Privacy Policy
Last updated: 20 September 2026
Operated by Nirmana Labs ("we", "us", "our") · Contact: info@nirmanalabs.lk
1. Introduction
Sumane AI ("the Service") is a multimodal artificial intelligence assistant that processes text, image, and document inputs to generate responses. This Privacy Policy explains what information we collect, how it is used, stored, and shared, and the rights and choices available to you. By creating an account or using the Service, you agree to the practices described in this Policy.
2. Information We Collect
a. Account Information. Registration and sign-in are handled by our authentication provider, Clerk. When you create an account, we receive information such as your name, email address, and profile details. We do not store your password; credentials are managed securely by Clerk.
b. Content You Provide. This includes the text prompts and messages you send, images and PDF documents you upload, your conversation history with the assistant, and any feedback you choose to submit about the Service.
c. Technical and Usage Data. We collect limited technical information such as device and browser type, IP address, session tokens (JWT), timestamps, and application logs used for security, debugging, and performance monitoring.
3. How AI Models Process Your Data
This section is important please read it carefully.
When you submit a prompt or upload an image or document, that content is transmitted to third-party AI model providers in order to generate a response. The Service currently routes requests, via LangChain and direct API integrations, to:
- Google (Gemini API) - for text, image, and document understanding and generation. PDF documents you attach are additionally held on Google's Files API infrastructure for up to 48 hours so the assistant can refer back to them across a conversation, independent of how long the conversation itself is retained.
- Groq (Groq API) - for high-speed AI inference
- OpenAI - for text and image understanding and generation, and to generate the personal-memory summaries described in Section 4
- OpenRouter - to route certain text requests to third-party model providers
These providers process your inputs on their own servers, under their own privacy policies and API data-use terms. Depending on the provider and API tier, inputs may be temporarily retained by them for purposes such as abuse monitoring, in accordance with their policies.
We do not use your conversations or uploads to train our own AI models.
Please do not include sensitive personal information such as national identity card or passport numbers, financial account details, passwords, or health information in your prompts or uploaded files.
4. How We Use Your Information
We use the information described above to:
- operate the Service and generate AI responses to your inputs;
- save and retrieve your conversation history and remember relevant context from past conversations, so responses can be personalised to you;
- authenticate you and keep your session secure;
- enforce fair-use limits on messages and file uploads;
- review feedback you submit about the Service, described further in Section 9; and
- maintain, debug, comply with applicable legal obligations, and improve the Service.
We do not sell your personal data, and we do not share it with third parties for advertising purposes.
5. Data Storage and Security
Your conversation history is stored using Firebase (Cloud Firestore), scoped to your account so that it is accessible only to you. Personal-memory summaries, feedback you submit, and usage/rate-limit records are stored using Supabase (PostgreSQL), with Row-Level Security (RLS) policies applied at the database level. PDF documents you attach are held temporarily by Google's Gemini Files API for up to 48 hours, as described in Section 3, rather than by us directly. Data is encrypted in transit (HTTPS/TLS), and sessions are secured using JWT-based authentication via Clerk.
No method of transmission or storage is completely secure, and while we take reasonable measures to protect your information, we cannot guarantee absolute security.
6. Third-Party Service Providers
The Service is built on the following third-party providers, each of which processes data in accordance with its own privacy policy:
| Provider | Purpose |
|---|---|
| Clerk | Authentication and session management |
| Firebase (Google) | Conversation history storage |
| Supabase | Personal-memory, feedback, and usage-limit storage |
| Google (Gemini API) | AI processing of text, image, and document inputs; temporary storage of attached PDFs |
| Groq | AI inference |
| OpenAI | AI processing of text and image inputs; memory summarisation |
| OpenRouter | Routing of certain text requests to third-party model providers |
| Vercel | Hosting and deployment |
We encourage you to review the privacy policies of these providers.
7. Data Retention and Deletion
Your conversation history is retained while your account is active, or until you delete a conversation within the Service - deleting a conversation permanently removes it from our database. Attached PDF documents are held by Google's Files API for a maximum of 48 hours regardless of whether the conversation itself is kept, after which they are no longer accessible even if the conversation referencing them still exists. [Confirm exact behaviour for feedback records and personal-memory retention before publication.]
You may request deletion of your account and associated personal data by contacting us at info@nirmanalabs.lk. We will action deletion requests within a reasonable period, except where retention is required by law. Please note that any transient retention of your inputs by third-party AI providers is governed by their respective policies.
8. Your Rights
Depending on your jurisdiction, including under the Personal Data Protection Act, No. 9 of 2022 of Sri Lanka and, where applicable, the EU General Data Protection Regulation (GDPR) you may have the right to:
- access the personal data we hold about you;
- request correction of inaccurate data;
- request deletion of your data;
- object to or request restriction of certain processing; and
- withdraw consent where processing is based on consent.
To exercise any of these rights, contact us at info@nirmanalabs.lk.
9. Feedback You Submit
From time to time, the Service may invite you to rate a recent response and, if you rate it unfavourably, to describe what could be improved. Participation is optional. Feedback you submit - your rating, any written comment, and the date it was given - is stored against your account and may be reviewed by us to improve the Service. It is not shared with the third-party AI providers listed in Section 3 or used to train any model.
10. Cookies and Session Storage
The Service uses essential cookies and browser storage to keep you signed in, remember your interface preferences, and maintain your session state. We do not use third-party advertising or tracking cookies.
11. Children's Privacy
The Service is not directed to children under the age of 13 (or the minimum age required in your jurisdiction). We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us so we can remove it.
12. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date above and, for material changes, notify you within the Service or by email.
13. Contact
Questions about this Privacy Policy can be sent to info@nirmanalabs.lk.
Also see our Terms of Service.