This Privacy Policy explains what information NanometerChip collects through AVERIFY (the "Service"), why, how long we keep it, and the choices you have about it. It applies to everyone who creates or is invited into an AVERIFY organization.
1. Information We Collect
| Category | What it includes |
|---|---|
| Account | Username, email (where provided), password (stored as a salted PBKDF2 hash — we never store or can recover your plaintext password), organization membership and role |
| Content | RTL, specifications, and other inputs you submit, and the testbenches, run results, and coverage data generated from them |
| Billing | Per-run cost and the credit-ledger history for your organization (grants and debits) |
| Admin activity | Role changes, invites, credit grants, and similar actions, recorded in an audit log scoped to your organization |
| Technical | IP address and request metadata, processed transiently for rate-limiting and abuse prevention — not retained as a standing log of your activity beyond what's needed for that purpose |
2. How We Use It
- To provide the Service: running verification, showing history, computing usage and billing.
- To secure accounts: authentication, session management, and detecting abuse (e.g. login rate-limiting).
- To communicate with you: password-reset and email-verification links, invite emails, and service notices sent to organization owners.
- To improve the Service: understanding aggregate usage patterns. We do not use Your Content to train models we operate; see Section 4 for how a third-party model provider handles it.
3. Legal Basis for Processing
We process personal data on the basis of your consent (given when you register or accept an invite), the necessity of processing to perform our contract with you (providing the Service you signed up for), and our legitimate interest in operating and securing the Service. Where the Digital Personal Data Protection Act, 2023 (India) or comparable law applies to you, we process personal data as a Data Fiduciary for these purposes and no others without further notice or consent.
4. Third-Party Sharing
We do not sell personal data. Data is shared with third parties only as needed to run the Service:
- LLM providers — RTL and specification text you submit is sent to the model provider configured for your organization's run, to draft and repair testbenches. That provider processes it under its own data-handling terms; we do not control, and are not responsible for, that provider's independent processing.
- Infrastructure providers — hosting and database infrastructure used to run the Service, bound by confidentiality obligations to us.
- Legal disclosure — if required to comply with applicable law, a valid legal process, or to protect the rights, property, or safety of NanometerChip, our users, or others.
5. Data Retention
We retain account and content data for as long as your organization's account is active. Billing and credit-ledger records tied to a completed run are retained even after the run, the account that created it, or the organization's active membership changes — this mirrors the standard accounting-records exception recognized by data-protection law (including the DPDP Act's exemption for legal and accounting obligations), and reflects our own invariant that an organization's billed total can never be reduced after the fact by deleting history. When retained past deletion, these records are kept solely for financial and legal-compliance purposes, not for any other use.
6. Your Rights and Choices
Depending on your jurisdiction, you may have rights to access, correct, export, or erase your personal data, and to withdraw consent. In AVERIFY these are available directly in the product, not just on request:
- Access & export — an organization owner can export the organization's full data (members, invites, runs, billing ledger, audit log) as JSON from Admin → Organization Settings at any time.
- Correction — update your display name and email from your account settings; contact us for anything you can't change yourself.
- Erasure — any member can delete their own account, which deactivates it and erases personal fields (email, name, password). An organization owner can do the same for a member who has left. In both cases the underlying run and billing records stay attached to the (now-anonymized) account, for the reason in Section 5.
For anything not self-service, email info@nanometerchip.com — this is also our designated contact for grievances and data-principal requests under the DPDP Act, 2023.
7. Security
Passwords are hashed with salted PBKDF2 (not stored or logged in plaintext). Session tokens are signed and time-limited. Login, signup, and password-reset endpoints are rate-limited. No method of transmission or storage is 100% secure; we can't guarantee absolute security, but we work to keep these protections current.
8. Cookies and Local Storage
AVERIFY does not use tracking cookies. Your session token is stored in your browser's local storage, sent only to our own API, and cleared on logout or expiry.
9. Children's Privacy
The Service is intended for business/professional use and is not directed to individuals under 18. We do not knowingly collect personal data from children.
10. International Users
If you access the Service from outside the country where it is hosted, your data will be transferred to and processed there, and (per Section 4) potentially by a model provider located elsewhere. By using the Service you consent to that transfer.
11. Changes to This Policy
We may update this Policy from time to time; material changes will be communicated to organization owners and reflected in the "Effective date" above.
12. Contact
Questions, requests, or grievances regarding this Policy: info@nanometerchip.com.