Nucleo OS
Nucleo OS Privacy Policy

Last updated: May 20, 2026

NúcleoOS is a social media automation and business operations platform developed by Gabriel Simone. This policy explains what data we collect, how we use it, where we store it, and your rights over it.

1. Who We Are

NúcleoOS ("the Platform", "we", "us") is developed and operated by Gabriel Simone, an individual operator based in Argentina. Contact: gabisimonenqn@gmail.com. The Platform is accessible at nucleo-os.com.

2. Data We Collect

2.1 Account Data

When you create an account, we collect:

2.2 Connected Platform Credentials

When you connect a social media account via OAuth, we store:

2.3 Content and Scheduling Data

2.4 Business Operations Data

3. How We Use Your Data

We do not use your data for advertising, do not sell it to third parties, and do not use platform data accessed via OAuth for any purpose beyond delivering the features you explicitly use.

4. Data Storage

Data typeStorage locationRetention
Account credentials (email, username, password hash)PostgreSQL database (Fly.io, encrypted at rest)Until account deletion
OAuth tokens (TikTok, Meta including Threads, X, YouTube, Google)Encrypted secrets in server infrastructure (Fly.io)Until revoked or account deletion
Scheduling and post metadataGoogle Sheets (operator-controlled)Indefinite (your historical record)
Video files (staging)Cloudflare R2 (temporary)Deleted automatically after publishing
AI-generated scripts and captionsGoogle Sheets (operator-controlled)Indefinite (your reference)
CRM, contract, and payment dataGoogle Sheets / Documenso / payment processorsAs required by applicable law
Session cookiesYour browser (HMAC-signed, HttpOnly, Secure)2 years or until logout

5. Third-Party Services

NúcleoOS integrates with the following third-party services, each governed by their own privacy policies:

ServicePurposeData shared
TikTok APIVideo publishingAccess tokens, video files, post metadata
Meta Graph API (Instagram, Facebook)Video/post publishingAccess tokens, video files, post metadata
YouTube Data API (Google)Video publishingAccess tokens, video files, post metadata
Google Drive APISource file retrievalFile IDs and content of your own Drive files
Google Sheets APIData storage and schedulingAll structured data listed in section 2
Cloudflare R2Temporary video stagingVideo file content (deleted post-publish)
Anthropic Claude APIAI content generation (scripts, captions)Prompts and content descriptions you provide
Google Gemini APIAI image generation (Stories)Image prompts you provide
OpenAI APITranscription (Whisper) and image generationAudio/video content for transcription; image prompts
ApifyCompetitor content researchPublic social media URLs you submit for analysis
MercadoPagoPayment processing (LATAM)Transaction metadata; payment details handled by MercadoPago directly
StripePayment processing (international)Transaction metadata; payment details handled by Stripe directly
DocumensoDigital contractsContract content and signatory information
ManyChatWhatsApp automation and lead scoringLead tags and message counts from your ManyChat account
DiscordInternal notificationsSystem event notifications (no personal user data)
Fly.ioApplication hostingServer infrastructure; all data in transit is encrypted
CloudflareDNS, CDN, and Workers (routing)IP addresses and request metadata per Cloudflare's privacy policy

6. Cookies and Sessions

NúcleoOS uses a single session cookie named session after you log in. It is:

We do not use tracking cookies, advertising cookies, or third-party analytics cookies.

7. Data Sharing

We do not sell, rent, or share your personal data with any third party for marketing or advertising purposes. Data is shared with third-party services solely to the extent necessary to deliver the features described in this policy (see section 5).

8. Security

9. Your Rights

To exercise any of these rights, contact gabisimonenqn@gmail.com.

Data Deletion Instructions

You can remove the Platform's access to your connected social media accounts (Facebook, Instagram, Threads, X, YouTube, TikTok) and delete the associated stored credentials yourself, at any time, without contacting us:

  1. Log in to NúcleoOS and go to nucleo-os.com/webhook/credenciales.
  2. Click "Desconectar" next to the platform you want to remove.
  3. This immediately deletes the stored access tokens and account identifiers for that platform from our database.

You can also revoke access directly from the source platform at any time: on Facebook/Instagram, go to Settings & Privacy → Apps and Websites and remove NúcleoOS; on Google/YouTube, go to myaccount.google.com/permissions and remove access.

To request full deletion of your account and all associated data (not only social media credentials), email gabisimonenqn@gmail.com from the email address associated with your account. We will confirm deletion within a reasonable timeframe.

10. Data Retention

Account data is retained until you request deletion. OAuth tokens are deleted upon account deletion or when you revoke access. Temporary files (video staging in R2) are deleted automatically after each publishing job. We retain scheduling history and CRM data for as long as your account is active, as this represents your operational records.

11. Children's Privacy

NúcleoOS is not directed at individuals under 18 years of age. We do not knowingly collect data from minors.

12. Changes to This Policy

We may update this policy as the Platform adds new features or as legal requirements evolve. The current version is always available at this URL. Significant changes will be communicated to active users.

Threads and X (Twitter)

When you connect a Threads or X account, we request only the permissions needed to publish the posts you write yourself:

We do not read your timeline, your followers, your direct messages, or any content posted by other people. We do not collect, store or analyse data about other users of those platforms. The only content we publish is content you write and schedule yourself.

You can disconnect either account at any time from the Credentials page: this deletes the stored tokens and identifiers immediately. Revoking access from Threads or X directly also works — Meta notifies us and we delete the stored data automatically.

13. Contact

For any privacy-related questions or requests:
Gabriel Simone
Email: gabisimonenqn@gmail.com
Platform: nucleo-os.com