Effective date:

This Privacy Policy explains how Nobox Labs Limited ("we", "us", "our") collects, uses, and shares information when you visit or use AIGenius, our pay-as-you-go AI chat platform available at https://aigenius.chat, including the website, web console, API, and related services (collectively, the "Services").

1) Who we are

Data controller: Nobox Labs Limited. We operate AIGenius. When you use our Services, we act as the controller of your account and usage information. If you use our backend platform to store or process data on behalf of your end users, you are the controller of that data and we act as your processor. Our Data Processing Addendum (DPA) governs processor activities and is available on request.

2) Scope

This policy applies to personal data we collect about visitors, account holders, and users of AIGenius. It does not apply to content, records, or datasets you store in our backend platform on behalf of your end users ("Customer Data")—we process Customer Data solely per your instructions under the DPA.

3) Information we collect

We collect the following categories of information (as implemented in our Services):

  • Account information: email, first name, last name, profile image, gender; password hash (if you use email authentication); OAuth profile data from Google or GitHub.
  • Wallet and billing: credit balance (wallet), payment transaction records (reference, amount, currency, status, provider response) via Paystack.
  • Conversations and AI usage: chat messages, model identifiers, token usage, cost per request, custom personalities (name, description, prompt, icon).
  • Uploads: file names, sizes, MIME types, storage URLs, and metadata for files you upload.
  • Usage and logs: request identifiers, user IDs, project and record-space references, client details, request details (e.g. timings, URLs), IP address, and user agent where logged.
  • Local storage and similar tech: we use browser localStorage and sessionStorage for authentication tokens, user details, model preferences, and integration states. We may use cookies where required for session management. See "Cookies and local storage" below.
  • Integrations: data we receive from third-party services you connect (e.g. Google OAuth, Gmail, Paystack), governed by their policies.

4) AI and LLM processing

AIGenius routes your prompts and conversation content to third-party AI providers via OpenRouter. These providers (e.g. OpenAI, Anthropic, Google, DeepSeek, Qwen, Mistral, Meta, xAI, and others) process your messages to generate responses. Their privacy policies and terms apply to that processing. We retain conversation data in our systems for chat history and billing; we do not control how AI providers retain or use data. When you use optional integrations (e.g. Gmail), the AI may call external APIs on your behalf.

5) How we use information

  • Provide, operate, secure, and maintain the Services.
  • Authenticate users, prevent fraud and abuse, and enforce policies.
  • Process payments, manage your credit wallet, and deduct usage costs.
  • Monitor performance, fix issues, and improve features.
  • Communicate important updates, security notices, and support responses.
  • Comply with legal obligations and defend legal claims.
  • Create aggregated or de-identified insights that cannot reasonably identify you.

7) Cookies and local storage

We use browser localStorage and sessionStorage for authentication tokens, user details, and preferences. We may use cookies for session management. You can control cookies through your browser settings and clear localStorage/sessionStorage; doing so may log you out. If required by law, we will request consent for non-essential cookies.

8) How we share information

  • AI providers: prompts and conversation content are sent to OpenRouter and underlying providers (OpenAI, Anthropic, Google, etc.) to generate responses.
  • Payment provider: Paystack processes payment data; their policies apply.
  • OAuth providers: Google and GitHub handle sign-in; their policies apply.
  • Storage: AWS S3 or Cloudinary may store uploaded files; their policies apply.
  • Service providers/subprocessors: bound by confidentiality and security obligations.
  • Legal and safety: to comply with law, protect rights, safety, and prevent fraud/abuse.
  • Business transfers: in relation to a merger, acquisition, or asset sale.
  • We do not sell personal information.

9) International transfers

We may transfer personal data to countries other than your own. Where required, we use appropriate safeguards such as Standard Contractual Clauses and technical or organizational measures.

10) Security

We implement administrative, technical, and physical measures to protect personal data. No system is 100% secure. You share responsibility for securing your account, API keys, and data (e.g. access controls, backups).

11) Data retention

We retain personal data for as long as necessary to provide the Services and comply with legal obligations. Logs and backups are kept for limited periods. You can request deletion of your account data; Customer Data retention is controlled by you as the controller.

12) Your rights

Subject to applicable law, you may have rights to:

  • Access, correct, or delete your personal data.
  • Object to or restrict processing, or request portability.
  • Withdraw consent where processing is based on consent.
  • Lodge a complaint with your local data protection authority.

Contact us to exercise these rights.

13) Children

The Services are not directed to children under 13 (or the age of digital consent in your jurisdiction). We do not knowingly collect personal data from such children.

14) Customer Data and DPA

For Customer Data you store or process via our backend platform, you are the controller and we are your processor. We process Customer Data only per your instructions and our DPA. For a copy of our DPA, contact us.

15) Changes to this policy

We may update this policy from time to time. We will post the updated version here and revise the "Effective date" above. Material changes will be communicated through the Service.

16) Contact

Nobox Labs Limited

Website: https://aigenius.chat

Email: nobox.hq@gmail.com