Your Privacy Matters
At Naiori, we're committed to protecting your privacy and being transparent about how we collect, use, and safeguard your information. This policy explains everything in clear, straightforward language.
1. Information We Collect
1.1 Information You Provide
When you use Naiori, you provide us with:
- Account Information: Email address, name, and password (encrypted)
- Business Intelligence Queries: Search queries, prompts, and analysis requests
- User-Generated Content: Saved prompts, ideas, feedback, and notes
- Payment Information: Processed securely through Stripe (we never store credit card details)
- Subscription Data: Plan type, usage limits, and billing cycle information
1.2 Automatically Collected Information
To improve your experience, we automatically collect:
- Usage Analytics: Features used, AI models selected, search patterns
- Device Information: Browser type, operating system, device identifiers
- Performance Data: Page load times, API response times, error logs
- Session Data: Login times, session duration, navigation paths
- IP Address: For security, fraud prevention, and rate limiting
1.3 AI Model Data
As a platform generating prompts optimized for major AI models, we collect:
- Model Usage: Which AI models you select
- Prompt Content: The prompts and queries you submit, and any content you explicitly choose to save (e.g., saved ideas)
- Quality Ratings: Optional feedback you choose to submit on AI outputs (you are never required to rate anything)
2. How We Use Your Information
2.1 Core Service Delivery
- Generate prompts optimized for 34 AI models (text, video, image, audio)
- Generate business intelligence and market analysis
- Store the prompts, ideas, and content you choose to save
- Enforce subscription limits and feature access
- Process payments and manage billing
2.2 Service Operation & Reliability
We use aggregated and anonymized data to operate, secure, and improve the reliability and speed of Naiori. We do not use your individual prompts or queries to train third-party AI models.
2.3 Product Improvement
- Analyze usage patterns to improve features
- Identify and fix bugs and performance issues
- Develop new features based on user needs
2.4 Communication
- Send service updates and feature announcements
- Provide customer support and respond to inquiries
- Send billing notifications and subscription updates
- Share tips and best practices (you can opt out)
3. How We Store and Protect Your Data
3.1 Data Storage
Your data is stored securely using enterprise-grade cloud infrastructure with encryption at rest and in transit. We use reputable sub-processors for database, hosting, payments, and error monitoring (full list available in our sub-processor disclosures on request).
3.2 Security Measures
- Encryption: Industry-standard encryption protects data in transit and at rest
- Access Controls: User-level access controls ensure you can only see your own data
- Authentication: Secure authentication with hashed credentials
- Rate Limiting: Automated rate limiting prevents abuse
- Monitoring: Error and performance monitoring
3.3 Data Retention
- Active Accounts: Data retained while your account is active
- Analytics: Aggregated analytics retained for 90 days
- Prompt Archive: Older prompts may be archived per our retention policy (summary metadata may be retained)
- Deleted Accounts: Personal data deleted within 30 days of account deletion
- Legal Obligations: Some data retained longer for compliance (billing records: 7 years)
4. Third-Party Services
Naiori integrates with trusted third-party services. Here's what each service accesses:
AI Model Providers
When you generate or run a prompt, its content is sent to the AI provider you select to produce a response:
- OpenAI — text, reasoning, image, and video models
- Anthropic — Claude family models
- Google — Gemini family models
- xAI — Grok models
- Other providers — additional supported text and multi-modal models
Note: We use API-only access to these providers. Current API terms from major providers exclude API data from model training by default. Your prompts are processed to generate a response and may be cached to improve performance.
Google Sign-In (OAuth)
If you choose to sign in with your Google account, Google shares the following with Naiori:
- Email address (used for your account identity and login)
- Name (used for your profile)
- Profile picture URL (optional, used for display)
- Google account unique ID (used to link sign-in sessions)
We request only the openid, email, and profile scopes — the minimum needed to create your account. Naiori does NOT access your Google Drive, Gmail, Calendar, or any other Google services. Sign-in is handled through Supabase Auth, which is verified by Google.
Google Analytics 4 (GA4)
We use Google Analytics 4 to understand how visitors discover and use Naiori. GA4 may collect:
- Page views and navigation paths
- Device, browser, and approximate location (city level, derived from IP)
- Anonymized session identifiers via cookies (
_ga,_ga_*) - Conversion events (CTA clicks, signup steps — no PII included)
We normalize all error codes before sending to GA4 to ensure no personally identifiable information leaks into analytics. GA4 data is retained for 14 months. Analytics scripts currently load by default. To opt out: use a browser ad blocker, install the Google Analytics opt-out add-on, or enable Do Not Track in your browser. We do not currently implement a category-level consent gate; that is on our roadmap.
