NúcleoOS ("the Platform", "we", "us") is developed and operated by Gabriel Simone, an individual operator based in Argentina. Contact: gabisimonenqn@gmail.com. The Platform is accessible at nucleo-os.com.
When you create an account, we collect:
When you connect a social media account via OAuth, we store:
We do not use your data for advertising, do not sell it to third parties, and do not use platform data accessed via OAuth for any purpose beyond delivering the features you explicitly use.
| Data type | Storage location | Retention |
|---|---|---|
| Account credentials (email, username, password hash) | PostgreSQL database (Fly.io, encrypted at rest) | Until account deletion |
| OAuth tokens (TikTok, Meta including Threads, X, YouTube, Google) | Encrypted secrets in server infrastructure (Fly.io) | Until revoked or account deletion |
| Scheduling and post metadata | Google Sheets (operator-controlled) | Indefinite (your historical record) |
| Video files (staging) | Cloudflare R2 (temporary) | Deleted automatically after publishing |
| AI-generated scripts and captions | Google Sheets (operator-controlled) | Indefinite (your reference) |
| CRM, contract, and payment data | Google Sheets / Documenso / payment processors | As required by applicable law |
| Session cookies | Your browser (HMAC-signed, HttpOnly, Secure) | 2 years or until logout |
NúcleoOS integrates with the following third-party services, each governed by their own privacy policies:
| Service | Purpose | Data shared |
|---|---|---|
| TikTok API | Video publishing | Access tokens, video files, post metadata |
| Meta Graph API (Instagram, Facebook) | Video/post publishing | Access tokens, video files, post metadata |
| YouTube Data API (Google) | Video publishing | Access tokens, video files, post metadata |
| Google Drive API | Source file retrieval | File IDs and content of your own Drive files |
| Google Sheets API | Data storage and scheduling | All structured data listed in section 2 |
| Cloudflare R2 | Temporary video staging | Video file content (deleted post-publish) |
| Anthropic Claude API | AI content generation (scripts, captions) | Prompts and content descriptions you provide |
| Google Gemini API | AI image generation (Stories) | Image prompts you provide |
| OpenAI API | Transcription (Whisper) and image generation | Audio/video content for transcription; image prompts |
| Apify | Competitor content research | Public social media URLs you submit for analysis |
| MercadoPago | Payment processing (LATAM) | Transaction metadata; payment details handled by MercadoPago directly |
| Stripe | Payment processing (international) | Transaction metadata; payment details handled by Stripe directly |
| Documenso | Digital contracts | Contract content and signatory information |
| ManyChat | WhatsApp automation and lead scoring | Lead tags and message counts from your ManyChat account |
| Discord | Internal notifications | System event notifications (no personal user data) |
| Fly.io | Application hosting | Server infrastructure; all data in transit is encrypted |
| Cloudflare | DNS, CDN, and Workers (routing) | IP addresses and request metadata per Cloudflare's privacy policy |
NúcleoOS uses a single session cookie named session after you log in. It is:
We do not use tracking cookies, advertising cookies, or third-party analytics cookies.
We do not sell, rent, or share your personal data with any third party for marketing or advertising purposes. Data is shared with third-party services solely to the extent necessary to deliver the features described in this policy (see section 5).
To exercise any of these rights, contact gabisimonenqn@gmail.com.
You can remove the Platform's access to your connected social media accounts (Facebook, Instagram, Threads, X, YouTube, TikTok) and delete the associated stored credentials yourself, at any time, without contacting us:
You can also revoke access directly from the source platform at any time: on Facebook/Instagram, go to Settings & Privacy → Apps and Websites and remove NúcleoOS; on Google/YouTube, go to myaccount.google.com/permissions and remove access.
To request full deletion of your account and all associated data (not only social media credentials), email gabisimonenqn@gmail.com from the email address associated with your account. We will confirm deletion within a reasonable timeframe.
Account data is retained until you request deletion. OAuth tokens are deleted upon account deletion or when you revoke access. Temporary files (video staging in R2) are deleted automatically after each publishing job. We retain scheduling history and CRM data for as long as your account is active, as this represents your operational records.
NúcleoOS is not directed at individuals under 18 years of age. We do not knowingly collect data from minors.
We may update this policy as the Platform adds new features or as legal requirements evolve. The current version is always available at this URL. Significant changes will be communicated to active users.
When you connect a Threads or X account, we request only the permissions needed to publish the posts you write yourself:
threads_basic to identify the connected profile,
and threads_content_publish to publish the text and images you schedule.
We store your Threads user ID, username and access token. Threads access tokens are valid
for 60 days and are refreshed automatically while the connection is active.tweet.write to publish, media.write to
attach the images you upload, users.read to show which account is connected, and
offline.access to keep the connection working without asking you to log in again.
We store your X user ID, username, access token and refresh token. X access tokens expire
every 2 hours and are refreshed automatically.We do not read your timeline, your followers, your direct messages, or any content posted by other people. We do not collect, store or analyse data about other users of those platforms. The only content we publish is content you write and schedule yourself.
You can disconnect either account at any time from the Credentials page: this deletes the stored tokens and identifiers immediately. Revoking access from Threads or X directly also works — Meta notifies us and we delete the stored data automatically.
For any privacy-related questions or requests:
Gabriel Simone
Email: gabisimonenqn@gmail.com
Platform: nucleo-os.com