Last updated 7 August 2026 · Effective 7 August 2026
Nuntivo (“Nuntivo”, “we”, “us”, “our”) is an independent software product operated by Nazar Leochko, a sole individual developer based in Ukraine, at https://nuntivo.me (the “Service”).
For the purposes of the EU General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”), the UK GDPR, and the Law of Ukraine “On Personal Data Protection” No. 2297-VI, Nazar Leochko is the data controller for the personal data described in this policy.
Contact for anything privacy-related: nuntivo@gmail.com. We are a small operation and answer this address ourselves; we aim to reply within 5 working days and always within the 30 days required by law.
This policy covers the Nuntivo website, the waitlist form on it, and the Nuntivo web application, including everything we do with data obtained from social platform APIs on your behalf.
If you submit the waitlist form, we store your email address, the time you submitted it, and the time you gave consent. It is used for exactly one purpose: to send you a single notification when Nuntivo opens to the public. No newsletter, no marketing, no sharing with advertisers.
Accounts are created with Google Sign-In. From Google we receive your name, email address, profile picture and a provider account identifier. We never receive, see or store your Google password. We also store your plan, your role, and session records needed to keep you signed in.
When you connect a social account, we store the credential needed to act on your behalf — an OAuth access and refresh token, or, for platforms that offer no OAuth, the bot token, app password or webhook URL you supply — together with the account name/handle and the identifiers required to post.
These credentials are encrypted at rest with AES-256-GCM under a key held only in our server environment. They are never returned to any browser, never shown back to you in full, never written to logs, and never shared with anyone other than the platform they belong to.
The updates you write, the per-platform variants generated from them, hashtags, images and videos you upload, videos we render for you, video metadata (titles, descriptions, tags), scheduled posts, content queues, RSS feed URLs you add, templates, presets, and any voice-calibration sample you provide.
To rewrite your update for each platform and to generate hashtags, hooks, overlay text and video metadata, the text you provide is sent to our AI provider, Groq, which runs an open-weights Llama model. If you use voice-to-post, your audio recording is sent to Groq for transcription. We send only what is needed for the requested generation, and we do not send your credentials, your email, or your analytics data. If you turn AI rewriting off, your text is published verbatim and no AI provider is contacted at all.
Where a connected platform’s API allows it, we retrieve metrics for your own posts — views, likes, comments, shares and the platform-specific figures listed in §4 — plus your own follower count over time, so we can show you an analytics dashboard. We only ever request data about your own account and your own content. We never access, collect or store data about other people’s accounts, and we do not scrape any platform.
Paid plans are processed by Stripe. Stripe collects your card and billing details directly — we never see or store your card number. We store only your Stripe customer and subscription identifiers, your plan, and its renewal date.
If you create an API key for the Nuntivo API, SDK, CLI or MCP server, we store only a SHA-256 hash of it plus a short display prefix. The full key is shown to you once, at creation, and cannot be recovered afterwards.
Our servers record IP address, browser and device type, requested URLs, timestamps and error diagnostics. This is used for security, abuse and rate-limit enforcement, and debugging. We do not run third-party advertising or cross-site tracking scripts.
If you enable browser push notifications, we store the push subscription endpoint and keys your browser issues, solely to deliver notifications about your own posts. Revoking notification permission in your browser ends this.
We request the narrowest set of permissions that makes each feature work. This table is the complete list of what we ask for and what we do with it. Connecting a platform is always an explicit, per-platform action you take, and you can disconnect any of them at any time (§12).
| Platform | What we can do | What we read back |
|---|---|---|
| TikTok | Publish videos and photo posts you created, at the privacy level you select | Your username and profile basics, your follower count, and view/like/comment/share counts for the posts you published through Nuntivo |
| YouTube | Upload videos you created, with the title, description and tags generated from your own text | Statistics and YouTube Analytics figures for your own videos, and your subscriber count |
| X (Twitter) | Post on your behalf, or — if you connect in manual mode — nothing at all | Public and, where available, non-public metrics for your own posts |
| Publish text, image and video posts on your behalf | Analytics for your own posts: impressions, members reached, clicks, followers gained | |
| Facebook / Instagram | Publish to a Page or Business account you manage | Insights for your own posts and your follower/fan count |
| Threads | Publish posts on your behalf | Insights for your own posts, and your follower count |
| Create Pins on a board you choose | Analytics for your own Pins, and your follower count | |
| Bluesky | Post on your behalf using the app password you generate | Public engagement counts for your own posts, and your follower count |
| Telegram | Send messages to the chat or channel your bot is in | Subscriber count only — Telegram exposes no per-post metrics to bots |
| Discord | Post through the webhook URL you supply | Reaction counts on the messages we sent |
We never request permission to read your private messages, your contacts, your followers’ identities, or anyone else’s content.
