← Back to Nagare

Privacy Policy

Last updated: 12 July 2026

This Privacy Policy explains how Nagare (“we”, “us”) collects, uses, stores, shares and protects your personal data when you use our platform, and the rights you have under the EU General Data Protection Regulation (GDPR) and applicable law. By creating an account you agree to the practices described here.

1. Who is responsible for your data

The data controller is the operator of Nagare. For any privacy request you can reach us at info@alessandrobonfante.com.

2. What data we collect

  • Account data, your email address and a securely hashed password (managed by our authentication provider; we never store your password in readable form).
  • Brand & project data you provide, brand name, website, tone/voice, guidelines, audience, logo, brand colors, uploaded fonts and any portfolio material you add.
  • Content, the posts, drafts, captions, images and schedules created for you, and your approvals/edits.
  • Connection credentials, access tokens for the social accounts, AI/email providers and sites (e.g. WordPress Application Passwords) you connect. These are encrypted at rest (AES‑256‑GCM), used only to perform the actions you ask for (e.g. publishing a post you approved), and revocable at any time: disconnecting an integration deletes the stored credential, and you can also revoke it on the provider's side whenever you want.
  • Notification settings, a notification email and, if you link it, your Telegram chat ID.
  • Usage data, limited operational data such as counts of AI generations, needed to run the service and enforce plan limits.

3. How and why we use your data (legal bases)

  • To provide the service, generate, schedule and publish content, and show it to you for approval (legal basis: performance of our contract with you).
  • To connect and act on your social accounts, only after you explicitly authorize each platform (legal basis: your consent, which you can withdraw at any time by disconnecting).
  • To send you notifications you asked for (approval reminders, briefings) via email or Telegram (legal basis: contract / consent).
  • To secure, maintain and improve the platform and prevent abuse (legal basis: our legitimate interest, balanced against your rights).

We do not sell your personal data, and we do not use it for advertising or profiling.

4. Who we share data with (processors & platforms)

We share data only with the providers strictly needed to run the service:

  • Hosting & infrastructure, Vercel (application hosting) and Supabase (authentication, database and encrypted storage).
  • AI providers, Anthropic (Claude) to generate content; and, only if you add your own key, other providers you choose (e.g. OpenAI, Google, xAI, Perplexity). Prompts and the brand context needed to generate a post are sent to the selected provider.
  • Social platforms, Meta (Instagram, Facebook), X, LinkedIn and TikTok, only for accounts you connect, and only to publish or read on your behalf as you authorized.
  • Messaging & email, Telegram (if you link the approval bot) and our transactional email provider (for reminders/briefings).

Some providers may process data outside the EU/EEA; where they do, transfers rely on appropriate safeguards such as the EU Standard Contractual Clauses.

5. Cookies

Nagare uses strictly necessary (functional) cookies only. These keep you signed in and maintain your session security, they are essential for the platform to work and are set only after you log in. We do not use advertising, analytics or third‑party tracking cookies, so no tracking consent is required. You can clear these cookies at any time in your browser; doing so will sign you out.

6. How long we keep your data

We keep your data for as long as your account is active. When you delete your account, or ask us to erase your data, we delete your personal data and connected credentials (subject to any short technical backup rotation and legal retention obligations). You can disconnect any platform at any time, which immediately deletes the stored credentials for it.

7. How we protect your data

  • All traffic is served over HTTPS.
  • Secrets and access tokens are encrypted at rest with AES‑256‑GCM.
  • Each account’s data is isolated at the database level (row‑level security), so one user can never read another’s data.
  • Passwords are hashed by our authentication provider and never stored in readable form.

8. Your rights

Under the GDPR you have the right to:

  • access the personal data we hold about you;
  • rectify inaccurate data;
  • erase your data (“right to be forgotten”);
  • restrict or object to certain processing;
  • data portability;
  • withdraw consent at any time (e.g. by disconnecting a platform);
  • lodge a complaint with your supervisory authority (in Italy, the Garante per la protezione dei dati personali).

To exercise any of these rights, contact us at info@alessandrobonfante.com.

9. Children

Nagare is not directed to children under 16, and we do not knowingly collect their data.

10. Changes to this policy

We may update this policy as the service evolves. We will change the “Last updated” date above and, for material changes, notify you in‑app or by email.

← Back to NagareTerms of Service