Privacy Policy
Last updated: May 27, 2026
1. Introduction
This Privacy Policy applies to Nashir (nashir.ai), a social media scheduling and management platform operated by Nashir, a service of The Next Gen (جيل الغد), Erbil, Iraq.
Nashir (“we”, “our”, or “us”) operates the Nashir social media scheduling and management platform. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use Nashir.
By using Nashir, you agree to the collection and use of information in accordance with this policy. If you do not agree, please discontinue use of Nashir.
2. Information We Collect
Account information
When you register, we collect:
- Name — used to personalise your experience
- Email address — used for login, transactional emails, and support
- Password — stored as a bcrypt hash; we never store plaintext passwords
Social account tokens
When you connect a Facebook Page or Instagram Business account, we store the Page access token issued by Meta. This token is used exclusively to publish posts on your behalf at your scheduled times. We do not store your Meta username, personal profile data, or password.
YouTube/Google data
When you connect a YouTube channel, we store the OAuth access and refresh tokens issued by Google. We also temporarily cache your channel name and profile picture to display them in your Nashir dashboard. We do not access your private videos, watch history, or comments.
TikTok data
When you connect your TikTok account to Nashir, we collect and store the following data from TikTok:
- TikTok Open ID — account identifier used to associate your TikTok account with your Nashir team
- Display name and profile picture — displayed in your Nashir dashboard to identify the connected account
- Access token — stored on our infrastructure with restricted internal access, used exclusively to publish content to your TikTok profile on your behalf
We use this data solely to publish content to your TikTok profile as instructed by you. We do not sell, share, or use your TikTok data for any other purpose.
Content posted to TikTok through Nashir is subject to TikTok's Terms of Service and Community Guidelines. You retain full ownership and responsibility for all content published through our platform.
WhatsApp Business data
When you connect your WhatsApp Business Account, we store the Phone Number ID, WhatsApp Business Account (WABA) ID, business display name, and a long-lived system-user access token issued by Meta. The token is stored on our infrastructure with restricted internal access. We use it exclusively to send and receive messages on your behalf, manage your message templates, and operate the inbox + automated-reply features you enable.
LinkedIn data
When you connect a LinkedIn personal profile or LinkedIn organization page, we store your LinkedIn user identifier (or organization URN), your display name, and the OAuth access and refresh tokens issued by LinkedIn. Tokens are stored on our infrastructure with restricted internal access. We use them exclusively to publish posts to the profiles and pages you have authorised.
Threads data
When you connect a Threads account, we store your Threads User ID, account display name, profile picture, and the OAuth access and refresh tokens issued by Meta for Threads. Tokens are stored on our infrastructure with restricted internal access. The Threads integration is publish-only; we do not access your inbox or replies.
Telegram bot data
To publish content to Telegram, you provide a bot token generated via Telegram's BotFather, along with the chat IDs your bot has admin access to. The bot token is stored on our infrastructure with restricted internal access and is used solely to send messages through your bot to the channels and groups you specify. Telegram integration is via manual bot token entry; there is no OAuth flow on Telegram's side.
Content you create
We store the content of posts you schedule (text, image URLs, target platforms, and scheduled time) so we can publish them automatically.
Usage and technical data
We log certain technical information including IP address (for security audit logs), browser type, and actions taken within Nashir (e.g., sign-in, password change). This data is used for security and fraud prevention only.
Payment information
Payments are processed by Wayl, a third-party payment gateway. Card numbers and payment instrument details are entered on Wayl's hosted checkout and never reach our infrastructure. We store only the gateway-issued transaction reference, the plan you purchased, the amount, and your subscription status — enough to determine your plan and reconcile billing.
Customer messages routed through Nashir
When you use Nashir to communicate with your own customers (via WhatsApp, Facebook Messenger, Instagram DMs, comments, or other connected platforms), we process your customers' messages and contact information on your behalf to deliver these services — including by using trusted third-party AI service providers to power features such as automated replies, classification, and knowledge-base search. You remain the controller of your customers' data; we act as a processor under your instructions.
3. How We Use Your Information
We use the information we collect to:
- Provide, operate, and maintain Nashir
- Publish posts to your connected social platforms — including Facebook, Instagram, WhatsApp, TikTok, YouTube, LinkedIn, Threads, and Telegram — on your behalf at scheduled times
- Send transactional emails (account creation, password reset, billing)
- Respond to support requests
- Detect and prevent fraud, abuse, and security incidents
- Comply with legal obligations
We do not sell your personal data. We do not use your content or social account data for advertising or marketing profiling.
4. Third-Party Services
Nashir integrates with the following third-party services:
Meta (Facebook & Instagram)
We use the Meta Graph API to publish posts to your connected Facebook Pages and Instagram Business accounts. Your use of these integrations is also governed by Meta's Privacy Policy.
Google & YouTube
We use the YouTube Data API to upload and schedule videos to your connected YouTube channel. Your use of this integration is governed by the YouTube Terms of Service and the Google Privacy Policy. You can revoke Nashir's access to your data at any time via the Google Security Settings page.
Data obtained through Google APIs, including YouTube data, is not used to develop, improve, or train generalized AI or ML models. YouTube data is only used to provide the core functionality of Nashir: scheduling and publishing video content to the user's YouTube channel on their behalf.
