Privacy Policy
Last updated: May 8, 2026 · Effective: May 8, 2026
NyxPixie is an AI-powered email triage and end-of-day digest service operated by CNG Studios LLC, a Florida limited liability company (“Company,” “we,” “our,” or “us”). NyxPixie is part of the My Pixie Suite family of products operated by CNG Studios LLC.
Umbrella relationship. This NyxPixie Privacy Policy is a product-specific supplement to CNG Studios LLC’s overall My Pixie Suite Privacy Policy and the broader Terms of Service, Data Processing Agreement, Cookie Policy, Acceptable Use Policy, DMCA Policy, and Refund Policy.
It addresses NyxPixie-specific data flows — in particular our read-only IMAP access to your inbox using an App Password you control, and our optional read-only Google Calendar API integration — and adds product-specific retention and security details. Where this NyxPixie policy is silent, the parent My Pixie Suite Privacy Policy applies. Where a conflict arises, this product-specific policy controls solely with respect to NyxPixie.
This policy explains how we collect, use, disclose, and safeguard your information when you use NyxPixie at nyxpixie.com, app.nyxpixie.com, or related services (collectively, the “Service”).
The short version: NyxPixie reads your inbox via IMAP (using an App Password you generate and can revoke at any moment) and, optionally, your Google Calendar (read-only OAuth, only to detect scheduling conflicts). It classifies your inbox using AI on our own self-hosted servers and sends you a daily digest of what mattered. We never share your data with third-party AI services, never sell it, never use it for advertising, and never use it to train models. You can disconnect or delete everything at any time.
1. Information We Collect
Account Information: When your account is provisioned, we collect your name and email address. If you authenticate via a magic link, we do not require a password. If you sign in via Google OAuth, we receive your name, email address, and Google profile picture from Google.
Inbox Data (IMAP, with an App Password you control): When you connect your inbox, you generate an App Password on your email provider (Gmail App Passwords, iCloud App-Specific Passwords, or equivalent) and provide it to NyxPixie. We do not use Gmail OAuth or any restricted Google scope — the App Password is your credential, scoped to mail access only, and you can revoke it at any time directly with your email provider without notifying us. The App Password is encrypted at rest with AES-256-GCM and used only to fetch messages over standard IMAP (TLS) for classification. Specifically, we read:
- Email headers (from, to, subject, date, snippet)
- Email body text (decoded from HTML when needed) up to ~3,000 characters per message
- Selected technical headers used for spam/phishing detection (List-Unsubscribe, Reply-To, Return-Path, Authentication-Results)
We use this data to classify each email (urgent, financial, reply-owed, calendar, security, suspicious, order, subscription, promo, can-wait, broken-unsubscribe), extract structured event data (appointments, ticket sales, subscription renewals, deadlines), and generate a one-sentence summary which together power the daily digest. We never send, reply to, delete, or forward email. Two operations write back to your mailbox in clearly user-initiated contexts only: (a) when our classifier categorizes a message we add a Nyx/<Category> Gmail label so it’s easy to find later, and (b) when you click “This IS spam” or “Confirm phishing” we move that single message to your Spam folder so your provider’s filter learns. No other write operations occur.
Google Calendar Data (OAuth, optional, read-only): If you choose to connect Google Calendar via the “Connect Google Calendar” button on your dashboard, we request the calendar.readonly and calendar.events.readonly scopes (sensitive scopes, free verification path). These let us read your busy intervals from the next 60 days across your visible calendars, which we use solely to flag scheduling conflicts when extracting events from your inbox (for example: “BaptistHealth visit on May 15 at 2 PM conflicts with an existing meeting”). We never modify, create, delete, or share calendar events. Connection is opt-in and you can disconnect at any time from the dashboard or by revoking access at myaccount.google.com/permissions; on disconnect we delete the OAuth tokens and the cached busy-interval list immediately. We do not request or use any Gmail OAuth scope.
Classification Data: The category, urgency score, and AI-generated summary we produce for each of your emails are stored in our database alongside the original message identifier so that historical digests remain accessible.
Telegram Data (optional): If you elect to receive your digest via Telegram, you provide a bot token (which you create via Telegram’s @BotFather) that we encrypt at rest. We use the token only to send you your digest and respond to commands you initiate (e.g., /today, /snooze).
