Nimble Privacy Policy
Last updated: October 1, 2026
This Privacy Policy explains how Bespoke Labs, Inc. (“Bespoke Labs,” “we,” “us”) collects, uses and shares personal data when you use Nimble, including the website at nimble.bespokelabs.ai, the Nimble console, and the Nimble API (together, the “Services”). Use of the Services is also governed by the Nimble Terms of Use.
1. Data we collect
Account data. Name, email address, organization name, role, and sign-in details. We authenticate you directly, or through Google sign-in. If you sign in with Google, we receive your name, email and profile image from Google.
Billing data. Billing name and address, tax ID if provided, payment history, credit balance and auto-reload settings. Card details are collected and stored by Stripe; we never see or store your full card number.
API content. The text, labels and label sets you send to the API or playground (“Inputs”) and the classifications we return (“Outputs”). Section 3 explains how we handle API content.
Usage and log data. API keys used (never the full secret), request IDs, timestamps, token counts, latency, error codes, IP address, and console activity such as key creation or member invites.
Device and cookie data. Browser type, device type, operating system, and cookies needed to keep you signed in. We use analytics cookies; see section 8.
Communications. Messages you send to support or sales, and survey answers.
2. How we use data
- Provide, operate and secure the Services, including authenticating you and processing API requests.
- Meter usage, charge for credits, send receipts, and run auto-reload.
- Detect and prevent fraud, abuse, and violations of our Terms.
- Debug issues and provide support.
- Send service messages such as low-balance alerts, security notices, and changes to these terms.
- Send product updates and marketing, which you can unsubscribe from at any time.
- Comply with legal obligations.
3. API content: retention and training
We do not train models on your API content by default. If we offer a data-sharing program, we will use Inputs and Outputs to train or improve Nimble only if your organization opts into our data-sharing program in the console. Opting will earn a discount. You will be able to opt out at any time; data shared before opting out may already be part of a trained model.
Retention. By default we keep Inputs, Outputs and request logs for 30 days, so you can view them in the console and so we can debug problems and investigate abuse. After 30 days they are deleted. An org admin can turn logging off in Settings. When logging is off, we process content only to return a response and do not store it. We still keep request metadata (token counts, timestamps, key ID, status), because we need it to bill you.
Exceptions. We may keep specific content longer if we need it to investigate a security incident or a serious violation of our Acceptable Use Policy, or if the law requires it.
Label sets you save through the API or console are kept until you delete them or close your account.
4. How we share data
We do not sell personal data or share it for cross-context behavioral advertising. We share data only with:
- Service providers who process data on our behalf under contract: Google Cloud and Modal, which runs the models and receives request content, Google sign-in (authentication), Stripe (payments), Twilio (email), Google Analytics, PostHog (analytics provider).
- Your organization. Org admins can see members, API keys, usage, billing, and request logs for their org.
- Legal and safety. When required by law, or to protect the rights, safety and security of users, the public or Bespoke Labs.
- Business transfers. As part of a merger, acquisition, or sale of assets, subject to this Policy.
5. How long we keep data
| Data | Retention |
|---|---|
| API Inputs and Outputs | 30 days by default; not stored if logging is off |
| Request metadata (for billing) | Life of the account + 7 years |
| Account data | Until you delete your account, then 30 days |
| Billing and tax records | 7 years, as required by law |
| Support communications | 3 years |
6. Your rights
Depending on where you live, including the EEA, UK and California, you may have the right to access, correct, delete or export your personal data; to object to or restrict processing; to withdraw consent; and to complain to a data protection authority. Email legal@bespokelabs.ai and we will respond within 30 days. We will not discriminate against you for exercising these rights.
If your organization gave you access to Nimble, your organization controls its API content, and we may refer some requests to your org admin.
7. International transfers
We are based in the United States and process data in the United States. When we transfer personal data from the EEA, UK or Switzerland, we rely on Standard Contractual Clauses or another lawful transfer mechanism.
8. Cookies
We use strictly necessary cookies for sign-in and security. We use analytics cookies from GA and Posthog to understand how the site is used; you can decline them in the cookie banner.
9. Security
We encrypt data in transit (TLS 1.2+) and at rest. API keys are stored only as hashes and shown to you once. Access to customer data is limited to staff who need it.
10. Children
Nimble is not directed to anyone under 18, and we do not knowingly collect their personal data.
11. Changes
We will post changes here and update the date above. For material changes, we will notify org admins by email at least 14 days before they take effect.
12. Contact
Bespoke Labs, Inc., Mountain View, CA. Privacy questions: legal@bespokelabs.ai.