Home/Privacy Policy

Privacy Policy

Last Updated: August 15, 2026Maintained by Nuratix LLChttps://nextviper.nuratix.com

This Privacy Policy explains how Nuratix LLC ("Nuratix", "we", "us", or "our") collects, uses, stores, protects, and discloses information when you use NextViper, NextViper Cloud, the NextViper website, package registry, documentation, developer tools, and other services that link to this Privacy Policy (collectively, the "Services").

NextViper is an open-source programming language and ecosystem maintained by Nuratix LLC.

By using the Services, you acknowledge that you have read this Privacy Policy.

1. Scope

This Privacy Policy applies to information processed by Nuratix through:

  • nextviper.nuratix.com
  • NextViper documentation
  • NextViper package registry
  • NextViper package services
  • NextViper developer services
  • NextViper accounts
  • NextViper authentication
  • NextViper downloads and release infrastructure
  • NextViper APIs
  • NextViper Cloud, if applicable
  • other Nuratix services that explicitly link to this Privacy Policy

This Privacy Policy does not necessarily apply to third-party websites, services, package repositories, APIs, libraries, or applications that are not operated by Nuratix.

2. Information We Collect

We follow a data-minimization approach and only collect information reasonably necessary to operate, secure, maintain, and improve the Services.

Depending on how you use NextViper, we may collect the following categories of information.

2.1 Account Information

If you create an account, we may collect:

  • name
  • username
  • email address
  • account identifier
  • profile information you choose to provide
  • authentication information
  • account creation date
  • account status
  • organization information, where applicable

We do not intentionally collect information that is unnecessary for operating the account.

2.2 Authentication Information

When you authenticate with the Services, we may process information required to:

  • create your account
  • authenticate your session
  • prevent unauthorized access
  • maintain login sessions
  • detect suspicious authentication activity
  • protect accounts

Passwords must not be stored in plaintext. Authentication credentials should be securely hashed or handled through a trusted authentication provider where applicable.

2.3 Package Registry Information

If you publish packages to the NextViper package registry, we may process:

  • package name
  • package version
  • package description
  • package metadata
  • package dependencies
  • package license information
  • repository information
  • author or maintainer information
  • package publication timestamps
  • package download statistics
  • package ownership information
  • package security information
  • package integrity information such as checksums

Package source code and package files may be publicly accessible when you publish them to a public registry. Do not publish passwords, private keys, API tokens, personal secrets, or confidential information inside packages.

2.4 Technical Information

When you access our websites or services, we may automatically receive limited technical information such as:

  • IP address
  • browser type
  • operating system
  • device type
  • approximate geographic information derived from IP address
  • request timestamps
  • HTTP request information
  • referring page
  • requested URL
  • response status
  • basic diagnostic information

We use this information primarily for security, abuse prevention, debugging, reliability, performance monitoring, and service operation.

2.5 Logs

Our infrastructure may generate operational logs. Logs may contain:

  • timestamps
  • IP addresses
  • request information
  • user-agent information
  • service events
  • error information
  • authentication events
  • security events

Logs are used to operate and secure the Services.

2.6 Cookies and Similar Technologies

The Services may use cookies or similar technologies. Cookies may be used for:

  • authentication
  • session management
  • security
  • preferences
  • functionality
  • analytics, where enabled

We will not use cookies for purposes inconsistent with this Privacy Policy. Where legally required, we will provide appropriate consent controls for non-essential cookies.

2.7 Information You Provide Voluntarily

You may provide information when you:

  • create an account
  • publish a package
  • contact us
  • submit a bug report
  • submit a security report
  • participate in discussions
  • contribute code
  • submit documentation
  • request support
  • subscribe to communications
  • interact with our Services

You should avoid submitting sensitive or confidential information unless it is specifically required and appropriate.

3. How We Use Information

We may use information to:

  • provide the Services
  • create and manage accounts
  • authenticate users
  • operate the package registry
  • distribute packages
  • process package publications
  • maintain package ownership
  • provide documentation
  • provide support
  • process requests
  • prevent abuse
  • detect malicious activity
  • protect infrastructure
  • investigate security incidents
  • maintain system reliability
  • diagnose errors
  • monitor performance
  • improve the Services
  • develop new features
  • comply with applicable legal obligations
  • enforce applicable terms and policies

We do not sell personal information to advertisers.

4. Legal Bases for Processing

Where applicable law requires a legal basis for processing personal information, we may rely on:

  • performance of a contract
  • legitimate interests
  • consent
  • compliance with legal obligations
  • protection of users, infrastructure, and services

The applicable legal basis depends on the type of information and the circumstances of processing.

5. Public Information

Some information submitted to public NextViper services may become publicly accessible.

For example, package registry information may include:

  • package name
  • package description
  • version
  • package files
  • documentation
  • author/maintainer information
  • repository information
  • license
  • release history

Do not publish information that you do not want to become public.

6. Package Registry Privacy

The NextViper package registry is designed to distribute software packages. Public package information may be indexed, cached, mirrored, or downloaded by third parties.

Once information has been publicly distributed, we cannot guarantee that all copies can be removed from third-party caches or mirrors.

