Privacy Policy
Last updated: 4 August 2026
Nfurl ("Nfurl", "we", "us") operates the website at nfurl.app and the creator studio at studio.nfurl.app. This policy explains what we collect, why, and your choices. If anything here is unclear, email hello@nfurl.app.
Who we are
Nfurl is a verified creator commerce and product-recommendation tool. Creators claim a handle, verify the social accounts they own, and publish a verified page that turns their posts into shoppable product boards.
Information we collect
- Account details from Google Sign-In: your name, email address, profile picture, and Google account identifier. We use these to create and secure your account.
- Content you create: your handle, profile, links, boards, products, and the notes you write about them.
- Verification data: when you connect a platform (YouTube first), we read only the minimum needed to confirm you own that account. See the Google section below.
- Team members: if you invite people to your account, we store the email addresses you enter to send or match those invitations.
- Usage analytics: aggregate, cookieless counts of page views and link clicks on public pages. We do not use advertising cookies or cross-site trackers, and we do not build profiles of the people who visit your pages.
How we use it
- To run the service: authenticate you, publish your pages, verify ownership, and show you your own analytics.
- To communicate with you about your account, invitations you send, and the waitlist you joined.
- To keep the service secure and prevent abuse.
We do not sell your personal data, and we do not inject or substitute affiliate tags into your links.
Google and YouTube data (Limited Use)
When you verify a YouTube channel, Nfurl requests read-only access
(youtube.readonly) for one purpose: to confirm the channel is yours and to check
that a URL you tag belongs to it. We read your channel's identifier and handle. We do not read
your videos' content, post on your behalf, or change anything on your channel.
We do not store your Google OAuth token. During verification the access token is used a single time, in memory, to read your channel's public identifier and handle, and is then discarded. It is never written to our database or logs. The only YouTube data we retain is your public channel id and handle, and only for as long as the connection stays verified. Disconnecting the platform deletes it.
Nfurl's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use this data only to provide and improve the verification feature, we do not transfer it to third parties except as needed to provide the service or as required by law, and we do not use it for advertising.
Nfurl uses YouTube API Services. By verifying a channel you also agree to the YouTube Terms of Service, and Google's Privacy Policy applies to Google's handling of your data. You can revoke Nfurl's access at any time from your Google account permissions.
How we protect your data
We apply the following safeguards to all personal data, and in particular to sensitive data such as the information obtained through Google Sign-In and YouTube verification:
- Encryption in transit: all traffic to and from Nfurl, including sign-in and verification, is served exclusively over HTTPS (TLS). We do not accept unencrypted connections.
- Encryption at rest: data is stored in MongoDB Atlas and Amazon Web Services, which encrypt stored data and backups at rest. Uploaded images are served from our CDN over HTTPS.
- Minimal retention of Google data: your Google OAuth access token is used once, in memory, during verification and is then discarded. It is never persisted to our database or logs. We retain only your public channel id and handle, and only while the connection is verified.
- Access controls: access to production data follows least-privilege principles and is limited to the operator of the service for maintenance and support. Sessions are authenticated with short-lived signed tokens.
- Deletion: disconnecting a verified platform removes its verification data, and you can request full deletion of your account and associated personal data at any time (see "Your choices and rights" below).
These providers process data on our behalf under their own security commitments. No method of transmission or storage is perfectly secure, but we work to protect your data using the measures above and review them as the service grows.
Cookies
Nfurl does not set advertising or tracking cookies. Signing in stores an authentication token in your browser so the studio remembers you. That is essential to the service, not tracking.
Your choices and rights
- You can edit or delete your pages, links, and products at any time in the studio.
- You can disconnect a verified platform, which removes the verification.
- You can ask us to delete your account and associated personal data by emailing hello@nfurl.app.
- Depending on where you live (for example the EU/EEA under the GDPR), you may have rights to access, correct, export, or erase your data. Contact us to exercise them.
Children
Nfurl is not intended for anyone under 16. We do not knowingly collect data from children.
Changes
We will update this page when our practices change and revise the date above. Significant changes will be communicated to signed-in users.
Contact
Questions or requests: hello@nfurl.app.