Payment Information: When you subscribe to a paid plan, payment is processed by Stripe, Inc. We do not store your full credit card number, expiration date, or CVC. Stripe provides us with a truncated card number (last 4 digits), card brand, and billing address for receipts.
Usage Data: We automatically collect information about how you access and use the Service, including IP address, browser type, operating system, pages viewed, features used, and timestamps. This is collected through server logs and session cookies.
Waitlist Email: If you submit your email through the waitlist form on our landing page, we store your email address along with the source page and timestamp, used solely to email you when NyxPixie becomes generally available.
2. How We Use Your Information
- Provide, maintain, and improve the Service
- Read your inbox via IMAP (with the App Password you provide) and your Google Calendar busy intervals (if you opt in) to classify emails, detect scheduling conflicts, and compose your daily digest
- Send you daily digests, account notifications, and security alerts
- Process subscription payments and send billing receipts
- Respond to your inquiries and support requests
- Detect, prevent, and respond to fraud, abuse, and security incidents
- Comply with legal obligations
3. Google API Services User Data Policy — Limited Use
NyxPixie’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically:
- Limited Use: Google user data obtained through the Google Calendar API is used exclusively to provide and improve user-facing features that are prominent in the Service’s user interface (specifically: detection of scheduling conflicts on events extracted from your inbox, surfaced on the “Coming up” dashboard view).
- No advertising: Google user data is never used for serving advertisements, including retargeting, personalized advertising, or interest-based advertising.
- No human reading: Humans do not read Google user data unless (a) we have obtained your affirmative agreement to view specific messages, (b) it is necessary for security purposes (such as investigating abuse), (c) it is necessary to comply with applicable law, or (d) the data has been aggregated and anonymized for the purpose of internal operations.
- No transfer: Google user data is never transferred to third parties except (a) as necessary to provide or improve user-facing features, (b) for security purposes, or (c) to comply with applicable law.
- No AI model training: Google user data is never used to develop, improve, or train generalized AI and machine learning models. AI classification of your data uses pre-trained open-source models that we run on our own infrastructure; your data never leaves our servers and is never used to update those models.
Self-hosted AI infrastructure
NyxPixie’s AI classification and digest generation runs on open-source models (Mistral Nemo 12B and Qwen 3 30B), all self-hosted on CNG Studios’ own private, offline infrastructure — dedicated physical servers running the Ollama inference engine on our private network. The AI models are not hosted by any cloud provider or third-party AI service. No Google user data, no email content, and no calendar data is ever sent to OpenAI, Anthropic, Google AI, or any other third-party AI service. All AI inference occurs entirely within our private network.
4. Cookies and Tracking
We use cookies and similar technologies to operate the Service. We do not use Google Analytics, Facebook Pixel, advertising cookies, or any third-party tracking scripts on our application pages.
- Essential cookies: Session cookies for authentication and security. Strictly necessary; cannot be disabled.
- Functional cookies: Language preferences and UI settings.
- Analytics: Self-hosted, privacy-respecting server-side analytics only.
5. How We Share Your Information
We do not sell, trade, or rent your personal information. We do not share your information for advertising or marketing purposes with any third party. We share information only in these limited circumstances:
| Provider | Purpose | Data Shared |
|---|---|---|
| Stripe, Inc. | Payment processing | Name, email, billing address, payment method |
| Brevo (Sendinblue) | Transactional email (digests, password resets, receipts) | Email address, email body of transactional message |
| Cloudflare, Inc. | CDN, DDoS protection, DNS, SSL/TLS | IP address, request metadata (encrypted in transit) |
| Google LLC (OAuth) | Optional authorized read-only access to your Google Calendar (busy intervals) | OAuth tokens (granted by you, revocable at any time) |
| Telegram Messenger Inc. (optional) | Digest delivery via your white-label bot | Bot token you provide; digest content |
Server hosting is on our own physical hardware. We do not use cloud hosting providers (AWS, GCP, Azure) for application data or AI processing.
We may also disclose information if required by law (court order, subpoena, governmental request) or to protect our rights, property, or safety, or that of our users or the public. If CNG Studios is involved in a merger, acquisition, or sale of assets, your information may be transferred; we will notify you by email and through the Service before this happens.
