NoBo Privacy Policy
Version: v2.2 Effective: 2026-06-25 Last updated: 2026-07-21
Plain-English summary. NoBo's whole purpose is to prove what you see in the app actually happened. We do that by controlling how media gets in — you can only record inside the app, with the native camera, on a verified genuine device. We do not run behavioral surveillance: we don't track your phone's motion for detection (the accelerometer is read on-device only, for screen orientation and shake-to-report, and never stored or sent), we don't track your taps and swipes, and we don't build a behavioral profile of you. We keep only what's needed (your content, a device-genuineness key, basic product counts), store it on our own servers, never sell it, never share it with advertisers, and let you delete or export everything at any time. What changed in v2.0 (2026-06-25): We removed our entire behavioral-detection system and permanently deleted all the behavioral data it had collected — phone-motion samples (during recording and while browsing), tap/swipe events, per-account behavioral fingerprints, and hand-tremor analysis. We also stopped logging IP addresses against your activity. Authenticity now comes from prevention (how media is captured), not from watching how you behave.
1. Who runs NoBo
NoBo is run by Oliver Parelius (single founder, no investors, no advertisers, no third-party trackers).
Contact: oliverparelius@protonmail.com
For privacy-specific requests (data export, deletion, questions about this policy), the in-app Settings → Privacy screen is the fastest path.
2. What we collect, why, and how we keep it
We group every piece of data into one of these categories:
2.1 Account data
| What | Why | How long we keep it |
|---|---|---|
| Email address | Sign in, send verification link | While your account exists |
| Username, full name, bio, avatar | Display in the app | While your account exists |
| Account creation date | Show when you joined | While your account exists |
2.2 Content you publish
| What | Why | How long we keep it |
|---|---|---|
| Videos you record in the app | The product itself | Until you delete the video, or your account |
| Audio inside those videos | Part of the video | Same as videos |
| Titles, descriptions, draft content | Part of the upload | Same as videos |
We never display or share your device data to other users. Only your published content is public.
2.3 How we prove authenticity (prevention, not surveillance)
NoBo proves a video is real by controlling how it gets in — not by analyzing your behavior afterward. The authenticity guarantee rests on four things, none of which is behavioral tracking:
| How we prevent fakes | What it is | Why | What we store |
|---|---|---|---|
| Native-camera-only capture | Public-feed videos begin inside the app. There is no device-gallery import or file picker into the public feed. A NoBo recording may be saved privately in NoBo's Camera Roll and published later. | A public video can't be on NoBo unless its capture began live in the app | The video itself + its thumbnail |
| App Attest device key | Apple's cryptographic proof your iPhone is genuine and the app is the real app (not tampered/jailbroken) | Blocks fake or modified apps from posting | A device key (cryptographic proof, not personal data), until you revoke the device |
| Structural file check | We read the video file's structure on upload to confirm it's a native iOS recording (and reject files re-encoded by editors like ffmpeg) | Catches non-native files | A short technical summary of the file structure (no behavioral data) |
| Freshness check | A single-use upload token + a 7-day server-clock limit | Stops replaying or smuggling old/AI-generated files | The recording timestamps you sign at upload |
What we deliberately do NOT do (removed 2026-06-25): We do not track your taps and swipes, and we do not build a per-account behavioral profile or "how you hold the phone" baseline. We do not record or store your phone's motion for detection: the old behavioral-motion capture was removed and the data we had previously collected was permanently deleted. (The one remaining use of the accelerometer is purely local and never leaves your phone: see "Motion sensor" in section 2.6.) The hard cases that behavioral detection used to chase (e.g. someone filming a high-resolution screen) we intend to address later with on-device hardware signals (content provenance signed at capture, depth/LiDAR sensing), never by surveilling you.
