Legal

Privacy Policy

This Privacy Policy describes how noor (“we”, “us”) collects, uses, and protects information when you use our marketing analytics platform at heynoor.ai.

Last updated: 2026-09-11

1. Information we collect

  • Account information: name, email, hashed password, optional profile photo. Collected when you sign up.
  • Connected platform data: when you connect a Meta (Facebook/Instagram) account via Facebook Login, we receive the permissions you approve (e.g. ads_read, pages_read_engagement). We use these tokens to pull public advertising data and resolve brand page IDs. Tokens are encrypted at rest.
  • Workspace content: brand websites, social handles, and the analyses, strategies, and creatives we generate for you.
  • Usage data: pages viewed, features used, errors encountered. We use this to improve the product.

2. How we use your information

  • To power the marketing analytics features you request.
  • To send transactional notifications (alerts, weekly reports) that you’ve subscribed to.
  • To respond to support requests.
  • To detect abuse and protect against security threats.

We do not:

  • Sell your data to third parties.
  • Use your data to train third-party AI models.
  • Share your workspace content with other users unless you explicitly invite them.

3. AI processing

noor uses large language models (Google Gemini, OpenAI) and image generation models to analyse your data and generate creative content. Inputs are sent to the model provider over HTTPS and are subject to their data-retention policies:

  • Google Gemini: no retention; not used for training (Enterprise terms).
  • OpenAI: no retention on API; not used for training.

4. Meta Ad Library data

We pull public advertising data from Meta’s Ad Library (/ads_archive) only for brands you explicitly track. Data is stored per-workspace with a 7-day TTL and never shared across workspaces.

5. Data storage and security

  • Database hosted on Supabase (PostgreSQL) in AWS ap-northeast-1.
  • Tokens encrypted at rest using AES-256-GCM.
  • All traffic over HTTPS / TLS 1.2+.
  • Row-level security (RLS) on all multi-tenant tables.

6. Your rights

You can:

EU / UK / California residents have additional rights under GDPR / CCPA (access, portability, objection, restriction, erasure). Contact privacy@heynoor.ai.

7. Cookies

noor uses essential session cookies (Supabase auth) and one analytics cookie (self-hosted, no third-party tracking). No advertising cookies, no Meta Pixel, no cross-site tracking.

8. Contact

noor (operated by Brandloop / India Accelerator) — privacy@heynoor.ai