Privacy Policy
Last updated: 16 August 2026
1Who’s responsible for your data
Nunarra 1335 Mississauga RoadMississauga, Ontario L5H 2J3
Canada
contact@nunarra.io
Nunarra is responsible for the personal data described here.
We’re based in Canada and handle personal data under PIPEDA. Because we serve customers internationally, we also apply GDPR and UK GDPR standards to users in those regions, and CCPA/CPRA rights to users in California.
2What we collect
Waitlist: your email address, and optionally your name, company, industry, and a one-line description of what you sell.
Account: your name and email, your market or service area, your focus and price segment, your social handle as text you type — we do not connect to, log into, or access your social accounts, and we never hold platform tokens or passwords, and your billing details.
Payment card details are handled entirely by Stripe. We never see or store your full card number.
Usage: which opportunities you open, skip, save and generate from; scripts you generate; your “did you post this?” responses; and your settings. This is what makes tomorrow’s five better than today’s.
Automatic: IP address, browser and device type, pages visited, approximate location derived from IP.
3Why we use it
- To provide the service and personalise your daily set
- To take payment and manage your subscription
- To send service messages — receipts, trial and renewal reminders, service changes
- To send your weekly recap and product updates, with an unsubscribe link in every one
- To improve Nunarra, in aggregated and de-identified form
- To detect abuse and meet legal obligations
Where GDPR applies, our lawful bases are: contract (providing the service), legitimate interests (improving and securing it), consent (marketing email, non-essential cookies), and legal obligation (tax and accounting records). Under PIPEDA we rely on your consent, given when you sign up and withdrawable at any time.
Marketing email: we comply with CASL. We only send commercial email where you’ve given express consent or where we have an existing business relationship, we identify ourselves and our address in every message, and unsubscribe takes effect immediately.
4AI processing
To generate your personalised output, we send relevant parts of your profile and your chosen content item to our AI provider. That processing happens under commercial API terms that prohibit using your data to train their models, and the provider does not retain your data beyond what’s needed to return a result.
We do not use your profile, your generated scripts, or your usage history to train any model of our own that would expose your data to another user.
5Public social content
Nunarra analyses content that is publicly available on third-party platforms. That analysis includes performance figures those platforms publish themselves — follower counts, likes, views, comments — and the URL of the post.
We do not store the media itself. Source content is embedded from the original platform when shown to you. We do not build profiles of the people who posted it, market to them, or contact them.
If you are the author of content that appears in Nunarra and want it removed from our analysis, write to contact@nunarra.io and we’ll action it.
6Who we share it with
Only with service providers who help us run Nunarra, under contract and only for that purpose:
| Purpose | Provider | Where |
|---|---|---|
| Payments | Stripe | United States and globally |
| Hosting, DNS, CDN | Cloudflare | Global edge network |
| Business and transactional email | Google Workspace | United States and globally |
| AI processing | Anthropic | United States |
We keep this list current and update it before adding any new provider. We may disclose data if legally required, or as part of a merger or acquisition, in which case we’ll tell you.
We do not sell your data. We do not share your email with advertisers or list brokers.
7International transfers
We’re in Canada; our providers operate in the United States and elsewhere. Where data leaves the UK or EEA, we rely on Standard Contractual Clauses and the UK Addendum with each provider. Canada holds an EU adequacy decision for commercial organisations.
8How long we keep it
| Data | Retention |
|---|---|
| Waitlist emails | Until launch and you sign up or unsubscribe; maximum 24 months |
| Account data | While your account is active, then 90 days after closure |
| Generated scripts and archive | While your account is active, then 90 days after closure |
| Usage data | 12 months in identifiable form, then aggregated |
| Billing records | 6 years, as Canadian tax law requires |
| Support email | 24 months |
9Your rights
You can ask us for a copy of your data, to correct it, delete it, restrict or object to its use, or export it. You can withdraw marketing consent at any time.
Write to contact@nunarra.io. We acknowledge requests within 3 business days and respond within 30 days.
If you ask us to delete your data: we disable your account immediately, so nothing is accessible or processed from that point. We keep it recoverable for 7 days in case the request was a mistake or you change your mind. After that we permanently delete it from our live systems, and in every case within 30 days of your request. Copies held in encrypted backups are overwritten as those backups cycle, within 90 days.
Two things survive deletion, and only these: billing and tax records we’re legally required to keep for 6 years, and a minimal suppression record — a one-way hash of your email — so that we never contact you or re-add you to a list again. Neither can be used to rebuild your profile.
In Canada: if you’re unhappy with our response, you can complain to the Office of the Privacy Commissioner of Canada.
In the UK or EEA: you can complain to your local supervisory authority.
In California: you have the right to know, delete, correct, and opt out of sale or sharing. We don’t sell or share personal information as the CCPA defines those terms, and we won’t discriminate against you for exercising these rights.
10Cookies
We use essential cookies only. They keep you logged in and keep the service secure, and the site doesn’t work without them. We don’t use advertising cookies, and we don’t track you across other websites.
11Security
Encryption in transit, access controls, and vetted infrastructure providers. No system is completely secure; if a breach creates a real risk of significant harm we’ll notify you and the Office of the Privacy Commissioner of Canada, as PIPEDA requires, and the relevant authority in other regions.
12Children
Nunarra is for business use and isn’t directed at anyone under 18. We don’t knowingly collect data from children.
13Changes
We’ll post updates here and email you about material ones.