Privacy Policy
Last updated: September 12, 2026
1. Data Controller
The data controller for this Privacy Policy is:
- Company: Nailing AI L.L.C.
- Platform: Nailing.AI
- Email: [email protected]
- Address: 30 N Gould St Ste N, Sheridan, WY 82801, USA
2. Introduction
At Nailing.AI ("we" or "platform"), we respect your privacy. This Privacy Policy explains how we collect, use, share, and protect your personal data when you use our services.
3. Data We Collect
3.1 Account Information
- Email address
- Full name
- Password (stored encrypted)
- Profile photo (optional)
3.2 Usage Data
- Canvases and content you create
- AI conversations
- Video analyses and notes
- Files and videos you upload for analysis or transcription
- Content you import from connected services (Google Drive, Notion)
- Platform usage statistics
3.3 Technical Data
- IP address
- Browser type and version
- Device information (screen resolution, operating system)
- Cookies and similar technologies
3.4 Interaction and Session Data
To improve our platform, the following data about your interactions is collected automatically during use:
- Page views and navigation history
- Clicks, scrolling, and mouse movements
- Time spent on page elements
- Performance metrics (page load times)
Note: Text you type into the application may be retained in session recordings for debugging and product improvement purposes. Passwords are masked at the browser level and payment card data is handled inside Stripe's isolated iframe — it never reaches our servers or session recordings. To request deletion of a specific recording, email [email protected].
4. How We Use Your Data
We use the data we collect to:
- Provide and improve our services
- Manage and secure your account
- Deliver AI-powered features
- Provide technical support
- Analyze and improve user experience (session recordings, heatmaps)
- Detect and resolve errors
- Detect and prevent abuse
- Comply with legal obligations
- Ensure platform security
4.1 Authorized Access
To operate the service, fix faults, resolve your support requests, improve the service, and detect and prevent abuse (payment fraud, spam, violations of our terms of use), people authorized by Nailing.AI may access the contents of your canvases, the links and videos you add, and your AI chat history.
This access is limited to the purposes listed above: your content is not used for anything else, is not shared with third parties, and is not used to train AI models. Legal basis: performance of the contract and legitimate interest.
5. Third-Party Services
We work with the following third-party providers to deliver our services:
5.1 Infrastructure Services
- Supabase: Database and authentication (USA)
- Railway: Application hosting (EU - Western Europe)
- Cloudflare: CDN, security, and bot protection (Turnstile) (USA)
- Upstash: Redis caching and rate limiting (Turkey/USA)
- Backblaze B2: Media and uploaded-video storage (USA)
5.2 AI and Analytics Services
- OpenRouter: AI model access (Claude, GPT, Gemini) (USA)
- YouTube Data API: Video metadata retrieval
- Apify: Social media data extraction (Instagram, TikTok) (EU)
- ScrapeCreators (USA): Social-media data retrieval from the handles/URLs you submit (same category as Apify). Data transfer under a DPA / Standard Contractual Clauses (SCC).
- Groq, Inc. (USA): Voice and audio transcription (Whisper). Audio you record or upload is sent for transcription. Data transfer under a DPA / Standard Contractual Clauses (SCC).
- OpenAI, Inc. (USA): Image and video-frame AI analysis. Data transfer under a DPA / Standard Contractual Clauses (SCC).
- KIE (kie.ai): AI image generation from your prompts and reference images (including photos you provide). Data transfer under a DPA / Standard Contractual Clauses (SCC).
- fal.ai (USA): AI image generation, video transcoding, and transcription (Whisper) of audio files larger than 24 MB. Data transfer under a DPA / Standard Contractual Clauses (SCC).
- LlamaIndex / LlamaParse (USA): Parsing of documents (PDFs) you upload. Data transfer under a DPA / Standard Contractual Clauses (SCC).
5.3 Payment Services
- Stripe, Inc. (USA): Used for payment processing, subscription management, and invoice generation. Stripe is PCI DSS Level 1 certified. Your card information is transmitted directly to Stripe during payment and is never stored on our servers. For details: stripe.com/privacy
5.4 Authentication
- Google LLC: Google Sign-In (OAuth) authentication service. Your Google account information (name, email, profile photo) is used to create your account. Data transfer is conducted under Standard Contractual Clauses (SCC).
