The small print

Privacy Policy

Last updated 8 August 2026

We read posts that are already public on the account you name, plus the metrics those posts display. We do not need your password and we never post as you. Your diagnosis is visible only to you and to anyone you invite. This page is that promise at length, including the parts that are awkward.

1. What we collect

  • The handle you give us, and the email address you want the diagnosis sent to. That is the entire intake form.
  • Your public posts and their public metrics — captions, thumbnails, durations, view, like and comment counts. The same things any of your followers can see.
  • Video frames from a small number of posts, extracted so the analysis can read your on-screen title cards and opening shots.
  • Anything you upload to your Case File — analytics exports, your offer, your price list, your audience research. You choose every one of these files.
  • Private account metrics such as watch time, retention and saves — only if you explicitly connect the account, and only ever read-only.
  • Account and security records: your email, your sessions, and a log of security-relevant events such as sign-ins, invitations and exports.

We do not use advertising trackers, we do not build a profile of you across other websites, and we do not buy data about you from anyone.

2. What we do with it

We use it to produce your diagnosis and to answer you when you write to us. That is the whole list. Specifically, we do not sell it, rent it, share it with advertisers, or use one client’s data to inform another client’s report.

Your email is used to send your diagnosis, to reply to you, and — if you are on a subscription — for the notices in section 5 of the Terms, such as a failed payment. We will not add you to a marketing list you did not ask for.

3. Who can see your diagnosis

  • You, and anyone you invite into your workspace. Nobody else.
  • Every read is scoped on the server to the workspace you belong to. A chart that is not yours returns “not found” rather than “forbidden”, because confirming that an account exists is itself a disclosure.
  • We never publish it, and we never use your report, numbers or hooks as a case study, screenshot or testimonial without your written permission.
  • The public marketing site uses an invented creator, and a check runs on every release that blocks it if any real client fingerprint reaches a public page.
  • A small number of people who work on Nerdy Doctor can reach production data to fix problems and to prepare your report. It is not browsed for interest.

4. The companies that touch it on the way through

Running the product means other companies process some of this data. These are the ones in use today:

  • Netlify — hosting and content delivery, and private file storage for your Case File documents. Those files are never placed in a public directory and are only ever served by a route that has already checked your session.
  • Prisma Postgres — the database. Your account, reports and extracted facts are stored in the eu-central-1 (Frankfurt) region.
  • Anthropic — the creative half of the analysis: reading a hook, writing an autopsy, drafting a brief. Captions, frames and Case File extracts are sent for that purpose. Your data is not used to train models.
  • YouTube Data API — used to read public data from a YouTube channel you name.

These are wired into the product but not currently switched on, and are listed so the picture is complete rather than to imply they already hold anything of yours: Apify (collecting public Instagram and TikTok posts), Stripe (card payments — we would never see your card details), OpenAI (optional audio transcription for verbatim spoken hooks). If one is turned on, this list changes and the date at the top of this page changes with it.

5. How long we keep it

  • While your account is active, we keep your reports and Case File so next month’s diagnosis can score last month’s prescriptions. That comparison is the product.
  • After you cancel, the workspace goes read-only and everything stays viewable and exportable for 60 days.
  • Nothing is deleted silently, ever. If something is going to be removed, you are told first.
  • An intake request that never becomes an examination is a handle, an email and a date. Ask and we will delete it.

6. Getting it out, or getting it deleted

Email hello@nerdydoctor.com from the address on the account and ask. You can ask us to:

  • send you a copy of everything we hold about you,
  • correct anything that is wrong,
  • delete all of it, or
  • stop processing while we sort out a disagreement.

Deletion means deletion: the account, the reports, the extracted facts and the uploaded files. We will confirm when it is done. Backups roll off on their own schedule, so a copy can survive there briefly after the live data is gone — we would rather say that than pretend otherwise.

You can also disconnect a connected account at any time, which stops us reading its private metrics immediately.

7. Security

  • Sessions live on the server, so removing someone’s access takes effect on their next request rather than whenever a token expires.
  • Passwords are stored only as salted hashes. We cannot read yours.
  • Sign-in attempts are rate limited, and sign-in links are single-use and short-lived.
  • Case File documents are stored privately and served only through a route that has already resolved who you are.
  • Security-relevant events are logged so an unexpected access can be investigated.

What this document does not cover yet

This page was written from how the product actually behaves, and it has not been reviewed by a lawyer. Everything above is a commitment we hold ourselves to. The points below are genuinely unsettled, and saying so is more useful to you than inventing a clause:

  • Who the data controller is, legally. The operating entity and its address are not stated here yet, and nor is an EU or UK representative.
  • The lawful basis for each kind of processing, in the words the GDPR expects, has not been mapped out — and neither has the equivalent for other regimes.
  • International transfers. The database is in Frankfurt, but some of the providers in section 4 process data outside the EU. The transfer mechanism for each has not been documented.
  • Exact retention periods. The 60-day read-only window is real and enforced. How long backups and security logs are kept is not yet written down.
  • One known gap we are fixing. Some video frames extracted during an examination are currently served from an address that does not check your session. They are not linked or listed anywhere, but that is not the same as private, and they are being moved behind the same authorisation as the rest of your chart.

If any of it matters to your decision, ask before you sign up: hello@nerdydoctor.com. You will get a straight answer or an honest “not decided yet”.