Return to Enclave Nexus Console
Legal Governance

Privacy
Statement

Effective Date: June 4, 2026
Enclave Nexus AI is a secure, browser-native local-first data intelligence and analytical console owned and operated by Sierra Holdings Inc. We are committed to maintaining the absolute data residency and privacy of our users. This Privacy Statement outlines our rigorous data protection practices, local storage models, and compliance mappings.

01 Introduction & Scope

This Privacy Statement applies to all users of Enclave Nexus AI (the "Application" or "Software") globally. It describes how Sierra Holdings Inc. ("we," "us," or "our") processes, protects, and respects your information when you run the Application on your localized workstation hardware.

Unlike traditional software-as-a-service (SaaS) tools, Enclave Nexus AI is built on a decentralized local-first architecture. This design dramatically minimizes the volume of personal data sent to our servers, keeping you in complete control of your analytical assets.

02 Local-First Client Architecture & Data Residency

All core calculations, SQL query runs (using DuckDB WebAssembly), and local AI processing execute entirely inside your device's browser sandbox.

Your private database records, prompt queries, workspace schemas, and operational results remain strictly local on your physical machine. They are never transmitted to, cached by, or stored on Sierra Holdings Inc.'s servers.

We do not own, maintain, or operate cloud storage repositories that host your analytics files, schemas, or databases. The physical residency of your datasets is governed solely by your device's browser sandbox settings.

03 Information We Collect & Process

Because of our local-first architecture, the information collected is strictly separated between what stays on your device and what is processed for licensing and operations:

  • Billing & Account Details (Server-Side): Subscription transactions, payment data, and invoices are managed securely by our payment processor, Stripe. Sierra Holdings Inc. receives billing metadata (such as customer email, payment confirmations, and active licenses) to validate software subscription access.
  • Workstation Credentials & Configurations (Local-Only): Credentials, passwords, and API keys used for custom connections are stored locally in the browser's encrypted vault and are never routed to our network servers.
  • System Telemetry & Monitoring (Optional): If you configure out-of-band telemetry streaming (e.g., to corporate SIEM endpoints), this data routes directly from your browser to your specified logging endpoint. We do not intercept or monitor this stream.
  • Technical Error Logs (Diagnostic-Only): If the application encounters an execution error, a localized anonymized report (containing details such as browser version, operating system, and a generic error type) may be generated to help resolve the issue. These logs never contain actual data rows, tables, or prompt queries.

04 Bring Your Own Key (BYOK) Data Safeguards

Enclave Nexus AI allows you to connect third-party AI reasoning models directly in-browser using your own private API keys (BYOK model).

These API keys are encrypted locally using AES-GCM (256-bit) and stored inside your browser's private IndexedDB storage.

All API requests to AI reasoning engines are routed directly from your local browser client to the respective AI provider's endpoints. Sierra Holdings Inc. does not proxy, read, store, or log these requests. You can also bypass cloud APIs entirely by running offline models locally via WebGPU or Ollama connections.

05 Third-Party Data Connections & Integrations

The Application allows optional direct connections to third-party databases, cloud data warehouses, and web-based storage solutions.

All authentication handshakes (such as OIDC/SAML tokens) and analytical queries are executed directly from your workstation device. You are responsible for ensuring that all external data integrations comply with your organization's internal security guidelines, compliance thresholds, and the respective third-party terms.

06 How We Use Your Information

We use the minimal administrative data we collect solely for the following purposes:

  • To activate, manage, and validate software subscription license keys.
  • To securely process payment transactions via Stripe.
  • To respond to user customer support inquiries.
  • To audit software installation volumes and prevent unauthorized licensing abuse.
  • To debug technical runtime failures (via anonymized error logs).

07 Information Sharing & Disclosures

Sierra Holdings Inc. does not sell, rent, lease, or trade your personal data to any third party under any circumstances.

We only share administrative details with trusted subprocessors strictly under confidentiality and data protection agreements, including Stripe (payment processing) and Auth0 (identity verification and login support).

We may disclose minimal account data if required to do so by law, court order, or regulatory request, or in connection with a corporate sale, merger, or acquisition of assets.

08 Workstation-Level Cookies & Local Storage

We do not place tracking, targeting, or advertising cookies on your machine.

We use standard browser-native storage utilities (such as IndexedDB, localStorage, and the Origin Private File System) exclusively to keep your custom analytical workspaces, data models, layout settings, and encrypted credentials persistent across visits. These elements reside strictly on your device and are never sent back to our servers.

09 Security Standards Alignment

To ensure maximum security for your local workspace, the software aligns with the following standards:

  • FIPS 140-2 Cryptography: Exported workspaces are package-encrypted in highly compressed, AES-GCM (256-bit) local binary archives.
  • NIST SP 800-63B Guidelines: Support for secure OIDC/SAML tokens and secure browser storage of session identifiers.
  • Tamper-Evident Local Logging: Locally audited events are cryptographically signed with SHA-256 HMAC keys to verify sequence integrity.

10 Data Retention & Erasure Protocols

You can wipe all local databases, schemas, configurations, and API keys instantly by clicking the "Clear Workspace" button in the application settings, or by manually clearing your browser cache.

Administrative subscription and billing data is retained on our servers for the duration of your license, plus any legally required retention periods under tax and accounting laws.

11 Your Regional Privacy Rights (GDPR Compliance)

For users residing in the European Economic Area (EEA), United Kingdom, or Switzerland, you possess the following rights under the General Data Protection Regulation (GDPR):

  • Right of Access & Portability: You can request details of the administrative data we hold about you.
  • Right to Rectification: You can request corrections to inaccurate account details.
  • Right to Erasure ("Right to be Forgotten"): You can request the deletion of your account and billing records.
  • Right to Restrict or Object: You can object to certain administrative processing operations.

To exercise these rights, please contact our data protection desk at [email protected].

12 California Privacy Rights (CCPA / CPRA)

Under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA), California residents have specific rights regarding their personal information:

  • Right to Know: Request disclosure of the personal data collected and how it is processed.
  • Right to Delete: Request the deletion of collected personal information.
  • Right to Correct: Request correction of inaccurate personal information.
  • Right to Opt-Out of Sale or Sharing: Confirming that Sierra Holdings Inc. does not sell or share personal information.
  • Right to Non-Discrimination: We do not discriminate against you for exercising CCPA/CPRA rights.

California users can submit requests by emailing us at [email protected].

13 Children's Privacy

Enclave Nexus AI is built strictly for professional use by individuals 16 years of age or older. We do not knowingly collect or request personal information from children under the age of 16. If we learn we have collected data from a child under 16, we will delete it immediately.

14 Changes to this Policy

We may update this Privacy Statement periodically. Significant updates will be posted directly to this URL, and the "Effective Date" at the top will be updated accordingly. We encourage you to review this page regularly.

15 Contact & Inquiry Details

For general questions, billing inquiries, or to exercise your privacy rights, please contact:

Sierra Holdings Inc.
Legal Compliance Desk
Email: [email protected]