Legal
Last updated: August 13, 2026 · Translated from French. The French version is the one that prevails.
This policy covers app.nurilabs.io and this website. It is written to be read, not to be survived. If something here is unclear, write to us and we will fix the wording.
Sign-in is by email and password, or through your Google account, and your address must be verified before the first sign-in. The password you choose is never stored in clear: we keep only a cryptographic hash of it, and a reset goes through your email address. Signing in with Google gives us no password at all.
The keys you enter are encrypted at rest (AES-256-GCM) under a master key held only on the server, and are decrypted solely at the moment a run needs to call that provider. Once saved, a key is never sent back to the browser, not even partially masked. The interface shows you its last four characters and the date you set it, taken from a note made at the moment you typed it, and nothing else.
The contact form on this site puts your name, your email address and your message into an email, and sends it to us through Resend. Nothing it collects is written to a database: what remains afterwards is an email in our mailbox, which we keep as long as the exchange is useful and then delete. Ask us to delete it sooner and we will.
Our servers keep short-lived request logs (IP address, page, timestamp) to operate the service and defend it against abuse. Errors are sent to Sentry so we can fix what breaks before you have to report it.
This site loads a Google Tag Manager container, which is what puts measurement tags on the page. The cookies those tags can set, what each one is for and how long it lasts are listed in the cookie policy, which is scanned from the site itself rather than written from memory.
If you connect a project to Google Search Console, you grant us, through Google’s APIs and with your explicit consent, read access to data about the property you choose: search performance (queries, pages, clicks, impressions, positions), the index status of the pages we inspect, and the list of your properties at the moment you pick one. We also receive the email address of the authorised Google account, which identifies the connection.
This data serves one purpose: showing you your own search performance inside your project, in the dashboard, in the weekly report email and in the suggestions built from it. It is never used for advertising, never sold, and never used to train models, ours or anyone else’s.
The OAuth tokens Google issues to us are encrypted at rest like your provider keys, and decrypted only while a collection runs. Disconnecting the property deletes the tokens immediately and stops all collection; statistics already collected stay attached to the project, so your history survives a reconnection, and are erased when the property changes or the project is deleted.
You can revoke our access at any time: from the project’s Search Console tab, or from your Google account permissions.
Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
We do not sell personal data, and we do not use your content to train models, ours or anyone else’s.
Every provider involved, named. Providers reached with your own keys (model providers such as Anthropic, and the stock photo services) receive what a run sends them under your own account with them, governed by their terms.
| Provider | Location | Purpose |
|---|---|---|
| Hetzner Online GmbH | Germany | Application and database hosting |
| Cloudflare, Inc. | EU (WEUR) / global | DNS, static site, object storage for images and backups |
| Resend | EU | Account emails (address verification, password reset), and messages sent from the contact form |
| Functional Software, Inc. (Sentry) | EU (Germany) | Error monitoring |
| DataForSEO | EU (Estonia) | Search results and keyword metrics |
| Firecrawl | United States | Reading competitor pages |
| Apify | EU (Czechia) | Image search and video transcripts |
| Unsplash · Pexels · Pixabay | United States / EU | Stock photography, on your own keys |
Where a provider is outside the EU, transfers rely on the European Commission’s standard contractual clauses.
Under the GDPR you can ask to access, correct, delete or export your data, to restrict or object to a processing, and to withdraw a consent you gave. Use the contact form or write to hello@nurilabs.io; we answer within a month.
If our answer does not satisfy you, you can complain to your national supervisory authority: in France, the CNIL.
Traffic is encrypted in transit (HTTPS); provider keys are encrypted at rest; access to your data is scoped to your organisation and enforced on the server, not merely hidden in the interface. Backups are taken daily and stored off the application server. No system is perfect: if a breach ever affects your data, we will tell you and the supervisory authority, as the law requires.
If this policy changes in a way that matters, we will email account holders before it takes effect. The date at the top always reflects the version in force.