Legal

Privacy Policy

Operated by Radhron LLC, a Texas Limited Liability Company

Contact: help@nirvah.ai

Last Updated: March 2, 2026

Introduction

Nirvah AI is a restaurant automation software-as-a-service (SaaS) platform provided by Radhron LLC, a Texas Limited Liability Company. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our services.

We value your privacy and are committed to protecting your personal and business data. We use your data solely to provide our automation services, including AI-powered guest communication, review management, and voice agent capabilities. We do not sell your data to third parties.

Google User Data & Limited Use Disclosure

Critical Compliance Information

Nirvah AI's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

We access your Google Business Profile data through OAuth 2.0 authorization with the following scope: business.manage

What We Access:

  • Reviews: Review content including reviewer display name, star rating, review text, and date posted. We do not store reviewer profile photos. Used to display in your dashboard and generate AI-drafted responses
  • Locations: To identify and manage your business listings
  • Business Hours: To configure voice agent availability and responses
  • Business Information: To ensure accurate representation in automated communications

AI Processing of Google Data: Google review content (text, rating, and reviewer name) is processed by OpenAI and/or Anthropic for sentiment analysis and generating draft reply suggestions. This processing is transient and governed by enterprise API terms that prohibit training on customer data.

Automated Syncing: When connected, Nirvah AI periodically syncs your Google Business Profile reviews (approximately every 15 minutes) to keep your dashboard current. New reviews are automatically analyzed for sentiment and draft replies are generated for your review and approval.

Our Commitments:

  • We do not sell your Google Business Profile data to third parties
  • We do not use your data for advertising or marketing purposes unrelated to our services
  • We only access the minimum data necessary to provide our stated features
  • You can revoke access at any time through your Google Account settings or by disconnecting the integration in Nirvah AI

Information We Collect

Identity Data

When you create an account, we collect your name, email address, and phone number through our authentication provider (Supabase Auth). If you sign in with Google, we receive your basic profile information (name, email, profile picture) as authorized.

Business Data

To provide our services, we collect information about your restaurant, including:

  • Restaurant name, address, and location identifiers
  • Operating hours (regular and holiday schedules)
  • Menu items, categories, prices, and modifiers
  • Service policies (reservations, delivery, pickup, catering, etc.)
  • Contact information and social media links

Content Data

  • Reviews: Customer reviews synced from Google Business Profile
  • Review Replies: AI-generated draft responses that you approve before posting
  • Knowledge Base: FAQs, documents, PDFs, and other materials you upload to train your voice agent
  • Menus: Menu data extracted from uploaded files or synced from POS systems

Inventory & Receipt Data

When using our Inventory Intelligence feature, we collect:

  • Vendor receipts submitted via photograph (processed by OpenAI Vision OCR)
  • Extracted line items: vendor name, product name, quantity, unit, and price per order
  • Z-tape and daily sales summary data you upload for food cost calculations
  • Food cost percentage history and trends calculated from your receipt data
  • HACCP compliance checklist entries and temperature log records

POS Integration Data

When connecting your POS system (Square, Toast via KitchenHub, or Clover via KitchenHub), we access:

  • Menu items, categories, modifiers, and pricing
  • Order data for voice agent orders injected into your POS
  • OAuth tokens to maintain the connection (encrypted at rest)

Voice & Call Data

When using our AI Voice Agent feature (powered by LiveKit, Deepgram, and Cartesia), we collect:

  • Call transcripts (audio processed by Deepgram speech-to-text)
  • Caller phone numbers (from and to)
  • Call duration, timestamps, and AI analysis (sentiment, intent, topic)
  • Orders placed during voice calls (customer name, items, fulfillment details)

Technical Data

  • IP address and browser information (for security and session management)
  • Session cookies (httpOnly, secure) to maintain your authenticated state
  • OAuth tokens (encrypted) to maintain connections to integrated services

How We Use Your Data

  • Account Provisioning: To create and manage your account, verify your identity, and provide access to our platform
  • AI-Powered Features: To generate draft responses to reviews, power your voice agent with accurate information, and extract menu data from uploaded files
  • Review Management: To sync reviews from Google Business Profile, analyze sentiment, and enable you to respond efficiently
  • Voice Agent Operation: To handle incoming calls, process orders, answer customer questions, and provide call analytics
  • Business Automation: To automate updates to your business listings and streamline operations
  • Transactional Communications: To send invoices, security alerts, service updates, and other essential notifications
  • Service Improvement: To analyze usage patterns and improve our platform (aggregated, non-identifying data only)

AI & Data Privacy

Zero-Training Guarantee

We do not use your proprietary business data (menus, private customer lists, internal notes, or any content you provide) to train our third-party AI providers' (e.g., OpenAI, Anthropic) public foundation models.

