Privacy Policy
How NOWScale collects, uses, shares and protects personal data, both as a controller of its own customer data and as a processor acting on behalf of business customers.
This Privacy Policy explains how NOWScale LLC (“NOWScale”, “we”, “us”) handles personal data in connection with the NOWScale platform, our websites and the related services we provide (together, the “Service”). It is written to be read alongside our Terms of Service and our Cookie Policy.
1. Scope and our role
NOWScale is a publishing and analytics tool for content creators. Our users are individual creators and the businesses they run, who connect the social media accounts they own, upload video and images, schedule and publish that content, moderate the comments on it, and review how it performed across platforms. Because of how the Service works, we handle personal data in two distinct capacities, and different parts of this policy apply to each.
1.1 Where we act as a controller
We are a controller (meaning we decide why and how personal data is processed) for the data that relates to our own relationship with you: account registration and login details, plan and subscription records, support correspondence, marketing preferences, security and audit logs, and the usage and device data generated when you use the Service. This policy is the primary notice for that processing.
1.2 Where we act as a processor
We are a processor (meaning we act on documented instructions from someone else) for the personal data contained in a customer’s content and in the data pulled from that customer’s connected accounts. That includes information about the customer’s audience and community: the people who comment on their videos, people appearing in uploaded media, and individuals reflected in the audience and engagement figures the platforms report. In those cases the customer is the controller. They determine what is collected, why, and for how long; we process it to deliver the Service to them.
If you are a member of a customer’s audience, or an employee of a customer, and you want your data accessed, corrected or deleted, please contact that organisation first. We will assist our customer in responding, as required by our data processing terms, but we generally cannot act on such a request without their instruction. If you cannot identify or reach the relevant organisation, contact us at support@nowscale.com and we will try to help.
1.3 Who this policy does not cover
This policy does not cover the social media platforms, analytics providers, advertising networks, commerce systems or payment services you choose to connect. Those services are independent controllers of the data they hold, and their own privacy notices govern their handling of it. Connecting an account authorises us to exchange data with that service on your behalf; it does not place that service under our control.
2. Personal data we collect
2.1 Account and identity data
Name, work email address, job title or role, organisation name, profile photo where you supply one, language and time zone preferences, and the authentication method associated with your login. Sign-in is passwordless. We send a one-time code to your email address, or you authenticate through a third-party identity provider. We do not ask for, collect or store a password. Where we need to confirm an account is genuine we may ask for a mobile number and verify it by sending a code to it. A verified number is used for fraud prevention and account recovery only. It is never a login factor and is never used for marketing.
2.2 Plan and billing data
Your plan, subscription and entitlement records, the token usage counted against them, billing contact details, billing address, tax identifiers, and invoice and transaction history. Payment card numbers and full financial instrument details are collected and processed directly by Stripe and are not stored on NOWScale systems.
2.3 Your content and uploaded media
Video, images, thumbnails, captions, titles, descriptions, tags and any other material you upload or author in the Service, together with the platform variants we produce from it. This content may contain personal data: faces, voices, names and other identifying details of the people who appear in it. You are responsible for having a lawful basis and any necessary releases for that material.
2.4 Data from connected platform accounts
When you connect an account on a supported platform (YouTube, TikTok, Instagram or Facebook), we receive, subject to the scopes you grant and each platform’s own rules:
- account and profile information, such as handle, display name, avatar, account type and connected page or channel identifiers;
- audience and follower metrics, typically in aggregate or demographic form as supplied by the platform;
- post and content performance data, such as views, reach, watch time, retention curves, likes, saves, shares and comment counts;
- the text of comments and replies on your own posts, together with the commenter’s public display name and account identifier, where you use the comment moderation features;
- publishing and scheduling metadata, including post status, errors and platform-side identifiers.
We also hold the access and refresh tokens needed to maintain each connection. Tokens are held in encrypted form and are used only to perform actions you have asked for. Data received from YouTube is additionally governed by section 15.
2.5 Usage, device and log data
Pages and features used, actions taken, timestamps, referring pages, IP address, approximate location derived from IP address, browser and operating system, crash and error reports, performance traces, and request metadata such as the rate-limit counters we use to protect the Service from abuse.
