Legal
Privacy Policy
Template wording for nepper.io. Not legal advice. Last updated July 28, 2026.
1. Who we are
nepper.io (“we”, “us”) operates the authenticity API and website at nepper.io. Contact: jurian@nepper.io.
2. Data we collect
Account data: email and authentication identifiers from our auth provider (Firebase). Usage data: API key identifiers, plan, request counts, and related logs. Content you submit: images (or image URLs) and analysis results needed to run the Service. Billing data: handled by our payment providers (e.g. RevenueCat / Stripe); we store plan status and subscription-related identifiers, not full card numbers. Technical data: IP address, user agent, and similar diagnostics for security and reliability. Analytics: if you accept, page-view metrics via Vercel Analytics.
3. How we use data
We use data to provide and improve the Service, authenticate users, enforce quotas and rate limits, process payments, detect abuse, and communicate about the Service (e.g. security or billing notices).
4. Image analysis
Images you submit are uploaded to our servers and processed in memory to produce authenticity reports. We do not permanently store image files in our application databases. When detection providers are configured, we may transmit the full image (or image bytes derived from a URL you provide) to third-party services — currently Sightengine (AI / scam image detection) and Google Cloud Vision (including face detection and reverse web image search). Those providers process the image under their own terms and retention policies. Do not submit images you are not authorized to process.
5. Sharing
We share data with processors who help run the Service: hosting (Vercel), authentication (Firebase), databases (Firestore), billing (RevenueCat / Stripe), optional detection providers (Sightengine, Google Cloud Vision), and — only if you consent — website analytics (Vercel Analytics). We do not sell personal data. We may disclose information if required by law or to protect the Service and users.
6. Cookies and analytics
Essential cookies or local storage may be used for authentication and security. Vercel Analytics runs only after you accept via our consent banner. Your choice is stored in local storage (nepper-analytics-consent). You can clear site data in your browser to be asked again. Declining does not affect use of the API or core product features.
7. Retention
We retain account and billing-related records while your account is active and as needed for legal, tax, and security purposes. Image bytes are processed for the request and are not kept as durable storage by nepper.io; provider retention follows each vendor’s policy. You may delete your account from Settings or by contacting us. Cancel paid billing separately with the payment provider if needed.
8. Security
We use industry-standard measures (encryption in transit, access controls, hashed API secrets) to protect data. No method of transmission or storage is perfectly secure.
9. International transfers
We may process data in the United States and other countries where our providers operate (including Google and Sightengine). Where required, we rely on appropriate safeguards for cross-border transfers.
10. Your rights
Depending on your location, you may have rights to access, correct, delete, or export personal data, or to object to certain processing (including withdrawing analytics consent). Contact jurian@nepper.io to exercise these rights. You may also lodge a complaint with your local supervisory authority.
11. Children
The Service is not directed to children under 16. We do not knowingly collect personal data from children.
12. Changes
We may update this policy. Material changes will be posted on this page with an updated date.
13. Contact
Privacy questions: jurian@nepper.io.