Effective September 22, 2026
Novaya ("we", "us") makes Novgraph, a hosted context API that
turns a codebase into a queryable graph, and Nexus, a coding agent
built on it. This policy covers trynovaya.com,
app.trynovaya.com, api.trynovaya.com,
login.trynovaya.com, which handles sign-in and OAuth callbacks, the
downloadable Novgraph client, and the data processed through those services.
The short version. Novgraph temporarily reads an authorized remote repository to build a derived graph. Repository contents exist in an ephemeral checkout while that job runs, then the checkout is deleted. The hosted database retains the graph, not a source-code archive.
The sections below state the current product boundaries. Where this summary and the detail differ, the detail governs.
Novgraph's knowledge-graph engine, indexing runner and Context API are hosted by Novaya. The graph engine is proprietary and is not currently available for customer self-hosting. The downloadable Novgraph client runs on your machine only to store the Context API credential outside repositories, connect supported coding agents, and relay their graph requests to the hosted API. It uses Windows DPAPI, macOS Keychain or Linux libsecret where available, with a per-user file restricted to that user as the fallback. Installing the client does not create a local graph engine or a local index.
Signing in and authorizing repository access are separate actions. Connecting GitHub or GitLab opens that provider's own consent screen. Novgraph uses the grant to list repositories, create or refresh a temporary checkout for indexing, read repository history and files, and maintain a push webhook where supported. Indexing never writes to your repository. It reads history and files and changes nothing.
A hosted agent run is the one feature that writes, and only when you
start one. A run edits files inside its own temporary checkout, pushes
those edits to a new branch it creates, and opens a pull or merge request for you to review.
It cannot do anything else to the repository: branch names are generated by
Novgraph and always begin with nexus/, a push to any other branch is
refused rather than merely discouraged, --force and
--force-with-lease are absent from the code entirely, and each branch
name carries a timestamp so one run cannot overwrite another's proposal. Novgraph
does not commit to your default branch, overwrite an existing branch, rewrite
history, or merge a pull request. Reviewing and merging stay with you.
The provider scopes are broader than those operational actions.
GitHub's OAuth application requests repo read:user. GitHub's
repo OAuth scope can authorize both read and write access to private
repositories; GitHub does not offer this OAuth application a private-repository
read-only equivalent. GitLab requests api read_repository; the API
scope is used to manage the push hook. These credentials therefore should not be
described as technically read-only. Indexing uses them only to read; the write
described below is limited to a new branch and a pull or merge request. You can
revoke the grant at the provider at any time.
For indexing, the runner clones the authorized repository into temporary filesystem space, reads it, and deletes the checkout when the job ends, including when the job fails. Repository content is therefore transferred to and temporarily present on Novaya infrastructure during indexing. It is not retained as a source archive or written into the hosted graph database. If you have configured a model key for relation enrichment, excerpts of that file text are also sent to your chosen model provider during indexing; see Data policy. When the dashboard opens one file, that path is fetched from the Git host and passed through without application caching.
Novgraph does not currently index a purely local repository without transferring source or providing repository access. The hosted runner indexes a connected GitHub or GitLab repository. Code that exists only in a local working tree — including unpushed branches and uncommitted edits — stays on that machine and is not included in the hosted graph. A team requiring local-only or customer-hosted indexing should treat that as an unsupported deployment requirement today.
Everything Novgraph holds is used to serve your own account, and nothing else. The graph, recorded why-history, conversations, activity and usage records exist to answer that account's queries, compute its architecture and savings views, enforce its plan limits, diagnose failures and improve retrieval quality for it. Every stored record is account-scoped and every query is filtered by account.
What leaves the graph, and what does not. An ordinary Context API call is answered from your own stored projection and sends nothing to a third party. Two features do send data onward, both to a provider you chose, under the model key you supplied:
The embedding used to search recorded why-history is computed on Novaya's own servers with a self-hosted model. That text is not sent to a third-party embedding service.
Access. No product surface exposes one account's graph, conversations or activity to another account. The operational endpoints available to Novaya return aggregate service statistics and recorded server errors, not customer graph or conversation content. Access to the underlying systems is limited to operating and supporting the service, and to what applicable law requires.
Nothing in the list below has an automatic time-based expiry unless the entry says so. Each item is held until you delete the codebase it belongs to, delete the account, or use the specific control named for it.
