Privacy Policy
Effective date: 17 July 2026
Last updated: 17 July 2026
1. Who we are
Neveshte is a registered trade name used by Denapia, an eenmanszaak (sole proprietorship) (“Neveshte,” “we,” “us,” “our”). Our full contact details are in section 22.
Privacy questions and requests can be sent to privacy@neveshte.com.
2. Scope
This policy covers personal data handled when you:
- visit neveshte.com or use a form there;
- join the waitlist;
- create or use an Account at app.neveshte.com;
- create, join, or collaborate in a Workspace;
- use research, content-workflow, AI-assisted, sharing, billing, feedback, or support features; or
- otherwise communicate with us.
Neveshte supports a structured content workflow using creator and channel context, ideas, research, outlines, scripts, short-form content, and publishing handoff. Third-party sites, platforms, and hosted payment pages apply their own privacy notices.
3. Our role
Our privacy role depends on the activity; no single label covers every use of data.
For activities where we decide why and how personal data is used — such as Account administration, security, billing administration, website operation, Service communications, provider selection, and our own limited service improvement — we act as the data controller.
For User Content that a business customer places in its Workspace, that customer may determine why personal data in the content is processed, and we process it to provide the requested Service. Business customers who need a data processing agreement can contact us at privacy@neveshte.com.
4. Personal data we collect
What we collect depends on how you use the Service. Free-form fields and uploaded material may contain personal data we cannot predict.
| Category | Examples |
|---|---|
| Account and contact | Name, email, verification state, waitlist details, invitation details |
| Authentication and security | Password hash, reset and verification tokens, optional two-factor and recovery data, session identifier, IP address, user agent |
| Workspace and membership | Workspace name, username, role, invitation and membership status |
| Creator DNA and content | Channel data, profiles, voice and style context, audience, values, goals, templates, ideas, research, scripts and versions, comments, tags, attachments, media, workflow material, AI outputs |
| Public-source and research | Submitted public URLs or handles, YouTube channel/video metadata and statistics, transcripts, snapshots, fetched content, queries, and research results |
| AI and workflow | Prompts, instructions, selected text, document or workflow context, inputs, outputs, errors, provider/model route, tokens, cost, timing, and diagnostics |
| Sharing and collaboration | Share tokens and status, access grants, attribution, last-viewed time, comments |
| Billing and transactions | Stripe customer and subscription identifiers, subscription status, payment-method type and last four digits, invoice references, Credit ledger |
| Communications | Waitlist and invitation records, transactional email, feedback text and images, support requests, delivery metadata |
| Usage, device, and diagnostics | Page or event data, referrer, campaign fields, browser, device, operating system, IP address, approximate location, session activity, errors, and application logs |
We do not ask for special-category or highly sensitive data, and you should not submit it unless we have expressly approved the Service for that use.
5. Data you provide about other people
Workspace users may provide personal data about invitees, collaborators, creators, people mentioned in content, or people appearing in public sources. You must have the rights and authority needed to provide that data. This does not remove our own obligations for processing we control.
6. How we use data
We use personal data to:
- create, authenticate, and secure Accounts;
- create and administer Workspaces and collaboration;
- provide the content, research, source, AI, sharing, and billing features you request;
- send transactional and support communications;
- operate, secure, troubleshoot, and maintain the Service;
- investigate fraud, misuse, and legal claims;
- comply with legal obligations and valid legal process; and
- use limited operational, security, usage, cost, performance, and error data, and aggregated or de-identified information, to analyse and improve the Service.
We do not sell personal information or User Content. We do not use customer User Content to train our own general-purpose AI models.
7. AI processing
AI-assisted features may use your Creator DNA, source material, research context, prompts, instructions, selected editor text, documents, and prior workflow steps to produce research, ideas, outlines, scripts, rewrites, and related results. Requests may be routed to different AI providers or models depending on the task, availability, quality, and cost.
Our no-training commitment applies to Neveshte: we do not train our own general-purpose AI models on customer content. Third-party AI providers — currently including OpenAI and Mistral AI — process text-generation requests under their own terms, and their retention, abuse-monitoring, and review practices depend on the provider and service used. Google services may also be used for public-source features where enabled. We select providers and configurations with data protection in mind and limit what we send to what the requested feature needs.
8. Public sources and YouTube
You can submit public URLs or handles — such as a public YouTube channel or video — without connecting your account on that platform. We may retrieve and store public channel or video metadata, statistics, transcripts, snapshots, and derived research or profile material to provide the features you request.
Neveshte uses YouTube API Services for some of this processing. You can review the Google Privacy Policy and YouTube Terms of Service. If we later add authorised account connections, we will explain the access and how to revoke it, including via your Google security settings.
9. Website analytics
The marketing website does not currently use an analytics service. If we enable analytics or another non-essential measurement technology, we will update this policy and the Cookie Policy before doing so where required.
10. Payments
Payments are processed by Stripe through Stripe-hosted checkout and billing pages. Stripe may collect payment-card, billing, authentication, device, fraud-prevention, and transaction information under its own privacy policy. We store customer and subscription identifiers, subscription status, payment-method type and last four digits, invoice references, and Credit transactions — not full card numbers.