7. Contributions

NextViper is an open-source project. If you contribute through a public repository, issue tracker, pull request, or public discussion, information associated with your contribution may be publicly visible.

This may include:

  • username
  • profile information
  • contribution content
  • commit history
  • pull requests
  • issue comments
  • documentation contributions

Do not include private information in public contributions.

8. Third-Party Services

The Services may rely on third-party infrastructure providers. Examples may include providers for:

  • cloud hosting
  • databases
  • authentication
  • content delivery
  • source-code hosting
  • package storage
  • email
  • analytics
  • monitoring
  • security

Third-party providers may process information on our behalf where necessary to provide the Services. We require appropriate safeguards from service providers where applicable.

9. Third-Party Links

The Services may contain links to third-party websites. We are not responsible for the privacy practices of third-party websites. You should review the privacy policy of any third-party service before providing information to it.

10. Data Security

We use reasonable technical and organizational safeguards designed to protect information. Security measures may include:

  • encryption in transit
  • secure authentication
  • password hashing
  • access controls
  • least-privilege access
  • security logging
  • monitoring
  • backups
  • infrastructure isolation
  • dependency security
  • vulnerability management

No internet service can guarantee absolute security. You should use strong passwords and protect your credentials.

11. Passwords and Credentials

We will not intentionally store passwords in plaintext. Users are responsible for protecting:

  • passwords
  • API tokens
  • package publishing tokens
  • private keys
  • access credentials

Never commit credentials to source repositories. If you believe your credentials have been compromised, change or revoke them immediately.

12. Data Retention

We retain information only for as long as reasonably necessary for the purposes described in this Privacy Policy, including:

  • providing the Services
  • maintaining security
  • resolving disputes
  • complying with legal obligations
  • enforcing agreements
  • maintaining necessary business records

Retention periods may vary depending on the type of information.

13. Account Deletion

Where account deletion is supported, you may request deletion of your account. Certain information may need to be retained where required for:

  • security
  • fraud prevention
  • legal obligations
  • dispute resolution
  • accounting
  • enforcement
  • legitimate technical reasons

Public package releases may not be automatically deleted merely because an account is deleted. Package ownership and release history may need to remain available to preserve ecosystem integrity.

14. Public Package Releases

Because package releases may be dependencies of other software, released package versions may be immutable. Deleting an account does not necessarily mean previously published public packages will disappear.

Problematic packages may instead be:

  • yanked
  • marked unavailable
  • blocked from new installation
  • associated with a security advisory

depending on the registry's capabilities.

15. Children's Privacy

The Services are not intentionally designed to collect personal information from children where prohibited by applicable law. We do not knowingly collect personal information from children in circumstances where such collection is prohibited.

If you believe a child has provided personal information improperly, contact us using the official contact method listed on our website.

16. International Data Transfers

Nuratix and its service providers may operate infrastructure in multiple countries. Your information may therefore be processed in countries other than the country in which you live. Where required by applicable law, appropriate safeguards will be used for international transfers.

17. Your Privacy Rights

Depending on your jurisdiction, you may have rights concerning your personal information. These may include:

  • access
  • correction
  • deletion
  • restriction
  • objection
  • portability
  • withdrawal of consent
  • complaint to a data protection authority

The availability of these rights depends on applicable law. To request privacy assistance, use the official contact information published by Nuratix.

18. How to Contact Us

For privacy questions or requests, use:

19. Security Reports

Security vulnerabilities should not be publicly disclosed before a reasonable opportunity exists to investigate and address them. Security reporting instructions are available at:

Do not include passwords, private keys, API tokens, or other secrets in vulnerability reports.

20. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. When changes are made, we will update the "Last Updated" date. Material changes may be communicated through appropriate channels where required by law.

Your continued use of the Services after an update means that the updated policy applies to future use, subject to applicable law.

21. Open-Source Software

NextViper is open-source software. The open-source license governs rights to use, modify, and distribute the software. This Privacy Policy governs information processed by Nuratix's websites and services.

The open-source license does not automatically grant access to private services, user accounts, databases, infrastructure, or confidential information.

22. No Sale of Personal Information

We do not sell personal information to third-party advertisers. We may disclose information to service providers where reasonably necessary to operate the Services.

23. Abuse and Security

We may process information to detect and investigate:

  • malicious activity
  • unauthorized access
  • abuse
  • fraud
  • attacks
  • malware distribution
  • package abuse
  • attempts to compromise infrastructure

This may include analyzing technical logs and security events.

24. Legal Disclosure

We may disclose information where reasonably necessary to:

  • comply with applicable law
  • respond to lawful requests
  • protect users
  • protect Nuratix
  • investigate security incidents
  • enforce agreements
  • prevent fraud or abuse

We will seek to limit disclosures to what is reasonably necessary where permitted by law.

25. Accuracy

We take reasonable steps to maintain accurate account information, but users are responsible for keeping information they provide accurate where appropriate.

26. Contact and Questions

If you have questions about this Privacy Policy or privacy practices, please use the official contact mechanism available at:

Copyright © 2026 Nuratix LLC. All rights reserved, except as provided by the applicable open-source license.