Your context stays under your control.
This product-level notice explains the privacy design implemented in NYRA. It is not a substitute for jurisdiction-specific legal notices AYS Innovations may publish before commercial launch.
Account and private content
NYRA uses Supabase Authentication for account sessions. Profiles, conversations, messages, memories, My Circle records, Canvas documents, speaking reports, generated images, files, and usage records are stored in the connected Supabase project.
- Private user tables use Row Level Security based on the authenticated user ID.
- Private files use non-public Storage buckets and time-limited signed URLs.
- Collaboration content is available only to active room members and administrators acting through backend-verified roles.
External AI processing
AI inference is separate from Lovable AI. NYRA's frontend calls protected Supabase Edge Functions, which validate authentication, plan limits, tools, and context before contacting the configured external provider.
Provider API keys are not stored in the browser, database tables, migrations, logs, or client environment variables. AI responses and usage metadata may be saved to Supabase for authenticated users; guest chat is not persisted by NYRA.
Memory and My Circle
You can review, add, and archive confirmed memories. My Circle contains only people and context you choose to add. NYRA retrieves relevant confirmed context for appropriate modes rather than attaching every memory to every request.
Retention and deletion
Conversation expiry is set when a chat is created and capped by plan rules. Scheduled backend cleanup removes expired conversation records and identifies abandoned uploads. Account-level export and deletion operations may require additional launch configuration and identity verification.
Security and access
Administrative access is checked against a backend role, not an email comparison or browser flag. Service-role credentials are restricted to protected backend functions. AYS Innovations should be contacted through its published support channel if you believe an account or record was accessed incorrectly.