Privacy Policy (Product)
ContentNest — Mobile app
Sites: https://contentnest.ai · https://waitlist.contentnest.ai (waitlist has a separate Privacy Policy)
App: ContentNest (iOS / App Store)
Effective date: 14 September 2026
This Privacy Policy explains how ContentNest (“we,” “us,” or “our”) collects, uses, and shares personal data when you use the ContentNest mobile application and related product services (the “Service”).
It does not cover the pre-launch waitlist at waitlist.contentnest.ai, which has its own Privacy Policy.
By using the Service, you acknowledge this Policy. If you do not agree, please do not use the Service.
1. Who is responsible (controller)
Controller
Business name: Solovyov IT Services
Owner (Inhaber): Nikita Solovyov
Legal form: Einzelunternehmen (Einzelfirma)
Address: Chilegässli 12d, 8904 Aesch (ZH), Switzerland
UID: CHE-185.007.270
Canton: Zürich
Founded: 2024
Country: Switzerland
Email: hi@contentnest.ai
We process personal data under the Swiss Federal Act on Data Protection (FADP) and, where applicable for users in the EEA/UK, the GDPR (and UK GDPR).
2. What data we collect
2.1 Account and authentication
- Email address
- Full name (Name) — collected at signup / stored in your profile or account data
- Authentication credentials / tokens (e.g. password hash or magic-link / OAuth tokens handled by our auth provider — we do not store plaintext passwords)
- Account identifiers and login metadata (e.g. account ID, last login time)
2.2 Profile
- Full name (Name)
- Display name or workspace name you choose
- Optional profile details you provide (e.g. avatar, bio, timezone, language preference) — exact optional fields may grow with the product UI
2.3 Uploaded content and workspace data
Content you create or upload in the Service, which may include:
- Photos, images, videos, and other media files
- Captions, copy, notes, hashtags, and post drafts
- Calendar / planning metadata (dates, platforms, status, labels)
- Client or project names and related workspace organization you enter
You control what you upload. Do not upload content you are not allowed to use.
2.4 Client review / share links
When you create a preview or approval link for a client:
- Link identifier / token and settings (e.g. which posts or materials are shared, expiry if any)
- Client interactions we may log to operate the feature (e.g. link opened, approval / feedback submitted, timestamp) — exact event set may evolve with the review feature
- Optional client name or email if you or the client provide it
Clients who open a link see only what you chose to share (see Section 5).
2.5 Device and app diagnostics
We may collect limited technical data needed to run and improve the app, such as:
- Device type, OS version, app version
- Crash logs, performance diagnostics
- Basic usage events strictly necessary for reliability
Default: We do not use third-party advertising trackers or behavioral advertising / marketing analytics products. If we add non-essential analytics later, we will update this Policy and (where required) obtain consent or another valid legal basis before collecting.
2.6 Payments and subscriptions (Apple)
If you purchase a subscription or in-app purchase:
- Apple processes payment as the merchant of record / payment processor under Apple’s terms and privacy policy.
- We may receive from Apple: subscription status, product identifiers, transaction IDs / original transaction IDs, purchase or renewal dates, and entitlement state — not your full card number.
- Region / storefront context may reflect App Store / CHF pricing for your storefront.
2.7 Support communications
If you email hi@contentnest.ai, we process the content of your message and contact details to respond.
2.8 Data we do not intentionally collect
We do not require government ID for standard use. We do not sell personal data.
3. Why we use data (purposes) and legal bases
| Purpose | Examples | Legal basis (FADP / GDPR) |
|---|---|---|
| Provide the Service | Account creation, auth, storing workspace content, calendars, sync | Contract (performance of the user agreement) / FADP overriding interest aligned with contract |
| Client preview & approval | Generate share links; show shared materials; record approvals/feedback | Contract; legitimate interest in enabling your workflow with clients |
| Customer support | Answer questions, fix bugs | Contract and/or legitimate interest |
| Security & abuse prevention | Detect fraud, protect accounts, prevent misuse | Legitimate interest; legal obligation where applicable |
| Improve reliability | Crash/diagnostic data (if enabled) | Legitimate interest — or consent if required for non-essential analytics |
| Subscriptions & billing status | Entitlements via Apple | Contract; Apple processes payment under its own terms |
| Legal compliance | Respond to lawful requests; keep required records | Legal obligation |
| Product communications | Service notices, security alerts, material Terms/Privacy changes | Contract / legitimate interest; marketing emails only with consent or soft opt-in where allowed |
Where we rely on consent, you may withdraw it at any time without affecting prior lawful processing.
