Privacy Policy

Effective Date: January 1, 2025
Last Updated: January 20, 2025

Noverload ("we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains in clear terms howNoverload collects, uses, and safeguards information when you use our service. It is designed to comply with applicable global privacy laws including the GDPR and CCPA, and we strive to follow privacy best practices.

1. Scope and Application

This Privacy Policy applies to the Noverload web application and any related services. By using Noverload, you acknowledge that you have read and understood this Policy. This Policy covers users globally and addresses the specific requirements of major privacy regulations.

2. Who We Are & Our Commitment

Noverload is an AI-powered action layer that transforms your saved content into goal-aligned action items. We help you turn consumed content from YouTube, X (Twitter), articles, and PDFs into concrete, actionable tasks.

🔒 You own your data. Full stop. We do not use your data for advertising profiling, training AI models, or any purpose beyond serving you.

For the purposes of data protection laws, the data controller of any personal data collected by Noverload is:

Noverload
Email: contact@noverload.com
Website: https://noverload.com

3. Information We Collect

We collect information in the following categories:

Account Information

  • Email address (for authentication and communication)
  • Authentication credentials (managed securely by Supabase Auth)
  • Account preferences and settings

Service Usage Data

  • Content you save (YouTube videos, X posts, articles, PDFs)
  • Goals you create and track
  • AI-generated summaries and action items
  • Action completion status and progress
  • Usage patterns and feature interactions

Saved Content

  • URLs and titles of saved content
  • Extracted text and metadata from content
  • Content embeddings for AI processing
  • Generated summaries and insights

Technical Information

  • Browser type and version
  • Device information and operating system
  • IP address (for security and fraud prevention)
  • Usage patterns and feature interactions

Payment Information

All payment transactions are processed by our third-party payment provider. We do not store credit card numbers or banking information directly.

4. How We Use Your Information

We use the collected information for the following purposes:

  • Service Delivery: To provide, maintain, and improve our content-to-action transformation service
  • AI Processing: To generate summaries, insights, and actionable tasks from your saved content
  • Goal Alignment: To align generated actions with your personal goals and objectives
  • Account Management: To manage your account, usage limits, and preferences
  • Communication: To send service updates, security alerts, support messages, and marketing communications (with your consent)
  • Analytics: To understand usage patterns and improve our service
  • Security: To detect and prevent fraud, abuse, and unauthorized access
  • Legal Compliance: To comply with legal obligations and enforce our terms

5. Content Privacy and AI Processing

We prioritize your content privacy:

  • Content Processing: Your saved content is processed by AI to extract key insights and generate actionable tasks
  • Data Minimization: We only extract and store what's necessary to provide actionable insights
  • User Control: You can delete any saved content and its associated data at any time
  • No Training on Your Data: We never use your personal content to train AI models. Your data remains yours alone.
  • Storage Security: Content is stored in Supabase's infrastructure with database-level access controls

6. Legal Basis for Processing

We process your data based on:

  • Contract Performance: To provide the services you've requested
  • Legitimate Interests: To improve our services and ensure security
  • Consent: For optional features and marketing communications
  • Legal Obligations: To comply with applicable laws

7. Data Storage and Security

Your data is stored and processed using the following infrastructure:

  • Database: Supabase (PostgreSQL) with infrastructure-level encryption at rest
  • File Storage: Supabase Storage with access controls
  • Data Transmission: HTTPS/TLS encryption for all data in transit
  • Authentication: Supabase Auth manages user authentication securely
  • Access Control: Row Level Security (RLS) policies ensure users can only access their own data

Transparency Note:

While we implement security best practices, including infrastructure-level encryption and access controls, your content data (summaries, actions, saved articles) is not encrypted at the application level. This means that:

  • Database administrators could potentially view your data
  • In case of a database breach, your content could be exposed
  • We recommend not saving highly sensitive or confidential information

We are continuously working to improve our security measures and may implement additional encryption layers in the future.

8. Third-Party Service Providers

We use carefully selected third-party services:

  • Supabase: Database and authentication services
  • Claude (Anthropic) and OpenAI: AI analysis (data processed under their privacy policy)
  • Stripe: Secure payment handling

All third-party providers are bound by data processing agreements and appropriate safeguards.