2.6 Cookies and similar technologies
Identifiers set through cookies, local storage, pixels and SDKs. See section 12 and our Cookie Policy.
2.7 Support and other communications
Messages you send us through support channels, email, forms or chat, including attachments, diagnostic information you choose to share, and our records of the response. Where calls or sessions are recorded, we will tell you at the time and seek consent where required.
2.8 Bug reports
If you report a bug from inside the Service, we receive the description you write, the product area you pick, the address of the page you were on, your language and time zone, your browser and screen size, the version of the Service you were running, your plan, how many channels you have connected, and a short trail of what happened just before: the pages you moved between and any requests or errors that failed. That trail is held only in your browser and is sent to us solely because you chose to submit a report.
If you leave the screenshot option switched on, the report also includes a picture of the page you were looking at, exactly as it appeared to you. That picture will contain whatever was on screen at the time, which may include your name, your email address, the names of your connected channels, and your own performance or billing figures. You can switch the option off before sending, and the modal shows you the image first. Bug reports and their screenshots are readable only by staff members granted that specific permission, and they are deleted ninety (90) days after you send them, whether or not the underlying issue has been resolved by then. If we need to keep talking to you about a report we will open a support ticket, which is retained under section 8 like any other support correspondence.
2.9 Sensitive data
We do not ask for special category data under GDPR Art. 9 (such as data revealing health, race or ethnic origin, political opinions, religious beliefs, trade union membership, sexual orientation, or genetic and biometric data processed for identification). Your content may incidentally contain such material because of what you choose to upload; you should not use the Service to process special category data unless you have satisfied yourself that you have a valid condition for doing so under applicable law.
3. Where the data comes from
- Directly from you: registration, configuration, uploads, support contact and marketing sign-ups.
- From connected platforms: via their APIs, under the authorisation you granted when you connected the account.
- Automatically: through your use of the Service, our servers, and cookies and similar technologies.
- From service providers: such as our fraud and abuse prevention tooling and our infrastructure providers, in each case limited to what is needed to run the Service.
- From public or commercial sources: limited business contact information used for sales and marketing outreach, where permitted by law.
4. How we use personal data and our legal bases
Where the GDPR or UK GDPR applies and we act as a controller, we rely on the legal bases set out below. Where we act as a processor, our customer is responsible for identifying the legal basis for the processing they instruct.
| Purpose | What this involves | Legal basis (GDPR Art. 6) |
|---|---|---|
| Providing the Service | Creating and maintaining accounts, storing and transcoding media, generating platform variants, scheduling and publishing, running approvals, returning analytics. | Performance of a contract (Art. 6(1)(b)); legitimate interests where the user is not the contracting party (Art. 6(1)(f)) |
| Maintaining connected accounts | Holding and refreshing access tokens, syncing profile and performance data, retrying failed publishes. | Performance of a contract (Art. 6(1)(b)) |
| Billing and account administration | Taking payment, issuing invoices, managing plans, collecting unpaid amounts, tax and accounting records. | Performance of a contract (Art. 6(1)(b)); legal obligation (Art. 6(1)(c)) for tax and accounting |
| Support and communications | Answering questions, investigating faults, sending service, security and change notices. | Performance of a contract (Art. 6(1)(b)); legitimate interests in supporting our users (Art. 6(1)(f)) |
| Security, fraud and abuse prevention | Authentication, rate limiting, anomaly and abuse detection, audit logging, protecting accounts and infrastructure. | Legitimate interests in securing the Service (Art. 6(1)(f)); legal obligation (Art. 6(1)(c)) where applicable |
| Service improvement and troubleshooting | Understanding feature usage, diagnosing errors, measuring performance and reliability. | Legitimate interests in maintaining and improving our product (Art. 6(1)(f)) |
| AI-assisted features | Suggesting keywords and titles, categorising a channel’s topic, drafting a reply to a comment, translating support messages and help articles, each at the user’s request. See section 5. | Performance of a contract (Art. 6(1)(b)) |
| Model improvement beyond delivering the feature | Any use of data to improve models beyond producing the requested output. See section 5. | Consent (Art. 6(1)(a)): opt-in |
| Marketing to business contacts | Product announcements, newsletters and event invitations to business contacts and prospects. | Consent (Art. 6(1)(a)) where required; otherwise legitimate interests in promoting our business (Art. 6(1)(f)) |
| Cookies and similar technologies | Session management, preferences, analytics and, where enabled, advertising measurement. | Consent (Art. 6(1)(a)) for non-essential cookies; legitimate interests (Art. 6(1)(f)) for strictly necessary ones |
| Legal claims and compliance | Responding to lawful requests, enforcing our terms, establishing or defending legal claims. | Legal obligation (Art. 6(1)(c)); legitimate interests in protecting our rights (Art. 6(1)(f)) |
| Corporate transactions | Due diligence and transfer in connection with a merger, financing or sale of assets. | Legitimate interests in corporate activity (Art. 6(1)(f)) |
Where we rely on legitimate interests, we have assessed those interests against your rights and freedoms and concluded that the processing is proportionate. You may ask for a summary of that assessment, and you may object to the processing, using the contact details in section 14.
