Noveum.ai

Privacy Policy

Last updated: July 10, 2026

This Privacy Policy describes how MagicAPI Inc (doing business as Noveum.ai) ("Noveum," "we," "us," or "our"), a Delaware corporation with its principal place of business at 548 Market St PMB 49761, San Francisco, CA 94104-5401, USA, collects, uses, and shares information in connection with our websites (including noveum.ai), our AI reliability platform for tracing, evaluating, simulating, and improving AI agents, our APIs, SDKs, and MCP server, and related services (collectively, the "Services").

If you do not agree with this Privacy Policy, please do not use the Services. Questions or requests can be sent anytime to privacy@noveum.ai.

1. Scope: our two roles

We handle information in two distinct roles, and your rights differ depending on which applies:

  • Noveum as a controller. For information about visitors to our websites and the people who register for and administer accounts (e.g., your name, email, billing details, and usage of our product), we decide how and why the information is processed and this Privacy Policy applies directly.
  • Noveum as a processor / service provider. The core of our product is processing Customer Content: the traces, prompts, model outputs, datasets, transcripts, recordings, and evaluation data that our business customers send to the Services from their own applications. That content may include personal information about their end users. We process Customer Content only on our customers' documented instructions, under our agreements with them (including a Data Processing Addendum where applicable). If your personal information has reached Noveum inside another company's Customer Content, that company is the controller: please direct requests to them, and we will support them in responding as required by law.

2. Information we collect

Account and profile information

When you create an account or are invited to an organization, we collect your name, email address, optional profile image and username, language preference, authentication credentials (a hashed password, passkey public keys, or tokens from a sign-in provider such as Google or GitHub), and email verification status.

Organization and billing information

For organizations we store the organization name, logo, member roles and permissions, invitations, plan and quota information, and usage metrics (such as span counts and storage consumption). Payments are processed by our payment processor (Stripe); we store a customer reference, subscription status, and purchase records, but we do not store full payment card numbers.

Customer Content (traces, evaluations, and voice data)

This is the heart of the product, so we describe it explicitly rather than hiding it in a definition:

  • Traces and spans: structured records of your application's AI activity that you choose to send us, which can include LLM prompts and completions, tool calls and their results, retrieval queries and retrieved context, latency/cost/token metrics, error details, and any attributes, tags, or end-user identifiers (such as a user or session ID) that you attach.
  • Datasets and evaluation data: dataset items built from traces or uploaded by you (inputs, expected outputs, agent responses, ground truth, conversation context), evaluation scores, judge reasoning, and reports.
  • Voice and simulation data: when you use voice testing features, we process synthetic call audio, speech-to-text and text-to-speech data, call transcripts, recordings and recording links, phone numbers used for testing, and your agent configurations (including system prompts and tool definitions).
  • Uploaded media and files: audio, images, and other files you upload or that your traces reference.

You control what goes into Customer Content. Please do not send us data you are not permitted to share, and use available controls (such as redaction in your SDK configuration) for content you consider sensitive.

Connected apps, API keys, and MCP credentials

When you create API keys or connect an MCP client or other application via OAuth, we store the key or grant metadata (name, scopes, organization, creation and last-used timestamps) and secrets in hashed form. When you store third-party model provider credentials with us for evaluations, we encrypt them at rest.

Usage, device, and log information

We automatically collect log and device information when you use the Services: IP address, browser and device type, operating system, pages viewed, features used, referring URLs, session identifiers, and timestamps. We also keep authorization audit logs (who attempted what action, whether it was allowed, and from what IP/user agent) for security and compliance.

Cookies and similar technologies

We use cookies and similar technologies on our websites and in the product:

  • Strictly necessary: session authentication (expires after 30 days) and language preference.
  • Analytics and product improvement: product analytics (Mixpanel), session analytics (Microsoft Clarity), and tag management (Google Tag Manager, where enabled).
  • Support and marketing (websites): live-chat support (Intercom), marketing and CRM (HubSpot), and business-visitor identification (RB2B) on our marketing pages.