6. Data Retention
| Data Type | Retention Period |
|---|---|
| Account information | Duration of account + 30 days after deletion request |
| Email metadata + classification (subject, from, category, summary) | Duration of account + 30 days |
| Email body content (for paying users) | Discarded immediately after classification (only metadata kept) |
| Email body content (for tester accounts) | Retained during testing period for classifier tuning; deleted on request or when tester promotes to paying user |
| Calendar events | Cached for 24-hour digest cycle only; not stored long-term |
| OAuth tokens (Google) | Until you disconnect, then revoked + deleted within 7 days |
| Telegram bot token | Until you disconnect, then deleted |
| Server access logs | 90 days (rolling) |
| Backup copies | 30 days after primary data deletion |
| Waitlist email | Until launch + 30 days, or earlier on unsubscribe |
Upon account deletion or Google access revocation, your tokens are revoked immediately and your data is removed from active systems within 30 days. Backup copies are purged within an additional 30 days.
7. Data Security
- Encryption in transit: All connections use HTTPS/TLS
- Encryption at rest: OAuth tokens (Google, Telegram) encrypted with AES-256-GCM
- Magic-link auth: Single-use, 14-day TTL, hashed in DB (raw token only ever in URL)
- Tenant isolation: Each customer’s data is isolated by tenant ID at the database query layer
- Automated backups: Database backups every 6 hours with 30-day retention
- Physical security: Servers located on private premises, not in shared data centers
While we take reasonable measures to protect your information, no method of electronic transmission or storage is 100% secure, and we cannot guarantee absolute security.
8. Data Breach Notification
In the event of a data breach affecting your personal information, we will (a) investigate and contain it, (b) notify affected users by email within 72 hours of confirming the breach, (c) notify applicable regulatory authorities as required by law (Florida Statute 501.171; for EU users, GDPR Article 33), and (d) provide follow-up communications with remediation steps.
9. Your Rights
Depending on your jurisdiction, you may have the following rights:
- Access: Request a copy of the personal data we hold about you
- Correction: Request correction of inaccurate data
- Deletion: Request deletion of your personal data
- Portability: Request your data in CSV or JSON
- Restriction: Restrict processing in certain circumstances
- Objection: Object to processing based on legitimate interests
- Withdraw Consent: Revoke OAuth access at any time via myaccount.google.com/permissions
To exercise these rights, email support@mypixiesuite.com. We respond to verifiable requests within 30 days (or 45 days for complex requests, with notice).
10. California Privacy Rights (CCPA/CPRA)
California residents have additional rights under the CCPA/CPRA: Right to Know, Right to Delete, Right to Correct, and Right to Non-Discrimination. We do not sell or share personal information for cross-context behavioral advertising. To submit a request, email support@mypixiesuite.com with “California Privacy Request” in the subject line.
11. EEA, UK, and Swiss Users (GDPR / UK GDPR)
If you are in the European Economic Area, United Kingdom, or Switzerland, you have rights under the GDPR / UK GDPR including those listed in Section 9. Our legal basis for processing your data is (a) contract (we process data necessary to provide the Service you signed up for, including IMAP inbox access using the App Password you provide) and (b) consent (for OAuth-based read-only access to Google Calendar). You may lodge a complaint with your local supervisory authority.
12. Children
The Service is not directed to children under 16. We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will delete it.
13. International Data Transfers
NyxPixie’s servers are located in the United States. If you access the Service from outside the U.S., your information will be transferred to and processed in the U.S. We rely on standard contractual safeguards where required.
14. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated by email and a prominent notice on the Service at least 30 days before they take effect. The “Last updated” date at the top reflects the most recent version.
15. Related CNG Studios LLC Policies
NyxPixie operates within the legal and policy framework of CNG Studios LLC. The following umbrella policies apply alongside this NyxPixie-specific Privacy Policy:
- My Pixie Suite Privacy Policy — the parent privacy policy covering all CNG Studios products
- My Pixie Suite Terms of Service — the parent terms; see also our NyxPixie Terms of Service
- Data Processing Agreement — for business customers processing personal data through the Service
- Cookie Policy — details on cookies and tracking
- Acceptable Use Policy — what is and isn’t allowed on the Service
- DMCA Policy — copyright takedown procedures
- Refund Policy — subscription refund terms
16. Contact
CNG Studios LLC
A Florida limited liability company
Miami, Florida, United States
Email: support@mypixiesuite.com
Web: nyxpixie.com · mypixiesuite.com