Legal

Noian Brand Studio Privacy Policy

We built Noian to help you publish great content — not to monetise your data. This policy explains exactly what we collect, why, and how you can delete it all instantly.

Last updated: June 11, 2026

01

Who We Are

Noian is a social media content management platform operated at noian.com. When this policy refers to "Noian", "we", "us", or "our", it means the Noian platform and its operators. Questions about this policy can be directed to [email protected].

02

What We Collect

Account dataYour name, email address, and a hashed password (we never store passwords in plain text). If you sign in with Google, we store your Google account ID and profile picture URL.
Brand & workspace dataYour brand profile, tone of voice, topic descriptions, and content angles that you configure inside Noian. This information shapes the ideas we suggest — it is never used for advertising or shared with third parties.
Content itemsDraft content generated by our AI pipeline, edits you make to those drafts, and the approval or rejection decisions you record for each item.
Social media tokensWhen you connect a social account, we store the OAuth access and refresh tokens issued by that platform. All tokens are encrypted at rest using AES-256-GCM before being written to our database.
Publish history & analyticsRecords of posts published through Noian, scheduled publish times, and basic engagement metrics (impressions, likes, comments, shares) fetched from connected platforms.
Usage logsServer-side request logs retained for up to 30 days, used solely for security monitoring and debugging.
03

How We Use Your Data

Delivering the serviceAuthenticating you, storing your content, scheduling publish jobs, and posting to connected social accounts on your behalf — always with your explicit instruction.
AI-assisted idea generationYour brand profile and topic descriptions are processed by our AI infrastructure to generate draft content ideas. This data is used solely for generating your drafts. It is not used to train AI models, sold to third parties, or used for any purpose beyond your own content pipeline.
Quality evaluationEvery draft passes through our quality gate before it is surfaced to you. The quality gate checks brand consistency, readability, and risk signals. Results are stored and visible to you in the Decision Log.
Anti-spam and rate enforcementWe monitor posting frequency against your configured daily and weekly limits. Our system enforces budget caps and backpressure controls to prevent any workspace from publishing at a rate that could be classified as spam by the connected platforms.
Token refreshWe automatically refresh expiring OAuth tokens using stored refresh tokens so your connections stay active without interruption.
Service communicationsTransactional emails only (password resets, critical notices, Autopilot alerts). We do not send marketing email without your explicit opt-in.
04

Quality Gate & Content Scoring

Every piece of AI-suggested content is evaluated by our quality gate before it reaches you. The gate scores each draft on multiple dimensions including brand alignment, readability, link safety, and risk indicators. Items that do not meet the quality threshold are routed to manual review or suppressed entirely — they are never auto-published without passing this evaluation.

Quality scores and the reasons behind each decision are recorded and visible to you in the Autopilot Decision Log. You can review, override, or permanently block any category of content through your Autopilot Policy settings.

05

Autopilot, Approval & Anti-Spam Safeguards

Noian's Autopilot feature is designed as a quality-controlled publishing assistant, not a bulk posting tool. Multiple safeguards prevent misuse:

• Every workspace has configurable daily and weekly posting limits. Our system enforces these limits through backpressure controls that halt the queue when caps are reached. • Content only reaches the "eligible for auto-publish" state after passing the quality gate. Ineligible content is held for your manual review. • In Autopilot, even eligible content can be configured to require your explicit approval before publishing. The default behaviour routes uncertain quality decisions to manual review, not automatic publishing. • A timed review window is available as an optional setting: rather than publishing immediately, Noian waits a defined period so you can review and reject the post before it goes live. • Autopilot can be paused instantly from your settings page. When paused, no new posts are scheduled or published until you reactivate it. • Our worker enforces minimum inter-post intervals to ensure no workspace publishes at a rate that would resemble automated spam on any connected platform.

06

Social Platform Integrations

When you connect a social account, we store an encrypted OAuth token issued by that platform. We use this token solely to publish content and fetch analytics on your behalf. We do not sell your social media data or use it for advertising.

For Google user data accessed through Google Sign-In or the YouTube API, we only share, transfer, or disclose that data in the following limited cases: (1) to infrastructure and security service providers that process data on our behalf under contract, solely to host, store, encrypt, secure, and transmit the data needed to operate Noian; (2) to Google and YouTube when you explicitly instruct Noian to authenticate, publish content, refresh tokens, or retrieve channel analytics on your behalf; and (3) if required by applicable law, regulation, legal process, or enforceable governmental request. We do not share Google user data with data brokers, advertisers, or other third parties for independent marketing purposes.

