Nevermore Technologies
Privacy Policy
Last updated: August 2, 2026
This policy explains what information Nevermore handles and the controls that apply to the AI-Agent and MCP services.
1. Scope
This Privacy Policy explains how Nevermore Technologies handles information in connection with the Nevermore AI-Agent application, authenticated APIs, and MCP interface (the “Services”). It does not replace a separate privacy notice or data-processing agreement that expressly applies to a particular service or organization.
2. Information we receive
Account and identity information may include your name, email address, profile information, provider account identifier, sign-in events, session data, and consent or authorization records. We receive only the information made available by the identity provider and the permissions used for the sign-in flow.
Service information may include client and OAuth metadata, requested scopes, effective product and client profiles, project and target-root bindings, MCP requests, tool inputs and outputs where needed for the operation or receipt, policy decisions, execution results, and timestamps.
Technical information may include IP address, browser or device details, request identifiers, error data, security events, and service logs. We may receive content that you intentionally submit to an approved capability or connected data source.
3. How we use information
We use information to authenticate users, issue and validate delegated access, bind requests to approved projects and resources, provide the Services, execute authorized capabilities, maintain receipts and audit evidence, prevent abuse, troubleshoot failures, improve reliability, comply with law, and communicate about the Services.
Automated or AI-assisted processing may be used to interpret requests or produce results. The effective profile, scopes, policy, and approval controls remain the authority for what a request may access or do.
4. How we share information
We may share information with service providers that host, secure, operate, monitor, or support the Services; with connected providers or data sources when you authorize a capability; with professional advisers; and when required to comply with law, protect rights or safety, investigate abuse, or support a corporate transaction.
We do not sell personal information. We do not disclose information to a model or other provider unless that processing is needed for an enabled Service capability, permitted by the applicable agreement, or directed by you.
5. Retention and deletion
We retain information for as long as needed for the purposes described in this Policy, to provide the Services, meet contractual and legal obligations, resolve disputes, maintain security and receipts, and enforce agreements. Retention is governed by Nevermore’s applicable retention policy and service-specific agreements; different data classes may have different retention periods.
You may request deletion or access through the support or contact channel provided by Nevermore Technologies for your account or service agreement. Some information may be retained where required by law, needed for security or fraud prevention, or preserved in immutable business or audit records.
6. Security
We use safeguards designed to protect information, including authentication controls, scoped capability admission, project and resource binding, encryption in transit where supported, access controls, logging, and security review. You are responsible for protecting your credentials and for reviewing results before relying on them.
No method of transmission or storage is completely secure. If you believe your account or data has been compromised, contact Nevermore through the support or security channel provided for your account or service agreement.
7. Rights and choices
Depending on where you live, you may have rights to request access, correction, deletion, portability, restriction, or objection, and to withdraw consent where processing is based on consent. We will handle verified requests as required by applicable law and may need information to verify identity and authority.
You may stop using a connected provider, revoke authorization where supported, or ask your account administrator to remove access. Revocation may not erase records that must be retained for security, legal, or audit purposes.
8. Children and international processing
The Services are not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child provided information, contact us through the applicable support channel.
Nevermore and its service providers may process information in countries other than where you live. Where required, we use appropriate contractual or other lawful transfer safeguards.
9. Changes and contact
We may update this Policy as the Services or legal requirements change. We will post the updated version and change the “Last updated” date. Material changes will be communicated through the Services or another reasonable channel when required.
For privacy, legal, or security requests, use the support or contact channel provided by Nevermore Technologies for your account or service agreement.