Privacy
Privacy Policy
Effective August 25, 2026
This notice explains what Nuvilo collects, why it is used, where it is shared, and the choices available to creators.
Who is responsible
Nuvilo provides creator profile, brand research, pitch preparation, and creator-approved outreach tools. Questions and privacy requests can be sent to hello@nuvilo.app.
Information we collect
- Account data: email address, authentication identifiers, session records, and—when you use Google sign-in—your basic Google account name, email address, and profile image.
- Creator workspace data: your name, creator-entered handles, content focus, collaboration goals, usual terms, pitch preferences, proof links, brand decisions, drafts, and manually recorded outreach status.
- Public profile evidence: bounded public profile metadata and public media evidence retrieved for an exact creator-entered handle. Missing or blocked information remains unavailable rather than being inferred.
- Connected creator accounts: when you authorize Instagram or TikTok, we store the provider account identifier, display name, username, avatar, granted scopes, connection time, and encrypted access or refresh tokens. Tokens remain server-side.
- Outreach data: the reviewed message, opaque brand/contact references, masked recipient information shown to you, provider delivery identifiers, and delivery/open/click signals. Raw active brand contacts stay server-side.
- Service and security data: limited request, device, rate-limit, error, and abuse-prevention records. Where the product contract calls for hashed identifiers, Nuvilo does not retain the original value in that record.
- Product journey and acquisition data: confirmed onboarding steps plus a first-touch campaign source, medium, campaign label, referring hostname, and QA classification. Nuvilo does not retain the referring path, full URL, arbitrary query parameters, creator content, email, handle, raw IP address, or full user-agent in this analytics record.
- Early-access responses: answers submitted through the public beta form are stored separately from an app workspace and used for beta research and contact.
How we use information
- Authenticate you, restore the correct private workspace, and secure the service.
- Show creator-entered profiles, retrieve bounded public evidence, prepare editable pitches, and preserve your choices.
- Connect a creator account only after provider consent and use the granted data to show and maintain that connection.
- Send a pitch only after explicit review and confirmation, then display provider delivery and engagement signals.
- Operate limits, prevent abuse, troubleshoot failures, and improve aggregate product journeys without exposing raw user content to operators.
Nuvilo does not sell your personal information or use connected social-account data for advertising.
Service providers and disclosure
Nuvilo uses infrastructure and specialist providers to operate the service, including Supabase for authentication and data services, Vercel for hosting, Resend for creator-approved email delivery, Google and OpenAI for bounded rewrite requests when available, and Google, Meta, or TikTok when you choose their authentication or connection flow. Each provider processes data under its own terms and our configuration.
We may also disclose information when required by law, to protect users or the service, or as part of a business transfer with appropriate safeguards. We do not disclose private workspace data to brands except through a message you explicitly approve for delivery.
Retention and security
Workspace data is generally retained while your account remains active. Raw product-journey and first-touch analytics events are retained for up to 90 days, while the operator receives aggregate views rather than raw creator content. Social tokens are deleted when you disconnect that provider or delete the account. Expired send-intent payloads are redacted; provider attempt and event identifiers are removed under the service's bounded retention schedule. Messages already accepted by an email provider or received by another party may remain in their systems.
We use access controls, row-level authorization, server-only secrets, encryption for connected-account tokens, and least-data browser responses. No internet service can promise absolute security.
Your choices and rights
- Edit creator-entered profile and pitch information inside Nuvilo.
- Disconnect Instagram or TikTok from Account settings.
- Revoke Google, Instagram, or TikTok access from the provider's own account settings.
- Delete your Nuvilo account and synced workspace using the in-product control.
- Request access, correction, deletion, restriction, or portability where applicable by emailing us.
See the step-by-step data deletion instructions.
Children and international processing
Nuvilo is not directed to children under 13, and users must be old enough to enter a binding agreement where they live. Service providers may process information in countries other than your own, subject to the protections available under their contracts and applicable law.
Changes
We may update this policy as the product or law changes. The effective date above will be updated, and material changes will be communicated when required.