Your data is sent to AI models only for the purpose of generating the specific response or analysis you requested. This includes:

  • Generating review response drafts based on review content
  • Powering real-time voice agent conversations
  • Extracting structured menu data from uploaded files
  • Analyzing review sentiment and themes

We use API access to these AI providers, which means your data is processed in real-time and is not retained by these providers for training purposes, in accordance with their enterprise API terms.

Data Security

We implement industry-standard security measures to protect your data:

  • Encryption in Transit: All data transmitted between your browser and our servers is encrypted using TLS/SSL protocols
  • Database Security:Row Level Security (RLS) policies ensure data isolation between customers—you can only access your own restaurant's data
  • Token Security: Sensitive tokens (like Google OAuth Refresh Tokens) are encrypted at rest and stored securely
  • Session Management: Authentication cookies are httpOnly, secure, and use SameSite protections to prevent cross-site attacks
  • Access Controls: Administrative access is protected with verification codes and role-based permissions
  • Customer PII (phone numbers, names, email addresses, delivery addresses) is encrypted at the application level using AES-256-GCM before storage

Third-Party Sub-processors

We use the following third-party services to provide our platform. These sub-processors may process your data as described:

ProviderPurposeData Processed
SupabaseIdentity, Database, StorageAccount data, business data, files
Google CloudAPIs (Business Profile, Places)Reviews, locations, business info
OpenAI / AnthropicAI InferenceReview content, menu data, queries
LiveKitVoice AI InfrastructureCall audio, real-time voice sessions
DeepgramSpeech-to-TextCall audio transcription
CartesiaText-to-Speech (Voice AI)No customer data stored
TwilioSMS & Phone ServicesPhone numbers, SMS content
StripePayment ProcessingBilling info (we do not store card numbers)
SquarePOS IntegrationMenu items, order data
KitchenHubPOS Middleware (Toast & Clover)Menu items, order injection
OpenAI VisionReceipt OCR (Inventory)Vendor receipt images (not stored by OpenAI)

Your Rights (GDPR/CCPA Compliance)

Depending on your location, you may have the following rights regarding your personal data:

  • Right to Access: Request a copy of the personal data we hold about you
  • Right to Correction: Request correction of inaccurate or incomplete data
  • Right to Deletion: Request deletion of your personal data (subject to legal retention requirements)
  • Right to Portability: Request your data in a structured, machine-readable format
  • Right to Object: Object to processing of your data for certain purposes
  • Right to Withdraw Consent: Withdraw consent for processing where consent is the legal basis

How to Exercise Your Rights

To request access to, correction of, or deletion of your data, please email us at help@nirvah.ai. We will respond to your request within 30 days.

To disconnect Google Business Profile access, you can either:

When you disconnect Google Business Profile, all synced review data, AI-generated analyses, draft replies, and approval conversations are permanently deleted from our systems.

Data Retention

We retain your data for as long as your account is active or as needed to provide you with our services. Specific retention periods include:

  • Account Data: Retained until you request account deletion
  • Call Recordings: Retained for 90 days for quality and dispute resolution, then automatically deleted
  • Transaction Records: Retained for 7 years as required for tax and legal compliance
  • Log Data: Retained for 30 days for security and debugging purposes
  • Google Business Profile Data: Retained while your account is active and the integration is connected. All synced Google review data (reviews, analysis, draft replies, and cached data) is immediately deleted when you disconnect the Google Business Profile integration or delete your account.

Upon account deletion, we will delete or anonymize your personal data within 30 days, except where retention is required by law.

Contact Us & Policy Changes

If you have questions about this Privacy Policy or our data practices, please contact us:

Radhron LLC

Email: help@nirvah.ai

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the "Last Updated" date. We encourage you to review this Privacy Policy periodically.

© 2026 Radhron LLC. All rights reserved.