Nurilabs
Features
Bring your own key Your providers, your rates, no markup. Topical maps One keyword in, a whole site plan out.
The content pipeline Ten stages between a keyword and a finished piece. Image studio Visuals that belong to your brand.
Content radar Know what to cover before your competitors do. The dashboard Every run, every cost, one screen.
A pipeline, not a prompt box Every feature above is a stage in the same run, not a separate tool. See all features
PricingFAQ
Log in Sign up

Legal

Privacy Policy

Last updated: 25 July 2026

Controller
Nourdine Chebcheb
Registration
SIRET 834 331 027 00021
Contact
hello@nurilabs.io

This policy covers app.nurilabs.io and this website. It is written to be read, not to be survived. If something here is unclear, write to us and we will fix the wording.

What we store

Your account

  • your email address: it is the account, and where sign-in links go;
  • a display name, an optional avatar and a currency preference, if you set them;
  • the date you last signed in, and the date you accepted these terms;
  • your organisation, its plan, and your role in it.

There is no password, because sign-in is by email link, so there is no password of yours for us to leak.

Your projects and content

  • the sites you configure: domain, niche, audience, language, image preferences;
  • the articles produced and every intermediate state of a run;
  • a record of each paid call made on your behalf, with its cost, so the dashboard can show you what a piece really cost.

Your provider keys

The keys you enter are encrypted at rest (AES-256-GCM) under a master key held only on the server, and are decrypted solely at the moment a run needs to call that provider. Once saved, a key is never sent back to the browser, not even partially masked. The interface shows you its last four characters and the date you set it, taken from a note made at the moment you typed it, and nothing else.

Technical logs

Our servers keep short-lived request logs (IP address, page, timestamp) to operate the service and defend it against abuse. Errors are sent to Sentry so we can fix what breaks before you have to report it. We use no advertising or analytics trackers, and this website sets no cookies of its own.

Why we store it, and on what legal basis

  • To provide the service: performance of our contract with you. Without your email and your projects, there is nothing to run.
  • To keep it secure and working: our legitimate interest in rate limiting, error monitoring and backups.
  • To bill, when paid plans open: contract and legal accounting obligations.

We do not sell personal data, and we do not use your content to train models, ours or anyone else’s.

Who else touches it

Every provider involved, named. Providers reached with your own keys (model providers such as Anthropic, and the stock photo services) receive what a run sends them under your own account with them, governed by their terms.

ProviderLocationPurpose
Hetzner Online GmbHGermanyApplication and database hosting
Cloudflare, Inc.EU (WEUR) / globalDNS, static site, object storage for images and backups
ResendEUSign-in emails
Functional Software, Inc. (Sentry)EU (Germany)Error monitoring
DataForSEOEU (Estonia)Search results and keyword metrics
FirecrawlUnited StatesReading competitor pages
ApifyEU (Czechia)Image search and video transcripts
Unsplash · Pexels · PixabayUnited States / EUStock photography, on your own keys

Where a provider is outside the EU, transfers rely on the European Commission’s standard contractual clauses.

How long we keep it

  • Account and content: for as long as your account exists.
  • After deletion: removed from the live database immediately; encrypted backups roll over on a fourteen-day cycle, so a copy may persist up to two weeks.
  • Technical logs: a few days.
  • Accounting records, once billing exists: ten years, as French law requires.

Your rights

Under the GDPR you can ask to access, correct, delete or export your data, to restrict or object to a processing, and to withdraw a consent you gave. Write to hello@nurilabs.io; we answer within a month.

If our answer does not satisfy you, you can complain to your national supervisory authority: in France, the CNIL.

Security

Traffic is encrypted in transit (HTTPS); provider keys are encrypted at rest; access to your data is scoped to your organisation and enforced on the server, not merely hidden in the interface. Backups are taken daily and stored off the application server. No system is perfect: if a breach ever affects your data, we will tell you and the supervisory authority, as the law requires.

Changes

If this policy changes in a way that matters, we will email account holders before it takes effect. The date at the top always reflects the version in force.

Nurilabs

The autonomous SEO content pipeline. Plug in your own model keys and let it research, write, illustrate and quality-check your content.

Product

  • All features
  • Bring your own key
  • Topical maps
  • Image studio
  • Content radar

Resources

  • How it works
  • Why Nurilabs
  • Pricing
  • FAQ

Company

  • Early access
  • Contact
  • Terms
  • Privacy
© 2026 Nurilabs. All rights reserved. Made for people who ship content.