Privacy Policy
Last updated: [CONFIRM: date — set at launch]
Noet is software for YouTube creators: it turns a creator's video catalog into public gear pages carrying the creator's own affiliate tags. This policy covers both the creator-facing app (accounts, the review queue, settings) and the public storefront pages it hosts. It describes what the software actually does; it is not legal advice.
Noet is operated by [CONFIRM: legal entity — e.g. WishWell LLC] under the trade name [CONFIRM: “Noet” trade-name registration / DBA status].
What we collect — creators (account holders)
- Sign-in identity — creators sign in with Google (via Supabase Auth) using identity scopes only: your name, email address, and profile picture. We never see your Google password.
- Session cookies — signing in sets authentication cookies (managed by Supabase) so you stay signed in. These are functional, not tracking, cookies.
- Account and storefront settings — your display name, storefront address, and the Amazon affiliate tag you enter. Your tag is used only to build the links on your own storefront.
- Catalog data — the videos you submit for processing and the product data extracted from them (product names, categories, timestamps, transcript excerpts used as evidence).
- Creator-supplied transcript evidence — you paste transcript text or upload a supported caption/text file, confirm that you have the right to use it and that it matches the selected video, and send the normalized evidence for AI processing. Noet discards the original upload bytes and filename; it keeps only private normalized evidence and content-minimal audit metadata until ordered video or account deletion.
- YouTube access [CONFIRM: not yet live at this writing] — a planned, separate authorization step will request permission to fetch captions of your own videos via the YouTube API. It is requested only when you connect it, never at sign-in.
- Billing [CONFIRM: not yet live at this writing] — billing is planned via Stripe. Card details would go directly to Stripe and never touch our servers.
⚖️ REVIEW NOTE: The YouTube-access and billing bullets describe PLANNED functionality and must be re-verified against the shipped product at launch — delete or un-flag them accordingly. If YouTube API access ships, this policy must incorporate the Google API Services User Data Policy (including the Limited Use requirements) by reference. [CONFIRM: YouTube API scopes actually requested at launch] · [CONFIRM: Stripe live at launch].
What we collect — storefront visitors
- Click analytics without personal identifiers — when a visitor clicks a buy link on a creator's storefront, we record an event for the creator's own analytics: the product, video, creator, retailer, destination URL, placement, the originating page path, a bot flag, and a timestamp. No IP address, no email, no name, no visitor identifier is stored in these events.
- No visitor accounts, no email capture — storefront visitors cannot create accounts, and we do not collect visitor email addresses anywhere on the site.
How we use it
- To run the product: sign you in, process the videos you submit, and render your storefront.
- To show creators their own storefront's aggregate link performance.
- To build affiliate links with the creator's own tag — tags are handled by deterministic code, are never sent to an AI model, and are never used for any purpose other than the creator's own links.
AI processing of video content
Product extraction uses OpenAI. For creator-supplied transcript intake, a request can include the video title, normalized transcript text, extracted product and category context, and evidence needed for matching or deduplication; the source URL, original filename, affiliate identifiers, and video description are excluded from that path. Noet sends every request with store: false, which disables optional Responses API application-state storage. This setting is not a claim of zero provider retention; applicable OpenAI retention and data-control policies may still apply. We do not send affiliate credentials or tags, Noet account email or internal account IDs, storefront visitor data, or raw affiliate destination URLs. Extraction output stays private in the review queue until you publish it. [LEGAL REVIEW: confirm processor, sent-data inventory, rights-attestation wording, and retention/data-control wording against the launch configuration and current OpenAI policy.]
Third-party services
These providers process data on our behalf; their own policies govern the data they handle:
- Supabase — database, authentication, and session management.
- Google — sign-in identity; and, if connected later, the YouTube API [CONFIRM: not yet live].
- OpenAI — AI processing of submitted video content (see above).
- Vercel — hosting [CONFIRM: hosting provider at launch].
- Stripe — billing [CONFIRM: not yet live].
- Amazon — buy links point to amazon.com under the creator's own tag; once a visitor clicks through, Amazon's own privacy policy applies.
Cookies & storage
- Authentication cookies (Supabase) for signed-in creators — functional only.
- We set no first-party tracking or advertising cookies, run no ad network, and use no cross-site tracking on either the app or the storefronts.
Affiliate disclosure posture
Buy links on a creator's storefront are that creator's own Amazon affiliate links — Noet does not add a tag of its own and takes no share of commissions. Each storefront page displays its own disclosure next to the links. Noet's marketing pages contain no affiliate links.
Your privacy rights
Creators can access and correct their account data in the app, and can request deletion of their account and catalog. Storefront click analytics hold no personal identifiers, so they cannot be tied back to a visitor. To make a request, use the contact address below.
⚖️ REVIEW NOTE: Which privacy regimes apply (CCPA/CPRA, GDPR/UK GDPR, other US state laws) drives the specific rights, response timelines, and any required “Do Not Sell or Share” statement — we do not sell personal data, which should be stated explicitly where required. [CONFIRM: applicable jurisdictions / privacy regimes] · [CONFIRM: data-deletion request handling and timeline].
Data retention
Account data is kept while the account is active. Private normalized creator-supplied transcript evidence remains with its video until ordered video or account deletion. Products a creator deletes are held in a pending-deletion state for roughly 30 days (restorable), then permanently deleted; click analytics survive product deletion but contain no personal identifiers.
⚖️ REVIEW NOTE: Retention periods beyond the built product-deletion window are a legal/business decision (account data after cancellation, backups, analytics horizon). [CHOOSE: retention periods for account data, catalog data, and analytics].
Children
Noet is a business tool for creators and is not directed to children. We do not knowingly collect personal information from children under [CHOOSE: 13 / 16].
⚖️ REVIEW NOTE: Age threshold is jurisdiction-dependent (COPPA under-13; GDPR 16, lowered to 13 by some member states). [CONFIRM: children's age threshold].
Changes to this policy
We may update this policy; material changes will be reflected in the “Last updated” date above, and where appropriate we will notify signed-in creators more prominently.
Governing law
This policy is governed by the laws of [CONFIRM: governing-law jurisdiction], consistent with the Terms of Service.
Contact
Privacy questions or requests: [CONFIRM: privacy contact email — must exist and be monitored before launch].