4. Processors and categories of recipients
We use service providers (“processors”) who process data on our instructions:
| Category | Role | Provider |
|---|---|---|
| Hosting / database / auth | Backend storage, authentication, APIs | Supabase (and its infrastructure subprocessors) |
| Email / transactional messaging | Account, support, or product emails | TBD — disclose specific provider when production email stack is fixed |
| Analytics | Product analytics | None by default — no ad trackers; disclose before enabling any analytics SDK |
| App distribution & payments | App Store distribution, IAP / subscriptions | Apple Inc. (and affiliates) — see Apple’s Privacy Policy and Apple Media Services Terms |
| Support inbox | Receiving support email | TBD with mailbox / email provider |
We may also disclose data:
- To you (via the app and exports, if offered)
- To clients you invite via review links (only shared materials and related feedback UI)
- To authorities if required by law
- In a business transfer (e.g. merger or asset sale), subject to appropriate safeguards
We do not sell your personal data.
5. Client sharing — what clients see
When you send someone a ContentNest preview / approval link:
Clients typically can see:
- The posts or materials you selected for that link (media, captions, and related planning info you chose to include)
- Status / approval UI (e.g. approve, request changes, notes)
- Branding of ContentNest as the tool presenting the preview
Clients typically cannot see (unless you put it in shared content):
- Your full account email or password
- Other workspaces, clients, or posts not included in the link
- Your subscription or billing details
- Internal-only notes if the product marks them as excluded from the share
Your responsibility: Only share links with people you intend to give access. Treat links like passwords if they are unauthenticated. Revoke or expire links when no longer needed.
We process client interaction data as described in Section 2.4 to provide this feature for you.
6. Retention and deletion
| Data | Retention (intended) |
|---|---|
| Account & profile (incl. full name) | While your account is active |
| Uploaded content & workspace | While your account is active, or until you delete the content |
| Review links & related feedback | While the link/workspace exists, or until you delete them |
| Diagnostics / logs | Typically short-lived (order of weeks) unless needed longer for security or legal reasons — exact window TBD |
| Support emails | As needed to resolve the request, then limited retention (target up to ~24 months) — exact window TBD |
| Billing / entitlement records from Apple | As needed for entitlements and legal/accounting |
Account deletion: You may request deletion by contacting hi@contentnest.ai (in-app “Delete account” when available). We will delete or anonymize personal data associated with your account within a reasonable period, except data we must keep for legal, security, or dispute purposes (e.g. limited transaction records).
Deleting the app from your device does not automatically delete your account or cloud-stored content.
7. International transfers (Swiss–EU and beyond)
We are based in Switzerland. Data may be processed in Switzerland, the EEA, and other countries where our processors operate (including Supabase hosting regions and Apple for payment-related data).
For transfers from Switzerland / EEA to countries without an adequacy decision, we use appropriate safeguards such as:
- Standard Contractual Clauses (SCCs) or Swiss-approved equivalents
- Processor terms that include transfer mechanisms
Apple may process payment-related data according to Apple’s own transfer practices.
8. Your rights
Depending on your location (Switzerland FADP and, where applicable, GDPR), you may have the right to:
- Access your personal data
- Rectify inaccurate data
- Erase data (“right to be forgotten”) where applicable
- Restrict or object to certain processing
- Data portability (where GDPR applies and processing is automated based on contract/consent)
- Withdraw consent where processing is based on consent
- Lodge a complaint with a supervisory authority
Switzerland: Federal Data Protection and Information Commissioner (FDPIC) — https://www.edoeb.admin.ch
EEA: Your local data protection authority
UK (if applicable): Information Commissioner’s Office (ICO)
To exercise rights, email hi@contentnest.ai. We may need to verify your identity before fulfilling a request.
9. Children
The Service is intended for users aged 16 and older. We do not knowingly collect personal data from children under 16. If you believe a child under 16 has provided data, contact us and we will take appropriate steps to delete it.
10. Security
We use reasonable technical and organizational measures appropriate to a small SaaS product (e.g. encrypted transit, access controls, and security features provided by Supabase and Apple). No method of transmission or storage is 100% secure.
11. Changes to this Policy
We may update this Privacy Policy from time to time. We will post the updated version at our Privacy URL and change the effective date. For material changes, we may also notify you in-app or by email when appropriate.
12. Contact
Questions about privacy or this Policy:
Email: hi@contentnest.ai
Controller: Solovyov IT Services (Nikita Solovyov, Inhaber), Chilegässli 12d, 8904 Aesch (ZH), Switzerland · UID CHE-185.007.270
13. Language
This Policy is provided in English. German (DE) and Ukrainian (UA) translations may be added later. If translations conflict, the English version prevails unless mandatory local law requires otherwise.
Product Privacy Policy — ContentNest mobile app. Not the waitlist Privacy Policy.