Privacy Policy

Last updated: 6 September 2026

This Privacy Policy explains how Ruan ("Ruan", "we", "us"), operated by Nanon.io, collects, uses, and protects information when you use our AI marketing platform at ruan.nanon.io (the "Service").

Information we collect

  • Account information — your name and email, provided via our authentication provider (Clerk) when you sign up.
  • Business & brand information — details you add to your workspace (business description, brand voice, audience, goals, uploaded knowledge) so the AI can create relevant marketing.
  • Connected social accounts — when you connect a Facebook Page, Instagram, or other platform, we receive access tokens and basic account details. Access tokens are encrypted at rest and used only to publish and read analytics on your behalf.
  • Content & usage data — campaigns, posts, schedules, performance metrics, and product-usage information.

How we use information

  • Operate the Service: plan, generate, schedule, publish, and measure content.
  • Publish to and read insights from the social accounts you connect.
  • Provide AI features (strategy, content, and creative generation).
  • Billing, support, security, and improving the Service.

Data from Meta platforms

When you connect Facebook or Instagram, we access only what you authorize (e.g. your Pages, the ability to publish content, and post insights). We use this data solely to provide the features you request within Ruan. We do not sell it, and we do not use it for advertising unrelated to your own campaigns. Our use complies with the Meta Platform Terms and Developer Policies.

Service providers we share data with

  • Clerk — authentication.
  • MongoDB / our hosting provider — data storage & hosting.
  • Meta, and other social platforms — to publish and read analytics you authorize.
  • AI providers (e.g. OpenAI, Anthropic) — to generate content from your prompts and brand data.
  • Stripe — subscription billing.

These providers process data only to perform services for us, under their own terms and safeguards.

Data retention

We keep your data while your account is active. You can delete content, disconnect accounts, or request full deletion at any time — see Data Deletion. Disconnecting a social account revokes and removes its stored tokens.

Security

Access tokens and secrets are encrypted at rest; all data access is scoped to your workspace and authorized per request. No method of transmission or storage is 100% secure, but we work to protect your information.

Your rights

You may access, correct, export, or delete your data. Contact us to exercise these rights. Depending on your location, additional rights (GDPR/CCPA) may apply.

Children

The Service is not directed to children under 13 (or the minimum age in your region).

Changes

We may update this policy; we'll revise the "Last updated" date above.

Contact

Questions or requests: privacy@nanon.io, Nanon.io.