Privacy Policy
Last updated: June 2026
What we collect
- Email address for account login and billing notifications
- Encrypted password, never stored as plain text
- Tweet text you are actively replying to, only when you use NurAi
- Daily usage count for billing and quota enforcement
- Crypto payment metadata such as transaction ID and plan purchased
- Referral codes, referral attribution, wallet ledger entries, and withdrawal requests
- BEP-20 USDT withdrawal address if you request a referral payout
- Dashboard announcements and global chat messages you send or read
What we do not collect
- Your X/Twitter login credentials
- Your DMs or private messages
- Your browsing history
- Tweets you did not actively reply to
- Generated reply text after the response is returned to you
- Your IP address or location beyond standard server logs
- Your payment wallet address for NOWPayments/Base Pay checkouts, except withdrawal addresses you submit for referral payouts
How we use your data
Tweet text is sent through our AI gateway to generate reply suggestions. We do not store the tweet text or generated reply text. Email is used for login, account recovery, and important service announcements. Announcements and global chat are stored so users can read updates and community messages inside the dashboard. Referral and withdrawal records are used to calculate bonuses, prevent duplicate credits, process manual payouts, and keep an audit trail.
Third-party services
- Vercel - hosts our application and AI gateway.
- AI providers - generate and ground reply suggestions through Vercel AI Gateway.
- NOWPayments - processes crypto subscription payments.
- Supabase - provides our PostgreSQL database.
Data retention
Account data and usage counters are retained as long as your account exists. Generated reply text is not retained. You may request deletion at any time. After deletion, all personal data is permanently removed within 30 days.
Your rights
You can request access to, correction of, or deletion of your data by emailing probably.nothing.to.say@gmail.com.
Security
All data is transmitted over HTTPS. Passwords are hashed with bcrypt. JWT tokens have 30-day expiry. Database access is restricted to our backend only.
Contact
Questions? Email probably.nothing.to.say@gmail.com or message us on Telegram @Nur_Xai.