Legal
Privacy Policy
Last Updated: July 2026
1. Definitions
To ensure clarity across our multi-platform and multi-vertical services, the following terms are used throughout this policy:
Source Identifiers
The repositories and development tools that you explicitly connect to Ninchi. The current Service does not connect to Learning Management Systems or cloud document workspaces.
Source Data
Repository context processed by Ninchi, plus plain-text or code excerpts that an authorized user manually submits for a challenge. Native PDF, DOCX, LMS, and cloud-document ingestion are not part of the current Service.
Service
The collective set of tools, analytics, and platform integrations provided by Ninchi.
2. Information We Collect
Account & Usage Data: Email address, organization, project and Source Identifiers (see Definitions), and usage metrics.
User Interaction Data: Questions generated by Ninchi, user responses to those questions, and evaluation results.
Metadata: Programming language/file type, question type and difficulty, and general classification of content changes.
3. What We Do NOT Store
Repository source context is processed transiently to generate analysis and is not retained as a full repository snapshot. Manually submitted challenge text may be retained with the challenge record.
Excluded Items:
4. How We Use Data
- Provide and operate the Service.
- Generate questions and evaluate responses.
- Record demonstrated understanding and analyze organizational knowledge distribution via the Ninchi Score and Knowledge Map.
- Improve product quality and performance.
- Generate aggregated, anonymized insights for platform optimization.
5. Data Sharing
Strict Guarantees: We do not sell data, share your data across organizations, or use your data to train external models.
Compliance & Security: We utilize third-party security and compliance platforms (e.g., Vanta, Drata) for the purpose of maintaining our SOC 2 readiness. Data shared with these platforms is restricted to audit logs and compliance metadata required to verify our internal controls.
6. Data Retention
We retain interaction data and metadata necessary to operate the Service. Repository context is processed transiently; manually submitted challenge text may be retained as part of the challenge record. The current Service does not ingest native documents from an LMS or document workspace.
7. Security
Safeguards Implemented: Encryption in transit (TLS) and at rest, secure cloud infrastructure (AWS), strict access controls, and private networking.
More Information: See our Data Handling & Security page for a full breakdown.
8. Third-Party Services
Providers:
- Platform Integrations: GitHub, GitLab, Bitbucket Cloud, and IDE-based MCP servers.
- Billing: Stripe.
- Analytics (opt-in): PostHog (US-hosted). Receives usage events with opaque identifiers only — never source code, diffs, challenge answers, or email addresses — and only after you accept optional cookies.
- Advertising & Analytics (opt-in): Rewardful (affiliate attribution) and the Google tag — Google Ads conversion measurement and, where enabled, Google Analytics. Rewardful loads only after you accept optional cookies; the Google tag runs without cookies unless you accept.
- Compliance/Security Partners: Vanta, Drata.
Note: These services operate under their own privacy policies.
9. Cookies & Consent
Essential cookies keep you signed in and protect against request forgery (session and CSRF cookies), and remember your consent choice. They are always on.
Optional cookies — analytics (PostHog, Google Analytics) and affiliate attribution (Rewardful) — are used only after you choose “Accept” in the consent banner. If you reject, no analytics or affiliate cookies are set. Your choice is stored for 12 months.
You can change your mind at any time: . Withdrawing stops analytics collection and clears the identifiers those cookies stored.
10. Your Rights
- Request deletion of your data.
- Disconnect source integrations at any time.
- Stop using the Service at any time.
11. Changes
We may update this policy periodically.
Continued use of the Service indicates acceptance of the updated policy.
12. Contact
For privacy-related inquiries, contact us at privacy@ninchi.ai.