5. Artificial intelligence and machine learning
The Service includes a small number of AI-assisted features. We take a deliberately conservative position on the data used to power them, and we would rather understate than overstate what we do. As of the date of this policy they are:
- Keyword and title suggestions: proposing phrases and draft titles for a video you are preparing.
- Metadata and chapter suggestions: when you request optimization for an owned YouTube video, using its title, description, tags and available caption track to draft titles, descriptions, tags and timestamped chapters for your review. Nothing is sent to YouTube until you explicitly save the staged changes.
- Channel topic categorisation: reading the titles of your videos and a sample of their comments to label the topic your channel covers. The titles and comment text are used to produce the label and are discarded immediately afterwards; only the resulting label is stored.
- Comment reply drafting: writing a suggested reply to a viewer comment when you ask for one. You review and edit it, and nothing is posted without you sending it.
- Support and help translation: translating support messages and help centre articles between languages.
- The support assistant: answering questions from our published help centre articles, and handing over to a person when it cannot.
Recommendations of the best time to publish are calculated statistically from your own past performance. They do not involve a language model and no data leaves our systems to produce them.
- Your content is not used to train general-purpose or foundation models, whether ours or a third party’s. Content submitted to an AI-assisted feature is processed to produce the requested output for you and is not added to a general training corpus.
- Model improvement. Where we work on improving models or features, we use aggregated or de-identified data that is not reasonably capable of identifying an individual or attributing content to a specific customer, or we rely on data a customer has explicitly opted in to share.
- Third-party model providers. Some AI features may be delivered using third-party model providers acting as our subprocessors under written terms. A current list of subprocessors is available on request.
- Human review. We do not routinely read customer content. Limited access may occur to investigate a fault the customer has reported, to respond to a suspected violation of our Acceptable Use Policy, or where the law requires it, and is subject to access controls and logging.
- No solely automated decisions with legal effect. AI outputs in the Service are suggestions and analyses intended to inform a person’s decision. We do not use them to make decisions producing legal effects concerning you or similarly significantly affecting you within the meaning of GDPR Art. 22.
- Accuracy. AI outputs may be incomplete or wrong. Recommendations, predicted performance and generated captions should be reviewed before they are relied on or published.
6. Sharing and disclosure
We share personal data only in the circumstances described below.
6.1 Subprocessors and service providers
We use vendors to provide infrastructure, storage, media processing, email delivery, error monitoring, product analytics, AI model hosting and support tooling. Each is engaged under written terms that restrict them to processing on our instructions, impose confidentiality and security obligations, and require them to assist with data protection obligations. A current list of subprocessors is available on request.
6.2 Connected platforms, at your direction
When you schedule, publish or sync, we transmit the relevant content and metadata to the platforms you have connected. This is done on your instruction, and each receiving platform then handles that data as an independent controller under its own terms.
