Skip to content

Privacy Policy – Nishee

How we collect, use and protect your data, and the rights you have over it.

Effective date
1 October 2026
Last updated
1 October 2026

Your trust matters. This Privacy Policy (“Policy”) explains what Personal Data Nishee collects when you use our review-management, AI reply and social publishing platform, why we collect it, how it is protected, who it is shared with, and the choices and rights you have.

By creating an account, connecting a Google Business Profile or other account, or otherwise using the Service, you acknowledge that you have read and understood this Policy. If you do not agree, please do not use the Service.

1. Definitions

In this Policy:

  • “Service” means the Nishee website, dashboard, APIs and related software.
  • “Customer” or “you” means the individual or business that registers a workspace or uses the Service.
  • “Personal Data” means any data about an identifiable individual, as defined under applicable law.
  • “Connected Account” means a Google Business Profile, Meta (Facebook / Instagram) or X account that you authorise us to access.
  • “Customer Content” means reviews, replies, posts, images and other material processed through your workspace.

2. Our role and scope

Nishee (“Nishee”, “we”, “us”), with its registered address at India, acts as the Data Fiduciary (controller) for account, billing and usage data about our Customers and their team members.

For reviewer names, review text and other Personal Data of your own customers that we retrieve from your Connected Accounts, you determine the purposes of processing and we act as your Data Processor, processing it only on your documented instructions through the Service.

This Policy is published in accordance with the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and the Digital Personal Data Protection Act, 2023 (“DPDP Act”). Where the GDPR or UK GDPR applies to you, Section 10 also applies.

3. Information we collect

3.1 Information you provide

  • Account data: name, email address, hashed password, workspace and team-member details.
  • Billing data: business name, billing address, GSTIN (if provided) and plan. Card, UPI and bank details are collected and held by our payment processor, Razorpay; we do not store them.
  • Content you create: post drafts, brand-voice settings, reply templates, uploaded media and support correspondence.

3.2 Information from Connected Accounts

When you authorise a connection through OAuth, we access only the scopes you approve:

  • Google Business Profile: business locations, reviews (including reviewer display name and star rating), existing replies, and the ability to publish replies and posts.
  • Meta and X: page or profile identifiers and the ability to publish content you schedule.
  • OAuth access and refresh tokens, which we store encrypted.

3.3 Information collected automatically

  • Device and log data: IP address, browser type, pages viewed, timestamps and error logs.
  • Essential cookies used for authentication and security (see Section 9).

We do not knowingly collect Sensitive Personal Data such as health or financial-instrument data, and we do not collect data from children under 18.

4. Purposes and legal basis

We process Personal Data only for specified, lawful purposes:

PurposeBasis
Providing the Service: syncing reviews, drafting and publishing replies, scheduling posts, analyticsPerformance of contract; your consent
Authentication, fraud prevention, security monitoringLegitimate use; legal obligation
Billing, invoicing, tax and accounting recordsContract; legal obligation
Service emails (verification, password reset, invoices, important notices)Contract; legitimate use
Product improvement using aggregated or de-identified usage dataLegitimate interest
Marketing communicationsConsent, withdrawable at any time

We do not sell Personal Data or Customer Content, and we do not use Customer Content to build advertising profiles.

5. Google user data and Limited Use

Nishee's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

  • We use Google user data only to provide and improve the user-facing features you request (review management, reply publishing, posting and analytics).
  • We do not transfer Google user data to others except as necessary to provide those features, to comply with law, or as part of a merger or sale with prior notice to you.
  • We do not use Google user data for serving advertisements, and we do not sell it.
  • Humans do not read Google user data unless you give consent for specific items (for example, for a support request), it is necessary for security or abuse investigation, or it is required by law.
  • Google user data is not used to develop, improve or train generalised AI or machine-learning models. Reviews are sent to an AI provider solely to generate a reply draft for you, as described in Section 6.

You may revoke access at any time from Settings or at myaccount.google.com/permissions.

