legal record · v2026-09-03
Argus Privacy Notice
How NovAI Limited collects, uses, shares, protects and retains personal data when you use Argus.
- Effective date
- Notice version
- 2026-09-03
1. Scope and controller
NovAI Limited, Hong Kong, is the controller of personal data described in this Notice ("NovAI", "we", "us" or "our"). This Notice applies to the Argus website, CLI, APIs, MCP endpoints, Casdoor-hosted authentication pages, documentation, support and related services.
This Notice does not govern the independent practices of GitHub or third-party data sources. If we process personal data solely on behalf of an enterprise customer under a separate agreement, that agreement may define the parties' roles and takes precedence for that processing.
2. Data we collect
- Account data: username, email address, display name, avatar, account status, password hash (never the plaintext password), verification status and account timestamps.
- GitHub registration data: GitHub user identifier, login name, display name, avatar and email information returned under the read:user and user:email scopes. Argus does not request repository-content access for sign-in.
- Authentication and security data: sign-in method, session and token metadata, provider link, failed sign-in events, timestamps, IP address, user agent and similar security logs. OAuth access and refresh tokens are handled by the identity service; the Argus CLI stores its token set locally in the operating-system credential store.
- Argus service and audit data: a Casdoor issuer/subject mapping, derived caller identifier, institution identifier, tool name, interface, stated purpose, bounded input and output summaries, policy decisions, evidence summaries, status and timestamps. Secrets and bearer tokens are redacted from audit payloads.
- Support data: your email address and any information you choose to include when contacting us. Never send credentials or unnecessary sensitive information.
- Website and aggregate data: ordinary server request logs and privacy-thresholded aggregate service-usage counts. The public website currently does not use third-party behavioural advertising or analytics trackers.
3. How we obtain data
We obtain data directly from you, from your browser or CLI when you use the Service, from GitHub when you choose GitHub registration or sign-in, from our self-hosted authentication and service infrastructure, and from an organisation that has authorised your access.
4. Why we process data
- Provide accounts, authentication, authorised tools, support and requested Service functionality; this is necessary to perform our agreement with you or take steps at your request.
- Protect accounts, prevent abuse, enforce permissions and licences, investigate incidents, maintain reliable audit trails and improve operational security; these are our legitimate interests and may also satisfy legal obligations.
- Send verification codes, password-reset messages, security notices and material service or policy notices; these are necessary for the Service or our legitimate interests.
- Comply with law, court orders and valid government requests, and establish, exercise or defend legal claims.
- Process optional communications or another purpose with your consent where consent is required. We do not treat acceptance of this Notice as consent for unrelated marketing.
5. Cookies and local storage
The authentication service may use strictly necessary cookies or equivalent browser storage to maintain a secure sign-in session, remember a requested language, prevent request forgery and complete OAuth redirects. The public documentation site does not currently set advertising cookies or use third-party behavioural analytics. If we introduce non-essential cookies, we will update this Notice and request consent where required.
The CLI stores OAuth credentials on your own device using the operating-system credential store. You can remove them with argus auth logout. Environment variables or machine credentials you configure remain under your control.
6. When we share data
We do not sell personal data and do not share it for cross-context behavioural advertising.
- GitHub, when you choose GitHub authentication, to complete the OAuth flow. GitHub processes data under its own privacy notice.
- Infrastructure, security, email-delivery and technical service providers that process data for us under appropriate confidentiality and data-protection obligations.
- Professional advisers, auditors, insurers and authorities where reasonably necessary and lawful.
- A successor in a merger, financing, restructuring or sale, subject to confidentiality and applicable notice requirements.
- Other parties when you direct us to share data or give valid consent.
7. International transfers
Argus is operated from Hong Kong and service providers or users may be located elsewhere. Personal data may therefore be processed outside your country. Where required, we use an applicable adequacy mechanism, contractual safeguards or another lawful transfer mechanism and assess the protections available in the destination.
8. Retention
Privacy-thresholded aggregate statistics that no longer identify a person may be retained indefinitely.
- Account and identity data: while the account is active, then for the time reasonably needed to complete deletion, prevent fraud, resolve disputes and meet legal obligations.
- Argus tool audit records: normally 365 days under the current production policy, unless a shorter period is required or a longer period is lawfully necessary for an incident, claim or legal hold.
- Authentication and web server security logs: for a limited period proportionate to security and operational needs.
- CLI credentials: on your device until logout, removal by you, expiry or revocation.
- Support records: for as long as needed to handle the request and maintain a reasonable record of the resolution.
- Backups: until overwritten under the applicable backup cycle; deleted data is not restored to active use except for disaster recovery and will be deleted again.
9. Security
We use measures designed to protect personal data, including HTTPS, asymmetric token validation, short-lived access tokens, PKCE for the public CLI, operating-system credential storage, least-privilege service boundaries, secret redaction and access-controlled audit records. No method of storage or transmission is completely secure, so we cannot guarantee absolute security.
10. Your choices and rights
Rights vary by jurisdiction and may be subject to exceptions. Send requests to [email protected]. We may ask for proportionate information to verify your identity and will respond within the period required by applicable law.
- Access personal data we hold about you and receive information about its use.
- Correct inaccurate or incomplete account data.
- Request deletion, restriction or objection where applicable.
- Receive portable data where the law provides that right.
- Withdraw consent without affecting processing already carried out lawfully.
- Unlink or revoke GitHub access through GitHub and request deletion of the Argus account.
- Complain to the data-protection authority in your place of residence or work.
11. Automated processing
Argus automatically evaluates authentication, permissions, rate limits, data licences and output policies to allow or deny tool requests. These controls protect the Service and do not make credit, employment, insurance or other decisions that produce legal or similarly significant effects about you. We do not use account data for behavioural advertising or sell it to data brokers.
12. Children
The Service is intended for adults and is not directed to anyone under 18. We do not knowingly collect personal data from children. If you believe a child has provided data, contact us so we can investigate and delete it where appropriate.
13. Changes and contact
We may update this Notice to reflect changes in the Service, law or providers. We will publish the effective date and give additional notice for material changes where appropriate.
Privacy questions and rights requests may be sent to: NovAI Limited, Hong Kong; [email protected]. Do not include passwords, tokens or API keys. If you need a postal contact channel for a formal request, ask by email and we will provide the appropriate company correspondence details.