Privacy Policy
Effective date: April 23, 2026
This Policy describes how E-Stoic, LLC ("NYLOS") collects, uses, shares, and protects your personal data when you use the service available at nylos.io. By using NYLOS you accept the practices described here.
1. Information we collect
1.1 Information you give us directly
- Account data: email, name, password (managed through our authentication provider). If you sign in with OAuth, we receive basic information from the directory provider (e.g., name, email, avatar).
- Billing data: processed entirely by the external payment processor. We only receive a customer identifier and the status of payments.
- Brand content: company name, colors, fonts, logos, descriptions, and brand DNA that you upload to customize generation.
- Uploads: product images, visual references, photos of people, moodboards, and other files you upload as input to generate content.
- Prompts and configuration: the text of the prompts, psychological angles, frameworks, audiences, and other generation parameters.
1.2 Information collected automatically
- Usage data: which features you use, which generations you run, how many credits you consume, response times, errors.
- Technical data: IP address, browser type, operating system, timezone, referrer URL.
- Cookies and similar technologies: used for session authentication, UI preferences, and analytics. See section 7.
1.3 Information generated by the service
- AI outputs: images, text, variations, edits, and other generated results. They are stored associated with your account.
- Metadata: the batch each generation belongs to, angle used, concept, framework, timestamps.
2. How we use your information
- Provide, operate, and maintain the service.
- Process payments and manage credits.
- Authenticate your identity and prevent fraud.
- Communicate with you (updates, support, changes to the Terms).
- Improve the service through aggregated and anonymized analytics.
- Comply with legal obligations and respond to requests from authorities.
- Investigate and prevent abuse or violations of the Acceptable Use Policy.
We do not sell your personal data to third parties. We do not use your individual content to train AI models, whether our own or third-party.
3. Service providers (sub-processors)
To operate NYLOS we work with third-party service providers with whom we share the data strictly necessary for the functions they perform. Categories of providers we currently use:
- Authentication and account management — registration, login, session management.
- Payment processing — charges, invoicing, subscription management. We do not store card data on our servers.
- Artificial intelligence models — generation of images, text, edits, variations, and creative content. Includes language-model providers and generative image models.
- Image processing and upscaling — resolution enhancement, background removal, and post-processing.
- Social media publishing — when you choose to publish or schedule content on external platforms.
- Cloud infrastructure and hosting — servers, databases, file storage.
- Analytics and error monitoring — to detect and resolve technical issues.
- Transactional email — account notifications, receipts, alerts.
Each provider operates under its own privacy policies and data processing agreements. We select providers with appropriate security standards and that, when they offer enterprise APIs, do not use customer data to train their own models by default.
Full list upon request: you may request the specific, up-to-date list of sub-processors (including names and purposes) by writing to legal@nylos.io. We respond within 30 days.
4. International transfers
NYLOS is operated from the United States and its sub-processors have infrastructure in multiple countries (U.S., EU, Asia). By using the service you consent to the transfer of your data to these jurisdictions, subject to appropriate safeguards (standard contractual clauses, certifications, etc.) when required by law.
5. Data retention
- Active account: we retain your data while your account is active.
- Closed account: after you cancel your account, we retain the data for 30 days to allow recovery in case of error. They are then permanently deleted.
- Billing and transaction data: we may retain them for up to 7 years to comply with tax and accounting obligations.
- Backups: backups may contain data for up to 60 additional days before being overwritten.
6. Your rights
6.1 General rights
You may exercise the following rights at any time by writing to legal@nylos.io:
- Access: obtain a copy of your personal data.
- Rectification: correct inaccurate data.
- Deletion: request that we delete your data (subject to legal retention obligations).
- Portability: receive your data in a structured, machine-readable format.
- Objection and restriction: object to certain processing or request that we limit it.
- Withdraw consent: when processing is based on your consent.
We respond to requests within 30 days.
6.2 California residents (CCPA/CPRA)
If you are a California resident, you have additional rights: to know what personal information we collect, to delete your information, and to opt out of "sales" and "sharing" of data. NYLOS does not sell or share personal data within the meaning of the CCPA.
6.3 Residents of the European Economic Area (GDPR)
If you reside in the EU, the United Kingdom, or Switzerland, you have rights under the GDPR including those listed in 6.1. You have the right to lodge a complaint with your local data protection authority. The legal basis for processing is: (a) performance of a contract to provide the service, (b) consent for marketing, (c) legitimate interest for security and improvement of the service.
7. Cookies and similar technologies
NYLOS uses cookies for:
- Essential: session authentication and UI preferences. They cannot be disabled without affecting functionality.
- Analytics: understand aggregated use of the service (anonymized).
We do not use third-party advertising cookies or cross-site trackers. You may manage cookies from your browser.
8. Minors
NYLOS is a service for persons 18 years of age or older. We do not knowingly collect data from persons under 18. If we detect an account belonging to a minor, we will close it and delete the associated data. If you are a parent or guardian and believe a minor created an account, contact us at legal@nylos.io.
9. Security
We implement reasonable technical and organizational measures to protect your data: TLS encryption in transit, access controls, multi-factor authentication for administration, environment isolation (production separated from staging), and periodic backups. However, no system is 100% secure. In the event of a breach affecting your personal data, we will notify you as required by applicable law.
10. Changes to this Policy
We may update this Policy from time to time. Material changes will be notified at least 15 days in advance. The effective date above indicates the last update.
11. Contact
Questions about privacy or to exercise rights: legal@nylos.io
E-Stoic, LLC · Delaware, USA