New — Iris AI drafts your firewall, routing & rate-limit rules. Explore AI features →

Privacy Policy

Last Updated: July 22, 2026

Welcome to Ngris. We are committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our SaaS product.

1. Information We Collect

We may collect personal information that you provide to us directly, as well as information that is automatically collected when you use our service.

  • Account Information: When you create an account, we collect your name, email address, and password.
  • Payment Information: If you subscribe to a paid account, we collect payment information via our payment processor (Stripe). We never store raw card numbers on our servers.
  • Usage Data: We automatically collect information about your interactions with our service, such as the features you use and the pages you visit.

2. Cookies & Analytics

We use strictly necessary cookies to run the service (session, security) and — only with your consent — Google Analytics 4 to understand aggregate, non-identifying usage (GA may collect a pseudonymous identifier, IP-derived approximate location, and device/usage data). Analytics cookies are disabled by default in the EEA, the UK and Switzerland until you accept them, and we honor the Global Privacy Control opt-out signal. You can change your choice at any time via Cookie settings. Our lawful basis is your consent for analytics, and contract performance / our legitimate interest in operating a secure service for necessary cookies. See the Cookie Policy for the full list.

3. How We Use Your Information

We use the information we collect to provide, operate, and maintain our service, to process your transactions, and to communicate with you about your account.

4. How We Share Your Information

We may share your information with service providers who process it on our behalf — including Stripe (payments), our email provider, and, where you consent, Google (Google Analytics 4). We may also share information in connection with a merger, sale of company assets, or other business transfer. We do not sell your personal information.

5. International Data Transfers

Some providers (including Google) process data in the United States. Where personal data of EEA/UK residents is transferred outside those regions, we rely on the EU-U.S. Data Privacy Framework and/or the Standard Contractual Clauses as the transfer mechanism.

6. Data Security

We use administrative, technical, and physical security measures to help protect your personal information. All data in transit is encrypted using TLS 1.3, and sensitive data at rest is encrypted using AES-256.

7. Data Retention

Inspector request data is retained based on your plan's retention window (24 hours to 30 days). Account data is retained for the duration of your account and deleted within 30 days of account closure, except where required by law.

8. Your Rights & Choices

Depending on where you live, you have the right to access, correct, delete, or port your personal data, and to object to or restrict processing. EEA/UK residents may withdraw analytics consent at any time via Cookie settings and may lodge a complaint with a supervisory authority.

California (CCPA/CPRA): you have the right to know, delete, and correct your personal information and to opt out of any "sale" or "sharing." We do not sell personal information; the use of analytics cookies may be considered "sharing" — opt out via Cookie settings ("Do Not Sell or Share"), and we honor Global Privacy Control signals. To exercise any right, contact us at the email below.

9. Contact Us

If you have any questions about this Privacy Policy, contact us at privacy@ngris.com.

Ask an AI to summarise this page
Iris