Privacy Policy
Last updated: August 26, 2026
This Privacy Policy explains how NaseKit, operated by Nase Digital LLC, collects, uses, and protects your information when you use the Service.
1. Information we collect
Account data: your name and email when you sign in (e.g., via Google).
Connected platform data: when you connect a social account, we access only what the scopes you approve allow, such as your profile, follower/subscriber counts, engagement metrics, and recent posts, through the platform's official API. We do not collect your platform password.
2. How we use it
We use this information solely to generate, display, and keep your media kit current, to operate and secure the Service, and to communicate with you about your account. We do not sell your personal information.
We also use aggregated, de-identified information (for example, how many creators work in a given category or city, or overall feature usage) to understand and improve the Service. Aggregated information never identifies you individually.
Support access: a small number of authorized Nase Digital staff can access account data when needed to operate the Service, investigate problems, or help you with a support request. Connected-platform tokens stay encrypted and are never displayed, and we use analytics about how the Service is used (via PostHog) to improve it.
3. Storage & security
Your data is stored with our infrastructure providers. Access and refresh tokens for connected platforms are encrypted at rest, and access to platform data is scoped to your own account through database row-level security.
4. Sub-processors
We rely on a small set of trusted providers to run the Service: Vercel (hosting), Supabase (database and authentication), Stripe (payments), and PostHog (product analytics). The social platforms you connect (Google/YouTube, Meta/Instagram, TikTok) are the sources of your metrics.
5. Cookies and device storage
NaseKit stores a small amount of information on your device, all of it to run the Service rather than to advertise to you. We do not use advertising cookies and we do not sell what is stored here.
Sign-in cookies keep you logged in between visits and are set by our authentication provider, Supabase. Clearing them signs you out.
Preference cookies remember small choices so screens open the way you left them, such as which brand you are working in and which planner view and month you were last on.
Browser storage on your device holds your unsaved work and interface preferences, including designs in progress in Create, your planner layer choices, light or dark mode, and whether you have already dismissed a one-time tip. Designs in progress are held locally so a refresh or a dropped connection cannot lose work you have not saved yet.
Analytics from PostHog set an identifier so repeat visits from the same browser are counted once rather than as new people each time.
You can clear all of it from your browser settings at any time. Doing so signs you out and discards unsaved local work, but nothing you have saved to your account is affected.
6. YouTube API Services
NaseKit uses YouTube API Services. When you connect a YouTube channel, we read its public statistics and analytics to build your dashboard and media kit, and, if you separately turn on publishing, we upload videos you have scheduled to that channel. By using NaseKit you agree to be bound by the YouTube Terms of Service. Google's handling of data is described in the Google Privacy Policy. You can revoke NaseKit's access to your Google account at any time through Google's security settings, or disconnect the channel inside NaseKit, which deletes the tokens we hold.
How long we keep YouTube data. Data we obtain from the YouTube Analytics API — your channel statistics and the daily numbers behind your charts — we keep while you are using NaseKit, so your history stays available to you. We check at least every 30 days that you still authorize us to hold it. Every successful sync is that check: it uses the permission you granted to call YouTube, and we record when it last succeeded. If we cannot confirm your authorization for 30 days — because you revoked access in your Google account, the permission expired, or the connection stopped working — we delete the YouTube data we are holding, including stored channel statistics, daily metrics, and video records synced from your channel. Your NaseKit account and your own posts and designs are not affected, and reconnecting the channel re-syncs it. You can delete this data at any time by disconnecting the channel in NaseKit or by revoking access in your Google account.
7. Sharing
Your media kit is only public if you choose to make it so. We share data with third parties only as needed to provide the Service (the sub-processors above) or where required by law.
8. Your choices & data deletion
You can disconnect any platform at any time, which revokes our access and removes its stored tokens. You can delete your account and associated data by contacting hello@nasekit.com. When you remove NaseKit from a connected platform, we delete the data associated with that connection.
9. Data retention
We retain your data while your account is active. When you delete your account or a connection, we delete the associated data within a reasonable period, except where retention is required by law.
10. Children
The Service is not directed to children under 13 (or 16 where applicable).
11. Changes
We may update this Policy; the "Last updated" date above reflects the latest version.
12. Contact
Privacy questions or requests? Email hello@nasekit.com.