Infrastructure & Security
- Supabase: Authentication, database, and user data
- Cloud hosting: Global edge hosting and deployment
- Caching / rate limiting: Session management and abuse prevention
- Error monitoring: Real-time error tracking and performance monitoring
A complete sub-processor list is available on request via privacy@naiori.ai.
Payments
- Stripe: Payment processing, subscription management
Note: We never store credit card details. All payment data is handled by Stripe (PCI-DSS certified).
5. Your Privacy Rights
You have comprehensive rights over your data:
5.1 Access & Portability
- View Your Data: Access your saved prompts and ideas via your account dashboard
- Request Full Data Export: Email privacy@naiori.ai for a complete copy of your personal data. We'll respond within 30 days (typically within 48 hours).
5.2 Control & Correction
- Update Information: Edit your profile, email, and preferences anytime in Settings
- Delete Content: Remove individual saved prompts, ideas, or items from your account
- Opt-Out of Communications: Unsubscribe from marketing emails at any time (essential account emails still sent)
5.3 Deletion & Account Closure
- Request Account Deletion: Email privacy@naiori.ai from your account email. We'll verify your identity and process the request within 30 days.
- What Gets Deleted: All personal data, prompts, saved content, and account information
- What's Retained: Anonymized usage analytics and billing records (the latter retained for 7 years per legal requirement)
5.4 GDPR Rights (EU Users)
- Right to access your personal data
- Right to rectification (correct inaccurate data)
- Right to erasure ("right to be forgotten")
- Right to restrict processing
- Right to data portability
- Right to object to processing
- Right to withdraw consent
5.5 CCPA Rights (California Users)
- Right to know what personal information is collected
- Right to delete personal information
- Right to opt-out of sale of personal information (we don't sell your data)
- Right to non-discrimination for exercising privacy rights
6. Cookies and Tracking
6.1 Essential Cookies
Required for the service to function:
- Authentication: Keep you logged in
- Security: CSRF protection, session management
- Preferences: Remember your theme, language settings
6.2 Analytics Cookies
Help us improve the service (you can opt out):
- Usage Analytics: Track feature usage, popular AI models
- Performance Monitoring: Identify slow pages, errors
7. Data Sharing and Disclosure
✅ We DO NOT sell your data. Ever.
Your business intelligence queries, prompts, and insights are yours. We will never sell, rent, or trade your personal information to third parties.
7.1 When We Share Data
We only share data in these specific circumstances:
- Service Providers: AI model APIs (OpenAI, Anthropic, etc.) to generate responses
- Payment Processing: Stripe for subscription billing
- Legal Obligations: If required by law, court order, or government request
- Security Threats: To prevent fraud, abuse, or illegal activity
- Business Transfer: In case of merger, acquisition, or asset sale (you'll be notified)
7.2 Aggregated Data
We may share anonymized, aggregated data that cannot identify you:
- "Naiori users generated 1M prompts this month" (no individual user data)
- "Reasoning models are the most popular for market analysis" (usage trends)
- Platform performance metrics and industry benchmarks
8. Children's Privacy
Naiori is a business intelligence platform intended for users aged 18 and older. We do not knowingly collect information from children under 18. If you believe a child under 18 has provided us with personal information, please contact us immediately at privacy@naiori.ai.
9. International Data Transfers
Naiori operates globally using cloud infrastructure. Your data may be processed in:
- United States: Primary data centers (Supabase, Vercel)
- European Union: Edge locations for EU users
- Other Regions: Global CDN for performance
We ensure appropriate safeguards are in place for international transfers, including Standard Contractual Clauses (SCCs) where required.
10. Changes to This Policy
We may update this Privacy Policy as our service evolves. We'll notify you of material changes by:
- Updating the "Last Updated" date at the top of this page
- Sending you an email notification (for significant changes)
- Displaying a prominent notice in the app
Continued use of Naiori after changes constitutes acceptance of the updated policy.
11. Contact Us
Questions about this Privacy Policy or how we handle your data? We're here to help:
Email:
privacy@naiori.aiSupport:
support@naiori.aiResponse Time:
We respond to privacy inquiries within 30 days (typically within 48 hours)
Privacy at a Glance
✅ What We Do
- • Encrypt all your data
- • Protect with strict access controls
- • Optimize performance and reliability
- • Use data to improve your experience
❌ What We Don't Do
- • Sell your data to anyone
- • Share data without permission
- • Train AI models on your private data
- • Store credit card information