← Back

Privacy Policy

Effective: August 2, 2026

1. Who We Are

NavOrb is operated by Knight AI AV ("we", "us", "our"), a company building autonomous AI agent technology. Contact: Build@KnightAIAV.com. Website: KnightAIAV.com.

2. What We Collect

  • Account data — email address and authentication records managed by Firebase Authentication. We do not store passwords in plain text.
  • Conversation data — messages you send and receive within NavOrb. Used to maintain conversation history and train the orb's memory for you.
  • Files and generated artifacts — files you upload, files your agent creates, content metadata, malware-scan results, checksums, and generation-bound storage receipts. New uploads remain inaccessible in private quarantine until automated validation and malware scanning succeed.
  • External bot bridge data — bot names, token metadata, scopes, rate limits, request timestamps, and messages sent through connected bots. Raw bridge tokens are shown once and stored only as hashes.
  • Voice data — standard voice input is streamed to Deepgram for transcription and voice output is generated by Fish Audio. A deployment may separately enable OpenAI Live Voice using a short-lived client credential; that lane is unavailable when no approved realtime credential is configured. We do not store raw microphone audio files. Transcripts may be stored as conversation messages.
  • Orb configuration — personality settings (soul.md), appearance, physics, scheduled tasks, and skills. Stored in your user profile.
  • API keys (legacy) — NavOrb no longer collects user API keys. Any keys provided before June 2026 remain stored encrypted server-side, are never returned to the browser, and are deleted with your account.
  • Payment data — processed by Stripe, Apple, Google, or RevenueCat depending on where you subscribe. We never see or store full card numbers. We store customer IDs, receipt identifiers, and subscription status.
  • Usage analytics — page views, feature usage, and session data via PostHog. No personally identifiable information is sent to analytics.
  • Device info — browser type, OS, screen resolution for rendering optimization. Stored in the devices table if you enable push notifications.
  • Long-term memory — facts the AI learns about you during conversations (preferences, goals, relationships) are stored as semantic embeddings for future recall. You can view and delete these in Settings.

3. How We Use Your Data

  • To operate the Service — routing messages to AI providers, maintaining conversation history, personalizing the orb.
  • To operate connected bots — authenticate bridge tokens, enforce plan limits, route bot messages, and let you revoke or rotate access.
  • To process payments and manage subscriptions.
  • To improve the Service — aggregate, anonymized analytics. We never sell your data or use individual conversations for training third-party models.
  • To prevent abuse — content moderation on external bridge inputs.
  • To communicate with you — account confirmations, billing receipts, critical service updates. No marketing emails unless you opt in.

4. Third-Party Processors

Your data is processed by these services on our behalf:
  • Google Firebase and Google Cloud — authentication, web hosting, application compute, PostgreSQL database hosting, and private object storage (US)
  • OpenAI — real-time speech processing only in deployments where Live Voice is explicitly enabled.
  • OpenRouter — AI model routing (US). Your messages are sent to the AI model you select. Refer to OpenRouter's privacy policy for their data retention practices.
  • Deepgram — speech-to-text transcription. Audio is processed in real-time and not stored by Deepgram after transcription.
  • Fish Audio — text-to-speech generation if you enable voice output.
  • Stripe — payment processing (US/EU). PCI-DSS Level 1 compliant.
  • Apple, Google, RevenueCat — mobile in-app purchase receipts, subscription status, and entitlement sync when mobile billing is used.
  • Google Workspace — transactional email delivery.
  • Google Cloud SQL — privacy-preserving request counters used for rate limiting.
  • PostHog — product analytics. Anonymized event data only.

5. Data Retention

  • Conversations — retained until you delete them or close your account.
  • Memory — semantic memories persist until you delete them in Settings or close your account.
  • Skills — retained until you delete them or close your account.
  • Uploaded files and generated artifacts — retained until you delete them, the applicable product lifecycle expires, or you close your account. Clean-file buckets use a seven-day soft-delete recovery window, during which deleted bytes are inaccessible to you but can remain recoverable by restricted storage administrators.
  • Quarantined uploads — inaccessible uploads that have not completed scanning are hard-deleted after two days. Quarantine does not use soft-delete retention.
  • Data export archives — available for up to seven days and then hard-deleted. Export storage does not use soft-delete retention.
  • Bridge tokens — token hashes and metadata are retained until you revoke them or close your account. Raw tokens are not retained.
  • Account data — retained for 30 days after account closure, then permanently deleted.
  • Billing records — retained for 7 years as required by tax law.
  • Audit logs — retained for 90 days for security investigation.

6. Your Rights

Depending on your jurisdiction, you may have the right to:
  • Access — request a copy of all data we hold about you.
  • Correction — update inaccurate data.
  • Deletion — request deletion of your account and associated data. Access is revoked when deletion begins; clean-file bytes can remain in restricted soft-delete recovery storage for up to seven days, and legally required billing records are retained as described above.
  • Portability — receive your data in a machine-readable format.
  • Objection — opt out of analytics tracking.

To exercise any of these rights, email Build@KnightAIAV.com. We respond within 30 days.

7. Cookies

We use essential cookies only:
  • Authentication — secure Firebase session cookie (__session). Required for sign-in.
  • Analytics — PostHog cookie. Can be blocked without affecting functionality.

We do not use advertising cookies or trackers.

8. Security

We protect your data with:
  • HTTPS (TLS 1.3) on all connections
  • Row-Level Security (RLS) on every tenant table and generation-bound ownership checks for stored objects
  • Private Cloud Storage with uniform bucket-level access, public-access prevention, customer-managed encryption keys, short-lived signed downloads, and malware quarantine
  • API keys stored encrypted server-side, never returned to the browser
  • Bridge tokens stored as SHA-256 hashes — raw token shown once at creation
  • Plan-level bot limits, per-token rate limits, and content moderation on bridge traffic
  • Rate limiting on all API endpoints
  • Content moderation on external bridge inputs

If you discover a security vulnerability, report it to Build@KnightAIAV.com. We do not pursue legal action against good-faith security researchers.

9. Children

NavOrb is not intended for children under 13 (or under 16 in the EU). We do not knowingly collect data from children. If you believe a child has created an account, contact us and we will delete it immediately.

10. International Transfers

Your data is processed in the United States. By using NavOrb, you consent to the transfer of your data to the US. We rely on the standard contractual clauses and transfer safeguards offered by Google Cloud and our other disclosed subprocessors for EU/UK data transfers.

11. Changes

We may update this policy. Material changes will be announced in-app and via email. Continued use after changes constitutes acceptance.

12. Contact

Knight AI AV
Email: Build@KnightAIAV.com
Web: KnightAIAV.com

See also: Terms of Service · Acceptable Use Policy