2.4 Device + environment
| What | Why | How long we keep it |
|---|---|---|
| Phone model, OS version, app version | Spot account takeover (sudden device change); basic analytics | While the upload exists |
| Locale and timezone | Display dates and let your phone set the daily recommendation-edition boundary; basic diagnostics | While account exists |
| App Attest device key | Cryptographic proof your iPhone is genuine | Until you revoke the device |
| IP address in abuse-rate-limit counters | Stop automated flooding without attaching the IP to your analytics or deriving your location | Automatically deleted within 2 days |
2.5 Usage analytics
| What | Why | How long we keep it |
|---|---|---|
| App opens, screen transitions, video views, likes, follows | Internal product analytics (how many people sign up, watch, return) | 90-day rolling raw data, plus daily summaries |
| Recommendation-edition size, whether you reached its end, and your optional yes/no answer to “Was this worth your time?” | Test whether a finite feed is useful rather than merely attention-grabbing | 90-day rolling raw data, plus daily summaries |
| Prevention failures + reasons (e.g. a rejected non-native file, a device-attestation failure) | Debugging + security | 90-day rolling |
| Server errors | Debugging | 90-day rolling |
We do not use third-party analytics (no Google Analytics, PostHog, Mixpanel, or Firebase Analytics). Everything in the table above is captured on our own servers. Android uses Firebase Cloud Messaging for notifications, not analytics. We do not store your IP address in your analytics record or use it to derive your location. A separate fixed-window abuse limiter may hold an IP address for up to 2 days, then deletes it automatically.
2.6 Sensors + data we mostly DON'T use
- Motion sensor (accelerometer). Read on your device only, for two small things: while you record, we check which way the phone is tilted so the video is saved right-side up; and anywhere in the app, a firm shake opens the "report a bug" screen. The reading stays on your phone in the moment it happens. It is never stored and never sent anywhere, and we do not use it to detect fakes, track behavior, or build any profile. We removed all of that motion detection in the 2026-06-25 prevention-only pivot.
- Gyroscope. Not used.
- Behavioral tracking (taps, swipes, scroll patterns). Not collected.
- GPS / precise location. We never request the iOS location permission, and we no longer derive even coarse location from your IP for analytics. The 05:00 recommendation-edition reset uses your phone's clock and timezone on the device; it does not use location services.
- Camera or microphone outside recording. We only access the camera and microphone while you're actively recording in the Create tab.
- Contacts. We never read your contacts.
- Photos library. Existing files cannot be imported into the public feed. You may deliberately select a photo or video for a private chat, where it is marked Not verified. Saving a NoBo recording to your phone's Photos is also optional and user-initiated.
- Health / HealthKit. Not used.
- Bluetooth. Not used.
3. Who we share data with
We share as little data as possible with as few third parties as possible. The full list:
| Third party | What they see | Why |
|---|---|---|
| Apple | App Attest assertion (cryptographic proof, not your data) | Verifies your iPhone is genuine and the app is real |
| Google / Firebase | Android push token and technical app/device identifiers; Play Integrity proof when that security check is enabled | Deliver Android notifications and verify the Android app/device environment |
| Expo | Push token, notification delivery data, and technical app/update request data | Relay push notifications and deliver app updates |
| Cloudflare | Your IP address (like every website you visit), HTTPS traffic | Hosting, DDoS protection, custom domain |
| Supabase (our database host) | All NoBo data sits in their infrastructure | Database, storage, authentication |
We never sell data, share it with advertisers, or use it to train third-party AI models for general-purpose use.
3.1 Cross-posting to other platforms (only if you connect them)
NoBo lets you optionally connect your own accounts on other platforms — YouTube, TikTok, Instagram, and X — and choose, per video, to also publish that video there. This is entirely opt-in: nothing is sent anywhere unless you connect the account and turn on cross-posting for that specific video.
| Third party | What they receive | When |
|---|---|---|
| Google / YouTube | The video you chose to cross-post, its title and description, and your thumbnail | Only when you connect YouTube and enable it for that video |
| TikTok | The video you chose to cross-post and its caption (your title + description) | Only when you connect TikTok and enable it for that video |
| Instagram (Meta) | The video you chose to cross-post and its caption (your title + description) | Only when you connect Instagram and enable it for that video |
| X | The video you chose to cross-post and its caption (your title + description) | Only when you connect X and enable it for that video |
| Zernio | The selected video and caption while it relays a founder cross-post to TikTok, Instagram, or X | Only while the temporary founder bridge is enabled and that platform is selected |
How it works and what we store:
- When you connect a platform, we store a secure access token for your account on that platform (kept encrypted in our server-side vault, never shown to other users) plus your public channel/handle name so we can display "Connected as @you".
