Legal
Privacy Policy
What Nephia stores — about you, and about the people whose public posts appear in your mentions — for how long, who processes it, and how to ask for something to be removed.
Last updated: September 3, 2026
This Privacy Policy explains what Nephia ("we", "us") stores and why — about you when you visit the website, sign in to the dashboard or use the API, and about the people whose public posts appear in the mentions we collect. It should be read with our Terms of Service, our Data Processing Agreement and the Sub-processors list.
1. What Nephia is, and the two roles we hold
Nephia watches public Sources for the terms you choose, keeps what it finds as mentions for a stated number of days, labels them with AI and delivers them to the channels you configure. It is a store, not a pipe, and this policy is written accordingly.
- We are the controller for your account and for what the Services do the same way for everyone: collecting public mentions, keeping them for the windows in section 7, labelling them with AI, embeddings, anonymous price observations and AI-answer runs.
- We are your processor for what you decide: the terms and Sources you watch, your mute and VIP rules, your channels, your exports, and what you do with mentions afterwards. The DPA covers that part.
2. Information we collect about you
2.1 Account and sign-in
- Your email address, and a normalised form of it (lower-case, without a
+tag, and without dots for Gmail addresses) that we keep so the same mailbox cannot open several accounts. The normalised form is never shown or emailed. - If you sign in with Google: your email, name, Google account id and profile picture if your account has one.
- Session tokens that keep you signed in, and hashed API keys.
- The domain of your email address, checked at sign-up against a list of disposable providers and for a valid mail server. The list is a package on our servers; the mail check is a DNS lookup. Neither sends your address to a third party.
2.2 What you configure and how you use the Services
- Your Queries: search terms, Sources, refresh intervals, AI instructions, sorting buckets, and mute or VIP rules — which may contain the public handles of people you chose to silence or highlight.
- Your delivery channels: Slack, Discord and HTTP endpoints, and the email addresses you chose as recipients. A recipient you add who is not you is told nothing by us; you are responsible for having their agreement.
- The usage ledger: which calls were made, when, with what result, and the credits they consumed.
- Your IP address, for rate limiting, the sign-up cap and security logs, kept as stated in section 7.
- Admin audit events when we act on your account.
2.3 Payments
None during the public beta: nothing is for sale and no payment provider is called. The provider that will act as merchant of record, and what it receives, will be added to the Sub-processors list before the first sale.
2.4 Communications
When you email us, or we send you sign-in links, account notices or the digests and reports you asked for, we process the content and metadata of those messages.
2.5 Website analytics
Only after you accept analytics cookies. If you decline, your visit is counted without a cookie and without an identifier that survives the tab. A refused sign-up is recorded as an event with the reason and the page, never with the address. See the Cookie Policy.
3. Mentions we store
A mention is a public post, comment, video, article, listing or AI answer that matched a Query. It is written by someone who is usually not our customer. This section is about them.
3.1 What a stored mention contains, by kind of Source
| Kind | Sources | What we keep |
|---|---|---|
| Posts and comments | X, Reddit, Bluesky, Mastodon, Lemmy, Hacker News, Stack Overflow, GitHub, Product Hunt | Post or comment id, permalink, title and body text, the author’s public handle and display name as shown on the platform, the community it was posted in (subreddit, instance, repository), public engagement counters (likes, replies, score, views), media URLs, posting time. |
| Videos | YouTube, TikTok | Video id, URL, title, description, the channel or creator’s public name and handle, view, like and comment counts, publishing time. |
| Feeds | RSS | Article URL, title, summary or excerpt, the byline if the feed carries one, publishing time. |
| AI answers | ChatGPT, Gemini | The question we asked, the answer the assistant returned, and the sources it cited. These runs contain no third-party author. |
| Marketplace listings | Vinted | Listing id, URL, title, description, price, brand, size, condition, photo URLs, the seller’s public nickname and the public profile counters shown beside a listing (feedback score, item counts, country and city as displayed), listing time. |
3.2 What we add to it
- AI labels: which group a mention belongs to, its sentiment, which sorting bucket it went to, whether a rule fired, and the result of any agent step you configured.
- Summaries, digests and weekly reports that quote or paraphrase mentions.
- A semantic embedding of the text, kept 30 days, so you can find similar mentions.
- Your own marks: read, starred, muted, and the notes you attach.
