Privacy Policy

Effective July 10, 2026

This Privacy Policy explains what information NurvexThink ("NurvexThink", "we", "us") collects when you use Lyrith (the "Service"), why we collect it, and the choices you have. It's written to describe what the Service actually does — not generic boilerplate.

1. Information we collect

Account information

  • Name and email address (email is used to sign in and is stored case-insensitively);
  • A bcrypt hash of your password — we never store your password in plain text;
  • Your workspace(s), role in each, and who invited you.

Meeting information

  • Meeting titles, schedules, invitee lists, and join codes;
  • Who joined a meeting and when, and moderation actions (mute, remove, host transfer);
  • In-meeting chat messages, stored so you can review a meeting's conversation after it ends;
  • Recordings, transcripts, and AI summaries — only when the host turns these on for that specific meeting (or has set an always-on default for their workspace). If a meeting isn't recorded, none of this data exists.

Billing information

  • Your workspace's credit balance and transaction history;
  • Bank-transfer reference codes and the payment screenshot you upload to confirm a top-up — we verify the file is a genuine image before storing it, and only platform admins reviewing your payment can view it;
  • We do not process card numbers or bank account credentials — payments are manual bank transfers you initiate yourself.

Technical information

Structured server logs (request metadata, error traces) and audit-log entries recording who did what and when, for security and abuse investigation. We do not use third-party advertising trackers or analytics cookies — see Cookies below.

2. How we use your information

  • To operate the Service — authenticate you, run meetings, deliver chat and notifications;
  • To generate AI transcripts, summaries, and assistant replies, only for meetings where you or the host enabled that feature;
  • To send transactional email — meeting invitations, recap emails, payment confirmations, password resets;
  • To review and approve manual bank-transfer payments;
  • To investigate abuse, enforce our Terms of Service, and keep the Service secure;
  • To comply with legal obligations.

We do not sell your personal information, and we do not use your meeting content to train third-party foundation models.

3. Who we share information with

We use the following service providers ("subprocessors") to operate Lyrith. Each only receives the data it needs to do its job:

  • LiveKit Cloud — real-time video/audio delivery during meetings.
  • OpenAI — meeting transcription (Whisper) and AI summaries/assistant replies (GPT), only for meetings with AI features turned on.
  • Cloudflare R2 — encrypted storage for recordings and payment screenshots.
  • Brevo — delivery of transactional email (invitations, recaps, receipts).
  • Database, cache, and application hosting providers that store and run the Service infrastructure.

We don't share your information with advertisers or data brokers. We may disclose information if required by law or to protect the rights, safety, or property of NurvexThink, our users, or the public.

4. Cookies

Lyrith uses one essential, strictly-necessary cookie to keep you signed in (your authentication session). We don't set advertising or analytics cookies, and we don't use any cross-site tracking. Because the sign-in cookie is required for the Service to function, it can't be turned off without also signing you out.

5. Data retention

We keep your account and meeting data for as long as your account is active. If you delete your account, we permanently delete your user record. Some records — like audit logs and billing history — are retained for a limited period afterward where needed for legal, security, or accounting reasons, with your personal identifiers removed where possible.

6. Your rights

You can, at any time:

  • Access and export your account and meeting data from your dashboard;
  • Correct your name or email from Settings;
  • Delete your account, which permanently removes your user record;
  • Ask us questions about what we hold on you by emailing support@lyrith.app.

If you're located somewhere with statutory data-protection rights (for example, the EU's GDPR), those rights apply to you in addition to what's described here.

7. Data security

Every workspace's data is isolated at the database level. Passwords are hashed with bcrypt. Payment screenshots and recordings are stored in access-controlled object storage with short-lived signed URLs — a download link expires within minutes and a fresh one is minted on every request. No system is perfectly secure, but we design for isolation by default, not as an afterthought.

8. Children's privacy

The Service is not directed at children under 13, and we don't knowingly collect information from them. If you believe a child has provided us information, contact support@lyrith.app and we'll remove it.

9. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be announced by email or an in-app notice before they take effect.

10. Contact

Questions about this policy or your data? Email support@lyrith.app or, for security concerns, security@lyrith.app.

Privacy Policy | Lyrith