6.3 Our own staff
Authorised NOWScale personnel can access account records, support correspondence and audit logs where their role requires it: to answer a support request, investigate a fault, or act on a suspected violation of our Acceptable Use Policy. Access is governed by role-based permissions, is limited to the least data needed, and is logged. We do not routinely read your content; see section 5.
6.4 Professional advisers
Lawyers, auditors, accountants, insurers and similar advisers, where they need the data to advise us and are bound by duties of confidentiality.
6.5 Legal and regulatory requests
We may disclose personal data where we believe in good faith that disclosure is required by applicable law, regulation, legal process or enforceable governmental request, or is necessary to protect the rights, property or safety of NOWScale, our users or the public. We assess such requests, seek to narrow those that are overbroad, and (unless legally prohibited or the request concerns an emergency) will notify the affected customer so they can seek protective relief.
6.6 Corporate transactions
If we are involved in a merger, acquisition, financing, reorganisation or sale of assets, personal data may be disclosed to counterparties and their advisers under confidentiality obligations, and may transfer as part of the transaction. We will provide notice before personal data becomes subject to a materially different privacy policy.
6.7 We do not sell personal information
We do not sell personal information, and we do not share personal information for cross-context behavioural advertising, as those terms are defined under the CCPA/CPRA and comparable US state privacy laws. We have not done so in the preceding twelve months.
We also do not sell or knowingly share the personal information of individuals under 16 years of age.
7. International transfers
NOWScale operates internationally, and personal data may be processed in countries other than the one in which it was collected, including the United States. Those countries may not offer the same level of data protection as your home jurisdiction.
Where personal data is transferred out of the European Economic Area, the United Kingdom or Switzerland to a country without an adequacy decision, we rely on an appropriate safeguard recognised under applicable law. The mechanism we rely on is the European Commission’s Standard Contractual Clauses (Decision 2021/914), together with the UK International Data Transfer Addendum issued under s.119A of the Data Protection Act 2018 for UK transfers, and the Swiss adaptations where relevant.
Alongside the contractual mechanism we apply supplementary measures such as encryption in transit and at rest, access restrictions and a policy of challenging overbroad government access requests. You may request a copy of the relevant safeguards, with commercially sensitive terms redacted, by writing to support@nowscale.com.
8. Retention
We keep personal data only as long as we need it. Rather than publish fixed periods we cannot honour consistently, we set retention by applying the following criteria:
- how long the data is needed to provide the Service and maintain the account;
- whether the customer has configured a shorter or longer period, or deleted the item themselves;
- statutory retention requirements, particularly for tax, accounting and corporate records;
- limitation periods for legal claims, and whether a claim, dispute or investigation is live or reasonably anticipated;
- the need to keep security, audit and abuse-prevention records long enough for them to be useful;
- the sensitivity of the data and the risk of harm from unauthorised access.
On termination or expiry of a customer’s subscription, we will delete or return customer content and associated personal data within ninety (90) days of the effective termination date, subject to any period the customer has agreed for export, and subject to backup rotation. Data held in encrypted backups persists until those backups expire on their ordinary cycle, during which it is isolated from active processing and is deleted when the backup expires.
Bug reports have a fixed ninety (90) day life, measured from the moment you send one, and that period does not extend because the issue is still open. The report, its diagnostics and any screenshot are deleted automatically at the end of it. See section 2.8.
Private YouTube caption transcripts cached for metadata and chapter suggestions are deleted after thirty (30) days without access. The same deletion removes the derived saved chapter generations. A new request may download the available caption track again.
We may retain aggregated or de-identified data that can no longer be associated with an identifiable person for as long as it remains useful.
9. Security
We commit to maintaining technical and organisational measures appropriate to the risk of the processing. These include:
- encryption of personal data in transit over public networks;
- encryption of personal data at rest in our production systems;
- encrypted storage of secrets, including platform access and refresh tokens and API keys;
- role-based access control, least-privilege provisioning, and prompt revocation when access is no longer required;
- multi-factor authentication for administrative and production access;
- logging and monitoring of access to production systems and personal data;
- network segregation, hardened configuration and managed vulnerability patching;
- a documented incident response process covering detection, containment, assessment, notification and post-incident review;
- confidentiality obligations and security awareness training for personnel with access to personal data;
- security requirements imposed on subprocessors through written terms.
