Privacy Policy
Last updated 15 August 2026
This policy explains how Nionto, Inc. ("Nionto", "we", "us") handles personal data when you use nionto.com, accounts.nionto.com, and our products. If you have questions about anything here, please contact us.
What we collect
- Account data. Your email address, the times you signed in, and a licence key we generate for you. We use passwordless sign-in links, so we do not store passwords at all.
- Billing data. Your subscription status, plan, renewal date, and a Stripe customer identifier. Card numbers go directly to Stripe; we never receive or store them.
- Product data. For Mayhem Monkeys, the targets you submit and the findings produced for you. For ModelCoor Lite, a record of the devices you register — a device name, platform, and last-seen time — so your fleet and licence can be managed.
- Messages. If you email us or use the contact form, we keep the message and your address so we can reply.
- Technical data. Ordinary server logs generated when you use the sites, used for security, debugging, and abuse prevention.
ModelCoor Lite: where your data actually goes
ModelCoor Lite coordinates inference across hardware you own, and we want to be precise rather than flattering about when anything leaves your machines.
- On your own network — nothing reaches us. When your devices talk to each other over your LAN, your prompts, your files, and the model's output never leave your hardware. What reaches Nionto is limited to licence validation and the device metadata described above.
- Using the hosted address to reach your fleet from elsewhere. If you use the hosted pass-through URL, that request travels through our servers to your own fleet and the answer comes back the same way. We pass it straight through and do not store the content: we record only the number of requests and a byte count, for your usage limits.
- Adding a device from outside your network. If a device joins your fleet from somewhere else, its connection to your coordinator is spliced through our servers because the two cannot reach each other directly. That traffic is relayed, not inspected or retained.
- Sharing idle capacity is opt-in, per device. If a capacity-sharing programme is offered, it is off unless you turn it on, and you can turn it off for any device at any time. We will never enable it by default or bury it in these terms.
In every case above we act as a conduit. We do not read, store, or train on the contents of your prompts, documents, or model output.
We do not use your content to train machine-learning models, and we do not sell personal data or share it with advertisers.
Why we use it
- To provide the Services, including authenticating you and delivering results.
- To take payment and manage subscriptions (a contractual necessity).
- To support you when you get in touch.
- To keep the Services secure, prevent abuse, and meet our legal obligations.
- To send service messages such as sign-in links, receipts, and material changes to a product you use.
Where the law requires a lawful basis, we rely on performance of our contract with you, our legitimate interest in operating and securing the Services, compliance with legal obligations, and your consent where consent is the appropriate basis (for example, joining an early-access list).
Who we share it with
We use a small number of processors to run the business, and we share only what each one needs:
- Stripe — payments, subscriptions, and invoices.
- Resend — transactional email such as sign-in links and receipts.
- Cloudflare — DNS and protection for our websites.
- Our hosting providers — the servers that run the Services.
We may also disclose data if legally required, or as part of a merger or acquisition, in which case we will tell you before your data becomes subject to a different policy.
How long we keep it
We keep account and subscription data while your account exists and for as long afterwards as we need it for legal, tax, and accounting purposes. Product data such as hunt findings is kept so you can return to it, and is deleted on request. Server logs are kept for a limited period for security and debugging.
Security
We encrypt traffic in transit, restrict administrative access, store sign-in tokens only as hashes, and back up our databases. No system is perfectly secure, but if a breach affects your personal data we will notify you and any relevant regulator as the law requires.
Your rights
Depending on where you live, you may have the right to access the personal data we hold about you, to correct it, to delete it, to object to or restrict certain processing, to receive a portable copy, and to withdraw consent. To exercise any of these, use the contact form and we will respond within the period the law allows. You may also complain to your local data protection authority. We will not treat you differently for exercising a right.
International transfers
Nionto is based in the United States and our providers may process data there and in other countries. Where data is transferred out of your region, we rely on appropriate safeguards such as the standard contractual clauses offered by those providers.
Cookies
We use a single essential cookie to keep you signed in to your account. It is not used for advertising or cross-site tracking, and there is no third-party advertising cookie on our sites.
Children
The Services are not directed to children, and we do not knowingly collect personal data from anyone under 18. If you believe a child has given us data, contact us and we will delete it.
Changes
If we change this policy materially, we will give notice through the product or by email before it takes effect, and update the date at the top of this page.