We do not carry out automated decision-making that produces legal or similarly significant effects on you.
Where GDPR applies to you, we rely on the following legal bases:
| Processing | Legal basis |
|---|---|
| Running your account, publishing your content, storing platform tokens, billing | Performance of a contract — Art. 6(1)(b) |
| Connecting each social platform; the waitlist email; optional product emails; push notifications | Consent — Art. 6(1)(a). You can withdraw it at any time, which does not affect processing already carried out. |
| Security, abuse prevention, debugging, product improvement | Legitimate interests — Art. 6(1)(f), balanced against your rights |
| Tax and accounting records for payments | Legal obligation — Art. 6(1)(c) |
We do not intentionally collect special-category data (Art. 9). If you choose to write such information into a post, it is processed only as ordinary post content, under your instruction.
We share personal data only with the providers that make the Service run, only to the extent needed, and under contracts that require them to protect it. This list is current as of the date at the top of this page.
| Provider | Purpose | Data involved |
|---|---|---|
| Google (Sign-In) | Authentication | Name, email, avatar, account identifier |
| The platforms you connect | Publishing your posts and reading your own metrics | Your content, media, and the token you authorised |
| Groq | AI text generation and audio transcription | The text or audio you submit for generation |
| Neon | PostgreSQL database hosting | All application data at rest |
| Upstash | Redis — background job queues | Job payloads and short-lived cached data |
| Render | Application and background-worker hosting | All data in transit and in process memory |
| Vercel | Website hosting | Request and technical data |
| Cloudflare | DNS, CDN, and R2 object storage for media | Your uploaded images and videos, rendered videos, request data |
| Stripe | Payments and subscriptions | Payment and billing data, collected by Stripe directly |
| Resend | Transactional and notification email | Your email address and the message content |
We may also disclose data where required by law, or where necessary to establish, exercise or defend legal claims, or to protect the rights and safety of our users or the public. If Nuntivo is ever acquired or merged, we will notify you before your data becomes subject to a different privacy policy.
We are based in Ukraine and several of our providers (§8) operate in the European Economic Area, the United Kingdom and the United States. Where personal data is transferred internationally, we rely on the safeguards available for that transfer — principally the European Commission’s Standard Contractual Clauses, an adequacy decision where one applies (Ukraine has been recognised as providing adequate protection), or the provider’s own certified transfer mechanism. You can ask us for details of the safeguards applied to a specific transfer at nuntivo@gmail.com.
| Data | Retention |
|---|---|
| Account, posts, settings, connected accounts | For as long as your account exists. Deleted when you delete your account (§11). |
| Platform access and refresh tokens | Until you disconnect that account, delete your account, or revoke access at the platform — whichever is first. |
| Rendered videos | Deleted automatically 3 days after rendering, and immediately when you render a replacement. A video still needed by a post that has not published yet is kept until it does. |
| Uploaded media | For as long as your account exists, unless you delete the post or asset. |
| Analytics snapshots | For as long as your account exists, so you can see trends over time. |
| Waitlist email | Until the launch notification is sent, or until you ask us to remove it — whichever is first. |
| Server and security logs | A short rolling window (typically up to 30 days), then overwritten. |
| Payment and invoice records | Retained as long as tax and accounting law requires, typically several years, even after account deletion. |
| Backups | Encrypted backups roll over on a limited cycle; deleted data disappears from backups as that cycle completes, within 90 days. |
We do not keep personal data indefinitely. Data obtained from a platform API is deleted when you disconnect that account, when you delete your account, or within 30 days of us being unable to confirm your authorisation is still valid.