- We only ever send a video you explicitly chose to cross-post. We never send your device signals or any authenticity data to these platforms — only the finished video and its caption.
- We send the finished frame without secretly cropping it. The destination platform controls how it displays that frame.
- Once a video reaches another platform, that platform's own privacy policy and terms govern it — it's on their servers under your account there. You can disconnect any platform at any time in Settings → Multi-upload, which deletes the stored token.
#### YouTube-specific disclosures
Because NoBo's YouTube cross-posting uses YouTube API Services, we want to be exact about what that means for you:
- By connecting your YouTube account, you agree to be bound by the [YouTube Terms of Service](https://www.youtube.com/t/terms).
- Google's own handling of any data it receives is governed by the [Google Privacy Policy](https://policies.google.com/privacy).
- What we access: with your permission, NoBo requests exactly two YouTube permissions and no others: the ability to upload videos to your channel (
youtube.upload), and read-only access used only to look up your own channel's name and ID (youtube.readonly) so we can show you "Connected as @your-channel" and attach uploads to the right channel. We do not read your existing videos, comments, subscribers, analytics, watch history, or anyone else's data. - How we store it: we keep an encrypted authorization token for your YouTube account in our server-side vault, plus your channel name and ID. We store nothing else from YouTube.
- How we use it: the token is used for one purpose only — to upload a video you explicitly chose to cross-post, to your channel. It is never used in the background, never shared, never sold, and never used to build a profile of you.
- Revoking access: you can disconnect YouTube at any time in Settings → Multi-upload (which deletes the stored token on our side), and you can independently revoke NoBo's access from your [Google security settings](https://myaccount.google.com/permissions) at any time.
- We do not transfer YouTube data to any third party, we do not use it for advertising, and we do not use it to train AI models.
4. Your rights
Under GDPR (EU/EEA users), CCPA (California users), and Apple App Store guidelines, you have the right to:
- Access all data we have about you. Use Settings → Privacy → Export my data. We'll give you a JSON document with every row we have on you within seconds.
- Delete all data we have about you. Use Settings → Privacy → Delete my account. Everything is wiped — videos, device records, analytics, the account itself. This is permanent.
- Correct inaccurate data. Profile fields you control (username, bio, avatar) are editable in-app. For anything else, contact oliverparelius@protonmail.com.
- Withdraw consent at any time. Same path as Delete.
- Lodge a complaint with your local data protection authority (e.g. Datatilsynet in Norway).
We aim to respond to data export and deletion requests immediately (the in-app buttons are automatic). For email requests we aim to respond within 7 days.
5. Children
NoBo is not intended for children under 13. We don't knowingly collect data from children under 13. If you believe a child under 13 has created an account, contact us and we'll delete it.
For users 13–17, NoBo treats your data with the same protections as adult users. Parental consent rules vary by jurisdiction; consult your local rules.
6. Security
- All traffic uses HTTPS.
- Our iOS app pins its server's TLS certificate (an attacker can't intercept your data even if they compromise a Wi-Fi network).
- Authenticity-related data (device records, prevention diagnostics) is stored in service-role-only database tables — not accessible from the public app.
- Apple App Attest cryptographically ties each upload to your specific iPhone.
- Database backups run automatically and are encrypted at rest by Supabase.
7. Changes to this policy
If we update this policy in a way that materially changes what we collect or share, we'll:
- Bump the version number at the top.
- Show you the new policy in-app on next launch.
- Ask you to accept the new version before continuing.
Old data captured under a previous policy version stays tagged with that version — we can't retroactively change the rules under which it was collected.
8. Contact
Oliver Parelius Email: oliverparelius@protonmail.com
We're not too big to read every email. Reach out.
