Legal

Privacy policy

Nivult data platform — for account holders and visitors of this site · last updated 4 October 2026

1. Who we are

This policy covers the Nivult data platform (the API, the portal and this site) operated by Nivult. Contact for everything below: [email protected]. Note: the Nivult job-alert service for candidates is a separate product with its own policy, on its own site.

2. What we collect

  • Account: your work email, and — if you sign in with Google, Microsoft or GitHub — the basic profile those providers hand us (name, email, avatar URL). No passwords: sign-in is by one-time link or OAuth.
  • Usage: API calls with your key (endpoint, time, credits consumed), portal actions (searches, reveals, exports), and the IP address for rate limiting and abuse prevention.
  • Billing: handled by our billing provider (Creem). We never see your card; we receive the payment status and the amount.
  • Cookies: one session cookie for the portal. No tracking, no advertising cookies, no third-party analytics on this site.

3. What we do with it

Run your account (keys, credits, downloads), bill you, keep the platform honest (rate limits, abuse detection), and answer you when you write. We do not sell or share your data with advertisers. We do not train models on your queries.

4. Where it lives

On servers hosted by Hetzner in the EU. Billing is processed by Creem; OAuth sign-in involves Google, Microsoft or GitHub only if you choose them. Each processor handles your data under its own terms and applicable data-protection law.

5. How long we keep it

Account and usage data live while the account does. When you close the account, they are deleted within 30 days; billing records persist as long as tax law requires. Our own job-postings index contains content published by employers on their public career pages, kept with the closure history that is the product.

6. Your rights

You can access, correct, export and delete your account data — write to [email protected] and we answer within a few days. If you are in the EU/UK you also have the right to lodge a complaint with your data protection authority.

7. Employers and recruiters in the index

A minority of postings includes a business contact (name, work email) as published by the employer. If that is you and you want the record corrected or removed, write to us: we act on verifiable requests. Customers receiving those fields through the API process them under their own legal basis — see the terms, section 6.

8. Changes

This policy evolves with the platform; material changes are announced by email to account holders before they apply. The date on top always says when it was last touched.