Privacy Policy
Last updated: September 5, 2026
Information processed
Nisaea stores account information through Supabase Auth, including email and age settings, and the aquarium records you provide: readings, maintenance and dosing history, livestock, equipment, photographs, and camera snapshots. Linked agents send hardware and connectivity information. Conversations, saved assistant memories, feedback, and incident notes may also be stored according to your choices.
AI and voice providers
Relevant aquarium records, images, conversation history, and preferences may pass through Vercel AI Gateway to OpenAI or Google. Direct provider connections and configured fallbacks may also be used. Changing your local conversation-retention choice does not change these processors' retention or data-use policies. The application cannot verify those account-specific settings.
Natural spoken replies are off until you consent in Settings. Consenting sends reply text to Cartesia to produce audio. Microphone transcription requires separate consent and device permission; recordings of up to 30 seconds may pass through Vercel to Google Gemini, with direct Google or OpenAI fallbacks. Recordings are processed in the transcription request and are not saved as application audio files. Live conversational voice is unavailable; accepting an invitation does not start a session.
Storage, payments, and sharing
Supabase stores application records and media. Access rules distinguish owners and authorized collaborators. Stripe handles checkout, subscriptions, customer information, and payment records. Collaborators may access information shared within their organization or aquarium. App recovery points contain selected aquarium records and are deleted with an erased owned aquarium; separate infrastructure backups follow the operator's and provider's policies.
Conversation and image retention
The default conversation policy is 90 days, including accounts that have never saved a preference. Settings also offers 30 days, one year, retention until account deletion, or no new saved conversations. These choices cover main chat, saved assistant memories, Observer conversation messages, feedback, and conversation-derived incident notes. Cleanup runs periodically; a delayed or failed cleanup is recorded for operator follow-up. Essential aquarium observations and operational team records follow their own retention.
Routine, unlinked camera snapshots are eligible for cleanup after 30 days. Coral-linked images, saved baselines, pinned images, and warning or critical evidence may be retained longer within the aquarium's storage allowance. Deleting an owned aquarium through account erasure removes its stored files before its records.
Account export and deletion
Settings provides a paged export of account records, owned aquarium history, conversations, and time-limited download links for stored files. Passwords, tokens, and other credentials are redacted. Pages reflect the records when each page is read. Shared aquariums owned by someone else are excluded.
Export and permanent deletion require a recent sign-in. Deletion must be explicitly confirmed; it ends active subscriptions, disables linked agents, forfeits unused voice credits, and queues removal of files, application records, and sign-in access. It does not itself issue a refund. Transfer ownership of shared aquariums or organizations first. Collaborators' aquariums are preserved, and shared operational records may remain with your author link removed. Keep the deletion receipt to check progress after sign-in is removed. Failed steps remain visible and retry; completion is reported only after the required steps succeed.
Limited payment ledger records are archived for seven years by the default business retention setting, configurable by the operator after legal and accounting review. This is a product policy, not a claim that every jurisdiction requires seven years. Minimal erasure markers remain to prevent account or aquarium restoration. Infrastructure backups and independent processor records are not verified as erased by the application's completion status.
Age settings and review
Age restrictions apply to assistant responses. A self-disclosure of being under 18 locks the account into the restricted response mode. Settings can queue a support review of an incorrect age setting; a request does not automatically remove the restriction. Minimal age-policy event records are retained for 90 days or until account erasure; raw spoken disclosures are not copied into that event log. The service is not directed at children under 13. The operator must review its age, notice, consent, and response obligations before launch.
Cookies and contact
The application uses authentication cookies and browser storage for preferences. Optional email preferences do not control payment-provider receipts or security notices. Contact Support@Nisaea.com about privacy or a failed request and include the request ID rather than your private receipt code.