Privacy Policy
Effective date: July 21, 2026
nerD AI (the “Service”) is an AI work platform for marketing agencies, operated by nerDigital and available at app.nerdos.ai. This policy explains what information we collect, how we use and protect it, and the choices you have. It applies to the platform itself; where an agency serves its own clients through a branded portal or shared report, the agency is responsible for its relationship with those clients.
1. Information we collect
Account information. Name, email address, and authentication credentials when you create an account or are invited to a workspace.
Workspace content. Files, brand assets, campaign content, prompts, and other material you or your team create or upload while using the Service.
Connected platform data. Data from third-party platforms you explicitly connect to a workspace (see sections 3 and 4), such as analytics and search-performance metrics.
Usage and billing data. Metered AI usage, plan and subscription state, and payment status. Card details are handled by our payment processor — we never store card numbers.
Technical data. Authentication cookies needed to keep you signed in, and standard server logs (timestamps, IP addresses, request metadata) used for security and reliability. We do not use advertising or cross-site tracking cookies.
2. How we use information
We use the information above to provide and operate the Service: authenticating you, running the features you invoke, generating the reports and deliverables you request, metering usage for billing, providing support, and keeping the platform secure.
AI processing. The Service is built around AI features. Workspace content and connected-platform data are processed by AI systems — including third-party AI infrastructure providers acting under data-processing agreements — solely to deliver the features you invoke (for example, generating a report you asked for). Our AI infrastructure providers are not permitted to use your content or your connected-platform data to train their general-purpose models.
We do not sell your data, and we do not use it for third-party advertising.
3. Connected platforms
You can connect third-party accounts (for example a CRM, an advertising account, or the Google services described below) to an individual client workspace. Every connection is an explicit, per-workspace choice made by you.
Access credentials for connected platforms (such as OAuth tokens) are stored encrypted at rest in a managed secrets vault and are used only server-side. Disconnecting a platform from the workspace’s Integrations page deletes its stored credentials.
4. Google user data (Search Console & Google Analytics)
When you connect Google Search Console or Google Analytics to a workspace, you grant the Service read-only access via Google’s OAuth consent flow:
- Search Console (scope: webmasters.readonly) — search queries, clicks, impressions, average positions, URL index status, and sitemap status for the property you choose.
- Google Analytics (scope: analytics.readonly) — aggregated reporting metrics (such as sessions, users, conversions, and traffic channels) for the property you choose.
How we use it. This data is displayed back to you inside your workspace — in dashboards, the Search Performance page, and the reports you generate — and is processed by our AI features only to produce the analyses, summaries, and recommendations you request. It is used for no other purpose.
What we never do with it. We do not sell Google user data; we do not transfer it to advertising platforms, data brokers, or information resellers; we do not use it for advertising, retargeting, or creditworthiness decisions; and we do not use it to train general-purpose AI models.
Storage and retention. OAuth tokens are stored encrypted at rest. Report responses are cached briefly (minutes) to render pages quickly. Small daily aggregate metric snapshots (for example, total clicks per day) are retained to power trend charts and alerts. Disconnecting the integration deletes the stored tokens; you can also revoke access at any time from your Google Account permissions.
Human access. Our personnel do not read your Google user data except with your consent (for example, during a support request), for security or abuse investigation, or where required by law.
Limited Use. nerD AI’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
6. Security
Data is encrypted in transit (TLS) and at rest. Every client workspace is isolated with database-level row security. Third-party credentials live in a managed, encrypted secrets vault and never reach the browser. Access to production systems is restricted and audited.
7. Retention and deletion
We keep your information while your account is active. Disconnecting an integration deletes its stored credentials; deleting a workspace removes its content; and closing your account removes your data from production systems, after which residual copies age out of encrypted backups. You can request deletion at any time via the contact below.
8. Your choices and rights
You can access and update your account information in the app, disconnect any integration at any time, and request a copy or the deletion of your data by emailing us. Depending on where you live, you may have additional statutory rights (such as access, correction, portability, and erasure) — we honor such requests for all users.
9. Children
The Service is built for businesses and is not directed to children under 16. We do not knowingly collect personal information from children.
10. Changes to this policy
If we make material changes, we will update this page and the effective date above, and notify account owners by email or in-app notice before the changes take effect.
11. Contact
Questions, data requests, or the current subprocessor list: admin@nerdigital.com.