You can control cookies through your browser settings; see also "Your privacy rights" below for opt-out choices.

3. How we use information

We use the information we collect to:

  • provide, operate, secure, and maintain the Services (including running the evaluations, simulations, and analyses you request);
  • authenticate you and enforce roles, permissions, scopes, and organization boundaries;
  • process payments, manage subscriptions and credits, and prevent fraud and abuse;
  • respond to support requests and communicate with you about the Services (service messages, security notices, and: where permitted: product news you can opt out of);
  • monitor performance and debug problems (including error reporting);
  • comply with legal obligations and enforce our agreements; and
  • develop, test, and improve the Services, as described below.

How we improve the Services: and our AI training commitment

We do not use Customer Content to train or fine-tune AI or machine-learning models. The models used for evaluations and analyses are foundation models operated by third-party providers (or configured by you), and we send them your content only to produce the results you requested: not to teach them.

We may use information that has been de-identified and aggregated: so that it no longer identifies you, your organization, or any individual: to test our systems, benchmark and improve evaluation quality, tune our automated analysis and reporting features, and understand product usage. We commit not to attempt to re-identify de-identified data.

Where the GDPR or similar laws apply and we act as a controller, we rely on: performance of a contract (providing the Services you signed up for), legitimate interests (securing and improving the Services, preventing abuse, and B2B communications, balanced against your rights), consent (where required, e.g., certain cookies and marketing), and legal obligation (e.g., tax and accounting records).

4. How we share information

We do not sell personal information for money. We share information only as follows:

  • Subprocessors and service providers that help us run the Services, bound by contracts limiting their use of the information: cloud hosting and storage (Amazon Web Services, in the United States), analytical trace storage (ClickHouse Cloud), error monitoring (Sentry), product and session analytics (Mixpanel, Microsoft Clarity), customer support and CRM (Intercom, HubSpot), email delivery (Resend), payment processing (Stripe), voice/telephony infrastructure for simulations (LiveKit), voice AI components (e.g., ElevenLabs), and our content management system for the blog (Strapi). A current subprocessor list is available on request at privacy@noveum.ai.
  • Third-party AI model providers, as described in Section 5.
  • Within your organization: members and admins of your organization can see content and activity in that organization according to their roles.
  • Integrations you enable: if you connect an MCP client, bring your own ClickHouse, configure your own model provider credentials, or enable another integration, we share data with that service as needed to make the integration work, under your instruction.
  • Legal, safety, and compliance: when required by law, subpoena, or legal process, or when necessary to protect the rights, safety, or property of Noveum, our users, or the public.
  • Business transfers: in connection with a merger, acquisition, financing, or sale of assets, subject to confidentiality protections and this policy's commitments.

Some website analytics and visitor-identification technologies described above may be considered "sharing" (or, under some U.S. state laws, a broad form of "sale") of personal information for targeted-advertising purposes. You can opt out as described in "Your privacy rights."

5. Third-party AI model providers

Running an evaluation, simulation, or automated analysis requires sending relevant Customer Content (for example, the prompt and response being judged) to a large-language-model provider. Depending on your configuration this may include OpenAI, Anthropic, Google, AWS Bedrock, Azure OpenAI, or another provider you select: including providers you connect with your own credentials.

We configure our own provider accounts using settings intended to prevent the provider from using your content to train its models (for example, API tiers with no-training commitments), and we send only what is needed for the requested operation. When you bring your own provider credentials, your agreement with that provider governs its handling of your content.

