1. Who we are and how to contact us
Jack Dickson trading as Novas Agency is the UK sole trader who operates Nova Content OS, also described in earlier application and technical documentation as Novas Content Tracker (collectively, “Nova”, “we”, “us” or “our”). For UK data-protection law, Jack Dickson trading as Novas Agency is the controller of the personal data described in this policy unless a connected social platform acts as a separate controller under its own terms.
Privacy questions and rights requests can be sent to help@novasagency.com. We may need to verify your identity before acting on a request.
Jack Dickson trading as Novas Agency89 Killyleagh Street
BT30 9DQ
Northern Ireland
2. Scope
This policy applies to our public website, account registration, creator workspace, uploads, support interactions, official social connector features, scheduled work and related operational logs. It does not replace the privacy terms of a social platform you connect or any website you visit through an external link.
3. Personal data we collect
- Account and identity data: Firebase UID, email, email-verification state, username, display name, optional phone number and profile picture.
- Workspace data: brands, ideas, content, notes, tasks, campaigns, goals, schedules, reminder preferences and files you upload.
- Connected-account data: provider and account identifiers, display name, handle, avatar, granted permissions, connection health and encrypted authorisation material.
- Publishing and performance data: user-selected content, per-post choices, provider job identifiers, status/error evidence, remote post identifiers and timestamped metrics returned by an official API.
- Security and technical data: opaque application sessions, IP and request metadata available to our hosting providers, rate-limit state, security events, timestamps and concise error diagnostics. We do not intentionally log passwords, tokens, secrets or raw card details.
- Support data: information you include when you contact us, together with the correspondence needed to resolve the request.
We receive data directly from you, from Firebase Authentication, from official APIs for accounts you choose to connect, and automatically from the application and hosting infrastructure when you use Nova.
4. Why we use data and our lawful bases
- Contract: to create and secure your account, provide the workspace, store your content, perform requested connector actions, provide exports and handle account deletion.
- Legitimate interests: to prevent abuse, protect Nova and its users, diagnose failures, keep reliable audit evidence and improve core service reliability. We balance these interests against your rights and expectations.
- Legal obligation: where we must keep or disclose information to comply with applicable law, a binding order or tax and accounting duties.
- Consent:where an optional permission or provider authorisation depends on consent. You may withdraw it by disconnecting the account or using the provider's own permission controls; withdrawal does not make earlier processing unlawful.
We do not sell personal data, serve behavioural advertising or use personal data for solely automated decisions that produce legal or similarly significant effects.
5. Social connectors
A connector is optional. We request only the permissions described in the connection flow and use official provider APIs. Depending on the provider, a connector may read account identity and authorised performance information, upload user-selected media, create or delete user-selected posts, check processing status and revoke or remove the local grant. Provider availability, approval and supported operations vary.
- Instagram, Facebook Pages and Threads:authorised Meta account/Page/profile data and supported publishing, status, deletion and insight data through Meta's official APIs.
- TikTok:Login Kit, Display API and Content Posting API data, including profile identity, granted scopes, user-selected media, publish status and authorised public-video metrics. If you choose to start the optional motion wall, Nova loads TikTok's official players for a curated selection of public posts; TikTok may receive technical browser, device and request data as a separate controller.
- YouTube: Google OAuth, YouTube channel identity, user-selected uploads, processing/visibility status, deletion and authorised channel or video analytics. The dedicated YouTube API Services disclosure below explains this processing and your controls.
- Bluesky / AT Protocol: DID, handle, public profile, encrypted OAuth/DPoP session material, user-selected public records, media and authorised metrics. Public AT Protocol records may remain in independently operated relays, indexes, caches or copies after deletion from the source PDS.
- X: displayed as coming soon until the official integration is enabled. Nova does not start an incomplete X OAuth flow from that state.
Connected providers normally act as separate controllers for their own services. Their terms, privacy notices, retention and public-data rules continue to apply.
6. YouTube API Services
Nova uses YouTube API Services. When you choose to connect YouTube, Nova receives and processes data through Google OAuth, the YouTube Data API and the YouTube Analytics API. Your use of those features is also subject to the YouTube Terms of Service. Google's handling of information is described in the Google Privacy Policy.
Depending on the actions and permissions you select, this data is:
- channel identifiers, name, handle, avatar, granted permissions, connection health and encrypted authorisation material;
- owner-selected video files and metadata such as title, description, category, visibility, audience settings and notification choices;
- video identifiers, watch URLs, upload and processing status, and evidence of requested publication or deletion actions; and
- timestamped, authorised channel and video analytics such as views, likes, comments, shares, subscribers, watch time and average view duration.