9. International Data Transfers

Your data may be transferred to and processed in countries outside your residence. We ensure appropriate safeguards are in place, including:

  • Standard contractual clauses
  • Data processing agreements
  • Adequacy decisions where applicable

10. Data Ownership & Portability

You own your data. You can access, export, or delete it at any time. We do not access or use your content for any reason other than delivering the features of our Service.

Data Portability: Your data should move with you. We provide full data export in JSON format including all your saved content, goals, actions, and settings. You always retain control—whether you stay with Noverload or move on.

11. Data Retention

We retain your data according to the following schedule:

  • Account Data: As long as your account is active
  • Saved Content: Until you delete it or close your account
  • Generated Actions: Until you delete them or close your account
  • AI Insights: Until you delete the associated content
  • Technical Logs: Up to 90 days for security purposes
  • Deleted Data: Removed within 30 days of deletion request

12. Your Privacy Rights

Depending on your location, you may have the following rights:

  • Access: Request a copy of your personal data
  • Rectification: Correct inaccurate or incomplete data
  • Erasure: Request deletion of your data
  • Portability: Export your data in JSON format anytime from Settings → Privacy
  • Restriction: Limit how we process your data
  • Objection: Object to certain processing activities
  • Withdraw Consent: Where processing is based on consent

To exercise these rights, contact us at contact@noverload.com. We will respond within 30 days.

13. Future Advertising Model (Not Yet Active)

📌 Important: Advertising features are not currently active

We are planning a privacy-preserving advertising model to keep Noverload free for all users. When implemented, it will protect your personal data with the following commitments:

Planned Privacy Protections

When advertising is introduced, we commit to:

  • Cohort-Based Targeting: Users will be grouped in large cohorts, never individually targeted
  • No Personal Data Sharing: Advertisers will never access individual user data
  • Protected Personal Information: Your goals, conversations, and content are access-controlled
  • Time-Limited Data: Any interest data will auto-expire
  • Full User Control: Complete opt-out available at any time

Our Advertising Principles

If/when we introduce advertising:

  • We will NEVER sell your data: Your information stays with us
  • Context over tracking: Ads based on content categories, not personal profiles
  • Transparent disclosure: Clear notification before any advertising features activate
  • Consent first: Explicit opt-in required for any advertising
  • Premium option: Ad-free tier will be available

Current Data Usage

Today, we only collect:

  • Essential account information (email, preferences)
  • Content you explicitly save for processing
  • Anonymous usage analytics (via PostHog)
  • Technical logs for security and debugging

Note: This section describes our future plans for sustainable monetization. We will update this policy and notify all users before implementing any advertising features.

14. Marketing Communications

When you create an account, you are automatically opted in to receive marketing communications from us. We use your email address to send:

  • Product updates and new features
  • Educational content and best practices
  • Special offers and promotions
  • Community updates and success stories

Your Control: You can manage your email preferences at any time:

  • Through your account settings under "Notification Preferences"
  • By clicking the unsubscribe link in any marketing email
  • By contacting us at contact@noverload.com

We respect your preferences and will process unsubscribe requests promptly. Note that you cannot opt out of essential service communications (e.g., security alerts, account notifications).

15. Cookies and Tracking

We use essential cookies and similar technologies to:

  • Maintain your session and authentication
  • Remember your preferences
  • Ensure security and prevent fraud

We do not use third-party tracking cookies or advertising cookies.

16. Children's Privacy

Noverload is not intended for children under 13 (or 16 in certain jurisdictions). We do not knowingly collect information from children. If we discover such data, we will delete it immediately.

17. Changes to This Privacy Policy

We may update this policy to reflect changes in our practices or legal requirements. We will notify you of material changes via email or through the service. The latest version will always be dated at the top.

18. Contact Us and Privacy Officer

If you have questions, concerns, or wish to exercise your privacy rights, please contact:

Privacy Officer
Noverload
Email: contact@noverload.com
Website: https://noverload.com

You may also file a complaint with your local data protection authority if you believe your rights have been violated.