Privacy policy
Last updated: 9 August 2026
Who we are
Nubu is a creative-automation platform operated by Bear Studios Creative Ltd (“we”, “us”). Teams use Nubu to turn campaign data, media assets, and video templates into finished advertising creatives, and optionally to deliver those creatives to advertising platforms they connect. This policy explains what data we collect, why, and the choices you have. For anything not answered here, contact hello@nubu.app.
Data we collect
- Account data — your name, email address, and password (stored as a salted hash by our authentication provider), plus optional two-factor authentication settings.
- Organisation data — your workspace name, team membership and roles, notification preferences, and billing plan. Payment details are handled by Stripe; we never see or store full card numbers.
- Content you upload — media assets (images, video, audio), video templates, campaign data, and the creatives rendered from them. Files are stored in Cloudflare R2; our database stores metadata only.
- Operational data — logs of renders, uploads, and errors, kept so we can trace failures and keep the service reliable.
- Usage analytics — with your consent, how you use our websites and app: pages visited, clicks, device and browser details, approximate location derived from your IP address, and session replays. See “Analytics, cookies and session replays” below.
Data from connected platforms (Meta and Google)
If your organisation’s owner connects a Meta (Facebook) account, Meta grants us a system-user access token for your business portfolio. With it we access only what the delivery features need:
- The names and IDs of your ad accounts, Facebook Pages, and Instagram accounts, so you can choose where a creative is delivered.
- The names and IDs of your campaigns and ad sets, so you can choose the destination for an ad.
- The ability to upload your rendered creatives and create ads — always created in a paused state; Nubu never activates ads or changes budgets.
If your organisation’s owner connects Google Ads, Google grants us OAuth tokens for the ad accounts you authorise. With them we access only the names and IDs of your ad accounts and campaigns (so you can choose a destination) and the ability to upload your rendered creatives and create ads — always created in a paused state; Nubu never activates ads or changes budgets on Google either.
All platform access tokens are encrypted (AES-256-GCM) before they are stored, are never exposed to your browser, and are used solely to perform the actions you request. We do not read your Page content, messages, followers, or insights, and we never post organic content. Disconnecting a platform in Settings deletes its token and every cached identifier immediately — see our data deletion instructions.
AI providers you connect (OpenAI, Google Gemini, Anthropic)
Your organisation’s owner may connect their own API keys for third-party AI providers — OpenAI, Google Gemini, and Anthropic — to power image, video, and copy generation inside Nubu.
- API keys are encrypted (AES-256-GCM) before they are stored, are never sent to your browser, and only their last four characters are ever shown again. A decrypted key exists in memory only for the duration of a single provider call.
- When you run a generation, the content you chose for that request (for example campaign text or imagery) is sent to that provider to produce the output. Nothing else is shared, and nothing is sent to a provider you have not connected.
- Your use of each provider is governed by its own terms and API data policies. We never use your content to train models ourselves.
- Removing a provider in Settings deletes the encrypted key immediately.
Analytics, cookies and session replays
With your consent, we use PostHog (hosted in the European Union) to understand how our websites and app are used: pages visited, clicks, device and browser details, approximate location derived from your IP address, and session replays showing how pages are used. Replays mask anything you type by default. Analytics traffic is routed via a first-party address on our own domain before it reaches PostHog.
Nothing is stored on your device and no analytics run until you make a choice in the consent banner. If you accept, PostHog sets first-party cookies and browser storage (names beginning ph_ and __ph_opt_in_out_) that recognise your browser for up to 12 months. If you decline, your visits are counted anonymously using a privacy-preserving, daily-rotating identifier computed on PostHog’s servers — nothing is stored on your device and no session replays are recorded. Strictly necessary cookies (such as sign-in sessions and your active workspace) do not require consent and are always on.
The legal basis for analytics is your consent (UK GDPR Article 6(1)(a) and PECR), which you can withdraw at any time via the “Cookie preferences” link in the site footer or in the app’s Settings under Privacy & Security. Analytics events are retained for 12 months and session replays for 30 days.
How we use data
- To provide the service: authenticate you, render creatives from your inputs, store your assets, and deliver creatives to platforms you connect.
- To keep the service safe and reliable: rate limiting, abuse prevention, and failure diagnostics.
- To understand how Nubu is used and improve it, through the consent-based analytics described above.
- To send transactional email you have opted into (render completions, team changes, billing notices).
We do not sell your data, use it for advertising of our own, or use your content to train machine-learning models.
Who we share data with
We share data only with the infrastructure providers that run Nubu, each bound by their own data-processing terms: Supabase (database and authentication), Cloudflare (hosting, file storage, and media processing), Stripe (billing), Resend (transactional email), and — only with your consent — PostHog (usage analytics and session replays, hosted in the EU). Where you connect them, we also share the minimum necessary with Meta and Google (only the data required to deliver the ads you ask us to create) and with the AI providers you connect — OpenAI, Google Gemini, or Anthropic (only the content you submit for a generation). We never share one organisation’s data with another.
Data retention
Your content stays in your workspace until you delete it or your organisation is deleted. Deleting your account or organisation removes the associated records and files from our systems, including any connected-platform tokens and AI provider keys. Read notifications are purged automatically after 24 hours; operational logs are kept only as long as needed for diagnostics. Analytics events are retained for 12 months and session replays for 30 days.
Security
All traffic is encrypted in transit (TLS). Files are accessed through short-lived signed URLs minted only after an ownership check. Platform access tokens are encrypted at rest and every database table enforces row-level security scoped to your organisation.
Your rights
You can access, correct, export, or delete your data at any time — most of it directly in the app’s Settings. You can change or withdraw your analytics consent whenever you like via the “Cookie preferences” link in the site footer or in the app’s Settings. You may also email hello@nubu.app to exercise any data-protection right you have under applicable law (including the UK and EU GDPR); we respond within 30 days.
Changes to this policy
If we make material changes we will update this page and, where appropriate, notify account owners by email. The date above always reflects the current version.