Legal

Privacy Policy

Template wording for nepper.io. Not legal advice. Last updated July 28, 2026.

1. Who we are

nepper.io (“we”, “us”) operates the authenticity API and website at nepper.io. Contact: jurian@nepper.io.

2. Data we collect

Account data: email and authentication identifiers from our auth provider (Firebase). Usage data: API key identifiers, plan, request counts, and related logs. Content you submit: images (or image URLs) and analysis results needed to run the Service. Billing data: handled by our payment providers (e.g. RevenueCat / Stripe); we store plan status and subscription-related identifiers, not full card numbers. Technical data: IP address, user agent, and similar diagnostics for security and reliability. Analytics: if you accept, page-view metrics via Vercel Analytics.

3. How we use data

We use data to provide and improve the Service, authenticate users, enforce quotas and rate limits, process payments, detect abuse, and communicate about the Service (e.g. security or billing notices).

4. Image analysis

Images you submit are uploaded to our servers and processed in memory to produce authenticity reports. We do not permanently store image files in our application databases. When detection providers are configured, we may transmit the full image (or image bytes derived from a URL you provide) to third-party services — currently Sightengine (AI / scam image detection) and Google Cloud Vision (including face detection and reverse web image search). Those providers process the image under their own terms and retention policies. Do not submit images you are not authorized to process.

5. Sharing

We share data with processors who help run the Service: hosting (Vercel), authentication (Firebase), databases (Firestore), billing (RevenueCat / Stripe), optional detection providers (Sightengine, Google Cloud Vision), and — only if you consent — website analytics (Vercel Analytics). We do not sell personal data. We may disclose information if required by law or to protect the Service and users.

6. Cookies and analytics

Essential cookies or local storage may be used for authentication and security. Vercel Analytics runs only after you accept via our consent banner. Your choice is stored in local storage (nepper-analytics-consent). You can clear site data in your browser to be asked again. Declining does not affect use of the API or core product features.

7. Retention

We retain account and billing-related records while your account is active and as needed for legal, tax, and security purposes. Image bytes are processed for the request and are not kept as durable storage by nepper.io; provider retention follows each vendor’s policy. You may delete your account from Settings or by contacting us. Cancel paid billing separately with the payment provider if needed.

8. Security

We use industry-standard measures (encryption in transit, access controls, hashed API secrets) to protect data. No method of transmission or storage is perfectly secure.

9. International transfers

We may process data in the United States and other countries where our providers operate (including Google and Sightengine). Where required, we rely on appropriate safeguards for cross-border transfers.

10. Your rights

Depending on your location, you may have rights to access, correct, delete, or export personal data, or to object to certain processing (including withdrawing analytics consent). Contact jurian@nepper.io to exercise these rights. You may also lodge a complaint with your local supervisory authority.

11. Children

The Service is not directed to children under 16. We do not knowingly collect personal data from children.

12. Changes

We may update this policy. Material changes will be posted on this page with an updated date.

13. Contact

Privacy questions: jurian@nepper.io.