← Back home

Privacy Policy

Last updated 7 August 2026 · Effective 7 August 2026

In short. Nuntivo publishes your own content to your own social accounts. We store what we need to do that — your account details, the posts you write, the media you upload, and the access tokens you grant us — and nothing else. We do not sell your data, do not use it for advertising, and do not use it to train AI models. You can delete everything yourself at any time (§11).

1. Who we are

Nuntivo (“Nuntivo”, “we”, “us”, “our”) is an independent software product operated by Nazar Leochko, a sole individual developer based in Ukraine, at https://nuntivo.me (the “Service”).

For the purposes of the EU General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”), the UK GDPR, and the Law of Ukraine “On Personal Data Protection” No. 2297-VI, Nazar Leochko is the data controller for the personal data described in this policy.

Contact for anything privacy-related: nuntivo@gmail.com. We are a small operation and answer this address ourselves; we aim to reply within 5 working days and always within the 30 days required by law.

2. Scope and current status

This policy covers the Nuntivo website, the waitlist form on it, and the Nuntivo web application, including everything we do with data obtained from social platform APIs on your behalf.

Current status: closed beta. Nuntivo is pre-launch and access to the application is restricted to an invited allow-list. If you are a member of the public visiting nuntivo.me today, the only personal data we collect from you is the email address you choose to submit to the waitlist (§3.1) — none of the other processing described below applies to you unless and until you create an account and connect a platform yourself. We publish the full policy now so that it is complete and verifiable before those features open.

3. What data we collect

3.1 Waitlist email

If you submit the waitlist form, we store your email address, the time you submitted it, and the time you gave consent. It is used for exactly one purpose: to send you a single notification when Nuntivo opens to the public. No newsletter, no marketing, no sharing with advertisers.

3.2 Account data

Accounts are created with Google Sign-In. From Google we receive your name, email address, profile picture and a provider account identifier. We never receive, see or store your Google password. We also store your plan, your role, and session records needed to keep you signed in.

3.3 Connected social account credentials

When you connect a social account, we store the credential needed to act on your behalf — an OAuth access and refresh token, or, for platforms that offer no OAuth, the bot token, app password or webhook URL you supply — together with the account name/handle and the identifiers required to post.

These credentials are encrypted at rest with AES-256-GCM under a key held only in our server environment. They are never returned to any browser, never shown back to you in full, never written to logs, and never shared with anyone other than the platform they belong to.

3.4 Content you create

The updates you write, the per-platform variants generated from them, hashtags, images and videos you upload, videos we render for you, video metadata (titles, descriptions, tags), scheduled posts, content queues, RSS feed URLs you add, templates, presets, and any voice-calibration sample you provide.

3.5 AI processing of your content

To rewrite your update for each platform and to generate hashtags, hooks, overlay text and video metadata, the text you provide is sent to our AI provider, Groq, which runs an open-weights Llama model. If you use voice-to-post, your audio recording is sent to Groq for transcription. We send only what is needed for the requested generation, and we do not send your credentials, your email, or your analytics data. If you turn AI rewriting off, your text is published verbatim and no AI provider is contacted at all.

3.6 Engagement and analytics data

Where a connected platform’s API allows it, we retrieve metrics for your own posts — views, likes, comments, shares and the platform-specific figures listed in §4 — plus your own follower count over time, so we can show you an analytics dashboard. We only ever request data about your own account and your own content. We never access, collect or store data about other people’s accounts, and we do not scrape any platform.

3.7 Payment data

Paid plans are processed by Stripe. Stripe collects your card and billing details directly — we never see or store your card number. We store only your Stripe customer and subscription identifiers, your plan, and its renewal date.

3.8 API keys

If you create an API key for the Nuntivo API, SDK, CLI or MCP server, we store only a SHA-256 hash of it plus a short display prefix. The full key is shown to you once, at creation, and cannot be recovered afterwards.

3.9 Technical and usage data

Our servers record IP address, browser and device type, requested URLs, timestamps and error diagnostics. This is used for security, abuse and rate-limit enforcement, and debugging. We do not run third-party advertising or cross-site tracking scripts.

