Privacy Policy
What we do not collect
- No account. Nothing on the site or in the extension asks you to sign up or sign in with us.
- No analytics or tracking. No Google Analytics, no pixels, no third-party scripts, no cookies. The page is one self-contained file.
- No copies of your work. Graphs, runs, templates, prompts and model responses are not sent to Orivael. We cannot see them.
What stays on your machine
NodeXLoop keeps its state in your browser's local storage (web app) or in VS Code's storage (extension). That includes your graphs and projects, run history, custom templates and favourites, panel layout, the model registry you configure, and the data for the Organizations preview.
- API keys. If you enter a key for a model provider or an integration such as GitHub, it is stored locally on your device and used only to call that service directly from your browser or editor. It is never transmitted to Orivael.
- Organizations is a local preview: org members, submissions and approvals live in your browser and are not synced to any server.
- Clearing your browser's site data, or uninstalling the extension, deletes all of it. There is no server-side copy to request or to delete.
Where your prompts go
- Live mode sends prompts and receives completions directly between your device and the model provider you chose — OpenAI, Anthropic, Google, OpenRouter, a local Ollama, or any endpoint you configure. Orivael does not proxy, relay or log those calls. The provider's own privacy terms apply to them.
- Sim mode makes no network calls at all.
- The Axiom guard classifies prompts and completions in-process, on your device. Nothing is sent anywhere for checking.
The one thing we do hold: server logs
Like every website, nodexloop.orivael.dev records a line in a web-server access log for each request. A line contains your IP address, the page or file requested, the time, your browser's User-Agent string, and the referring page if your browser sends one.
- Why: to keep the site running securely, to detect abuse and scanners, and to count aggregate traffic — for example, how many visitors a launch brought. We look at these logs in aggregate; we do not build profiles of individual visitors.
- Retention: up to 12 months, then deleted automatically.
- Sharing: not sold, not shared with advertisers, not shared with anyone except where the law requires it. The server is hosted by Hetzner Online GmbH in Germany.
Installing through a registry
If you install the extension from the Visual Studio Marketplace or Open VSX, those registries record the download under their own privacy policies (Microsoft's and the Eclipse Foundation's respectively), and VS Code's own telemetry is governed by Microsoft. Orivael receives only the aggregate counts those registries publish.
A hand-installed .vsix from this site periodically fetches /version.json to learn whether a newer version exists. That request carries no data beyond the ordinary server-log line described above.
Your rights
If you are in the EU, UK or another jurisdiction with data-protection rights, the legal basis for the server log is our legitimate interest in running a secure website. You can ask us what we hold about an IP address, or ask us to delete it, by emailing [email protected]. Since we hold nothing else about you, that is the whole of it.
Children
The site and extension are developer tools, not directed at children, and we knowingly collect no personal data from anyone — children included.
Changes
If this policy changes, the new version is published at this address with an updated date. Material changes to what is collected would be called out at the top of the page, not buried.
Contact
Orivael · [email protected]