6. Sharing and sub-processors

We share Personal Data only with service providers bound by confidentiality and data-protection obligations, and only as needed to run the Service:

ProviderFunction
Hosted PostgreSQL providerPrimary application database
CloudinaryMedia storage and delivery
ResendTransactional email
UpstashRate limiting and caching
RazorpayPayment processing and subscription billing
NVIDIA / OpenAIAI generation of reply and post drafts
Google, Meta, XPlatforms you connect, to read and publish on your instruction

We may also disclose Personal Data where required by law, court order or a lawful request of a competent authority, to enforce our agreements, or to protect the rights, safety or property of Nishee, our users or the public. In a merger, acquisition or asset sale, data may transfer to the successor, which will remain bound by this Policy.

7. Artificial intelligence processing

The Service uses third-party AI models to draft review replies and social posts. When you request or enable a draft, the relevant review text, rating, business name and brand-voice instructions are transmitted to the AI provider for that single generation request.

We configure providers so that your content is not used to train their models where such a setting is available. AI output may be inaccurate; you remain responsible for content you approve or that is published under rules you configure in Autopilot.

8. Retention

  • Account and workspace data: for as long as your account is active.
  • After deletion of a workspace: review and post history is removed within 30 days, except as stated below.
  • Billing and tax records: retained for the period required by Indian tax and company law (generally up to 8 years).
  • Security and audit logs: up to 12 months.
  • Disconnected accounts: OAuth tokens are deleted promptly upon disconnection.
  • Backups: overwritten in the ordinary course within 35 days.

9. Security

We maintain reasonable security practices consistent with IS/ISO/IEC 27001-style controls, including: encryption in transit (TLS); encryption at rest of OAuth tokens; hashed passwords; role-based access control within workspaces; rate limiting; signed webhooks; and least-privilege access by our personnel.

No method of transmission or storage is completely secure. In the event of a Personal Data breach affecting you, we will notify you and the Data Protection Board of India as required by law, without undue delay.

10. Cookies

We use only strictly necessary cookies: a signed session cookie to keep you logged in, a CSRF-protection cookie, and a theme preference. We do not use third-party advertising or cross-site tracking cookies. Blocking essential cookies will prevent you from signing in.

11. Your rights

Subject to applicable law, you have the right to:

  • obtain confirmation and a summary of the Personal Data we process about you, and the identities of those with whom it is shared;
  • correct, complete or update inaccurate Personal Data;
  • request erasure of Personal Data that is no longer necessary for its purpose;
  • withdraw consent at any time (without affecting prior lawful processing);
  • nominate another person to exercise your rights in the event of death or incapacity; and
  • seek readily available grievance redressal, and approach the Data Protection Board of India if unresolved.

International users

If you are in the European Economic Area or United Kingdom, you additionally have the rights of access, rectification, erasure, restriction, portability and objection, and the right to lodge a complaint with your supervisory authority. Our legal bases are those in Section 4. Transfers outside your jurisdiction rely on appropriate safeguards such as standard contractual clauses.

To exercise any right, email privacy@nishee.app. We may verify your identity first and will respond within 30 days.

12. Cross-border transfers

Our providers may process data in India and other countries, including the United States and the European Union. Transfers are made only to jurisdictions not restricted by the Government of India under the DPDP Act and are protected by contractual and technical safeguards.

13. Children

The Service is intended for businesses and is not directed at persons under 18. We do not knowingly process Personal Data of children. If you believe a child has provided us data, contact us and we will delete it.

14. Changes to this Policy

We may revise this Policy from time to time. The “Last updated” date above shows the current version. For material changes we will notify workspace owners by email or in-app notice at least 14 days before they take effect. Continued use after that date constitutes acceptance of the revised Policy.

15. Contact and grievance redressal

In accordance with the Information Technology Act, 2000 and the DPDP Act, the details of our Grievance Officer are:

Grievance Officer, Nishee
India
Email: privacy@nishee.app

We acknowledge complaints within 48 hours and aim to resolve them within 30 days.

This document is provided for general information about the Service and forms a binding agreement only as set out in its terms. If you have questions, write to legal@nishee.app.