3.10 Push notification subscriptions

If you enable browser push notifications, we store the push subscription endpoint and keys your browser issues, solely to deliver notifications about your own posts. Revoking notification permission in your browser ends this.

4. What each connected platform gives us

We request the narrowest set of permissions that makes each feature work. This table is the complete list of what we ask for and what we do with it. Connecting a platform is always an explicit, per-platform action you take, and you can disconnect any of them at any time (§12).

PlatformWhat we can doWhat we read back
TikTokPublish videos and photo posts you created, at the privacy level you selectYour username and profile basics, your follower count, and view/like/comment/share counts for the posts you published through Nuntivo
YouTubeUpload videos you created, with the title, description and tags generated from your own textStatistics and YouTube Analytics figures for your own videos, and your subscriber count
X (Twitter)Post on your behalf, or — if you connect in manual mode — nothing at allPublic and, where available, non-public metrics for your own posts
LinkedInPublish text, image and video posts on your behalfAnalytics for your own posts: impressions, members reached, clicks, followers gained
Facebook / InstagramPublish to a Page or Business account you manageInsights for your own posts and your follower/fan count
ThreadsPublish posts on your behalfInsights for your own posts, and your follower count
PinterestCreate Pins on a board you chooseAnalytics for your own Pins, and your follower count
BlueskyPost on your behalf using the app password you generatePublic engagement counts for your own posts, and your follower count
TelegramSend messages to the chat or channel your bot is inSubscriber count only — Telegram exposes no per-post metrics to bots
DiscordPost through the webhook URL you supplyReaction counts on the messages we sent

We never request permission to read your private messages, your contacts, your followers’ identities, or anyone else’s content.

5. How we use your data

  • To provide the Service — create your account, connect your platforms, rewrite and publish your content, schedule posts, render videos, and show you your analytics.
  • To run the automations you set up yourself — scheduled posts, evergreen queues, and RSS-triggered posts run without you being present, but only for content you created and to destinations you configured. You can review, edit or cancel anything pending before it goes out.
  • To process payments and manage your subscription.
  • To communicate with you — service messages such as a failed publish or a platform token that needs reconnecting, and receipts. Product announcements only if you opted in.
  • To keep the Service secure — prevent abuse and unauthorised access, enforce rate limits, and investigate incidents.
  • To fix and improve the product — diagnose errors and understand which features are used, working from aggregated or de-identified data wherever that is sufficient.
  • To comply with legal obligations, including tax and accounting records for payments.

We do not carry out automated decision-making that produces legal or similarly significant effects on you.

6. What we never do

  • We never sell or rent your personal data, to anyone, for any price.
  • We never use your data, your content, or data obtained from a platform API for advertising, ad targeting, or building profiles about you.
  • We never use your content or platform data to train, fine-tune or improve AI models — ours or anyone else’s.
  • We never access data about people other than you. We do not scrape any platform.
  • We never share data obtained from one platform’s API with another platform, a data broker, or an analytics reseller.
  • We never post anything you did not write, upload or configure.

8. Who we share data with

We share personal data only with the providers that make the Service run, only to the extent needed, and under contracts that require them to protect it. This list is current as of the date at the top of this page.

ProviderPurposeData involved
Google (Sign-In)AuthenticationName, email, avatar, account identifier
The platforms you connectPublishing your posts and reading your own metricsYour content, media, and the token you authorised
GroqAI text generation and audio transcriptionThe text or audio you submit for generation
NeonPostgreSQL database hostingAll application data at rest
UpstashRedis — background job queuesJob payloads and short-lived cached data
RenderApplication and background-worker hostingAll data in transit and in process memory
VercelWebsite hostingRequest and technical data
CloudflareDNS, CDN, and R2 object storage for mediaYour uploaded images and videos, rendered videos, request data
StripePayments and subscriptionsPayment and billing data, collected by Stripe directly
ResendTransactional and notification emailYour email address and the message content

We may also disclose data where required by law, or where necessary to establish, exercise or defend legal claims, or to protect the rights and safety of our users or the public. If Nuntivo is ever acquired or merged, we will notify you before your data becomes subject to a different privacy policy.