11. Email, support, and feedback
We process names, email addresses, message content, and delivery metadata to send verification, password-reset, waitlist, invitation, billing, and service emails, and to handle feedback and support requests. Transactional email is delivered through a third-party email provider.
12. Legal bases (where GDPR or UK GDPR applies)
| Purpose | Legal basis |
|---|---|
| Registration, authentication, Workspace administration, and requested features (including AI and source analysis) | Performance of a contract, or steps you request before a contract |
| Security, fraud prevention, and service integrity | Legitimate interests, and legal obligation where applicable |
| Billing, payments, disputes, tax, and accounting | Contract, legal obligation, and legitimate interests |
| Waitlist and product communications | Consent or legitimate interests, depending on the interaction |
| Optional analytics and non-essential browser technologies | Consent where required by law |
| Limited operational, error, aggregated, or de-identified improvement data | Legitimate interests |
| Legal rights, compliance, and claims | Legal obligation and legitimate interests |
Where we rely on consent, you can withdraw it at any time for future processing by contacting privacy@neveshte.com or using the relevant control where one is provided.
13. Who we share data with
We share personal data with service providers that help us run the Service, only as needed for the purposes above. Current provider categories include:
| Provider or category | Purpose |
|---|---|
| OpenAI and Mistral AI | AI-assisted text generation and routing |
| Google services | Public-source features where enabled |
| Stripe | Payments, subscriptions, top-ups, invoices, fraud prevention |
| Transactional email provider | Verification, notification, and service emails |
| YouTube/Google APIs and research providers | Public channel, video, and source analysis |
| Sentry | Error monitoring and diagnostics |
| Vercel | Marketing website hosting |
| Hosting, database, storage, queue, and backup infrastructure | Running the application |
We may also disclose limited relevant data to professional advisers, auditors, insurers, authorities, courts, or parties to a corporate transaction where lawfully necessary. We do not sell personal data.
14. International transfers
Some providers may process data outside your country, including outside the EEA, UK, or Switzerland. Where the law requires safeguards for such transfers, we rely on appropriate mechanisms — such as adequacy decisions or standard contractual clauses — with the relevant provider.
15. Retention
We keep personal data only as long as needed for the purposes described in this policy, and then delete or de-identify it. How long that is depends on the record: account data is kept while your Account is active; content is kept while the Workspace needs it; billing and tax records are kept for legally required periods; security logs and diagnostics are kept for shorter operational periods.
When something is deleted, it is first removed from normal use and then purged from underlying systems over time. Copies may persist temporarily in backups and logs, and limited records may be retained where necessary for security, fraud prevention, disputes, tax and accounting, legal claims, or legal holds.
16. Account closure and deletion requests
Account closure, leaving or being removed from a Workspace, content deletion, Workspace deletion, subscription cancellation, and a privacy-rights request have different effects.
Account deletion requires password confirmation, removes your memberships, and logs you out. Workspace deletion has a 24-hour cancellation window before deletion is carried out. After deletion, we remove or de-identify the underlying records as described in section 15.
To make a deletion or other privacy request, email privacy@neveshte.com. We may need to verify your identity before acting on a request.
17. Security
We protect personal data with measures that include hashed passwords, email verification, optional two-factor authentication, session and device management, role-based Workspace access, request-forgery protection, security headers, and verified payment webhooks. No service can promise perfect security, so use a strong unique password and enable two-factor authentication.
18. Children
The Service is intended for adults. It is not directed to, and may not be used by, anyone under 18. If we learn that a person under 18 has created an Account, we will close it and delete the associated data as described in this policy.
19. Your rights
Depending on where you live, you may have rights to information, access, correction, deletion, restriction, portability, objection, withdrawal of consent, marketing opt-out, appeal, non-discrimination, or complaint. These rights are subject to legal conditions and exceptions and do not apply identically everywhere.
Where GDPR or UK GDPR applies, you can request access, rectification, erasure, restriction, or portability, object to certain processing, withdraw consent, and complain to a supervisory authority. We do not make solely automated decisions about you that produce legal or similarly significant effects.
To exercise a right, email privacy@neveshte.com. We may need to verify your identity, and we will respond within the time the applicable law requires.
20. US state privacy laws
If a US state privacy law such as the CCPA applies to you, you may have rights to know, access, correct, delete, and opt out of the sale or sharing of personal information. We do not sell personal information, and we do not share it for cross-context behavioural advertising. You can exercise these rights, or appeal a decision, via privacy@neveshte.com. We will not discriminate against you for exercising them.
21. Policy changes
We may update this policy. The current version always shows its effective date at the top. If a change is material, we will notify you — for example by email or an in-product notice — before it takes effect.
22. Contact
Operator: Denapia, an eenmanszaak using Neveshte as a registered trade name
Address: San Marinostraat 129, 3541 DS Utrecht, The Netherlands
KVK number: 90325648
VAT number: NL458083197B01
Email: privacy@neveshte.com
If you are in the EEA or UK, you can also lodge a complaint with your local data protection authority.