Nova uses this data only to provide the YouTube feature you request: connect and map your channel, prepare or upload selected videos, observe processing, show provider-backed status and analytics, delete a selected remote video, disconnect the channel, support the feature and protect it from abuse. YouTube data is visible only inside the workspace belonging to the authenticated owner. Nova does not sell it, use it for advertising, or disclose it to other Nova users.
Processing is server-side. Google and YouTube receive the data needed to perform your selected API action. Google Firebase and Google Cloud provide authentication and database services, and Vercel provides application hosting and uploaded-file storage. These processors receive only the data needed to operate Nova under their applicable service and data-protection terms.
Nova uses only the necessary application-session and preference storage listed in our Cookie Notice. Nova does not store Google or YouTube browser-session cookies. Google's OAuth and YouTube pages may use cookies and similar technologies under Google's own policy.
Current YouTube connector analytics are refreshed through the authorised APIs during scheduled or owner-requested syncs. Nova keeps connector-derived YouTube metric snapshots for no more than 30 days. Older connector snapshots are removed during sync and excluded from workspace views and exports. Owner-authored content and local publishing records are separate from API-derived analytics and remain under the general retention rules below.
Disconnecting YouTube revokes the Google grant and removes Nova's encrypted authorisation material, channel identifiers, connector metrics and pending YouTube jobs. Permanent Nova account deletion performs the same cleanup. Deleting a local Nova record does not delete an already-published YouTube video; use Nova's separate confirmed “Delete from YouTube” action or YouTube directly for that. You can also revoke Nova's access at any time from Google's third-party connections page. Contact help@novasagency.com if you need help with access or deletion.
7. Sharing and processors
We disclose data only as needed to run Nova, follow your instructions, protect the service or comply with law. Current service categories include Google Firebase and Google Cloud for authentication and database services; Vercel for application hosting and uploaded-file storage; email or push-delivery providers when those channels are configured; and the social providers you explicitly connect. A selected post and its media must be sent to the relevant provider to perform the requested action.
We do not give unrelated third parties access to connected-account data. If our business is reorganised or transferred, data may be disclosed under confidentiality and data-protection safeguards, with notice where required.
8. International transfers
Some infrastructure and social providers operate outside the United Kingdom. Where UK personal data is transferred internationally, we rely on an applicable adequacy regulation, approved contractual safeguards or another lawful transfer mechanism. Provider publication may also make content public or distribute it globally at your direction. Contact us for further information about the safeguard relevant to a specific service.
9. Retention
Workspace and account data is generally retained while your account is active. Normal application sessions expire after 12 hours of inactivity or 14 days at the latest. Short-lived OAuth state is kept only long enough to complete or reject the connection. Provider data, publishing evidence and security records are retained while needed to operate the feature, resolve failures, prevent abuse or meet legal obligations.
Account deletion removes the active workspace, uploads, connector credentials and scheduled jobs through the account-deletion process. A limited record may be retained only where law, fraud prevention, a dispute or infrastructure recovery requires it, and only for the relevant period. Data already sent to a connected provider remains subject to that provider's retention and deletion rules.
10. Security
Nova uses verified Firebase identity, opaque Secure/HttpOnly session cookies, server-side authorisation on every data route, owner-scoped records, same-origin checks, restrictive browser security headers, persistent throttling and authenticated encryption for connector credentials. Direct browser access to the production database is denied. No internet service can promise absolute security; please use a unique password, protect your email account and report suspected compromise promptly. See our Security page for responsible disclosure.
11. Your choices and rights
From Nova you can update profile information, disconnect social accounts, export your workspace and permanently delete your account. Depending on the circumstances, UK data-protection law may also give you rights of access, correction, erasure, restriction, objection and portability, and the right to withdraw consent.
Send a request to help@novasagency.com. You also have the right to complain to the UK Information Commissioner's Office. We encourage you to contact us first so we can try to resolve the issue.
12. Children
Nova is intended for people aged 18 or over and is not directed to children. If you believe a child has provided personal data, contact us so we can investigate and take appropriate action.
13. Changes to this policy
We may update this policy when the service, providers or legal requirements change. The effective date identifies the current version. We will provide an appropriate notice, and request renewed acceptance where required, before a material change takes effect for existing users.