NiniOneNiniOne← Back to home

Legal

Privacy Policy

Last updated: July 27, 2026

1. Who we are

NiniOne is operated by N1 AI LLC (Gabriel Isakadze st. N 12, apt. 44, Saburtalo district, Tbilisi, Georgia). We make an AI tool that plans, creates and publishes social media content for small businesses. This policy explains what personal data we handle when you use ninione.appand the dashboard behind it (together, the "Service"), and what you can do about it.

For anything in this policy, or to exercise any right in section 8, write to privacy@ninione.app.

2. What we collect

Four kinds of data, and nothing beyond what the Service needs.

  • Account data — the email address you sign up with, your name, optionally a phone number, and your password. Passwords are hashed by our authentication provider; we never see or store them in readable form.
  • Brand data — what you tell us about your business during onboarding: business name, industry, tone of voice, language, target audience, content themes, logo and brand colours. This is what makes the output sound like you rather than like a generic robot.
  • Content data — the prompts you write, the photos, videos and audio you upload, and everything generated from them. If you use voice cloning or an AI presenter, this includes a voice sample and a photograph.
  • Technical data — IP address, browser type, timestamps and error logs, collected automatically so the Service can run, resist abuse, and be debugged when it breaks.

When you connect a social account we also receive an access token for it, plus basic profile information such as the account name and follower count. The token is encrypted before it is stored and is used only to publish what you scheduled.

3. What we do not do

  • We do not sell personal data. Not to anyone, at any price.
  • We do not use your content to train AI models, and the providers we work with are not permitted to train on it on our instruction.
  • We do not run advertising trackers or third-party analytics — see our Cookie Policy.
  • We do not read private messages on connected accounts. We publish; we do not browse.

4. Why we are allowed to process it

Under the GDPR, our legal bases are:

  • Performance of a contract — account, brand and content data. Without them there is no Service to provide.
  • Legitimate interests — technical data, for security, abuse prevention and keeping the Service working. We collect the minimum that achieves it.
  • Consent — voice cloning and AI presenter features, which you switch on deliberately and can withdraw at any time by deleting the saved voice or presenter. Withdrawal does not affect what was lawfully done beforehand.
  • Legal obligation — billing and accounting records we are required to keep.

5. Who else sees it

To run the Service we use third-party providers for hosting, AI generation, video processing, email delivery and payments. They act on our instructions and may use your data only to perform the task we gave them.

We describe them by category rather than by name — see Data Recipients — because our specific choice of providers is commercially sensitive. Customers who need the exact list for their own compliance records can request it.

Separately, your content goes to the social platforms you connect, because that is the entire point. Once published there it is governed by that platform's privacy policy, not ours.

6. Where it goes

Our hosting and database are in the European Union. Some AI generation providers operate from the United States; where personal data reaches them, the transfer is covered by the European Commission's Standard Contractual Clauses, and we send only what the request itself requires — a prompt, a photo, an audio file — never your account or billing records.

7. How long we keep it

  • While your account is open — account, brand and content data, because you are using it.
  • 30 days after you delete your account — then erased from live systems. Backups roll off within a further 90 days.
  • Social access tokens — deleted immediately when you disconnect the account.
  • Technical logs — 90 days.
  • Billing records — as long as tax and accounting law requires, regardless of account deletion.

8. Your rights

If the GDPR applies to you, you can ask us for a copy of your data, correct it, delete it, receive it in a portable format, restrict what we do with it, or object to processing based on legitimate interests. If the CCPA applies to you, you can ask what we collected, ask us to delete it, and opt out of sale — though as section 3 says, there is no sale to opt out of.

Write to privacy@ninione.app from the address on your account. We reply within 30 days, at no charge, and using these rights will never degrade your service. Deletion can also be done yourself — see how to delete your data.

If you think we have handled your data badly, you may complain to your local data protection authority. We would rather you told us first, but it is your right either way.

9. Keeping it safe

Traffic is encrypted in transit. Social access tokens are encrypted at rest with AES-256-GCM before they reach the database. Access to production data is limited to what is needed to operate the Service.

No system is perfect. If a breach affects your personal data and poses a real risk to you, we will notify you and the relevant authority within 72 hours of becoming aware, and we will tell you what actually happened rather than a sanitised version of it.

10. Children

The Service is for businesses and is not directed at children. We do not knowingly collect data from anyone under 16. If you believe a child has given us data, write to us and we will delete it.

11. Changes

If we change this policy in a way that matters, we will email the address on your account at least 14 days before it takes effect. Smaller corrections are published here with a new date at the top.

N1 AI LLC, a Limited Liability Company registered in Georgia with the LEPL National Agency of Public Registry under identification number 405872649. Registered address: Gabriel Isakadze st. N 12, apt. 44, Saburtalo district, Tbilisi, Georgia. Contact: privacy@ninione.app.

© 2026 NiniOne
TermsPrivacyContact