Legal
Privacy Policy
Nebva respects your privacy. This Privacy Policy explains how we collect, use, store, share, and protect your information — including data obtained through LinkedIn and other platform APIs — when you use our platform.
Introduction
This Privacy Policy applies to the Nebva platform, including all related websites, mobile applications, APIs, and services ("Service") operated by Nebva ("Nebva," "we," "us," or "our"). It describes how we collect and process your personal information and the choices available to you.
By using Nebva, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our data practices, you should not use the Service.
This policy covers data collected directly from you, data collected automatically when you use our Service, and data received through third-party platform integrations — including the LinkedIn API.
Information We Collect
We collect information in several categories depending on how you use the Service:
A. Account Information
- Name (if provided)
- Email address
- Login method and authentication details
- Profile settings and preferences
- Workspace memberships and roles
B. Workspace and Brand Information
- Workspace name and configuration
- Persona details, including tone, voice, and communication style
- Industry, niche, and target audience
- Content goals and platform preferences
- Website URLs submitted for intelligence extraction
- Extracted website intelligence (publicly available data)
- Brand kit details and visual preferences
C. Content Data
- Prompts, instructions, and chat messages
- Generated posts, blog drafts, and image outputs
- Approved, scheduled, and published content
- Uploaded files, documents, and reference materials
- Edits, approvals, rejections, feedback, and comments
D. Platform Integration Data
- Connected platform identifiers (e.g. LinkedIn member URN, X user ID, organization page URN)
- OAuth access tokens and refresh tokens — encrypted at rest using AES-256, never stored in plaintext
- Token expiry timestamps and last-refresh timestamps
- Display names and profile image URLs retrieved from connected platforms
- Publishing status, scheduling settings, and connection state per workspace
- OAuth permission scopes granted by you at the time of authorization
E. Usage and Device Data
- IP address
- Browser type and device information
- Pages viewed and features used
- Session timestamps, interaction logs, and error reports
- Analytics events and usage patterns
F. Payment Data
If you subscribe to a paid plan, payment information is processed by our third-party payment provider. Nebva may store limited billing metadata such as plan type, billing cycle, and transaction history, but does not directly store full payment card details.
How We Use Information
We use the information we collect to:
- Create, manage, and authenticate user accounts
- Personalize AI-generated content based on persona, brand, and workspace data
- Generate posts, blog drafts, image prompts, and visual assets
- Schedule and publish content to connected platforms on your behalf
- Maintain, improve, and optimize workspaces
- Provide customer support and respond to inquiries
- Improve product quality, features, and user experience
- Prevent abuse, fraud, and security threats
- Monitor Service performance and system health
- Enforce our Terms of Service and related policies
- Comply with applicable laws and legal obligations
Data obtained via third-party platform APIs — including the LinkedIn API — is used exclusively to provide the core publishing and scheduling functionality that you explicitly authorize. We do not use API-sourced data for advertising, profiling unrelated to the Service, or any purpose beyond what is described in this policy.
LinkedIn API Data
When you connect a LinkedIn personal account or LinkedIn Organization page to Nebva, we access and store data from the LinkedIn API solely to enable you to schedule and publish content to your authorized LinkedIn destinations. Specifically, we collect and process:
A. Data Collected via the LinkedIn API
- Authentication data: Encrypted OAuth access tokens, token expiry timestamps, and refresh tokens issued by LinkedIn during the authorization flow
- Member profile data: LinkedIn member URN (
urn:li:person:XXXX), display name, and profile image URL — used to identify the authorizing user within the Nebva interface - Organization page data: LinkedIn Organization URN (
urn:li:organization:XXXX), page name, and logo URL — collected only when you explicitly authorize Nebva to publish on behalf of a page you administer - Content data: Text, images, and media that you intentionally compose within Nebva and choose to publish to your LinkedIn profile or Organization page
- Scope metadata: The OAuth permission scopes you granted (e.g.
w_member_social,w_organization_social) so that we can accurately display your integration status
B. How We Use LinkedIn API Data
- To authenticate your administrative permissions on the selected LinkedIn personal profile or Organization page
- To transmit, schedule, and publish posts you compose in Nebva to your LinkedIn feed or Organization page via the LinkedIn Posts API
- To display your connection status, connected page name, and profile image within the Nebva application
- To refresh your access token before expiry so that scheduled posts are not interrupted
We do not read, track, monitor, or analyze your personal LinkedIn activity, private messages, connection graph, follower data, or any LinkedIn content that you have not explicitly submitted through Nebva for publishing.
C. Token Retention
LinkedIn access tokens and all associated metadata are retained only for as long as your integration remains active. When you disconnect your LinkedIn account or Organization page — either through your Nebva account dashboard or by contacting us — all stored LinkedIn tokens, URNs, and cached profile data are immediately and permanently deleted from our active systems. Residual copies in automated backups are overwritten within 30 days.
D. LinkedIn Compliance
Our use of the LinkedIn API is governed by the LinkedIn API Terms of Use. We comply with all applicable LinkedIn developer policies, including restrictions on data storage, data portability, and prohibited use of LinkedIn data.
Platform Credentials and Token Security
All OAuth access tokens and refresh tokens obtained from connected platforms — including LinkedIn, X (Twitter), and any other integrated services — are handled with the following security controls:
- Encryption at rest: Tokens are encrypted using AES-256 before being stored in our database. They are never stored in plaintext.
- Encryption in transit: All communication between Nebva and external platform APIs is conducted exclusively over HTTPS/TLS.