For each Context API call, Novgraph can record the tool or verb, a short target such as a file path, symbol or query label, timestamp, latency, success or failure, returned-token estimate, deduplicated-token estimate, baseline-token estimate, and the account and Context API key that made the call. We use these records to show account activity and estimated context savings, enforce usage limits, diagnose failures and improve retrieval quality. They do not contain complete source files, but targets can reveal repository paths, symbol names or short query text.
Novaya does not run advertising and does not load third-party analytics or tracking scripts on the website. There is currently no self-service opt-out from service telemetry because it supports authentication, limits, reliability and the usage information shown to the account owner.
httpOnly session cookie valid for
up to 30 days. GitHub sign-in does not itself authorize repository access.Dropping a codebase from the dashboard deletes that codebase's graph structure, summaries, relationships, embeddings and recorded why-history from the live database. It also cancels outstanding indexing or embedding jobs for that codebase and, when it is the last graph for that repository, removes the repository's live-sync subscription so an old job or later webhook cannot recreate it. It does not modify the repository at its Git host. If you deliberately index the repository again later, Novgraph builds a fresh graph and establishes a new live-sync subscription. The fresh index can rebuild structure from the repository, but it cannot reconstruct reasoning that agents recorded only in Novgraph. Dropping a graph does not by itself revoke the Git-host grant, remove Context API keys or erase account-level activity; use the separate controls for those records. Backup limitations are described under Data retention.
You can also delete individual conversations, clear all conversations, remove model keys, revoke Context API keys, disconnect a Git host, or revoke the host grant at the provider. The separate Delete account control removes the account and its graphs, conversations, credentials, settings, sessions and application activity from the live service. It also signs the browser out. An authorization granted at a Git provider must still be revoked at that provider. Backup limitations are described under Data retention.
The self-service account export downloads account identity, preferences, masked model-key metadata, model roles, connected-host names, device records, codebase inventory and usage status. It does not include reusable credentials or source code.
Each codebase has a separate self-service graph export. It is a versioned JSON document containing codebase provenance, file and symbol metadata, relationships, co-change edges, architecture hubs and recorded why-history. It does not contain source files, reusable credentials, embedding vectors, query-vector caches, or Novaya's proprietary ranking and graph-construction logic. Exporting a graph does not delete or otherwise change it.
A free account can connect up to five codebases and make up to 1,000 hosted Context API calls in each 30-day account period. Plus and Pro increase those limits. Monthly and annual subscriptions use the same 30-day allowance windows; unused calls do not roll over. Re-indexing an existing codebase does not create an additional codebase. Novaya does not meter or charge by tokens returned. Charges from a model provider, Git host or other service you connect remain between you and that provider.
Polar is Novaya's merchant of record and processes checkout, payment methods, taxes, invoices, refunds, and subscription management. Polar may collect your name, email, billing address, tax information, and payment details under its own privacy policy. Novaya does not receive or store your complete card number. We retain the Polar customer and subscription identifiers, selected plan, subscription status and signed billing-event history needed to grant access, prevent duplicate checkout, support cancellation through the paid period, and reconcile account deletion.
Querying the Novgraph Context API does not require a model-provider key. Nexus model features are bring-your-own-key. Those hosted model calls originate from Novaya's servers using the stored encrypted key; their contents go to the provider you chose and are governed by that provider's terms and privacy policy. What is and is not sent to a model provider, and the limits on how Novaya uses data held in the graph, are described under Data policy.
Our servers and websites are hosted on Render; the Context API and indexing runner run in Render's Oregon region, in the United States, so data processed by the hosted service is processed there wherever you are. Transactional email, including sign-in codes, is sent through Resend. Beyond those processors, Polar handles checkout and subscription records as merchant of record. Data also goes to services you choose and connect, including your Git host and model provider. We do not sell or rent personal information.
Depending on where you live, you may have rights under laws such as the GDPR or CCPA. We honor valid requests to access, correct, export or delete personal data we hold. Codebase graph export and live-service account deletion are available through the separate self-service controls described above. Write to the contact address below for other privacy requests.
Novaya is not directed to children under 16, and we do not knowingly collect their personal information.
We will update this policy as the product changes. Material changes will be reflected by the effective date above and, where appropriate, noted in the product or on this page.
Questions about privacy: shourya@trynovaya.com.
Novaya is an independent software project (not a registered company).