Nooberly
Terms Privacy Contact

Privacy Policy

Last modified April 13, 2026

Nooberly, Inc. ("Nooberly," "we," "us," or "our") operates the Nooberly mobile application ("App") and the website at nooberly.com ("Site"). This Privacy Policy describes how we collect, use, share, and protect your personal information.

1. Information We Collect

Account Information: When you register, we collect your email address, date of birth, name, and optionally your school or occupation. We use your date of birth to determine your age tier (Junior: 13–17, Adult: 18+) and never display your exact age publicly.

Biometric Data (Face Verification): During verification, we capture facial imagery from your guided video profile. This imagery is processed by AWS Rekognition to generate a facial feature vector (faceprint). The faceprint is used to confirm your identity is unique on the platform and to prevent fraud. Your facial biometric data is stored securely and is never sold to third parties.

Video & Audio Content: Your video profile is recorded, uploaded, and transcoded for playback within the App. We use AI-powered transcription (OpenAI Whisper) to generate text from your video for profile creation, language detection, and content moderation. Video content is stored on secure cloud infrastructure (AWS S3, CloudFront).

Location Data: With your permission, we collect your approximate location to show nearby users, posts, and community content. Location data is processed using PostGIS and is never shared with third parties for advertising purposes.

Usage Data: We collect information about how you use the App, including interactions, device type, operating system, and crash reports, to improve the service.

Communications: Chat messages between users are stored in our database to provide the messaging service. We do not read or monitor private messages unless required by law or to investigate reported abuse.

2. How We Use Your Information

We use the information we collect to:

(a) Provide, maintain, and improve the App and its features.
(b) Verify your identity and prevent fraud through face recognition.
(c) Match you with nearby users and relevant community content.
(d) Process transactions through Stripe Connect.
(e) Send you push notifications about messages, reviews, and platform activity (via OneSignal or Expo Push Notifications).
(f) Generate and display your reputation metrics (Star Power, reviews, Star Badges).
(g) Moderate content using AI tools and community jury systems.
(h) Comply with legal obligations.

3. How We Share Your Information

We do not sell your personal information. We share data only with:

Service Providers: AWS (facial recognition, video storage, content delivery), OpenAI (transcription, AI features), Stripe (payment processing), OneSignal (push notifications), LiveKit (video calling infrastructure), and Supabase (database and authentication). These providers process data on our behalf under contractual obligations to protect your information.

Other Users: Your public profile (name, video profile, reviews, Star Power, Star Badges) is visible to other users within your age tier. Junior-tier profiles are never visible to adult-tier users and vice versa.

Law Enforcement: We may disclose information if required by law, subpoena, or court order, or if we believe disclosure is necessary to protect safety or prevent fraud.

4. Biometric Data Policy

Your facial biometric data (faceprint) is collected solely for identity verification and fraud prevention. We process biometric data under GDPR Article 6(1)(f) (legitimate interest) and, where applicable, with your explicit consent. Your faceprint is:

(a) Stored in AWS Rekognition's secure, encrypted facial index.
(b) Used only to verify uniqueness (one person = one account) and to re-associate returning users with their reputation history.
(c) Never sold, licensed, or shared with third parties for their own purposes.
(d) Retained as described in the Data Retention section below.

5. Children's Privacy

Nooberly requires users to be at least 13 years old. Users aged 13–17 are automatically placed in the Junior tier, which provides a separate, age-appropriate environment. Junior-tier users cannot access adult content, arrange real-world meetups, or participate in financial transactions. We do not knowingly collect personal information from anyone under 13. If we learn that we have collected information from a child under 13, we will delete it promptly. If you believe a child under 13 has provided us with personal information, please contact us at privacy@nooberly.com.

6. Data Retention

We retain different categories of data for different periods based on their purpose:

Personal Profile Data (name, bio, posts, school/occupation): Deleted upon your request or account deletion. Removal is typically completed within 30 days.

Facial Biometric Data (faceprint in AWS Rekognition): Retained indefinitely, even after account deletion. This is necessary to prevent fraud, enforce one-person-one-account integrity, and protect the SP economy. Legal basis: GDPR Article 6(1)(f) — legitimate interest in fraud prevention and community safety.

Community Reviews (reviews written by other users about you): Retained indefinitely as community safety records. Reviews are third-party authored content and are not subject to deletion by the reviewed individual. If you re-register, prior reviews re-attach to your profile. Legal basis: GDPR Article 6(1)(f) — legitimate interest in community safety.

Star Power Ledger & Reputation Data: Retained indefinitely and tied to your biometric identity. SP cannot be reset by deleting and re-creating an account.

Criminal & Ban Flags: Retained permanently by biometric identity to protect the community.

Chat Messages: Retained while both participants have active accounts. If both participants delete their accounts, messages are purged within 90 days.

Video Profiles: Source video files are deleted within 30 days of account deletion. Transcoded versions on CDN caches may persist for up to 90 days.

Usage & Analytics Data: Retained in anonymized form for up to 24 months for service improvement.

7. Your Rights

Depending on your jurisdiction, you may have the right to:

(a) Access — Request a copy of the personal data we hold about you.
(b) Rectification — Correct inaccurate personal data.
(c) Erasure — Request deletion of your personal profile data (subject to the retention exceptions described above).
(d) Portability — Receive your data in a structured, machine-readable format.
(e) Object — Object to processing based on legitimate interest. We will assess your request and respond within 30 days.
(f) Withdraw Consent — Where processing is based on consent, you may withdraw it at any time.

To exercise these rights, contact privacy@nooberly.com. We will respond within 30 days. Note that certain data (biometric records, community reviews, flags) is retained under legitimate interest exceptions as detailed in Section 6.

8. Your California Privacy Rights

If you are a California resident, California law may provide you with additional rights regarding our use of your personal information. California's "Shine the Light" law (Civil Code Section 1798.83) permits users of our App that are California residents to request certain information regarding our disclosure of personal information to third parties for their direct marketing purposes. To make such a request, please send an email to privacy@nooberly.com.

9. Security

We implement industry-standard security measures including encryption in transit (TLS), encryption at rest for sensitive data, row-level security policies on our database, and secure API authentication. All AWS service calls are proxied through our backend — the mobile app never communicates directly with AWS. Despite these measures, no system is perfectly secure, and we cannot guarantee absolute security.

10. International Transfers

Your data may be processed in the United States and other countries where our service providers operate. We ensure appropriate safeguards are in place for international data transfers, including Standard Contractual Clauses where required by GDPR.

11. Third-Party Links

The App may contain links to third-party websites or services. We are not responsible for the privacy practices of those third parties. We encourage you to read their privacy policies.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes through the App or by email. Your continued use of the App after changes constitutes acceptance of the updated policy.

13. Contact Us

For privacy-related questions or to exercise your data rights:

Email: privacy@nooberly.com
Website: nooberly.com/contact

Nooberly, Inc.
New York, NY

Nooberly, Inc.
Terms of Use Privacy Policy Contact Us
© 2026 Nooberly, Inc. All rights reserved.