Legal
Privacy Policy
How we handle personal information on www.nylon.dev, in the Nylon dashboard, and in the Nylon API.
Last updated September 1, 2026
This Privacy Policy explains how Nylon (“Nylon”, “we”, “us”) collects, uses and shares personal information when you visit https://www.nylon.dev, create a Nylon account, or integrate the Nylon API into your own product. It applies to information we handle as a controller. Where we process personal data contained in your end users’ social accounts and published content, we act as a processor on your instructions — those activities are governed by our Data Processing Addendum.
1. Who we are
Nylon is the data controller for the processing described in this policy. The operating company is established in the European Union and is named under Company details at the foot of this page. Our production infrastructure is located in the United States. You can reach us at support@nylon.dev.
2. Information we collect
We collect the following categories of information:
- Account information — name, work email address, company name, and the password hash or identity-provider subject we use to authenticate you.
- Billing information — billing address, VAT number, plan, and the number of connected accounts. Card details are collected and stored by our payment processor; we never see or store full card numbers.
- Integration credentials — OAuth access and refresh tokens for the social accounts connected through Nylon, and, if you use bring-your-own-keys, the client identifiers and secrets for your own platform applications. These are encrypted at rest and are never returned by the API once written.
- Content you send through the API — post text, media, scheduling metadata and the responses returned by the social networks. This may contain personal data about your end users; we handle it as a processor.
- Usage and technical data — API request logs (endpoint, timestamp, status code, latency, truncated request identifiers), IP address, browser and device information, and error diagnostics.
- Support and marketing data — messages you send us, and your subscription preferences.
3. Why we process it, and on what legal basis
- To provide the service — authenticating you, executing API calls, publishing to the networks you have connected, and billing you. Legal basis: performance of a contract.
- To keep the service secure and reliable — abuse detection, rate limiting, fraud prevention, incident investigation and capacity planning. Legal basis: legitimate interests.
- To improve the product — aggregated usage analysis and error monitoring. Legal basis: legitimate interests.
- To communicate with you — service notices, security advisories, changelog and, where required, marketing. Legal basis: legitimate interests or consent, depending on the message.
- To meet legal obligations — accounting, tax and responding to lawful requests. Legal basis: legal obligation.
4. Sharing and subprocessors
We do not sell personal information. We share it only with service providers acting on our behalf under written contract, and only as needed to run the service: cloud hosting and storage, media transcoding and delivery, transactional email, payment processing, error monitoring and product analytics. A current list of subprocessors is maintained with our Data Processing Addendum.
We also transmit the content you submit to the social networks you have chosen to connect. Once content reaches a network, that network processes it under its own terms and privacy policy, which we do not control.
We may disclose information where required by law, to enforce our agreements, or in connection with a merger, acquisition or sale of assets — in which case we will notify you before your information becomes subject to a different privacy policy.
5. International transfers
Our production infrastructure is located in the United States, in the state of Virginia. Where a subprocessor processes personal data outside the European Economic Area, we rely on an adequacy decision or on the European Commission’s Standard Contractual Clauses, together with supplementary technical measures such as encryption in transit and at rest.
6. Retention
- Account and billing records: for the life of the account, then as required by tax law.
- Integration credentials: until you disconnect the account or delete the credential, whichever is first, then deleted.
- Published content and API payloads: 90 days by default, or the retention window in your plan.
- API request logs: 30 days, then aggregated or deleted.
- Support correspondence: 24 months.
When you close your account we delete or irreversibly anonymise your data within 30 days, except where we must keep it to comply with a legal obligation or to establish, exercise or defend legal claims.
7. Security
We encrypt data in transit with TLS and at rest, store integration credentials under per-tenant encryption keys, enforce least-privilege access with multi-factor authentication for staff, log administrative access, and review our dependencies for known vulnerabilities. No system is perfectly secure, but we will notify you and, where required, the competent supervisory authority without undue delay if a breach affecting your personal data occurs.
8. Your rights
If you are in the European Economic Area, the United Kingdom or Switzerland, you have the right to access, rectify, erase, restrict and port your personal data, to object to processing based on legitimate interests, and to withdraw consent at any time without affecting processing carried out before the withdrawal.
Exercise any of these by writing to support@nylon.dev. We respond within one month. You also have the right to lodge a complaint with your local data protection supervisory authority.
If your request concerns data we process on behalf of one of our customers, we will refer you to that customer, who is the controller for it.
9. Children
Nylon is a business product and is not directed at children. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided us with personal information, contact us and we will delete it.
10. Changes to this policy
We may update this policy as the service changes. We will post the new version here with a revised “last updated” date and, for material changes, notify account holders by email at least 14 days before the change takes effect.
11. Contact
Questions about this policy, or about how we handle your data, go to support@nylon.dev.