9. International data transfers

We are based in Ukraine and several of our providers (§8) operate in the European Economic Area, the United Kingdom and the United States. Where personal data is transferred internationally, we rely on the safeguards available for that transfer — principally the European Commission’s Standard Contractual Clauses, an adequacy decision where one applies (Ukraine has been recognised as providing adequate protection), or the provider’s own certified transfer mechanism. You can ask us for details of the safeguards applied to a specific transfer at nuntivo@gmail.com.

10. How long we keep data

DataRetention
Account, posts, settings, connected accountsFor as long as your account exists. Deleted when you delete your account (§11).
Platform access and refresh tokensUntil you disconnect that account, delete your account, or revoke access at the platform — whichever is first.
Rendered videosDeleted automatically 3 days after rendering, and immediately when you render a replacement. A video still needed by a post that has not published yet is kept until it does.
Uploaded mediaFor as long as your account exists, unless you delete the post or asset.
Analytics snapshotsFor as long as your account exists, so you can see trends over time.
Waitlist emailUntil the launch notification is sent, or until you ask us to remove it — whichever is first.
Server and security logsA short rolling window (typically up to 30 days), then overwritten.
Payment and invoice recordsRetained as long as tax and accounting law requires, typically several years, even after account deletion.
BackupsEncrypted backups roll over on a limited cycle; deleted data disappears from backups as that cycle completes, within 90 days.

We do not keep personal data indefinitely. Data obtained from a platform API is deleted when you disconnect that account, when you delete your account, or within 30 days of us being unable to confirm your authorisation is still valid.

11. Deleting your data

Delete everything yourself, in under a minute: sign in and go to Dashboard → Account → Delete account, and type DELETE to confirm. The deletion is immediate and permanent — there is no recovery step and we cannot restore it afterwards.

What gets deleted

Deleting your account removes, from our production database and storage: your profile (name, email, avatar, sign-in records and sessions); every connected social account and its encrypted tokens or credentials; every post you wrote, together with its per-platform variants, drafts and publish history; all media you uploaded and every video we rendered for you; all analytics we collected about your posts and followers; and your settings, presets, templates, schedules, queues, RSS feeds, webhooks, notifications, push subscriptions and API keys. These are removed by database cascade, so nothing is left orphaned.

What is not deleted, and why

  • Posts already published to a platform. Once a post is live on TikTok, YouTube, X or anywhere else, that copy belongs to that platform’s account and only you can remove it there. Deleting your Nuntivo account does not and cannot delete it.
  • Invoices and payment records, where tax and accounting law requires us to keep them.
  • Encrypted backups, until the backup cycle rolls over — within 90 days.

Deleting less than everything

You do not have to delete your whole account to remove data. Disconnecting a single platform (Dashboard → Platforms → Disconnect) deletes that platform’s stored credentials and its associated records. Deleting an individual post removes it and its media from our systems. Removing a waitlist email needs only a message to us.

If you cannot sign in

Email nuntivo@gmail.com from the address on the account, with the subject “Delete my data”. We will verify that you own the account, carry out the deletion described above, and confirm to you in writing — within 30 days, and normally within a few days. This request is free, and we will not ask you why.

12. Revoking access at each platform

Separately from deleting data on our side, you can withdraw Nuntivo’s access from the platform’s own settings. Doing so immediately stops us being able to act on that account, and the stored token becomes useless.

  • TikTok — in the TikTok app: Profile → Menu → Settings and privacy → Security & permissions → Manage app permissions, then remove Nuntivo.
  • Google / YouTube myaccount.google.com/permissions, select Nuntivo, then Remove access.
  • Facebook / Instagram / Threads Facebook Settings → Business Integrations, or Instagram Settings → Website permissions → Apps and websites.
  • X (Twitter) x.com/settings/connected_apps.
  • LinkedInSettings & Privacy → Data privacy → Permitted services.
  • PinterestSettings → Security → Apps connected to your account.
  • Bluesky — revoke the app password you created, in Settings → App Passwords.
  • Telegram — remove the bot from the channel or chat, or revoke its token via @BotFather.
  • Discord — delete the webhook in the channel’s Integrations settings.