5.5 Analytics and Error Tracking
- PostHog: Usage analytics, session replay, heatmaps, and click tracking (USA servers). Your interactions on the platform (clicks, scrolling, page navigation) are recorded for product improvement purposes. Text you type into the application may also be captured in session recordings for debugging and product improvement. Passwords are always masked, and payment card data is handled exclusively by Stripe and never reaches PostHog.
- Sentry: Error tracking and performance monitoring (USA). Technical error data is sent to detect and resolve application issues.
5.6 Content Import Services
When you choose to import content from an external service, we access only the specific items you select:
- Google Drive (Google LLC, USA): Using Google's file picker with the restricted "drive.file" scope, we access only the files you explicitly select for import. If you choose to connect your Google Drive account, we store the Google authorization tokens (refresh and access tokens) on our servers, encrypted at rest with AES-256-GCM, so that the connection persists across sessions and you do not have to reconnect every time. These tokens are never shared with third parties, never used for AI processing, and are used solely to access the files you select. When you disconnect Google Drive from your account settings, the authorization is revoked at Google and the stored tokens are deleted. Data transfer is conducted under Standard Contractual Clauses (SCC).
- Notion (Notion Labs, Inc., USA): When you import a Notion page, its content is added to your canvas and indexed in our search system (RAG, via Cohere) in the same way as your other canvas content. We access only the pages you authorize.
5.7 Email Delivery
- Resend (USA): Transactional and campaign email delivery (account, billing, and product emails). Your email address and name are processed to send these messages. Data transfer under a DPA / Standard Contractual Clauses (SCC).
6. AI Service Providers
Your canvas content, AI conversations, and help/support chat messages are sent to third-party AI services such as OpenRouter and Cohere to generate responses.
- OpenRouter: AI model API gateway (Claude, GPT, Gemini, Llama, etc.). Your data is not used for model training.
- Cohere: Text embedding and RAG system. We use the Enterprise API; your data is not used for model training.
7. Data Retention
- Account data: As long as your account is active
- Canvas content: Until you delete it
- Log records: 90 days
- Analytics data: 12 months (anonymized)
When you delete your account, your data will be permanently deleted within 30 days.
8. Your Rights Under GDPR
Under the General Data Protection Regulation, you have the right to:
- Access your personal data
- Rectify inaccurate data
- Erase your data ("right to be forgotten")
- Restrict processing
- Data portability
- Object to processing
- Withdraw consent at any time
- Lodge a complaint with a supervisory authority
9. Cookies, Session Recording, and Tracking
9.1 Cookies
Our platform uses the following types of cookies:
- Essential cookies: Session management, security (always active)
- Functional cookies: Remember your preferences
- Analytics cookies: Usage analysis and session recording
9.2 Session Recording
Our platform uses session replay technology via PostHog. This technology creates a visual recording of your interactions on the platform to improve user experience and identify issues.
Data that is recorded:
- Clicks and mouse movements on the page
- Page scrolling behavior
- Page transitions and navigation flow
- Interface elements clicked (buttons, links, menus)
- Heatmaps (areas that are frequently clicked)
Data that may also be recorded (visible to our team):
- Text you enter into the interface — form fields and content inputs (excluding passwords and payment card data)
Data that is NEVER recorded:
- Passwords (masked at the browser level)
- Payment card data (handled exclusively by Stripe inside an isolated iframe — never reaches our servers or PostHog)
Session recordings are reviewed only by authorized team members for product development and debugging purposes, and are automatically deleted after 12 months.
10. Data Security
Measures we take to protect your data:
- SSL/TLS encryption (in transit)
- AES-256 encryption (at rest)
- Row Level Security (RLS) for data isolation
- Regular security audits
- Cloudflare Turnstile bot protection
11. International Data Transfers
Your data may be transferred to the EU and USA through our service providers' servers. These transfers are carried out under GDPR-compliant data processing agreements.
12. Children's Privacy
Our services are intended for users 18 years and older. We do not knowingly collect personal data from children under 18.
13. Policy Changes
We may update this policy from time to time. We will notify you via email if there are significant changes.
14. Contact
For privacy-related questions:
- Email: [email protected]
- Address: 30 N Gould St Ste N, Sheridan, WY 82801, USA
For GDPR-related requests, please contact [email protected]. Your request will be answered within 30 days.