Nurilabs
Features
Bring your own key Your providers, your rates, no markup. The content pipeline Ten stages between a keyword and a finished piece.
Image studio Visuals that belong to your brand. Content radar Know what to cover before your competitors do.
The dashboard Every run, every cost, one screen.
A pipeline, not a prompt box Every feature above is a stage in the same run, not a separate tool. See all features
PricingFAQ
Log in Sign up

Legal

Privacy Policy

Last updated: August 13, 2026 · Translated from French. The French version is the one that prevails.

Controller
Nourdine Chebcheb
Registration
SIRET 834 331 027 00021
Contact
Contact form · hello@nurilabs.io

This policy covers app.nurilabs.io and this website. It is written to be read, not to be survived. If something here is unclear, write to us and we will fix the wording.

What we store

Your account

  • your email address: it is the account, and where account emails go (address verification, password reset);
  • a display name, an optional avatar and a currency preference, if you set them;
  • the date you last signed in, and the date you accepted these terms;
  • your organisation, its plan, and your role in it.

Sign-in is by email and password, or through your Google account, and your address must be verified before the first sign-in. The password you choose is never stored in clear: we keep only a cryptographic hash of it, and a reset goes through your email address. Signing in with Google gives us no password at all.

Your projects and content

  • the projects you configure: domain, niche, audience, language, image preferences;
  • the articles produced and every intermediate state of a run;
  • a record of each paid call made on your behalf, with its cost, so the dashboard can show you what a piece really cost.

Your provider keys

The keys you enter are encrypted at rest (AES-256-GCM) under a master key held only on the server, and are decrypted solely at the moment a run needs to call that provider. Once saved, a key is never sent back to the browser, not even partially masked. The interface shows you its last four characters and the date you set it, taken from a note made at the moment you typed it, and nothing else.

What you send through the contact form

The contact form on this site puts your name, your email address and your message into an email, and sends it to us through Resend. Nothing it collects is written to a database: what remains afterwards is an email in our mailbox, which we keep as long as the exchange is useful and then delete. Ask us to delete it sooner and we will.

Technical logs

Our servers keep short-lived request logs (IP address, page, timestamp) to operate the service and defend it against abuse. Errors are sent to Sentry so we can fix what breaks before you have to report it.

Cookies

This site loads a Google Tag Manager container, which is what puts measurement tags on the page. The cookies those tags can set, what each one is for and how long it lasts are listed in the cookie policy, which is scanned from the site itself rather than written from memory.

Your Google data (Search Console)

If you connect a project to Google Search Console, you grant us, through Google’s APIs and with your explicit consent, read access to data about the property you choose: search performance (queries, pages, clicks, impressions, positions), the index status of the pages we inspect, and the list of your properties at the moment you pick one. We also receive the email address of the authorised Google account, which identifies the connection.

This data serves one purpose: showing you your own search performance inside your project, in the dashboard, in the weekly report email and in the suggestions built from it. It is never used for advertising, never sold, and never used to train models, ours or anyone else’s.

The OAuth tokens Google issues to us are encrypted at rest like your provider keys, and decrypted only while a collection runs. Disconnecting the property deletes the tokens immediately and stops all collection; statistics already collected stay attached to the project, so your history survives a reconnection, and are erased when the property changes or the project is deleted.

You can revoke our access at any time: from the project’s Search Console tab, or from your Google account permissions.

Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

Why we store it, and on what legal basis

  • To provide the service: performance of our contract with you. Without your email and your projects, there is nothing to run.
  • To keep it secure and working: our legitimate interest in rate limiting, error monitoring and backups.
  • To bill, when paid plans open: contract and legal accounting obligations.

We do not sell personal data, and we do not use your content to train models, ours or anyone else’s.

Who else touches it

Every provider involved, named. Providers reached with your own keys (model providers such as Anthropic, and the stock photo services) receive what a run sends them under your own account with them, governed by their terms.

ProviderLocationPurpose
Hetzner Online GmbHGermanyApplication and database hosting
Cloudflare, Inc.EU (WEUR) / globalDNS, static site, object storage for images and backups
ResendEUAccount emails (address verification, password reset), and messages sent from the contact form
Functional Software, Inc. (Sentry)EU (Germany)Error monitoring
DataForSEOEU (Estonia)Search results and keyword metrics
FirecrawlUnited StatesReading competitor pages
ApifyEU (Czechia)Image search and video transcripts
Unsplash · Pexels · PixabayUnited States / EUStock photography, on your own keys

Where a provider is outside the EU, transfers rely on the European Commission’s standard contractual clauses.

How long we keep it

  • Account and content: for as long as your account exists.
  • After deletion: removed from the live database immediately; encrypted backups roll over on a fourteen-day cycle, so a copy may persist up to two weeks.
  • Technical logs: a few days.
  • Accounting records, once billing exists: ten years, as French law requires.

Your rights

Under the GDPR you can ask to access, correct, delete or export your data, to restrict or object to a processing, and to withdraw a consent you gave. Use the contact form or write to hello@nurilabs.io; we answer within a month.

If our answer does not satisfy you, you can complain to your national supervisory authority: in France, the CNIL.

Security

Traffic is encrypted in transit (HTTPS); provider keys are encrypted at rest; access to your data is scoped to your organisation and enforced on the server, not merely hidden in the interface. Backups are taken daily and stored off the application server. No system is perfect: if a breach ever affects your data, we will tell you and the supervisory authority, as the law requires.

Changes

If this policy changes in a way that matters, we will email account holders before it takes effect. The date at the top always reflects the version in force.

Nurilabs

The autonomous SEO content pipeline. Plug in your own model keys and let it research, write, illustrate and quality-check your content.

hello@nurilabs.io

Product

  • All features
  • Bring your own key
  • Image studio
  • Content radar

Resources

  • How it works
  • Why Nurilabs
  • Pricing
  • FAQ

Company

  • Sign up
  • Contact
  • Terms
  • Privacy
  • Cookies
  • Refunds
English
  • English
  • Français
  • Español
  • Italiano
  • Português
  • Deutsch
  • Nederlands
  • Русский
  • 日本語
  • 한국어
  • 简体中文
  • 繁體中文
© 2026 Nurilabs. All rights reserved. Made for people who ship content.