TikTok
We use the TikTok API to publish videos to your connected TikTok account. When you connect your TikTok account, we store your Open ID, display name, profile picture, and access token solely for this purpose. Your use of this integration is governed by TikTok's Terms of Service and TikTok's Privacy Policy. You can revoke Nashir's access to your TikTok account at any time via your TikTok account settings.
We use the LinkedIn API to publish posts to your connected LinkedIn personal profile and organization pages you administer. Your use of this integration is governed by LinkedIn's User Agreement and LinkedIn's Privacy Policy. You can revoke Nashir's access at any time via your LinkedIn permitted-services settings.
Threads (Meta)
We use the Threads API to publish posts to your connected Threads account. The Threads integration is operated by Meta and is governed by Meta's Privacy Policy and the Threads Supplemental Privacy Policy. You can revoke Nashir's access via your Meta account settings.
Telegram
When you provide a Telegram bot token, we use Telegram's Bot API to send messages from your bot to the channels and groups you specify. Your use of this integration is governed by Telegram's Terms of Service and Privacy Policy. You can revoke Nashir's access at any time by regenerating the bot token via Telegram's BotFather.
Infrastructure providers
Nashir runs on secure third-party cloud infrastructure. We use established providers for compute, storage, transactional email delivery, and customer-message processing (including AI services for automated replies). We do not sell or transfer your data to these providers for their own purposes; they act as our processors under contractual confidentiality and security commitments.
Wayl (payments)
Subscription billing is handled by Wayl. When you subscribe, your payment instrument data is entered on Wayl's hosted checkout page and processed by Wayl directly. Nashir receives only a gateway-issued transaction reference, the plan you purchased, the amount, and the payment status. A Data Processing Addendum (DPA) covering Wayl's handling of your billing data is available on request — email support@nashir.ai.
5. Data Retention
When you delete your account, we hard-delete all user-generated content (social account tokens, scheduled posts, automations, knowledge bases, inbox messages, WhatsApp contacts, WhatsApp conversation state) within seconds. Billing records (invoice history, payment-gateway transaction reference, subscription state) are retained for up to 7 years to comply with applicable tax and accounting requirements.
During active accounts, we apply the following rolling-retention windows:
- Inbox messages (DMs and comments received via connected social platforms, including WhatsApp messages): 90 days rolling, auto-deleted by a daily job.
- Activity and audit logs (sign-in events, OAuth connect/disconnect, billing actions, IP addresses, user-agent strings): 90 days rolling, auto-deleted by a daily job.
- WhatsApp contacts (phone numbers and display names from contacts you have added or received messages from): retained while your account is active. Removed on account deletion.
- Knowledge-base content (text uploaded to power your AI chatbot): retained while your account is active. Removed on account deletion.
- Encrypted database backups sent to off-site storage: target 30 days rolling. Rotation tooling is in active development; older backups in the transition window are removed manually.
Connected social account tokens are revoked at the provider (Meta, Google, TikTok, LinkedIn) immediately upon disconnection or account deletion, in addition to being deleted from our database.
6. Your Rights
You may request access to, correction of, deletion of, or a portable copy of your personal data at any time. To exercise these rights, contact support@nashir.ai from the email address associated with your account.
Data portability: if you request an export of your data, we will fulfil the request manually within 30 days. A self-service export endpoint is on our roadmap; until it ships, exports are produced by our team on request.
For account deletion, we recommend the self-service path described in the next section — it is effective immediately.
7. Data Deletion
You may request deletion of your data at any time. You can:
- Delete your account via Settings → Profile → Delete Account
- Disconnect individual social accounts via Accounts in the dashboard
- Submit a manual deletion request at /data-deletion
- Email us at support@nashir.ai
Self-service deletion is effective immediately. Email-based deletion requests are processed within 30 days.
8. Security
We implement industry-standard security measures including TLS encryption in transit, hashed passwords (bcrypt), and hashed API keys (SHA-256). Access to production data is restricted to authorised personnel.
Additional defence-in-depth measures we apply:
- Inbound webhooks from third-party platforms (Meta, TikTok, Wayl, and others) are verified using HMAC signatures before any side effect is taken.
- User passwords are stored as bcrypt hashes; API keys are stored as SHA-256 hashes only, with the cleartext shown once at creation and never persisted in recoverable form.
- Resetting your password immediately invalidates all existing sessions across every device.
- Outbound requests to URLs you supply (for example, custom webhook endpoints) are restricted to public address space to mitigate server-side request forgery (SSRF).
- Customer personal data received via third-party webhooks is redacted from our internal event logs.
No method of transmission over the internet is 100% secure, and we cannot guarantee absolute security.
9. Children's Privacy
Nashir is not directed to individuals under the age of 16. We do not knowingly collect personal information from children. If you become aware that a child has provided us with personal data, please contact us and we will delete it promptly.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by posting the new policy on this page with an updated “Last updated” date. Your continued use of Nashir after changes constitutes acceptance of the revised policy.
11. Contact Us
If you have any questions about this Privacy Policy, please contact us:
NashirEmail: support@nashir.ai
Phone: +964 7706 930 930
Postal address: Iraq — Erbil — Gulan Str., Nergiz Plaza Building, 4th floor, Office 409
Response times: we acknowledge security-related inquiries within 72 hours. Other privacy inquiries — including access, deletion, correction, and portability requests — are answered within 30 days.