Noian's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

You can disconnect any social account at any time from your Social Accounts settings page. Disconnecting immediately deletes the stored token from our database. You can also revoke access directly from each platform's settings (e.g. Facebook Settings → Apps & Websites, LinkedIn Settings → Permitted Services).

07

Data Deletion

When you delete your Noian account, all of your personal data is deleted immediately and automatically — no manual request required:

• Your profile (name, email, password hash, Google ID, avatar) • All workspaces you own, including every topic, content item, media asset, social connection, social account token, publish job, quality gate result, and analytics snapshot within those workspaces • Your workspace memberships and approval decisions

If you share a workspace with other members, that workspace is only deleted if you are the sole owner. Otherwise, your membership is removed and workspace data is preserved for the remaining members.

Meta (Facebook/Instagram) data deletion requests received via the Facebook platform are processed within 24 hours via our dedicated webhook at /api/v1/auth/meta/data-deletion.

To delete your account, go to Account Settings → Danger Zone → Delete Account. For assistance, email [email protected].

08

Data Security

Encryption at restAll OAuth access tokens and refresh tokens are encrypted with AES-256-GCM using a server-side key before storage.
Encryption in transitAll data between your browser, our API, and third-party platforms travels over HTTPS/TLS.
Password hashingPasswords are hashed with bcrypt (12 rounds) before storage. We never store plain-text passwords.
Access controlDatabase access is restricted to internal services only. No external parties have direct database access.
Audit trailEvery publish action and approval decision is logged with a timestamp and user identity for accountability.
09

Pinterest Integration

If you connect your Pinterest account to Noian Brand Studio, we use Pinterest's official OAuth authorization flow to request permission to create, schedule, publish, and manage Pins on your behalf, according to the permissions you approve.

We do not collect or store your Pinterest password. We do not collect Pinterest session cookies. You may disconnect Pinterest access at any time from your account settings or from your Pinterest account authorization settings.

Data we access when you connect Pinterest: • Your Pinterest username and profile image (displayed in your Noian workspace only) • Your boards list (so you can select which board to publish to) • The ability to create Pins on your boards — only when you explicitly schedule or publish a Pin

Data we do NOT access or store: • Your Pinterest password or login credentials • Your private messages or direct messages on Pinterest • Any boards or Pins outside those you explicitly select • Browser cookies or Pinterest session data of any kind

Your Pinterest OAuth access token is encrypted at rest using AES-256-GCM. We use it solely to create Pins on your behalf when you initiate a publish or schedule action. It is never shared with third parties.

To revoke Pinterest access: go to Social Accounts → Pinterest → Disconnect in your Noian settings, or visit Pinterest Settings → Security → Apps with access to Pinterest and remove Noian directly.

10

Third-Party Services

AI infrastructureUsed for content idea generation. Data sent: your brand profile, topic description, and angle details. No data is used for model training under our service agreement.
Meta (Facebook & Instagram)OAuth and publish API. meta.com/privacy.
LinkedInOAuth and publish API. linkedin.com/legal/privacy-policy.
GoogleOAuth sign-in and YouTube API. Google user data is disclosed only to contracted infrastructure/security subprocessors, to Google/YouTube when you direct Noian to authenticate or publish, or when required by law. policies.google.com/privacy.
TikTokOAuth and publish API. tiktok.com/legal/privacy-policy.
X (Twitter)OAuth and publish API. x.com/privacy.
PinterestOAuth Pin creation API. See Section 09 for full Pinterest data handling details. policy.pinterest.com/privacy-policy.
11

Data Retention

We retain your data for as long as your account is active. When your account is deleted, all associated data is deleted immediately as described in Section 07. Anonymised aggregate statistics (e.g. total number of posts published across the platform) may be retained indefinitely as they cannot be linked to any individual. Server logs are purged after 30 days.

12

Your Rights

You have the right to access the personal data we hold about you, correct inaccurate data, export your content, and delete your account and all associated data. To exercise any of these rights, use the in-app account settings or contact us at [email protected]. We will respond within 30 days.

13

Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page. Continued use of Noian after changes are posted constitutes acceptance of the revised policy. For material changes, we will notify you by email or by a notice within the app.

14

Contact

For privacy questions, data requests, or to report a concern, contact us at [email protected]. We aim to respond to all requests within 30 days.

Questions? Email us at [email protected]. We respond within 30 days. Also see our Terms of Service.