Legal

Privacy Policy

Last updated: 24 July 2026

1. Who we are

Noven is a content-automation platform operated by NOVEN STUDIO LTD, a company registered in England and Wales (“Noven”, “we”, “us”). For privacy questions, account deletion requests, or data-access requests, email hello@noven.studio.

Noven is operated by NOVEN STUDIO LTD, a company registered in England and Wales (company number 17359115).

2. What data we collect

We collect only what we need to run the service:

  • Account info: name and email (via Clerk authentication).
  • Uploaded media: videos and audio you upload for transcription and clipping. Stored temporarily on our processing infrastructure (Railway) during the workflow and deleted after a short retention window.
  • Generated content: AI-generated transcripts, clips, captions, carousels, posts, and any edits you make.
  • Third-party tokens: OAuth access and refresh tokens for the platforms you connect (LinkedIn, X, Instagram, Threads, YouTube). Tokens are stored in our database to publish on your behalf and can be revoked at any time from Settings → Connected Accounts.
  • Scheduled posts: the text, media URLs, scheduled times, and post statuses you queue through the app.
  • Billing data: Stripe handles all payment information. We never see or store your card details — we only receive a customer ID and subscription status.
  • Operational logs: standard server logs (timestamps, IP, user-agent, error traces) for debugging and abuse prevention.

3. How we use it

  • To run the core service: transcribe your media, generate clips/carousels/posts, render media files, and publish or schedule them to the platforms you connect.
  • To bill you for the plan you choose.
  • To send transactional emails (account events, billing receipts, deletion confirmations).
  • To monitor abuse and keep the service running.
  • To understand, in aggregate, what kind of content Noven is used for, so we can improve it. This means counts and patterns — how long imported videos are, which formats are generated, which platforms are connected, and the title of a video you import from a public URL (for example a YouTube link). We do not watch your videos or read your transcripts to profile you, and we never publish or share anything that identifies you or your content.

We do not sell your data, use your media to train AI models, or share your content with other Noven users.

A note on files you upload from your own device: we record the file name only, because that is what lets you find your project again. If a file name would tell us something you would rather we did not know, rename it before uploading.

If your media contains other people — a guest, a client, an interviewee — you are responsible for having their permission to process it. We treat that footage exactly as we treat yours: it is processed to produce your content, and it is not used for anything else.

4. Third-party processors

We rely on the following sub-processors to deliver the service:

  • Clerk — authentication and session management.
  • Supabase — application database (user records, OAuth tokens, scheduled posts).
  • Vercel — web hosting.
  • Railway — media processing (transcription, video rendering, image generation).
  • Z.ai and Anthropic — AI-generated clip selection, social copy, and carousel content. Your transcripts and generated content pass through these providers' APIs solely to generate your content; they are not used to train their models.
  • Deepgram — speech-to-text transcription.
  • Stripe — payments.
  • LinkedIn, X (Twitter), Meta (Instagram + Threads), Google (YouTube) — when you connect these platforms, your posts and media are sent to them under your authorization.

Each processor receives only the minimum data needed for its role.

5. Third-party platform scopes

When you connect a platform we request the minimum OAuth scopes required to publish on your behalf:

  • YouTubeyoutube.upload, youtube.readonly: upload the videos you queue to your channel, and read your channel name to show which account is connected. We never read, edit, or delete your existing videos, comments, or subscriptions.
  • Instagraminstagram_business_basic, instagram_business_content_publish: read your account name and publish image / carousel posts.
  • Threadsthreads_basic, threads_content_publish: publish threads.
  • LinkedInopenid, profile, w_member_social: identify you and publish posts.
  • X (Twitter) — tweet.read, tweet.write, users.read: publish tweets.

We never read your inbox, your DMs, your followers, or anything beyond what is strictly required to publish the content you queue.

Google user data. Noven's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data (your channel name and the videos you queue for upload) is used solely to provide the publishing features you request — it is never used for advertising, never sold or transferred to data brokers, and never used to develop, improve, or train AI/ML models.

6. Data retention and deletion

  • Uploaded source videos are deleted from our processing infrastructure once the workflow completes.
  • OAuth tokens are deleted the moment you click “Disconnect” on a platform.
  • Scheduled-post rows are kept indefinitely as an audit log of publishes; you can request deletion.
  • If you delete your Noven account, we delete all of the above within 30 days, with the exception of billing records we are legally required to retain.
  • To delete your account, email hello@noven.studio from the address on file.

7. Your rights

Depending on where you live (GDPR, UK GDPR, UAE PDPL, CCPA, etc.) you may have the right to access, correct, port, or delete your data, and to object to or restrict certain processing. Email us and we will respond within 30 days.

8. Cookies

We use first-party cookies set by Clerk to keep you signed in. We do not use third-party advertising cookies. We may add a basic, privacy-respecting analytics cookie later; if we do, this policy will be updated and you will see a notice.

9. Children

Noven is not directed at children under 16. Do not use the service if you are under 16. If we learn we have collected data from someone under 16, we will delete it.

10. International transfers

Our infrastructure runs in the United States and the European Union. By using Noven you consent to your data being processed in those regions.

11. Security

Tokens and sensitive fields are stored in an access-controlled database. We use TLS in transit. No system is perfect — if we ever experience a breach affecting your data we will notify you without undue delay.

12. Changes

If we materially change this policy we will post the new version here and update the “Last updated” date. Continued use of the service after a change constitutes acceptance of the revised policy.

13. Contact

hello@noven.studio