NASHIR

Privacy Policy

Last updated: April 6, 2026

1. Introduction

This Privacy Policy applies to Nashir (nashir.ai), a social media scheduling and management platform operated by Nashir.

Nashir (“we”, “our”, or “us”) operates the Nashir social media scheduling and management platform. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use Nashir.

By using Nashir, you agree to the collection and use of information in accordance with this policy. If you do not agree, please discontinue use of Nashir.

2. Information We Collect

Account information

When you register, we collect:

  • Name — used to personalise your experience
  • Email address — used for login, transactional emails, and support
  • Password — stored as a bcrypt hash; we never store plaintext passwords

Social account tokens

When you connect a Facebook Page or Instagram Business account, we store the Page access token issued by Meta. This token is used exclusively to publish posts on your behalf at your scheduled times. We do not store your Meta username, personal profile data, or password.

YouTube/Google data

When you connect a YouTube channel, we store the OAuth access and refresh tokens issued by Google. We also temporarily cache your channel name and profile picture to display them in your Nashir dashboard. We do not access your private videos, watch history, or comments.

TikTok data

When you connect your TikTok account to Nashir, we collect and store the following data from TikTok:

  • TikTok Open ID — account identifier used to associate your TikTok account with your Nashir team
  • Display name and profile picture — displayed in your Nashir dashboard to identify the connected account
  • Access token — stored encrypted, used exclusively to publish content to your TikTok profile on your behalf

We use this data solely to publish content to your TikTok profile as instructed by you. We do not sell, share, or use your TikTok data for any other purpose.

Content posted to TikTok through Nashir is subject to TikTok's Terms of Service and Community Guidelines. You retain full ownership and responsibility for all content published through our platform.

Content you create

We store the content of posts you schedule (text, image URLs, target platforms, and scheduled time) so we can publish them automatically.

Usage and technical data

We log certain technical information including IP address (for security audit logs), browser type, and actions taken within Nashir (e.g., sign-in, password change). This data is used for security and fraud prevention only.

Payment information

Payments are processed by Stripe. We do not store credit card numbers or payment instrument details. We store only your Stripe customer ID and subscription status to determine your plan.

3. How We Use Your Information

We use the information we collect to:

  • Provide, operate, and maintain Nashir
  • Publish posts to Facebook, Instagram, and YouTube on your behalf at scheduled times
  • Send transactional emails (account creation, password reset, billing)
  • Respond to support requests
  • Detect and prevent fraud, abuse, and security incidents
  • Comply with legal obligations

We do not sell your personal data. We do not use your content or social account data for advertising or marketing profiling.

4. Third-Party Services

Nashir integrates with the following third-party services:

Meta (Facebook & Instagram)

We use the Meta Graph API to publish posts to your connected Facebook Pages and Instagram Business accounts. Your use of these integrations is also governed by Meta's Privacy Policy.

Google & YouTube

We use the YouTube Data API to upload and schedule videos to your connected YouTube channel. Your use of this integration is governed by the YouTube Terms of Service and the Google Privacy Policy. You can revoke Nashir's access to your data at any time via the Google Security Settings page.

Data obtained through Google APIs, including YouTube data, is not used to develop, improve, or train generalized AI or ML models. YouTube data is only used to provide the core functionality of Nashir: scheduling and publishing video content to the user's YouTube channel on their behalf.

TikTok

We use the TikTok API to publish videos to your connected TikTok account. When you connect your TikTok account, we store your Open ID, display name, profile picture, and access token solely for this purpose. Your use of this integration is governed by TikTok's Terms of Service and TikTok's Privacy Policy. You can revoke Nashir's access to your TikTok account at any time via your TikTok account settings.

Supabase

We use Supabase to host our database. Your data is stored in Supabase-managed PostgreSQL infrastructure. See Supabase's Privacy Policy.

Stripe

Subscription billing is handled by Stripe. When you subscribe, your payment data is processed by Stripe in accordance with their Privacy Policy.

5. Data Retention

We retain your account data for as long as your account is active. If you delete your account, we delete your personal data within 30 days, except where we are required to retain it for legal or fraud-prevention purposes (e.g., billing records for up to 7 years as required by tax law).

Connected social account tokens are deleted immediately upon disconnection or account deletion.

6. Data Deletion

You may request deletion of your data at any time. You can:

  • Delete your account via Settings → Security → Delete Account
  • Disconnect individual social accounts via Accounts in the dashboard
  • Submit a manual deletion request at /data-deletion
  • Email us at legal@nashir.ai

We will process deletion requests within 30 days.

7. Security

We implement industry-standard security measures including TLS encryption in transit, hashed passwords (bcrypt), and hashed API keys (SHA-256). Access to production data is restricted to authorised personnel. However, no method of transmission over the internet is 100% secure, and we cannot guarantee absolute security.

8. Children's Privacy

Nashir is not directed to individuals under the age of 16. We do not knowingly collect personal information from children. If you become aware that a child has provided us with personal data, please contact us and we will delete it promptly.

9. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by posting the new policy on this page with an updated “Last updated” date. Your continued use of Nashir after changes constitutes acceptance of the revised policy.

10. Contact Us

If you have any questions about this Privacy Policy, please contact us:

Nashir
Email: legal@nashir.ai
Privacy Policy — Nashir