Section 1
Data we collect, why, and how long we keep it
We keep only the data needed to run Nora. Each category below lists what it contains, the legal basis we rely on, and how long we retain it.
Account
Name, email, password hash, business type, goal
Account lifetime; deleted with the account; backups purged within 30 days
Workspace
Products, orders, customers, knowledge entries, uploads (MinIO/S3)
Deleted with the workspace or account; backups purged within 30 days
Meta conversations
Messenger/Instagram message content, sender PSIDs, Page and IG IDs, attachments
Deleted with the workspace or account; backups purged within 30 days
Meta tokens
Page/IG OAuth tokens, Fernet-encrypted at rest
Deleted immediately on channel disconnect or account deletion
TikTok profile
Username, display name, bio, avatar URL, verified status, profile link
Deleted with the workspace or account; backups purged within 30 days
TikTok stats and videos
Follower/like/video counts; public video titles, captions, cover image URLs, share URLs
Deleted with the workspace or account; backups purged within 30 days
TikTok tokens
Login Kit access/refresh tokens, Fernet-encrypted at rest
Revoked at TikTok and deleted immediately on channel disconnect or account deletion
TikTok conversations
DM content, sender open_ids, message ids (only where Business Messaging access is granted)
Deleted with the workspace or account; backups purged within 30 days
TikTok Shop
Seller-authorized catalog products (ids, titles, prices, images)
Deleted with the workspace or account; backups purged within 30 days
Technical
Locale preference, IP and rate-limit logs (security/abuse prevention), single-use short-lived password-reset tokens
Kept only as long as needed for security, then deleted; backups purged within 30 days
Newsletter
Email address, subscription source
Until consent is withdrawn, then deleted; backups purged within 30 days
AI processing and safeguards
AI processing (OpenAI / OpenRouter models) is used only to generate replies, embeddings and retrieval. We do not sell personal data and do not use it for advertising. Data is encrypted in transit (TLS); OAuth tokens are Fernet-encrypted at rest.
Section 2
Meta permissions
These are the only Meta permissions we request. The exact set is minted by the backend authorize URL.
- pages_messaging
Receive customer messages via webhook and send AI replies
- pages_show_list
List Pages the merchant administers to connect the right one
- pages_manage_metadata
Subscribe the Page to webhooks for incoming messages
- pages_read_engagement
Fallback discovery of Business-owned Pages for connection
- business_management
Access Business-owned Pages and IG accounts for connection
- instagram_basic / instagram_business_basic
Read connected IG account identity for connection
- instagram_manage_messages / instagram_business_manage_messages
Receive IG DMs and send AI replies
Connecting a Page or IG account authorizes token storage and webhook processing for these purposes only; disconnecting stops sync and deletes stored tokens immediately.
Section 3
TikTok scopes
These are the only TikTok scopes we request. Scopes you do not grant are simply unavailable — connection still succeeds on user.info.basic.
- user.info.basic
Account identity for connection: open_id, avatar, display name
- user.info.profile
Username, bio, verified badge and profile link for business identity and ICP
- user.info.stats
Follower, like and video counts for onboarding and ICP
- video.list
Public video captions and covers as product candidates and training content
TikTok Shop access is authorized separately per seller. Disconnecting revokes the token at TikTok and deletes stored tokens immediately.
Section 5
Retention and deletion
Retention per category is listed in section 1. You can act on your data at any time through these self-serve paths:
- 1
Disconnect a channel
Channels → Delete. Removes tokens and disables sync immediately.
- 2
Export workspace JSON
Settings. Download a copy of your workspace data.
- 3
Delete workspace
Settings → Security. Removes the workspace with its orders, customers, knowledge and uploads.
- 4
Delete account
Settings → Security. Removes the tenant and all workspaces.
Backup copies are purged within 30 days of the source deletion.
Section 6
Your rights and contact
Exercise your rights
Access, correction, export, erasure, restriction, objection and consent withdrawal: info@numu-digital.com. We verify identity via the account email before acting and respond within 30 days.
You may also complain to the INPDP (Instance Nationale de Protection des Données Personnelles, Tunisia).
Age and policy changes
Service is 18+ only; accounts or data found to belong to under-18 users are removed on discovery — report them to info@numu-digital.com. Material changes bump this version and require re-acceptance at signup or login.