13. Your rights

Under GDPR, Ukrainian data protection law, and comparable regimes, you have the right to:

  • Access the personal data we hold about you, and get a copy.
  • Rectify data that is inaccurate or incomplete.
  • Erase your data — see §11, which you can do yourself.
  • Port your data: receive it in a structured, machine-readable format, or have it sent to another controller where technically feasible.
  • Restrict or object to processing based on our legitimate interests, including direct marketing.
  • Withdraw consent at any time — by disconnecting a platform, unsubscribing, or asking us.
  • Complain to a supervisory authority: in Ukraine, the Ukrainian Parliament Commissioner for Human Rights (Ombudsman); in the EU/EEA, your local data protection authority; in the UK, the ICO.

To exercise any of these, email nuntivo@gmail.com. We respond free of charge within 30 days.

California residents. We do not sell or share personal information as those terms are defined by the CCPA/CPRA, and we have not done so in the preceding 12 months. You have the right to know, delete, correct, and not be discriminated against for exercising those rights; use the same address above.

14. Platform-specific disclosures

TikTok

Nuntivo uses the TikTok Content Posting API and the TikTok Display API to publish content you create to your own TikTok account and to read back public engagement counts for those posts and your own follower count. We do not use TikTok’s Marketing/Ads APIs. Before every post we read your account’s available privacy settings and default to the most private option your account allows; you choose the visibility. Data received from TikTok is used only to provide the features described in this policy, is never sold, never used for advertising, and never used to train models. Your use of TikTok itself is governed by the TikTok Privacy Policy. To revoke our access, see §12.

YouTube and Google

Nuntivo uses YouTube API Services. By connecting a YouTube account you agree to be bound by the YouTube Terms of Service, and Google’s handling of your data is described in the Google Privacy Policy. You can revoke Nuntivo’s access to your Google data at https://myaccount.google.com/permissions. We store YouTube-derived data (video identifiers and your own statistics) only for as long as your account exists, and delete it within 30 days of a deletion request or of being unable to confirm your authorisation.

Nuntivo’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Meta (Facebook, Instagram, Threads)

Nuntivo uses Meta’s Graph and Threads APIs to publish to Pages and accounts you manage and to read insights for your own posts. Data received from Meta is used only for those features, and is deleted when you disconnect the account or delete your Nuntivo account. Our data deletion instructions are §11 of this page, directly linkable at https://nuntivo.me/privacy#data-deletion.

15. Security

We protect your data with: TLS/HTTPS for everything in transit; AES-256-GCM encryption at rest for every connected-platform credential; SHA-256 hashing for API keys, which are never stored in recoverable form; signed, time-limited state on every OAuth connection to prevent request forgery; server-side validation of outbound media requests to prevent server-side request forgery; rate limiting; and least-privilege access to production systems, which only the operator holds.

No system is perfectly secure. If a breach affects your personal data and is likely to result in a risk to your rights, we will notify the relevant supervisory authority within 72 hours and notify you without undue delay, as GDPR requires. Report a suspected vulnerability to nuntivo@gmail.com — we will not pursue good-faith security research.

16. Children's data

Nuntivo is not directed to children. You must be at least 16 years old to create an account (or older, where your country sets a higher age of digital consent), and at least 18 to purchase a paid plan. We do not knowingly collect personal data from children. If you believe a child has provided us data, email us and we will delete it promptly.

17. Cookies

We use strictly necessary cookies only — a session cookie that keeps you signed in, and security cookies that protect the sign-in flow. We do not use advertising cookies, cross-site trackers, or third-party marketing pixels, which is why you are not shown a consent banner. Blocking necessary cookies in your browser will prevent you from signing in. Your browser’s local storage is also used to remember interface preferences on your own device; that data never leaves it.

18. Changes to this policy

We may update this policy as the product changes. We will update the date at the top and, for material changes — particularly any change to what data we collect or who we share it with — notify you in the application or by email before the change takes effect. If a change means we would use data from a platform API in a way you did not originally authorise, we will ask for your consent again rather than relying on the old authorisation. Previous versions are available on request.

19. Contact

Questions about this policy, requests to exercise your rights, or anything else about your data:

Nazar Leochko
Data controller, Nuntivo
nuntivo@gmail.com
Ukraine

Nuntivo is operated by an individual, not a company. If that changes, this page will be updated with the new controller’s details before the change takes effect.