← Back to Nourous

Privacy

Privacy Policy

Last updated July 24, 2026

Overview

Nourous is built around a simple rule: the judgment about whether a video belongs in your feed happens on your device, not on our servers. This policy explains what we collect to make your account and dashboard work, what never leaves your device, and who we share information with.

Information we collect

Account information. The email address you sign up with. Authentication and password storage are handled by Supabase Auth — we never see or store your password in plain text.

Profile and filter settings. For each profile you create — your own, or a child’s — we store the settings that define it: strictness level, topic and keyword rules, channel allow/block lists, search filtering choices, school-hours and bedtime schedules, and the personalization weights the adaptive engine learns as you correct it. A parent PIN, if set, is stored as a one-way hash, never as plain text.

Corrections and override requests. When you restore a hidden video, hide one that slipped through, or a child requests an override, we store that specific video’s ID, title, and channel. This is the only per-video information that ever reaches our servers, and it’s only stored because you or your child took an explicit action on it — it’s how the parent dashboard, weekly family report, and cross-device sync work.

Device information. A device name, the extension and browser version, and when the device last checked in. This is how we know which devices belong to which profile and how policy changes reach them.

Diagnostic events. Lightweight events like “policy updated” or “device paired”, used to keep sync reliable. These don’t contain video content.

Beta feedback. If you submit feedback through the in-product beta form, we store the message and the page it was sent from so we can follow up.

What never leaves your device

The classifier that reads and judges each recommended video runs locally, in the extension, as the page loads. Your actual YouTube watch history, and the full set of videos shown or filtered in a normal session, are never uploaded — the exceptions above exist only because you explicitly acted on a specific video.

How we use this information

  • To operate your account and sync filter policy across your devices.
  • To power the parent dashboard — activity, override requests, and profile settings.
  • To send transactional email (verification, password reset, override notifications) and, if you’re subscribed, product email like the weekly family report — sent through Resend, our email delivery provider.
  • To respond to beta feedback and support requests.

Every non-transactional email includes an unsubscribe link.

Who we share it with

We use Supabase for authentication and database infrastructure, and Resend for email delivery. Both process data on our behalf under their own security commitments. We don’t sell your data, don’t share it with advertisers, and don’t use it to train third-party models.

Nourous’s free trial requires no payment details. If we introduce paid billing, card data will be handled directly by a PCI-compliant payment processor — we won’t store card numbers on our own servers.

Data retention and deletion

We keep account and profile data for as long as your account is active. To delete your account and associated data, email hello@nourous.com — we’ll confirm once it’s done.

Security

Passwords are managed and hashed by Supabase Auth, parent PINs are stored as one-way hashes, and connections between your devices and our servers are encrypted in transit.

Children’s privacy

Child profiles are created and controlled by a parent or guardian’s account. A child does not sign up on their own or provide account information directly — the parent account holder does.

Changes to this policy

If this policy changes in a material way, we’ll update the date at the top of this page and, for significant changes, let you know by email.

Contact

Questions about this policy — hello@nourous.com.