6. MCP connectors and OAuth

If you connect an AI assistant or agent (such as Claude, Cursor, VS Code, or ChatGPT) to Noveum through our MCP server:

  • Scopes: access is limited to the scopes you approve on the consent screen: noveum.read (read projects, traces, datasets, evaluations, and reports), noveum.write (create and update resources), and noveum.execute (start jobs). Scopes only narrow what a connected app can do; your organization's roles and permissions always apply on top.
  • Organization binding: each OAuth token is bound to the single organization you select at consent time.
  • Credentials: OAuth access and refresh tokens and authorization codes are stored only in hashed form; access tokens are short-lived.
  • Revocation: you can revoke any connected app at any time in Settings → Connected apps, which immediately invalidates its tokens. API keys can be deleted in your organization's API key settings.
  • What the connector sees: an MCP client acting with your grant can access the same Customer Content your role permits: treat connected apps with the same care as team members.

7. Data retention

We keep information for as long as needed for the purposes above, and specifically:

  • Account information: for the life of your account; deleted when you delete your account (deletion cascades to sessions, credentials, API keys, and OAuth grants).
  • Customer Content (traces, evaluations, datasets, voice recordings, and related telemetry): retained for up to 90 days by default so you can analyze recent activity, unless your plan or order specifies a different window; deleted when you delete the relevant project or organization, and: at your request: we will delete specific Customer Content, or all of your Customer Content, ahead of that schedule. After account or organization deletion, Customer Content is removed from production systems within 30 days, with backups expiring on a rolling basis within 90 days.
  • Sessions: expire after 30 days.
  • OAuth credentials: authorization codes expire after 60 seconds, access tokens after 1 hour, refresh tokens after 30 days; revoked grants are invalidated immediately.
  • Audit and security logs: retained for up to 12 months unless a longer period is required for an investigation or by law. If you ask us to delete your data, we will also honor that request for logs tied to your account, except where we are required to keep them for security, legal, or accounting reasons.
  • Billing records: retained as required by tax and accounting law.

8. International data transfers

We are a U.S. company and process data in the United States (primarily in AWS US regions). Where we receive personal data from the EEA, UK, or Switzerland as a processor or controller, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (and UK/Swiss addenda) with our customers and subprocessors. A Data Processing Addendum is available for business customers: contact support@noveum.ai.

9. Security

We maintain a security program with administrative, technical, and physical safeguards appropriate to the sensitivity of the data we process, including encryption in transit (TLS) and at rest, application-layer encryption for stored provider credentials, storage of API secrets and OAuth tokens in hashed form, role-based access control, organization-level data isolation, audit logging, and support for phishing-resistant sign-in (passkeys). We are pursuing SOC 2 Type II certification (currently in progress); our security program is designed to meet its criteria, and we will make compliance documentation available to customers once it is complete. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If you believe you have found a vulnerability, please email security@noveum.ai (or support@noveum.ai).

10. Your privacy rights

Depending on where you live, you may have rights to access, correct, delete, or export your personal information, to restrict or object to certain processing, and to withdraw consent.

  • EEA/UK/Switzerland (GDPR): you may exercise the rights above and lodge a complaint with your local supervisory authority. Where we act as processor for Customer Content, we will refer your request to the responsible controller.
  • California (CCPA/CPRA) and other U.S. states: you have the right to know, correct, and delete personal information, the right to opt out of "selling" or "sharing" (including for targeted advertising), and the right not to be discriminated against for exercising these rights. To opt out of website analytics/advertising sharing, email privacy@noveum.ai with "Opt-Out" in the subject or adjust your cookie settings.

To exercise any right, email privacy@noveum.ai from the address associated with your account (we may need to verify your identity). We respond within the timeframes required by applicable law. You can also delete your account directly in the product (Settings), which initiates the deletions described in Section 7.

11. Children

The Services are intended for business use and are not directed to children. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided us personal information, contact privacy@noveum.ai and we will delete it.

12. Changes to this policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or a prominent notice in the Services before the change takes effect. The "Last updated" date above reflects the current version.

13. Contact us

MagicAPI Inc (DBA Noveum.ai) 548 Market St PMB 49761 San Francisco, CA 94104-5401, USA Phone: +1 (415) 792-0933 Privacy requests: privacy@noveum.ai General support: support@noveum.ai