These are commitments about how we operate. We make no claim in this policy to hold any particular security certification or attestation.
No system is perfectly secure. You are responsible for keeping access to your email account secure (because sign-in codes are sent there, it is effectively the key to your NOWScale account) and for enabling the account protections we make available. If you believe your account has been compromised, or you have found a vulnerability, contact support@nowscale.com promptly.
10. Your rights
The rights available to you depend on where you live and on whether we act as controller or processor for the data in question. Where we act as a processor, we will refer your request to the relevant customer and assist them in responding.
10.1 EEA, UK and Switzerland
Subject to the conditions in applicable law, you have the right to:
- access the personal data we hold about you and obtain information about how it is processed;
- rectification of inaccurate data and completion of incomplete data;
- erasure of your data in the circumstances set out in Art. 17;
- restriction of processing while a dispute about accuracy or lawfulness is resolved;
- data portability: receiving data you provided in a structured, commonly used, machine-readable format, and having it transmitted to another controller where technically feasible;
- object to processing based on legitimate interests, and to object at any time and without justification to processing for direct marketing;
- withdraw consent at any time where processing is based on consent, without affecting the lawfulness of processing before withdrawal;
- lodge a complaint with your local supervisory authority or, in the UK, the Information Commissioner’s Office. We would appreciate the chance to address your concern first.
10.2 United States state privacy rights
If you are a resident of California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana or another state with a comprehensive privacy law, you may have the right to:
- know what personal information we collect, the categories of sources, the purposes, the categories of third parties we disclose it to, and to obtain a copy;
- delete personal information we have collected from you, subject to statutory exceptions;
- correct inaccurate personal information;
- opt out of the sale or sharing of personal information and of targeted advertising (see section 6.7 for our position on this);
- limit the use and disclosure of sensitive personal information to what is necessary to provide the Service;
- opt out of profiling in furtherance of decisions producing legal or similarly significant effects;
- non-discrimination: we will not deny service, charge a different price or provide a lesser quality of service because you exercised a privacy right;
- appeal a decision to refuse a request. To appeal, reply to our decision or write to support@nowscale.com with “Privacy Appeal” in the subject line. We will respond within the period your state’s law allows and, if we deny the appeal, tell you how to contact your state attorney general.
You may use an authorised agent, and we may ask for proof of their authority and verify your identity directly. We honour opt-out preference signals such as Global Privacy Control as described in our Cookie Policy.
10.3 How to exercise your rights and what to expect
Write to support@nowscale.com, or use the in-product privacy controls where available. We will verify your identity, usually by confirming control of the email address on the account, and by asking for further information where the request is sensitive or high risk. We do not collect additional data solely to verify a request beyond what is necessary.
We aim to respond substantively within one month for requests under the GDPR or UK GDPR, extendable by a further two months where a request is complex or numerous, in which case we will tell you within the first month and explain why. For requests under US state laws we aim to respond within 45 days, extendable once by a further 45 days with notice. Requests are free of charge unless manifestly unfounded or excessive, in which case we may charge a reasonable fee or decline, and will explain our reasoning.
11. Children
The Service is a business tool and is not directed to children. You must be at least 16 years old to hold a NOWScale account, and older if the age of digital consent in your country is higher. We do not knowingly collect personal data from children below that age. If you believe a child has provided personal data to us, contact support@nowscale.com and we will delete it promptly.
Customers are responsible for the content they upload, including content featuring minors, and for obtaining any consent required from a parent or guardian.
12. Cookies and similar technologies
We use cookies, local storage and similar technologies to keep you signed in, remember preferences, measure how the Service is used and, where applicable, measure our marketing. Non-essential technologies are set in the EEA and UK only with your consent, and can be declined or withdrawn at any time. Our Cookie Policy sets out the categories used, how long they last, and how to control them.
13. Changes to this policy
We may update this policy as the Service, our practices or the law change. The date at the top of this page shows when the current version took effect. If a change is material (for example a new purpose of processing, a new category of recipient, or a change that reduces your rights), we will give advance notice by email to the address on the account, by an in-product notice, or both, before it takes effect. Continuing to use the Service after a change takes effect means the updated policy applies; where the law requires consent for a change, we will ask for it.
