Privacy Policy
Last updated July 22, 2026
Nagaru (“Nagaru”, “we”, “us”) helps you publish content to your own social media accounts. This policy explains what we collect, how we use it, who we share it with, and how you can delete it. It is written to comply with India’s Digital Personal Data Protection Act, 2023 (“DPDP Act”) and, where applicable, the EU/UK General Data Protection Regulation (“GDPR”). By using Nagaru you consent to the processing described in this policy.
Who we are
Nagaru is operated by Accuprosys Global Private Limited (CIN U74140TG2008PTC060467), a company incorporated in India with its registered office in Hyderabad, Telangana. For the purposes of the DPDP Act, Accuprosys Global Private Limited is the “Data Fiduciary”, and under the GDPR the “Data Controller”, for the personal data described below. Contact details are at the end of this policy.
Information we collect
- Account information. The email address and password you use to create a Nagaru account. Passwords are stored only as secure hashes.
- Connected social accounts. When you connect Twitter/X, LinkedIn, Instagram, or Threads, we receive and store an OAuth access token, your platform user ID, and your handle. We only request the permissions needed to read your basic profile and publish posts you approve.
- Project integrations. If you connect GitHub or Notion to a project, we receive and store an encrypted access token and read only the repository or workspace content you select, so we can draft posts about your ongoing work.
- Content you create. The post ideas, drafts, images, and project context you enter, plus the AI-generated variants and your edits to them.
- Voice profile. Your onboarding answers, tone summary, and writing samples you provide, which we use to generate posts in your voice.
- Usage data. Basic technical data needed to operate the service, such as device push tokens (if you enable notifications) and request logs.
How we use your information (purposes and legal basis)
- To generate posts in your voice and adapt them per platform (consent; performance of our contract with you).
- To publish posts to the social accounts you connect, only after you approve them (or automatically, only if you explicitly enable auto-publish) (consent; performance of contract).
- To send you approval and account emails, and optional push notifications (performance of contract).
- To learn your writing style from your edits so future drafts match your voice (consent).
- To secure the service, prevent abuse, and comply with legal obligations (legitimate interests; legal obligation).
We do not sell your personal information, we do not use it for third-party advertising, and we do not use your content to train AI models. You may withdraw consent at any time by disconnecting a platform or deleting your account (see “Deleting your data” below); withdrawal does not affect processing already carried out.
How we share information
We share data only with the service providers (processors) required to run Nagaru:
- Anthropic — to generate and refine post drafts. Your post ideas and drafts are sent to Anthropic’s Claude API for processing.
- Supabase — database, authentication, and file storage.
- Vercel — application hosting.
- Resend — transactional email delivery.
- Google Firebase — push notification delivery, if you enable notifications in the mobile app.
- Sentry — error monitoring, so we can detect and fix failures in the service. Error reports may include technical request data.
- Upstash — rate-limiting and abuse-prevention infrastructure, which processes short-lived request identifiers (such as IP addresses).
- Tavily — web search used to discover topics for scheduled posts; it receives search queries derived from the project context you provide, never your account details.
- The social platforms you connect (Twitter/X, LinkedIn, Meta’s Instagram and Threads) — to publish your approved posts.
- GitHub and Notion — only if you connect them, to read the project content you choose to share with Nagaru.
Our use and transfer of information received from Meta APIs and the LinkedIn API adheres to the Meta Platform Terms and Developer Policies and the LinkedIn API Terms of Use, respectively. We may also disclose information if required by law or to protect our rights, users, or the public.
International data transfers
Our service providers listed above may store and process data on servers located outside India (including the United States and the European Union). Where required, we rely on our providers’ standard contractual safeguards for such transfers. By using Nagaru you consent to these transfers.
Data storage, security, and retention
OAuth tokens are encrypted at rest using AES-256-GCM before they are stored. Data is held in Supabase (PostgreSQL) with row-level security so each user can only access their own records. We retain your data for as long as your account is active. When you delete your account, your data is permanently deleted; short-lived operational logs and backups are purged on a rolling basis thereafter. If we become aware of a personal data breach affecting you, we will notify you and the relevant authority (including the Data Protection Board of India) as required by law.
Deleting your data
You can disconnect any social account at any time from Settings, which deletes the stored token for that platform. You can permanently delete your entire Nagaru account and all associated data from Settings → Delete account. Removing Nagaru from your Instagram or Threads settings also triggers automatic deletion of the stored connection. Full instructions are on our data-deletion page.
Your rights
Depending on where you live, you have the right to:
- Access a summary of the personal data we hold about you and how it is processed.
- Correct inaccurate or incomplete data, or ask us to update it.
- Erase your personal data (subject to any legal retention requirements).
- Withdraw consent at any time, as easily as it was given.
- Nominate another individual to exercise your rights in the event of death or incapacity (DPDP Act).
- Receive a portable copy of your data, restrict or object to certain processing, and lodge a complaint with your supervisory authority (GDPR), or approach the Data Protection Board of India after first raising the issue with us (DPDP Act).
To exercise any of these rights, email us at the address below. We will respond within the timelines required by applicable law.
Grievance redressal
In accordance with the DPDP Act and the Information Technology Rules, our Grievance Officer is Rohan Ravipati, reachable at rohankravipati@gmail.com. We acknowledge grievances within 24 hours and aim to resolve them within 15 days.
Children
Nagaru is not directed to anyone under 18, and we do not knowingly collect or process the personal data of children. If you believe a child has created an account, contact us and we will delete it.
Changes
We may update this policy from time to time. Material changes will be reflected by the “Last updated” date above, and we will notify you of significant changes by email or in-app notice.
Contact
Questions or requests: rohankravipati@gmail.com.