Privacy Policy
Effective 18 August 2026 · NiuwnAI
NiuwnAI lets one person build one Digital AI Twin — a conversational AI that answers questions in their own voice — and share it through a link. Two very different people meet that Twin: the owner who builds it, and the visitor who chats with it. This policy is split that way, because what we store is different for each.
There are no advertising or analytics trackers anywhere in the product. No Google Analytics, no pixels, no ad networks. What follows is the whole list of what we actually keep.
Who we are
NiuwnAI operates the website at www.niuwn.com and the product at app.niuwn.com. We decide what is collected and why, which under European data protection law makes us the controller of the data described here.
For anything in this policy — a question, a correction, an export, a deletion — write to support@niuwn.com. A person reads it.
If you chat with a Twin
You do not need an account to chat with someone’s Twin. Before your first message you are asked one question: may this conversation be recorded? You can decline and still chat. The Twin answers you exactly the same way either way.
Stored whatever you choose
- A session record: when the conversation started, the language you wrote in, and — if you allowed recording — how many messages were exchanged. That record carries no name, no email address, no IP address and no device or browser identifier.
- A short-lived session token that identifies your conversation while it is open. It is not stored on your device — closing or reloading the page ends the conversation and starts a new one. On our side the session expires about two hours after your last message.
Stored only if you allow recording
The transcript — your messages and the Twin’s replies — saved and visible to the Twin’s owner. If you decline, no transcript is kept.
Questions the Twin could not answer
When the Twin cannot answer a question well, we note that a knowledge gap exists, so its owner can teach the Twin the missing answer. If you allowed recording, the text of your question is kept and shown to them. If you declined, the text is not kept — the owner is told only that an unanswered question happened, never what it said. No identity is attached either way: an owner who sees a question does not see who asked it.
Processing is not recording
Either way, your messages are sent to OpenAI to generate the reply. That is processing — it is what makes an answer possible at all. It is not the same as recording. Declining recording means we do not keep the transcript; it does not stop the Twin from answering you.
Our demo Twin
Wherever we embed a demo Twin on our own pages — this website or app.niuwn.com — it always runs in no-recording mode, so demo transcripts are never stored. The session record and the unanswered-question behaviour described above still apply.
If you own a Twin
Your account
Your email address, your name, and either a hashed password or a Google sign-in identifier. If you sign in with Google we receive and store only your email address, your name and the account identifier — no profile photo, and no Google access tokens.
What you teach your Twin
Everything you give the Curator: your answers in the teaching interviews, CVs you upload, web pages you ask it to read, and your profile photo. It is stored as markdown files — those files are the source of truth — plus a derived search index holding excerpts of that text and their embeddings, the numerical representations that make search work.
An uploaded CV file is deleted right after its text is extracted. We keep the extracted text and the original filename, not the document.
Your conversations with the Curator
Teaching conversations are stored so a session can pick up where you left it.
Emails we send you
Two, both transactional: a verification email when you sign up, and a welcome email. They are sent through Resend from noreply@niuwn.com. There are no marketing emails.
Cookies and tracking
Cookies are essential-only. Signing in as an owner sets a signed session cookie that browser scripts cannot read (httpOnly), a simple flag recording that you are signed in, and short-lived cookies that carry the sign-in handshake.
A visitor chatting with a Twin gets no tracking cookies at all, because there is no tracking to carry.
Who else handles your data
Running the service takes a small number of providers. They process data on our instructions, for the purposes below and nothing else.
- OpenAI (United States) — generates Twin and Curator replies and the embeddings behind search. Chat messages and knowledge text are sent to it for processing.
- Neon — the managed PostgreSQL database holding accounts, sessions, transcripts and gap questions. Hosted in Frankfurt, EU.
- Zilliz Cloud — the managed vector database behind Twin search, holding text excerpts and their embeddings. Frankfurt, EU.
- Tavily (United States) — web search, used only while an owner is teaching their Twin, never during a visitor conversation. It receives the search query the Curator writes and nothing else — no conversation transcript, no account or visitor identifier.
- Hetzner — server hosting, in the EU.
- Cloudflare — the network and security layer in front of the app, so all traffic passes through it; and the store for our off-site backups — knowledge bases and photos — encrypted at rest by the provider.
- Vercel — hosts this marketing website only.
- Resend — sends the two transactional emails.
- Google — only if you choose to sign in with Google.
- Sentry — error monitoring, configured so that no message content, request bodies, cookies or IP addresses are recorded in error reports.
Our servers also keep standard access logs — IP address, browser type, the request made — as every web server does. We use them to keep the service running and to investigate abuse.
How long we keep things
- Recorded conversations and stored gap questions are kept for as long as the owner’s Twin exists. There is no automatic expiry.
- Aggregate per-day statistics — how many visitors, how many messages, what share allowed recording — are kept with no visitor identifiers attached to them.
- A visitor session token expires about two hours after the last message.
- Off-site backup copies, encrypted at rest by the provider, are kept for 30 days.
Erasure on request, described below, removes your live data. Backup copies are not individually edited; they age out on their own within 30 days.
Your rights and choices
If you own a Twin
- You can edit or delete any individual piece of your Twin’s knowledge in the app, at any time.
- Deleting your account in the app takes your Twin offline, signs you out everywhere and disables password sign-in. If you use Google sign-in, write to us to close the account fully. Full erasure — the account, the knowledge base, the search index entries, the visitor conversations and your teaching conversations — is completed on request to support@niuwn.com. We state it that way because the in-app delete is not by itself the whole erasure.
- A machine-readable export of your account data, your Twin’s configuration and your full knowledge base is available on request to support@niuwn.com. There is no self-serve export button yet.
If you chatted with a Twin
If you allowed recording and want that conversation deleted, ask the Twin’s owner, or write to support@niuwn.com. There is no automated flow for this yet; a person handles it.
If you are in the EU or EEA
The GDPR gives you the right to access your data, to have it corrected, to have it erased, to receive a portable copy, and to object to how it is processed. Exercise any of them by writing to support@niuwn.com. You also have the right to complain to your local data protection supervisory authority.
Changes to this policy
This policy will change as the product does. If a change is material, we will say so on this page and update the effective date at the top.
Contact
Privacy questions, data requests and complaints all go to the same address: support@niuwn.com.
The rules for using the service are in our Terms of Service.