NALV
Privacy Policy
NALV provides behavior verification for AI customer-support agents. This policy explains how NALV handles information when you connect and use the NALV Dify plugin.
Last updated: September 1, 2026
Overview
Using the plugin sends verification data from Dify to NALV's hosted service over HTTPS so NALV can manage the connection, run behavior checks, store evidence and run artifacts, and return results for inspection.
Information processed
Depending on how you use the plugin, NALV may process:
- The selected Dify app identifier (app_id) and app mode
- Frozen test or check turns issued for the requested verification
- Observed assistant replies from the selected Chatbot or Chatflow
- The Dify conversation identifier and NALV job or execution identifiers needed for the verification
- An adapter or infrastructure error code and message text when a Dify reverse invocation fails
The plugin does not collect billing data or send Dify workspace API keys to NALV.
Test content and observed replies may contain personal information, such as names, order details, addresses, or similar information, if users or connected systems include it in the conversation. NALV processes that content as part of the requested verification. The plugin does not automatically detect or remove it.
How information is used
NALV uses this information to establish and manage the Dify connection, execute the requested behavior verification, store evidence and run artifacts, and present results that you can inspect.
Connections and authentication
Connect NALV uses Google OpenID Connect, limited to the openid and email scopes. NALV receives your Google subject identifier and email to create or reuse a personal workspace and connect your account. The plugin does not request Gmail, Drive, Contacts, or Calendar access. Google credentials never enter the plugin.
Connection setup uses a short-lived connect session that the plugin exchanges with NALV server-to-server. The browser never receives a NALV connection key.
Storage and credentials
NALV persists workspace-scoped check jobs, evidence, and run artifacts so you can inspect verification results later. Connection credentials are handled as follows:
- Persisted NALV server-side connection credentials are stored as hashes, not raw secrets.
- The scoped NALV connection token may be stored in Dify plugin storage so it can authenticate requests.
- A temporary connection secret may be stored during connection setup and is removed after successful completion or a terminal expiry or error.
- An optional manual connection credential may be stored as a Dify-managed secret setting.
- A connection credential supplied for an individual advanced request is used only for that request and is not persisted by the plugin.
Dify provides and manages the plugin storage used for the connection token.
Third-party service providers
NALV may use third-party AI or model service providers when semantic evaluation is required. In those cases, the check statements and conversation evidence needed for the evaluation may be processed by those providers under their applicable terms and privacy practices.
The Dify plugin itself does not call third-party model APIs.
Your choices
You can disconnect NALV from Dify. Disconnecting removes the plugin-stored connection and asks NALV to revoke the scoped connection token on its service.
NALV does not currently publish a fixed retention period for plugin-generated verification data or provide a self-service deletion control.
Contact
Privacy questions can be sent to privacy@nalv.ai.