What we collect, why we collect it, who we share it with, how long we keep it, and how to make us delete it.
Pyxeon ("Pyxeon", "we", "us") is a software agency based in New York. We design, build, host and continuously improve custom AI-powered applications for small businesses.
This policy covers pyxeon.com, the customer portal at portal.pyxeon.com, the admin console at app.pyxeon.com, our API at api.pyxeon.com, and the email we send.
Contact: support@pyxeon.com
Postal: Pyxeon, 3535 Jerusalem Ave, Wantagh, NY 11793
We handle personal information in two distinct capacities, and your rights differ depending on which applies:
The free consultation tool at pyxeon.com/consultation collects the answers you type — business name, industry, size, the problems you describe, your contact details — plus the messages you exchange with the AI assistant. Submissions are stored in our database and emailed to us.
If you submit an email address through a form on this site, we receive that address and any message you include. Form delivery runs through Formspree.
Account creation, sign-in and session management for the customer portal and admin console run through Clerk. Clerk holds your name, email address, authentication credentials and login metadata (IP address, device, timestamps). We read your identity from Clerk; we never store your password.
Subscriptions and one-time builds are billed through Stripe. Stripe collects and stores your payment card details — we never see or store full card numbers. We retain the Stripe customer and subscription identifiers, plan tier, billing status, and invoice history.
We run a business-to-business outreach program. For that we hold publicly available business contact information (company name, business address, business phone, business website, publicly listed work email addresses, business reviews and public role titles) obtained from sources including Google Places, Yelp, OpenStreetMap, Apollo, Hunter and public websites. We also record engagement events reported by our email provider — deliveries, opens, clicks, bounces, unsubscribes and spam complaints — and any reply you send us. This is business contact data, used to evaluate whether our services are relevant to your business.
Applications we build for customers store whatever that business's workflow requires — which can include client names, contact details, uploaded documents, signatures, appointment records and payment status. Each customer application runs against a separate database. We hold this data on the customer's behalf; see section 12.
Our servers and CDN record standard request logs: IP address, user agent, requested URL, response status, timestamp and a request identifier used for support tracing. We do not run third-party advertising or cross-site tracking pixels on this website.
We do not use your information for automated decision-making that produces legal or similarly significant effects about you.
Read this before typing anything sensitive into an AI feature. When you use the consultation chat, an in-app AI assistant, or any feature that summarises or generates text, the content of that request — including anything you paste into it — is transmitted to a third-party large language model provider so the model can produce a response.
The providers we route AI requests through are OpenRouter (which forwards requests to the underlying model, primarily Anthropic) and Groq. Those providers process the request under their own terms and privacy policies and return a response to us. We do not authorise them to use your content to train their models, and our provider agreements are set up on that basis, but we do not control their infrastructure.
Our automated coding agent also transmits source code, feature requests and test output to these providers in order to plan, write and review changes. Do not place secrets, credentials or information you cannot share with a subprocessor into a feature request.
AI-generated output can be wrong. Where a feature produces a summary, classification or draft, treat it as a draft and not as professional advice.
We share personal information with the following providers, only to the extent each needs it to perform its function for us:
| Provider | What it does for us | Data it can see |
|---|---|---|
| Clerk | Authentication, accounts, sessions | Name, email, credentials, login metadata |
| Stripe | Payments, subscriptions, invoicing | Name, email, billing address, payment card, transaction history |
| Brevo | Outbound email delivery and engagement events | Recipient email, message content, delivery and engagement events |
| Supabase | Managed PostgreSQL hosting for our database and per-customer databases | Anything stored in our or a customer's application database |
| DigitalOcean | Application server hosting | Request logs, application data in transit and at rest on the server |
| Cloudflare | DNS, CDN and hosting for this marketing site | IP address, request metadata |
| Formspree | Website form delivery | Whatever you type into a form, including your email address |
| OpenRouter / Anthropic | Large language model inference for AI features and the coding agent | The content of AI requests and responses |
| Groq | Large language model inference for the consultation chat, enrichment and reply classification | The content of those requests and responses |
We also use MillionVerifier for email-address validation, and Apollo and Hunter for business contact data, in connection with outreach only.
Beyond these providers we disclose personal information only: to you or at your direction; to a business customer whose end users' data we hold; where required by law, subpoena or lawful request; to establish or defend legal claims; or to a successor entity in a merger, acquisition or sale of assets, subject to this policy.
We do not sell personal information, and we do not share personal information for cross-context behavioural advertising. We do not disclose personal information to third parties for their own independent marketing purposes.
Every marketing or outreach email we send includes a working unsubscribe link and an RFC 8058 one-click List-Unsubscribe header, plus our physical postal address, as required by the CAN-SPAM Act.
Unsubscribing from outreach does not stop transactional and service messages to an active customer — billing notices, security notices and request status. Those stop when the account closes.
| Category | Retention |
|---|---|
| Consultation submissions and AI chat | 24 months from submission, unless you ask us to delete sooner |
| Portal account records | For the life of the account, then 90 days after closure |
| Billing and invoice records | 7 years, to meet tax and accounting obligations |
| Outreach contact and engagement records | 24 months from last engagement |
| Suppression list entries | Indefinitely — we must keep them to keep honouring your opt-out |
| Customer application data | For the life of the engagement plus a 30-day export window, then deleted (see section 12) |
| Server and request logs | 30 days rolling |
| Database backups | 7 days rolling |
Deleted records may persist in backups until those backups age out on the schedule above.
We encrypt data in transit with TLS. Access credentials and repository tokens are encrypted at rest. Each customer application runs against a separate database, so one customer's data is not co-mingled with another's. Administrative actions on customer accounts are written to an immutable audit log. Access to production is limited to the founders.
No system is perfectly secure. If we become aware of a breach affecting your personal information, we will notify you and any affected business customer without undue delay and as required by applicable law.
You can ask us to:
Email support@pyxeon.com with the request and the email address or account it concerns. We will verify that the request comes from you or your authorised agent, and respond within 30 days. We do not charge for these requests and we will not discriminate against you for making one.
If your information is in an application we built for one of our business customers, we cannot action a deletion request directly — please contact that business, which is the controller of that data. If you contact us, we will forward the request to them.
When we build, host or maintain an application for a business customer, we act as that customer's service provider and process end-user personal information solely on the customer's documented instructions and for the purpose of delivering the agreed services. We do not use that data for our own purposes, we do not sell it, and we do not use it to train models.
In practical terms this means:
Our services are for businesses. They are not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child has provided us information, write to support@pyxeon.com and we will delete it.
We may update this policy. When we do, we change the "Last updated" date at the top of this page. If a change materially reduces your rights or materially expands how we use your information, we will give active customers notice by email before it takes effect.
This policy and any dispute arising from it are governed by the laws of the State of New York, without regard to its conflict-of-laws rules.
Questions, requests, or a security report:
Email: support@pyxeon.com
Postal: Pyxeon, 3535 Jerusalem Ave, Wantagh, NY 11793
See also our Terms of Service.