Privacy Policy
Last updated: August 23, 2026
Overview
Nyami ("we", "us", "our") operates nyami.cc and provides a service that compiles, encrypts, and hardens Python code against reverse engineering. This policy explains what we collect, why we collect it, how we store it, and the choices you have.
This policy describes real data handling for the current version of Nyami, which runs on a metered credits model. It replaces any prior version. If you do not agree with this policy, do not use the service.
Information We Collect
Account Information
- Email address and username, which are required to create an account.
- An optional display name.
- A password, which we store only as a salted one-way hash. We never store your password in readable form and cannot recover it.
- Account role, email-verification status, and the date you accepted our terms.
Sign-In With Discord
- If you sign in with Discord, we store your Discord account identifier and Discord username to link and authenticate your account.
- We do not receive or store your Discord password.
Credits, Plans, and Billing
- Your credit balances, the plan or pack each balance came from, how many credits were granted and remain, and when each balance started and expires.
- An append-only credit ledger that records when credits were granted or consumed and how many. These ledger rows never contain your file names, file sizes, or file contents.
- Subscription and business records used for accounting and fraud prevention, which may include plan changes, amount and currency of a purchase, country, and referral or campaign parameters captured at sign-up.
- Purchases are completed through our storefront and its payment processor. We receive confirmation and plan details, not your full payment-card number.
Files You Submit for Obfuscation
- The file you upload and the protected output generated from it, stored in encrypted object storage for the time needed to run the job and let you download the result.
- Limited job metadata for API jobs: the original file name, input and output file sizes, status, and timestamps. This lets the API function and lets you see your job history.
- We do not read, analyze, sell, or reuse the contents of your code for any purpose other than performing the obfuscation you requested and returning the result.
API Keys
- We store only a one-way hash of each API key plus a short non-secret prefix, its name, and usage counters. The full key is shown once at creation and cannot be retrieved afterward.
Technical and Security Data
- Security audit records for sensitive actions, which may include your IP address, the action taken, and the time.
- Rate-limiting counters used to protect the service from abuse.
- Country and campaign parameters captured at registration.
How We Use Information
- To create and secure your account and authenticate you.
- To run obfuscation jobs and deliver their results to you.
- To meter and display your credit balances and usage.
- To process purchases, honor redemption codes, and manage plans.
- To prevent fraud, abuse, and unauthorized access, and to keep security audit records.
- To send account emails such as verification and password reset.
- To comply with legal, tax, and accounting obligations.
How Obfuscation Is Processed
- The obfuscation engine runs only on our dedicated processing infrastructure. It never runs in your browser and never runs on the public website tier.
- Files are transmitted and stored in encrypted form and retrieved through a controlled proxy.
- Usage graphs are built only from timestamps and credit counts, so they show when work happened and how much, never what was in your files.
Service Providers
We rely on a small number of processors to run the service. They process data only to provide their function to us:
- Website hosting.
- A managed PostgreSQL database for account, credit, and audit records.
- Encrypted object storage for submitted files and generated outputs.
- Discord, for optional sign-in and for our bot.
- An email provider for account emails.
- Our storefront and its payment processor for purchases.
Data Retention
- Account, credit, subscription, and audit records are kept for as long as your account exists and for as long as needed for accounting, tax, security, and fraud-prevention purposes.
- Submitted files and their generated outputs are retained only as long as needed to run the job and deliver the result to you, after which they are removed from active storage.
- When you delete your account, your associated records are removed, except where we must retain limited information to meet a legal obligation or resolve a dispute.
Cookies
- We use essential cookies to keep you signed in and to protect the service. These are required for the site to function and cannot be disabled while you are logged in.
- We do not sell your data and do not use it for third-party advertising.
Security
- Passwords and API keys are stored only as one-way hashes.
- Files are stored and transmitted in encrypted form.
- Access to sensitive actions is rate-limited and recorded in security audit logs.
- No system is perfectly secure. You are responsible for keeping your password and API keys confidential and for keeping your own backups of your source files.
Your Rights and Choices
- You can view and update your account details from your settings.
- You can delete your account, which removes your associated records as described above.
- You can revoke API keys at any time from your dashboard.
- You can contact us to ask about the data we hold about you or to request its correction or deletion, subject to legal limits.
Children
Nyami is not directed to children and is not intended for use by anyone under the age required to form a binding contract in their country of residence. If you believe a child has provided us with personal data, contact us so we can remove it.
Changes to This Policy
- We may update this policy from time to time.
- Material changes will be posted on this page with a new date, and your continued use of the service after a change constitutes acceptance of the updated policy.
Contact
For privacy questions or requests, contact us at projectnyami@proton.me or through our Discord. Purchases are handled at our storefront.
This policy reflects our commitment to collecting only what the service needs, keeping your files private, and metering usage by time and count rather than by content.