Privacy Policy
This document is a draft under legal review. It describes what the platform actually does today, written in plain language by the people who built it. It has not yet been reviewed by counsel, and the final wording may change. If anything here is unclear or looks wrong to you, write to privacy@neverhidden.com and we'll answer.
1. Who we are
Never Hidden is a marketing operations platform for small businesses, built and operated from the European Union. We are the data controller for the account information you give us directly, and a data processor for the marketing data we retrieve on your behalf from the services you connect.
Contact for anything privacy-related: privacy@neverhidden.com.
2. What this policy covers
It covers two things: this website, and the Never Hidden application (the customer workspace, its API, its command-line tool and its MCP endpoint).
This website
This site sets no cookies, runs no analytics and loads nothing from a third party. There is no tracking pixel, no advertising tag, no font or script fetched from another domain. That is why you are not being asked to accept anything. Our web server keeps standard request logs (IP address, page requested, timestamp, user agent) for security and troubleshooting, and deletes them after 30 days.
3. What the platform processes
Account data
Your name, work email address, hashed password, workspace name, role, and the timestamps of your logins and approvals. Approvals are recorded deliberately and permanently — see section 7.
Marketing data from services you connect
Nothing is connected unless you connect it. Each connection is made by you, with your own account, and can be disconnected by you at any time. Depending on what you connect, we retrieve:
- Google Search Console — search queries, clicks, impressions, average position and page-level performance for the properties you select.
- Google Analytics (GA4) — aggregated traffic, channel and conversion metrics for the property you select. We do not retrieve user-level or personally identifying analytics data.
- Google Ads — campaign, ad group, keyword, search-term, ad and conversion performance; and, for changes you approve, bid, budget and status updates written back to your account.
- Microsoft Advertising — the equivalent campaign performance and structure data, and approved changes written back.
- LinkedIn and X — the identity of the page or account you authorise, and posts published from the platform after you approve them, together with their published state read back for verification.
- Your website and CMS — page content and metadata we fetch to analyse or to publish drafts you approve.
- Third-party marketing data — keyword, ranking, competitor and AI-answer data obtained from data providers about domains and topics, not about people.
Alongside this we store what the platform derives from it: weekly snapshots, computed changes, reports, drafts, and the audit record of every action taken.
Credentials
OAuth tokens and API keys for the services you connect are stored encrypted at rest and are used only to make the calls the platform needs to run your workspace. They are never displayed back to anyone, never shared with another customer, and never sent to a third party other than the service they belong to.
Billing data
Payments are handled by Stripe. Card details are entered on Stripe's systems and never reach ours — we hold only the subscription state, invoice records and the billing contact.
4. Google user data and Limited Use
When you connect a Google account, Never Hidden requests only the scopes needed for the modules you use: read access to Search Console and Analytics data, and read and write access to the Google Ads account you nominate (writes happen only for changes you have explicitly approved — see section 7). You can review and revoke this access at any time in your Google Account permissions.
Never Hidden's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
In practice, this means data received from Google APIs is:
- used only to provide and improve the features you asked for in your workspace;
- never sold, and never transferred to anyone except as needed to provide those features, for security purposes, or where required by law;
- never used for advertising, ad targeting, credit assessment or lending;
- never used to train generalised or foundation AI or machine-learning models;
- never read by a human, except with your explicit permission (for example when you ask us to look at a specific problem), for security or abuse investigation, or where the law requires it.
Google data is processed by our AI provider only to interpret it inside your workspace — see section 6 for exactly what that means and what it excludes.
5. Where your data lives and how it's protected
- Hosting is in the European Union. Application servers and database are hosted with Hetzner in Germany.
- All traffic to the application and this site is encrypted in transit (TLS).
- Integration credentials are encrypted at rest with per-installation keys, separately from the rest of the database.
- Access to production systems is limited to the operator of the service, over authenticated channels, and is logged.
- Workspaces are isolated at the database query level: data belonging to one workspace is not readable from another, by design rather than by convention.
- API tokens are workspace-scoped and permission-scoped. A token that lacks approval permission cannot approve anything, and cannot grant itself that permission.
6. What we do not do
- We don't sell your data. Not to advertisers, not to data brokers, not in aggregate.
- We don't train AI models on your data. Your content and metrics are sent to our AI provider only to produce the analysis, drafts and answers inside your own workspace. They are not used to train foundation models, and our provider is contractually bound not to train on data submitted through their business API.
- We don't act in your name without your approval. This is a privacy matter as well as a product one: nothing is published, sent or spent under your identity until you approve that specific action.
- We don't quietly move your data outside the EU. Where a subprocessor operates elsewhere, it is named in section 8 with the safeguard that applies.
7. The record of what happened
The platform keeps an append-only audit log: every action taken in your workspace, who approved it, what was sent, what came back, and whether it could be verified afterwards. This log cannot be edited or deleted by the application itself — that restriction is enforced in the database, and it is the point of the product.
It follows that individual audit entries can't be amended on request while your account is active. The whole record is deleted when your workspace is deleted (section 9).
8. Subprocessors
These are the third parties that process data on our behalf. We'll update this list before adding another.
| Subprocessor | What it processes | Where |
|---|---|---|
| Hetzner | Hosting and storage for the application, database and backups — that is, everything described in section 3. | Germany (EU) |
| Stripe | Payment and subscription processing: card details, billing contact, invoices. | EU / US (Data Privacy Framework, EU standard contractual clauses) |
| Postmark | Transactional email delivery: your email address and the contents of the emails we send you (approval requests, weekly summaries, password resets). | US (EU standard contractual clauses) |
| Anthropic | AI interpretation and drafting: the marketing data and content excerpts we send to produce your reports, drafts and assistant answers. Not used to train models. | US (EU standard contractual clauses) |
Marketing data providers (for keyword, ranking and AI-answer data) are queried about domains, keywords and topics rather than about you, and receive no customer personal data.
9. Retention and deletion
- While your workspace is active, marketing snapshots, reports and the audit log are kept for as long as the workspace exists — the value of the product is the history.
- Website request logs: 30 days.
- Deletion on request: ask at privacy@neverhidden.com and we will delete your workspace and everything in it within 30 days, including backups within a further 30 days. We'll confirm in writing when it's done.
- After you cancel: we keep the workspace for 60 days so you can come back or export, then delete it. Tell us to delete it sooner and we will.
- Invoices are kept for as long as tax law requires (currently 10 years) — this is the one category we cannot delete on request.
- Disconnecting a service deletes its stored credentials immediately. Data already retrieved stays until you ask us to remove it or the workspace is deleted.
Export: your data is yours and leaves with you. Reports, action history and the audit log can be exported through the API or on request.
10. Your rights
Under the GDPR you can ask us for a copy of your personal data, ask us to correct it, delete it, restrict how we use it, or object to a use. You can also ask for it in a portable format. Write to privacy@neverhidden.com — we'll respond within 30 days, and we won't make you use a form.
We rely on your consent for the services you choose to connect, and on the performance of our contract with you for running the workspace itself. If you believe we've handled your data badly you have the right to complain to your national data protection authority.
11. Children
The platform is a business tool and is not directed at anyone under 16. We don't knowingly collect data from children.
12. Changes to this policy
Each version carries a version string and a date at the top of this page. If a change materially affects what we do with your data, we will email account holders before it takes effect rather than changing the page quietly.
13. Contact
privacy@neverhidden.com for anything in this document. hello@neverhidden.com for everything else.