Deleting your account removes, from our production database and storage: your profile (name, email, avatar, sign-in records and sessions); every connected social account and its encrypted tokens or credentials; every post you wrote, together with its per-platform variants, drafts and publish history; all media you uploaded and every video we rendered for you; all analytics we collected about your posts and followers; and your settings, presets, templates, schedules, queues, RSS feeds, webhooks, notifications, push subscriptions and API keys. These are removed by database cascade, so nothing is left orphaned.
You do not have to delete your whole account to remove data. Disconnecting a single platform (Dashboard → Platforms → Disconnect) deletes that platform’s stored credentials and its associated records. Deleting an individual post removes it and its media from our systems. Removing a waitlist email needs only a message to us.
Email nuntivo@gmail.com from the address on the account, with the subject “Delete my data”. We will verify that you own the account, carry out the deletion described above, and confirm to you in writing — within 30 days, and normally within a few days. This request is free, and we will not ask you why.
Separately from deleting data on our side, you can withdraw Nuntivo’s access from the platform’s own settings. Doing so immediately stops us being able to act on that account, and the stored token becomes useless.
Under GDPR, Ukrainian data protection law, and comparable regimes, you have the right to:
To exercise any of these, email nuntivo@gmail.com. We respond free of charge within 30 days.
California residents. We do not sell or share personal information as those terms are defined by the CCPA/CPRA, and we have not done so in the preceding 12 months. You have the right to know, delete, correct, and not be discriminated against for exercising those rights; use the same address above.
Nuntivo uses the TikTok Content Posting API and the TikTok Display API to publish content you create to your own TikTok account and to read back public engagement counts for those posts and your own follower count. We do not use TikTok’s Marketing/Ads APIs. Before every post we read your account’s available privacy settings and default to the most private option your account allows; you choose the visibility. Data received from TikTok is used only to provide the features described in this policy, is never sold, never used for advertising, and never used to train models. Your use of TikTok itself is governed by the TikTok Privacy Policy. To revoke our access, see §12.
Nuntivo uses YouTube API Services. By connecting a YouTube account you agree to be bound by the YouTube Terms of Service, and Google’s handling of your data is described in the Google Privacy Policy. You can revoke Nuntivo’s access to your Google data at https://myaccount.google.com/permissions. We store YouTube-derived data (video identifiers and your own statistics) only for as long as your account exists, and delete it within 30 days of a deletion request or of being unable to confirm your authorisation.
Nuntivo uses Meta’s Graph and Threads APIs to publish to Pages and accounts you manage and to read insights for your own posts. Data received from Meta is used only for those features, and is deleted when you disconnect the account or delete your Nuntivo account. Our data deletion instructions are §11 of this page, directly linkable at https://nuntivo.me/privacy#data-deletion.
We protect your data with: TLS/HTTPS for everything in transit; AES-256-GCM encryption at rest for every connected-platform credential; SHA-256 hashing for API keys, which are never stored in recoverable form; signed, time-limited state on every OAuth connection to prevent request forgery; server-side validation of outbound media requests to prevent server-side request forgery; rate limiting; and least-privilege access to production systems, which only the operator holds.
No system is perfectly secure. If a breach affects your personal data and is likely to result in a risk to your rights, we will notify the relevant supervisory authority within 72 hours and notify you without undue delay, as GDPR requires. Report a suspected vulnerability to nuntivo@gmail.com — we will not pursue good-faith security research.
Nuntivo is not directed to children. You must be at least 16 years old to create an account (or older, where your country sets a higher age of digital consent), and at least 18 to purchase a paid plan. We do not knowingly collect personal data from children. If you believe a child has provided us data, email us and we will delete it promptly.
We may update this policy as the product changes. We will update the date at the top and, for material changes — particularly any change to what data we collect or who we share it with — notify you in the application or by email before the change takes effect. If a change means we would use data from a platform API in a way you did not originally authorise, we will ask for your consent again rather than relying on the old authorisation. Previous versions are available on request.
Questions about this policy, requests to exercise your rights, or anything else about your data:
Nuntivo is operated by an individual, not a company. If that changes, this page will be updated with the new controller’s details before the change takes effect.