We keep prior versions and will provide one on request to support@nowscale.com.
14. Contact us
For any privacy question, request or complaint, or to exercise a right under section 10:
- Privacy team: support@nowscale.com
- Data protection contact: support@nowscale.com. This mailbox is monitored by the team responsible for data protection.
- Security reports: support@nowscale.com
- Legal notices: support@nowscale.com
- Postal address: NOWScale LLC, 30 N Gould St Ste R, Sheridan, WY 82801, United States
NOWScale LLC is formed in Wyoming. This policy is governed by Wyoming, without limiting any mandatory rights you have under the data protection law of your own country.
15. YouTube API Services
NOWScale uses the YouTube API Services. This section is the disclosure required of every application that does so, and it applies in addition to the rest of this policy. It is written to stand on its own, so you can read it without reading the whole document.
By connecting a YouTube channel to NOWScale you agree to be bound by the YouTube Terms of Service. Google’s handling of your data is described in the Google Privacy Policy.
15.1 What YouTube data we access
We access a YouTube channel only after its owner connects it through Google’s OAuth consent screen, and only within the permissions granted there. We never access a channel our user does not own, and we never ask anyone to give us another person’s credentials. Subject to those permissions we access:
- Channel information: channel ID, title, description, thumbnail, declared country, and subscriber, view and video counts.
- Video information: titles, descriptions, tags, category, privacy status, scheduled and actual publish times, thumbnails, duration and processing status for the videos on the connected channel.
- Video statistics: view, like and comment counts.
- Comments: the text of comments and replies on the connected channel’s videos, the commenter’s public display name and channel ID, timestamps and moderation status.
- Caption tracks and playlists: the metadata and content of caption tracks and playlists belonging to the connected channel.
- Analytics reports: aggregated performance and audience reports for the connected channel from the YouTube Analytics API.
- Authorisation tokens: the OAuth access and refresh tokens that keep the connection working. These are stored encrypted and are used only to carry out actions the channel owner has asked for.
15.2 How we use and share it
We use YouTube data solely to provide the features the channel owner asked for: publishing and scheduling videos to their channel, listing and editing their existing videos, managing their thumbnails, captions and playlists, moderating the comments on their own videos, and showing them their own performance analytics. YouTube data is shown only to the user who connected the channel.
We do not sell YouTube data, we do not share it with other customers or with advertisers, and we do not use it to train general-purpose or foundation models. We transmit content to YouTube on the user’s instruction when they publish, and we disclose data otherwise only in the limited circumstances set out in section 6, principally to the infrastructure subprocessors that run the Service, and where the law requires it. YouTube data is always identified as coming from YouTube and is never blended with another platform’s data into a single undifferentiated figure.
15.3 How long we keep it
- Video titles, descriptions, channel and creator names, and comment text are refreshed from the YouTube API or deleted within thirty (30) days. We do not keep a stale copy of this material beyond that window.
- Statistics and metrics derived from them are kept for up to thirty-six (36) months so that historical performance charts remain available. Older points are aggregated and then deleted.
- Authorisation tokens are kept until you disconnect the channel or revoke access, at which point they are deleted and we ask Google to revoke them.
15.4 Deleting your data and revoking our access
You can disconnect a YouTube channel from NOWScale at any time from the Connections screen in the product. Disconnecting stops all further access immediately and deletes the stored YouTube data associated with that channel, including its tokens, cached video and channel information, and collected statistics.
In addition to that normal deletion procedure, you can revoke NOWScale’s access to your data at any time through the Google security settings page at https://security.google.com/settings/security/permissions, also reachable at https://myaccount.google.com/permissions. Revoking there withdraws our authorisation directly at Google and does not require any action from us.
You may also ask us to delete YouTube data we hold about you by writing to support@nowscale.com. Questions or complaints about our privacy practices, including those concerning YouTube data, can be raised through any of the channels in section 14.
Questions about this document? Contact support@nowscale.com.