3.3 What we do not do with authors
- We do not build profiles of authors across Queries or across customers. The only author-level view is the Authors tab of a Query: at most 25 public handles ranked by how often they mentioned your terms in a window, showing what the mentions themselves carry and nothing more.
- We do not re-identify anyone — we do not link a handle to a real name, an employer or another platform — and the Terms forbid our customers from doing so with our data.
- We do not train, fine-tune or evaluate any AI model on mentions, and forbid our customers from doing so.
4. How we use information
- Provide, secure and improve the Services
- Authenticate you and manage your account, API keys, Queries and channels
- Collect, store, label and deliver mentions as your Queries instruct
- Meter usage, enforce quotas and prevent fraud or abuse
- Send service communications — not marketing unless you opt in later
- Comply with law and enforce our Terms
- Produce aggregated, non-identifying analytics about product health
5. Legal bases (EEA/UK)
Where the GDPR or UK GDPR applies, we rely on:
- Contract — to provide the Services you signed up for
- Legitimate interests — ours and our customers’, for collecting and labelling public mentions of names, brands and products (Article 6(1)(f)); for security, abuse prevention and product improvement. The interest is weighed against the author’s: we keep public content only, for a stated time, without profiling, and with a removal procedure (section 8).
- Legal obligation — tax, accounting and lawful requests
- Consent — analytics cookies, which are set only after you accept them and which you can withdraw at any time from the "Cookie settings" link in the site footer or the Privacy card on your Account page
6. AI processing
Grouping, sentiment, sorting, summaries, weekly reports, agent steps and semantic embeddings are produced by large language models. The content of mentions and the instructions you wrote for a Query are sent for that purpose to OpenRouter, which routes each request to a model host. Every request carries a data policy that restricts routing to hosts that neither train on nor retain the content, and OpenRouter refuses the request rather than route it elsewhere. We do not name the model, because it changes; the policy does not.
AI outputs are estimates. A sentiment, a group or a summary is an automated reading of a text written by a stranger, offered as decision support; it is not a statement of fact about the author or about you.
8. If you appear in a mention
If something you posted publicly has been collected by Nephia and you want it removed, email [email protected] with the subject "Removal request" and the URL of the post. We will:
- Confirm receipt, and answer within 30 days.
- Delete the mention and its AI labels from every Query that holds it, and tell you when it is done. We do not tell you which customers were watching it.
- Tell you if we cannot act — for example if the URL is not one we hold, or if the request is really about the platform where the post still lives.
You can also ask what we hold about a public handle. We do not re-check Sources for posts their authors have since deleted; a removal request is how a deletion reaches us before the retention window does.
9. Export and switching providers
Your data is yours to take. At any time, without charge and in open formats, you can export a Query’s mentions with their AI labels as CSV from the dashboard (5,000 rows per file) or page through them with the product API, and read your account and Query configuration from the same API. When the Services end — for you, or for everyone — you keep that access for 30 days before deletion. This is our commitment under the EU Data Act’s switching provisions, stated in full in the Terms.
10. Security
- TLS for data in transit
- Access controls for production systems and admin actions
- API keys stored as hashes; sign-in by link or Google, never by password
- Rate limiting, a per-address sign-up cap and abuse monitoring
No method of transmission or storage is perfectly secure. You are responsible for protecting your API keys and the endpoints you configure.
11. International transfers
Data is stored in France. Some providers in section 7 process data in the United States; for those we rely on the EU–US Data Privacy Framework where the provider is certified, and on Standard Contractual Clauses with supplementary measures otherwise.
12. Your rights
12.1 GDPR / UK GDPR
You may have the right to:
- Access, rectify or erase your data
- Restrict or object to certain processing — including the collection of a public post you wrote
- Receive the data you provided in a portable format
- Lodge a complaint with a supervisory authority. Ours is the CNIL, cnil.fr.
12.2 California and similar US state laws
We do not sell personal information. Residents of California and similar jurisdictions may request to know or delete the personal information we hold about them.
To exercise a right, email [email protected] with the subject "Privacy Request". We may need to verify your identity, and we answer within 30 days.
14. Children
The Services are not directed to individuals under 18, and we do not knowingly open accounts for them. Public posts by minors can appear in mentions like anyone else’s; a removal request from a minor or their parent is handled as in section 8, with priority.
15. Changes
We update this policy by posting a revised version and dating it. For material changes we email account holders 30 days before they take effect.
16. Contact
Privacy questions and requests: [email protected]