Privacy Policy
Last Updated: March 15, 2026
1. Introduction
Ferox AI Inc. ("Ferox AI," "we," "our," or "us"), a corporation registered in Alberta, Canada (operating as 2628965 Alberta Ltd.), operates the Ferox Nodus desktop application and the website located at www.feroxai.ca. This Privacy Policy explains how we collect, use, disclose, and protect personal information in accordance with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), Alberta's Personal Information Protection Act (PIPA), and Québec's Act respecting the protection of personal information in the private sector (Law 25).
By using our Services, you consent to the collection and use of personal information as described in this Policy.
2. Who We Are
Legal name: 2628965 Alberta Ltd. (operating as Ferox AI Inc.)
Privacy Officer: Jordan Toth
Address: Calgary, Alberta, Canada
Privacy inquiries: privacy@feroxai.ca
General inquiries: hello@feroxai.ca
3. Scope of This Policy
This Policy applies to personal information collected through:
- The Ferox Nodus desktop application ("Application")
- The feroxai.ca website ("Website")
- Any communications between you and Ferox AI
This Policy does not apply to information processed entirely on your local device that never leaves your device. Ferox Nodus is designed so that the vast majority of data processing occurs locally.
4. Our Privacy-First Architecture
Ferox Nodus is built on a local-first architecture. Approximately 80% of all AI tasks are processed entirely on your device using on-device models optimized for Apple Silicon. Your documents, conversations, and sensitive data are stored locally and never transmitted to our servers for routine tasks.
When you choose to escalate a query to frontier cloud models, that content passes through a 6-layer PII scrubbing pipeline that detects and replaces personally identifiable information with synthetic tokens before any data leaves your device. This is a user-initiated action, not a default behaviour.
Zero Telemetry: Ferox Nodus contains no analytics, no usage telemetry, no tracking, and no automatic usage reporting. We do not collect or transmit data about how you use the application.
5. Information We Collect
5.1 Information You Provide Directly
- Waitlist / early access registration: Email address (optional, used only for product updates and newsletter)
- Contact form submissions: Name, email address, and message content
- Support correspondence: Information you include in support requests sent to hello@feroxai.ca
5.2 Payment Information
All payment processing for Ferox Nodus subscriptions and cloud credit purchases is handled exclusively by Paddle.com (Paddle Payments Ltd.), our Merchant of Record. Ferox AI does not collect, store, or have access to your payment card information. Paddle's privacy policy governs the handling of payment data.
5.3 Information Collected Automatically
Our Website may collect standard server logs including IP addresses, browser type, referring URLs, and page visit timestamps. This information is used solely for security monitoring and is not used for advertising or tracking purposes.
5.4 Information We Do NOT Collect
| Data Type | Collected? | Notes |
|---|---|---|
| Chat content / AI conversations | No | Stays on your device |
| Documents you process | No | Indexed locally only |
| Usage analytics / telemetry | No | Zero telemetry architecture |
| Crash reports | No | Opt-in only if added in future |
| Payment card details | Paddle | Handled exclusively by Paddle |
| Email address | If provided | Only if you voluntarily submit |
6. How We Use Your Information
We use the personal information we collect for the following purposes:
- To provide, maintain, and improve the Application and Website
- To respond to your inquiries and support requests
- To send you product updates and newsletters (only if you opted in; you may unsubscribe at any time)
- To process subscription payments via Paddle
- To comply with applicable laws and regulations
- To protect the security and integrity of our systems
We do not use your personal information for advertising, profiling, or sale to third parties.
7. Legal Basis for Processing
Under applicable Canadian privacy legislation, we process personal information based on:
- Consent: Where you have voluntarily provided information (e.g., waitlist sign-up, contact form)
- Contractual necessity: To fulfil subscription agreements
- Legitimate interests: For security monitoring and service improvement, balanced against your privacy interests
- Legal obligation: Where required by law
8. Disclosure of Personal Information
We do not sell, rent, or trade personal information. We may share information only in the following limited circumstances:
- Paddle.com: For payment processing. Paddle acts as Merchant of Record and handles all billing independently.
- Cloud AI providers (user-initiated): When you explicitly choose to escalate a query to a cloud model, your scrubbed (PII-removed) query may be transmitted to a third-party AI provider. This is always a user-initiated action.
- Legal requirements: If required by a court order, law enforcement request, or applicable law.
- Business transfers: In the event of a merger, acquisition, or asset sale, with notice provided to you.
9. Data Storage and Canadian Sovereignty
Ferox AI is committed to Canadian data sovereignty. Any server-side infrastructure operated by Ferox AI is located in Canada. Our relay server operates in Toronto, Ontario. No personal data collected by Ferox AI crosses international borders without your knowledge.
On-device data (the vast majority of Ferox Nodus data) is stored exclusively on your device and encrypted using your device's hardware security capabilities. Ferox AI has no access to this data.
10. Data Retention
- Waitlist emails: Retained until you unsubscribe or request deletion
- Contact form submissions: Retained for up to 2 years for correspondence history
- Server logs: Retained for up to 90 days for security purposes
- Payment records: Retained by Paddle per their retention policies; Ferox AI retains only transaction confirmations for accounting compliance
11. Your Rights
Under PIPEDA, PIPA, and Law 25, you have the right to:
- Access: Request a copy of personal information we hold about you
- Correction: Request correction of inaccurate or incomplete information
- Withdrawal of consent: Withdraw consent to certain uses of your information (with possible service implications)
- Deletion: Request deletion of personal information we hold, subject to legal retention obligations
- Complaint: File a complaint with the Office of the Privacy Commissioner of Canada or the Office of the Information and Privacy Commissioner of Alberta
To exercise any of these rights, contact us at privacy@feroxai.ca. We will respond within 30 days.
12. Security
We use appropriate technical and organizational measures to protect personal information against unauthorized access, disclosure, alteration, or destruction. These measures include:
- Hardware-backed encryption for on-device data via Apple Secure Enclave
- 6-layer PII scrubbing before any cloud escalation
- Principle of minimal data collection
- Zero telemetry and zero tracking in the Application
No method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security.
13. Cookies and Tracking
The feroxai.ca website does not use advertising cookies or behavioural tracking technologies. We do not use Google Analytics or similar third-party analytics services that track individual users across sites.
If we implement privacy-respecting analytics in the future (such as Plausible.io, which uses no cookies and no cross-site tracking), we will update this Policy and disclose the change on the Website.
14. Children's Privacy
Ferox Nodus is intended for professional use by adults. We do not knowingly collect personal information from individuals under the age of 18. If you become aware that a minor has provided us with personal information, please contact us at privacy@feroxai.ca.
15. Third-Party Links
Our Website may contain links to third-party websites. We are not responsible for the privacy practices of those sites and encourage you to review their privacy policies independently.
16. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated by posting the updated Policy on the Website with a revised "Last Updated" date. Your continued use of our Services after the effective date of any update constitutes acceptance of the revised Policy.
17. Contact Us
For any questions, concerns, or requests related to this Privacy Policy or your personal information, please contact our Privacy Officer:
Jordan Toth
Privacy Officer, Ferox AI Inc.
Calgary, Alberta, Canada
privacy@feroxai.ca
If you are not satisfied with our response, you have the right to contact:
- Office of the Privacy Commissioner of Canada: www.priv.gc.ca
- Office of the Information and Privacy Commissioner of Alberta: www.oipc.ab.ca