Privacy Policy
Last updated: March 2026
1. Introduction
Nebulas.ai ("we", "our", "us"), operated by Gnomon Digital, is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and safeguard your personal data when you use our platform and website, including where you choose to connect a third-party account such as TikTok or Facebook.
2. Data We Collect
We collect information you provide directly, including account details (name, email), billing information for paid plans, content you upload to knowledge bases, and usage data such as interaction logs and feature usage analytics. We offer API access that lets you retrieve performance data from a connected TikTok account; where you use this, we collect only the data covered by the scopes you authorize, limited to your TikTok account identifier and performance metrics for your own posts — such as post IDs, view counts, and like counts. We also provide content-generation tools you can use to create content and, at your initiation and with your approval, publish it to Facebook or other social media platforms; where you connect a Facebook account for this purpose, we retrieve performance metrics for the posts you publish — such as post IDs, view counts, and like counts. We do not collect data about individual viewers of your posts on either platform.
3. How We Use Your Data
Your data is used to provide and improve the Nebulas platform, process AI queries against your knowledge bases, and communicate product updates. We never sell your data to third parties.
4. Data Storage & Security
All data is stored in EU data centers (Google Cloud Platform, Europe). We use encryption at rest and in transit, and implement industry-standard security practices including SOC 2 compliance.
5. Data Retention
We retain personal data only as long as necessary for the purposes described in this policy. Your Nebulas account data (such as your account ID, email address, and content you've uploaded directly) is retained for the duration of your account plus up to 30 days after deletion, regardless of whether a TikTok or Facebook account is also connected. As soon as you disconnect a TikTok or Facebook integration in Nebulas, or revoke Nebulas's access from that platform's own account settings, we stop retrieving any new data. Post IDs and metrics already imported into your knowledge base at that point become part of your own content and are retained and deleted according to your own account and workspace settings, the same as any other content you've uploaded, rather than on a separate fixed schedule.
6. TikTok Integration
Where you connect a TikTok account, we use the authorized connection solely to retrieve performance analytics for that account's own posts — such as post IDs, view counts, and like counts — to display within Nebulas; this data is not used for advertising and is not shared with third parties beyond what is described in this policy. You can disconnect the TikTok integration in Nebulas at any time, which stops us from retrieving further data, and reconnect it later. Disconnecting in Nebulas does not itself revoke TikTok's underlying authorization; to definitively revoke Nebulas's access, use the app-permissions settings in your TikTok account. Data already imported into your knowledge base before a disconnect or revocation remains there as your own content — governed by your account's data retention and deletion choices, described in Section 5 — until you remove it. Your Nebulas account itself, including your account ID and the email you signed up with, is separate from any TikTok connection and is unaffected by disconnecting or revoking that access. Visibility of TikTok-derived data within your knowledge base is governed by the access permissions you configure for your workspace, which you are responsible for managing. Our collection, use, and transfer of information received from TikTok's APIs adheres to TikTok's Developer Terms of Service and Developer Policy, including its Limited Use requirements.
7. Content Generation & Social Media Publishing
Nebulas provides tools that assist you in generating content and, at your initiation, publishing it to Facebook or other social media platforms you connect; content generation is not specific to any single platform, and publishing only happens when you choose to initiate it and have approved the content beforehand — Nebulas does not publish on your behalf automatically. Where you connect a Facebook account for this purpose, you manage the permissions granted to Nebulas through your own Facebook account settings, including what we are authorized to retrieve or publish; we also retrieve performance metrics for the posts you publish through Nebulas — such as post IDs, view counts, and like counts — to display within Nebulas. You can disconnect the Facebook connection in Nebulas at any time, which stops us from publishing further content or retrieving further data, and reconnect it later. Disconnecting in Nebulas does not itself revoke Facebook's underlying authorization; to definitively revoke Nebulas's access, use the app-permissions settings in your Facebook account. Data already imported into your knowledge base before a disconnect or revocation remains there as your own content — governed by your account's data retention and deletion choices, described in Section 5 — until you remove it. Your Nebulas account itself, including your account ID and the email you signed up with, is separate from any Facebook connection and is unaffected by disconnecting or revoking that access. Visibility of Facebook-derived data within your knowledge base is governed by the access permissions you configure for your workspace, which you are responsible for managing. Our collection, use, and transfer of information received from Facebook's APIs adheres to Meta's Platform Terms and Developer Policies, including any applicable data use restrictions.
8. Payment Processing
For paid plans, billing is processed by default through Stripe, our third-party payment processor. Stripe collects and stores your payment method details (such as your card number) directly; we do not store full payment card numbers on our own systems. We receive limited billing information from Stripe, such as your name, billing address, and transaction history, to manage your subscription and invoicing. Stripe's handling of your data is governed by Stripe's own privacy policy and may involve processing outside the EU. Enterprise and on-premise customers can arrange alternative billing methods that do not involve Stripe; contact our sales team for details.
9. Your Rights (GDPR)
Under GDPR, you have the right to access, rectify, delete, and export your data. You can also object to processing and withdraw consent. Contact us at contact@nebulas.ai to exercise these rights.
10. Your Rights (CCPA)
If you are a California resident, you have the right to know what personal information we collect, request its deletion, and opt out of the sale or sharing of personal information. We do not sell or share personal information as defined under the CCPA/CPRA. To exercise these rights, contact us at contact@nebulas.ai.
11. Children's Privacy
Nebulas.ai is not directed to, and we do not knowingly collect personal data from, individuals under the age of 16. If you believe a child has provided us with personal data, contact us at contact@nebulas.ai and we will delete it.
12. Contact
For any privacy-related inquiries, contact our Data Protection Officer at contact@nebulas.ai.