehouse passwords, repository tokens, AI provider keys — are encrypted at rest in your own database, using an encryption key that exists only in your deployment. We do not hold, escrow or have any means of recovering that key. That is deliberate: a recovery path for us would be an attack path against you. It also means that if the key is lost, everything encrypted with it is permanently unreadable, so back it up — see section 8 of the Terms.
Support for self-hosted deployments
In a self-hosted deployment, the only time we might see your data is when you ask us for help. You may choose to send us logs, screenshots, configuration or a diagnostic bundle. Anything we receive is something you decided to share; we have no way to collect it ourselves. Please redact secrets and personal data before sending. We use it only to resolve your issue and delete it once the issue is closed, and we will not access a customer environment unless you explicitly grant access, for only as long as that takes.
Part 2 — This website
Separate from the product: nervestax.ai is a marketing site with a contact form, sharing no infrastructure with the product.
What we collect
Only what you type into a form on this site: your name, email address, company (if you give one) and your message. We also store the country your request came from, your browser’s user agent, and a one-way hash of your IP address — the hash exists purely to rate-limit spam and cannot be turned back into an IP address.
Why
To reply to you and, if you asked for early access, to let you know when your workspace is ready. We do not sell or share this data, and we do not add you to a marketing list you didn’t ask for.
Where it lives
In a Cloudflare D1 database on our own Cloudflare account, and in our email inbox. Cloudflare hosts this site and provides bot protection; the notification email is delivered by Resend. We keep submissions until they’re no longer useful for the conversation you started.
Cookies and analytics
No tracking cookies and no third-party analytics. Your theme preference is stored locally in your own browser and never leaves it. Cloudflare’s bot check may set a short-lived token when you submit a form.
Your choices
Email [email protected] and we’ll send you a copy of what we hold, correct it, or delete it. For data inside a self-hosted NerveStax deployment there is nothing for us to action — we have no access to it, and it is already yours. For data in the hosted service, contact the same address.
Who to contact
NerveStax is a product of J4M4L Technology, licensed in Dubai (1602382). Reach us at [email protected]. Licence terms are at nervestax.ai/terms/.