Privacy Notice
This notice describes the current Palim website, Beta desktop app, optional account, update, support, and first-party telemetry paths. It does not govern an AI service you configure yourself; that service's own privacy terms apply when you choose to use it.
1. Scope, Operator & Contact
NYXEVO LLC (“NyxEvo”) operates Palim and is responsible for the Palim-controlled processing described here. This notice covers palim.nyxevo.com, official downloads and updates, the Beta desktop app's Palim account, support intake, and Palim-owned telemetry. Privacy questions and requests can be sent to contact@nyxevo.com.
The local workbench does not require an account. Palim AI is not currently available for purchase, and this notice does not claim that a hosted Palim AI service is generally available.
2. Data Palim Processes & Why
Website and local preferences
The static site uses ordinary hosting and security request data, such as IP address, browser or device information, requested URL, and time of request. Language and theme choices are stored only in your browser's local storage. The site has no advertising pixels, behavioral analytics, checkout script, or third-party support widget.
Optional account and security
To create or sign in to a Palim account, you provide an email address. The email delivery provider receives that address to send a one-time code. Palim stores protected hashes of the normalized email, one-time-code and session records, device and session identifiers, account state, access permissions, and delivery outcomes. The code is valid for 10 minutes and an issued app session is valid for up to 30 days unless revoked earlier. Without an email you cannot sign in or use account-gated online services, but the local workbench remains available.
First-party telemetry
Beta builds send allowlisted operational events with coarse product, outcome, version, platform, locale, feature, flow, operation, model and service-configuration, bucketed performance, and error-fingerprint fields. Install and client-session identifiers are hashed before server storage. Only account-security events may carry the current Palim account and session link; other telemetry is not linked to the account. A feedback report you explicitly submit follows the separate support contract below. Telemetry rejects manuscript text, prompts, generated text, full paths, raw logs, credentials, cookies, email addresses, and third-party account identifiers.
Support and feedback
When you send feedback, Palim stores the summary, observed and expected behavior, reproduction steps, locale, optional low-content focus identifiers, app version and release channel, a hash used for abuse prevention, and—if you are signed in—an optional account link. Palim does not automatically upload a diagnostic archive or manuscript; a local diagnostics export remains under your control.
Downloads and updates
Official download and update services process the requested artifact, app version, update outcome, and ordinary network request data needed to deliver and protect those services. Update checks do not require manuscript text or project paths.
Depending on the law that applies, Palim processes this data to provide actions you request or take steps connected with the service; for legitimate interests such as security, abuse prevention, reliability, support, and product improvement where those interests are not overridden by your rights; with consent where a feature or law requires it; and to meet legal obligations. Where processing is based on consent, you may withdraw it for future processing.
3. Local Projects & Device Data
Manuscripts, project assets, sources, local databases, and preferences stay in local project or device storage under the desktop architecture. Developer-configured AI credentials stay in device-native credential storage and never in the Project Library. Creating an account does not create a cloud manuscript repository. You control local deletion, backup, synchronization, and any third-party backup tool you choose.
- No website manuscript upload: the public product site has no manuscript upload form.
- No hidden cloud sync: Palim does not silently turn local projects into remote copies. Any future Palim-hosted synchronization requires a separate product and privacy review.
4. AI Actions & Third-party Services
When you explicitly start an AI action, Palim sends only the instructions, selected text, bounded project context, and limited task metadata needed for that task. Palim AI may use approved marketplace routes and upstream services that process task content in other regions under varying privacy, training, retention, and security rules; Palim’s online service records do not store raw task content. A service you configure follows its own terms. Do not send confidential, personal, or unpublished material unless you have authority and accept the active service boundary.
Palim-controlled telemetry does not contain AI prompts or generated text. This telemetry boundary does not change what the active AI service itself receives for an AI task you start.
5. Service Providers, Disclosure & International Processing
Palim currently relies on Cloudflare for website delivery, bot protection, API hosting and Palim-controlled storage, and on Resend for account email. If the Palim AI Paid Beta opens, Alipay will process purchase authorization, payment, refund, invoice, and settlement data; Palim will retain only the customer, order, service-period, entitlement, Usage, and reconciliation records needed to operate the service and meet legal obligations. A user-selected AI provider remains a separate service.
- No sale or targeted advertising: Palim does not sell personal data and does not use it for cross-context behavioral advertising.
- Required disclosures: data may be disclosed when reasonably necessary to comply with law, protect users or the service, investigate abuse, or establish and defend legal claims.
- International processing: infrastructure and an AI provider you choose may process data outside your region. Applicable transfer safeguards and provider locations depend on the service and jurisdiction.
6. Retention
- Local projects: remain until you delete them or the storage location is removed.
- Telemetry: sanitized raw events are deleted after 30 days; non-identifying daily aggregate rollups are deleted after 400 days.
- Account and security records: are kept while needed to operate or secure the account, enforce access decisions, prevent abuse, and meet legal or dispute-resolution obligations. Expired codes and sessions cannot be used after their validity period.
- Support records: are kept while the issue is handled and afterward as reasonably needed for follow-up, security, abuse prevention, and legal obligations.
- Provider logs: ordinary hosting, email, and user-selected AI provider logs follow the relevant provider's retention terms.
7. Your Choices & Privacy Rights
- Optional telemetry: turn product-improvement and AI-quality events off in Support & updates. Essential operations, security, and reliability events remain active.
- Account control: sign out to revoke the local session. Account access, correction, export, objection, restriction, or deletion requests are handled through Palim Support.
- Local data: use your operating system and Palim's project tools to copy, export, back up, or delete local projects. A Palim account request does not erase local files on your device.
- No solely automated legal decisions: Palim does not use account, support, or telemetry data to make solely automated decisions that produce legal or similarly significant effects. Access controls may limit an online Beta service, but do not decide ownership of or erase local projects.
Send a request to contact@nyxevo.com from the account email when possible. Palim may need to verify control of the account and may retain limited security or legal records where permitted or required. Depending on applicable law, you may also have rights to access, correct, delete, restrict, object, withdraw consent, receive a portable copy, or complain to a data protection authority.
8. Security, Children, Changes & Contact
Palim minimizes remote data, uses encrypted network transport, stores one-time codes and session tokens as hashes on the server, restricts telemetry fields, and limits operator access. No security measure is perfect; keep local backups and protect your device, email account, and any AI credentials.
Palim accounts and network services are not directed to children who cannot lawfully consent to data processing in their jurisdiction. A parent or guardian who believes a child provided account or support data should contact us.
Material changes will update the effective date and, where appropriate, be highlighted in the app or website before they apply. For privacy questions, rights requests, or suspected privacy incidents, contact contact@nyxevo.com.