Privacy
last updated 16 September 2026
The short version
Nicole stores the minimum it needs to do the job you asked for: your account, the channels you told it to study, the content it generated for you, and encrypted credentials for the services you connected. It does not sell anything, does not run advertising, and does not use your channel data or your generated content to train models.
What we store
- Your account. An email address and an authentication record, so you can sign back in.
- Your research. The competitor groups you create, the public YouTube data fetched about the channels in them, and the analysis produced from it.
- Your content. Titles, outlines, scripts, thumbnails, audio and video produced by the pipeline, plus a record of which jobs ran and what happened.
- Your credentials. API keys you add and OAuth tokens you grant, held encrypted in a secrets vault.
Every row is scoped to the account that created it and enforced in the database itself, not only in the app. One account cannot read another account's data.
Google user data
If you connect a YouTube channel, Nicole requests access to read your channel's basic information and to upload videos to it. That access is used for exactly two things: showing you which of your channels a video can go to, and uploading the video you asked it to upload.
Nicole's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, Google user data is never sold, never transferred to others except as required to provide the upload you requested or to comply with law, never used for advertising, and never used to train generalised models. No human reads it except where you have asked for support and given permission, or where the law requires it.
Your Google refresh token is stored encrypted and is used only by the server that performs uploads. You can revoke it at any time from your Google account permissions, or by disconnecting the channel in the app. Revoking it stops uploads immediately.
Your own API keys
Nicole runs generation on your provider accounts, not ours. The keys you add are written into an encrypted vault and are decrypted only by the server process that runs your jobs. They are never returned to the app, never logged, and never used to serve anyone else's work. If a key is missing or rejected, the job fails and tells you so rather than quietly running on another account.
What those providers do with the content of a request is governed by their own policies, not this one, because the request is made on your account with them.
Third parties we use
- Supabase, for database, authentication and file storage, hosted in the EU (Stockholm).
- Providers you connect yourself, currently Anthropic, Replicate, ElevenLabs and YouTube, each called with your own credentials.
- Rendering services operated by us, which process your audio and video while a job runs.
There is no analytics tracker, no advertising pixel and no session recorder on this website or in the app.
How long we keep things
Your content and research stay until you delete them or close your account. Job history is kept while the account is open so a run can be audited after the fact. Deleting your account removes your rows, your stored files and your vaulted credentials. Backups roll off within thirty days.
Waitlist
If you gave us an email address on this site, it is stored to tell you when the beta opens, and for nothing else. It is not added to a newsletter and not shared. Reply to any message from us, or write to boneless@nicole-ai.com, and it is removed.
Your rights, and how to use them
You can ask for a copy of your data, ask for it to be corrected, or ask for all of it to be deleted. Write to boneless@nicole-ai.com from the address on the account and we will action it within thirty days. If you are in the UK or EU, you also have the right to complain to your data protection authority.
Changes
If this policy changes in a way that affects what we do with data you have already given us, we will email the address on your account before the change takes effect.
Contact
boneless@nicole-ai.com handles privacy questions, deletion requests, and anything on this page that is not clear enough.