- Access controls: Decrypted tokens are only accessible to the server-side publishing pipeline for the specific operation they are required for and are never exposed to client-side code or logged.
- Automatic expiry tracking: Tokens with known expiry windows are monitored and refreshed automatically. Expired tokens are flagged and you are notified to reconnect.
- Deletion on disconnect: Disconnecting any platform integration immediately deletes all associated token records from active storage.
AI Processing
Nebva uses artificial intelligence to generate content, learn user preferences, and personalize outputs. To provide these features, Nebva may send relevant context to AI providers, including:
- Prompts and user instructions
- Persona and brand context from your workspace
- Website intelligence and extracted data
- Content drafts and user feedback
We strive to minimize the data shared with AI providers and to work with providers that maintain appropriate data handling practices. Platform integration tokens — such as LinkedIn access tokens — are never shared with AI providers.
Memory and Personalization
Nebva may store learned preferences, communication patterns, editing tendencies, approval history, and workspace context to improve the quality and relevance of future content suggestions. This "Brand Memory" makes AI outputs progressively more aligned with your voice and goals.
You may request the deletion of stored memory and personalization data through your account settings or by contacting us directly.
Website Intelligence
When you submit website URLs, Nebva may crawl or analyze publicly available content on those websites to extract brand context, business information, messaging patterns, and content signals. This extracted intelligence is used to personalize your workspace and improve content relevance.
Website intelligence data is stored within your workspace and is not shared with other users or used across workspaces without your consent.
Third-Party Integrations
When you connect third-party platforms such as LinkedIn, X (Twitter), WordPress, or others to your Nebva workspace, those platforms may receive content and data that you choose to publish through the Service.
Each connected platform is governed by its own privacy policy and terms of service. Nebva is not responsible for the privacy practices, data handling, or policy enforcement decisions of third-party platforms.
No Sale of API Data
Nebva does not sell, lease, rent, trade, transfer, or share any data obtained via third-party platform APIs — including the LinkedIn API — with advertisers, data brokers, data aggregators, or any external parties for commercial or marketing purposes.
API-sourced data — including LinkedIn tokens, member URNs, organization URNs, and content published through integrations — is used exclusively to operate the Nebva platform on your behalf. It is never used to build advertising profiles, to train models on behalf of third parties, or to enrich data sold to external entities.
Data Retention and Deletion
Nebva retains your information for as long as necessary to provide the Service, comply with legal obligations, resolve disputes, enforce agreements, and maintain backups.
Platform Integration Token Retention
OAuth tokens, platform user IDs, organization URNs, and metadata retrieved from third-party platform APIs are retained only for as long as the corresponding integration remains connected in your Nebva account.
- On integration disconnect: All tokens and cached platform metadata for that integration are immediately deleted from active database records
- On account deletion: All platform tokens, workspace data, and personal information are removed from active systems within a reasonable timeframe
- Backup purge: Residual copies in automated backup systems are overwritten and purged within 30 days of deletion from active systems
To request deletion of all LinkedIn API-related metadata specifically, contact us at the email address in Section 19 of this policy with "LinkedIn Data Erasure" in the subject line.
Security
We implement reasonable technical and organizational measures to protect your information against unauthorized access, alteration, disclosure, or destruction. These include:
- AES-256 encryption of all stored OAuth tokens and platform credentials
- TLS/HTTPS encryption for all data in transit
- Role-based access controls limiting which internal systems can decrypt tokens
- Secure authentication and session management
- Regular security reviews and dependency audits
However, no method of transmission over the internet or electronic storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.
International Data Transfers
Your information may be processed, stored, and transferred to countries other than your country of residence, including countries where Nebva, its affiliates, or its service providers operate. These countries may have different data protection laws than your jurisdiction.
By using the Service, you consent to the transfer of your information to these countries. We take appropriate steps to ensure that your data is treated securely and in accordance with this Privacy Policy regardless of where it is processed.
User Rights
Depending on your location and applicable laws, you may have the right to:
- Access — request a copy of the personal information we hold about you
- Correction — request correction of inaccurate or incomplete information
- Deletion — request deletion of your personal information, including all LinkedIn API data and tokens
- Export — request a portable copy of your data
- Restriction — request restriction of certain processing activities
- Withdrawal of consent — disconnect any platform integration at any time from your account dashboard, which immediately revokes our access and triggers deletion of all associated tokens
- Objection — object to certain types of processing
To exercise any of these rights, please contact us at hello@nebva.com. We will respond within the timeframe required by applicable law.
Children's Privacy
Nebva is not intended for use by children under the age of 18 (or the minimum legal age in your jurisdiction). We do not knowingly collect personal information from children. If we become aware that a child has provided personal information, we will take steps to delete it promptly.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will update the "Last updated" date at the top of this page and may notify you through the Service or via email.
Your continued use of the Service after any changes constitutes acceptance of the updated Privacy Policy.
Contact and Data Erasure Requests
If you have questions about this Privacy Policy, wish to exercise your data rights, or want to request the erasure of all LinkedIn API-related metadata or any other personal data held by Nebva, please contact us at:
Please include your account email address and specify the data or integration you would like deleted. We will confirm receipt and complete the erasure within a reasonable timeframe.
For LinkedIn API data erasure requests, include "LinkedIn Data Erasure" in your email subject line.
This page is provided for transparency and may be updated as Nebva evolves. Questions about this policy? hello@nebva.com

