NOISEYPrivacy
DocsOpen the app

Privacy policy

Last updated 24 August 2026

The short version: we collect what the product needs to run, nothing is sold or shared for advertising, your phones’ screens and messages never touch our servers, and media deletes itself on a clock you can see.

The full version is below. The “in plain words” cards are honest summaries for orientation; the full text is what governs.

1Who we are2What this policy covers3What we collect4What we deliberately do not collect5Why we use it, and the legal bases6Cookies7Where your data lives8How long we keep things9Who we share it with10People in your profiles11Your rights12How we protect it13Children14Changes to this policy15Contact

1. Who we are

In plain words

NOISEY is a small independent project. Anything in this policy, ask us directly: support@noisey.app.

NOISEY (“NOISEY”, “we”, “us”) is the trading name of the operator of noisey.ai, my.noisey.app and the NOISEY desktop application. We are the data controller for the personal data described in this policy.

For anything about your data — questions, requests, complaints — contact support@noisey.app.

2. What this policy covers

This policy covers personal data processed when you use:

  • the marketing site at noisey.ai, including these docs and legal pages;
  • the web app at my.noisey.app;
  • the NOISEY desktop app on your computer;
  • the NOISEY Android companion app, if you install it on a phone;
  • our API, which the apps above talk to.

It does not cover the platforms you automate (TikTok, Instagram and the rest) or the services you connect through webhooks. Those have their own privacy policies, and what your automations post to them is governed by theirs, not ours.

3. What we collect

In plain words

Your account details, the media you upload, the automations you write, basic facts about your phones, and payment status. Nothing exotic, and nothing scraped from anywhere.

Everything below is something you give us or something the product needs to run:

CategoryWhat it is
AccountYour name, email address and a password. Passwords are hashed before storage — we cannot read them. If you sign in with Google, we receive your Google account’s name, email and profile picture instead of a password.
SessionsWhen you sign in we record the session, the IP address and the browser it came from, so you can see and revoke your sessions in Settings and so we can spot suspicious sign-ins.
MediaThe files you upload or send through your webhook, plus their names, sizes and the folder you put them in. Retention is set by your plan — see section 8.
NotificationsIf you install the Android companion and grant it access: the title and text of notifications from the six social apps listed in section 4, the phone that saw them, and when. Never from any other app. Bodies are deleted after 72 hours.
AI key (optional)Only if you store one for flows: the provider, the model, and the key itself encrypted. We never display it back to you or anyone else.
CommunityThe threads and replies you post, your likes, and any reports you file. Posts and likes are visible to other signed-in users, shown under your display name and avatar — never your email. Reports are visible only to staff, together with who filed them.
AutomationsThe automations, routines and schedules you author, and a record of each run (what posted, where, when, and whether it worked). Failed runs may include a screenshot of the phone’s screen at the moment of failure, taken so you can see what went wrong.
Phones & computersFor each phone you register: its model, serial number, the name you give it, and whether it is online. For each computer running the desktop app: an installation ID and the app version.
ProfilesThe account profiles you create: a name, platform handles, your notes, an optional written brief, and an optional avatar image. See section 10 — these often describe other people.
BillingYour subscription status and history. Payments are processed by Stripe; card numbers go to Stripe directly and never touch our servers.
Affiliate programmeIf you arrive through a referral link we record the click with a random visitor ID, a hashed IP address, the browser user-agent and the landing page. If you become an affiliate we hold your Stripe Connect account reference and payout records.
Bug reportsWhat you write in the report, an optional contact email, the app version, platform, OS version and how many phones were connected.
SupportEmails you send to support@noisey.app.
Server logsStandard request logs (IP address, endpoint, timestamp), kept briefly for security and debugging.

4. What we deliberately do not collect

In plain words

Your phones’ screens, messages and notifications are yours. The parts of NOISEY that touch them run on your machine, not on our servers.

  • Screen mirroring never reaches us. Mirroring is your computer talking to your phone over a cable on your desk. Video frames are not sent to, stored on, or visible to our servers.
  • No messages, and no notifications outside six social apps. The Android companion reads notifications from LinkedIn, TikTok, Instagram, X, Facebook and YouTube — and nothing else. That list is compiled into the app: it cannot be widened by a setting, by us, or by anyone else, only by a new version you choose to install.

    Messaging and SMS, your dialer, mail, banking and payment apps, wallets, authenticators and password managers are excluded outright, and that exclusion is checked first — before the allowed list — so a mistake in one cannot open the other. Anything shaped like a verification code is discarded on the phone before it is written down, counted or sent anywhere. The companion cannot reply to, tap or dismiss a notification; it only reads.
  • No AI keys, unless you ask us to hold one. AI in the desktop app runs with credentials kept on your own machine and never sent to us. Flows are the exception, and only if you choose: a flow runs on our servers so it works while your Mac is asleep, which is out of reach of a key on that Mac. You may store one with us for that purpose — it is encrypted, never shown again to anyone including you, and deleting it takes one click in Settings. If you do not, flows that ask a model simply stop at that step.
  • Claw sends the screen to the AI you chose, while it is running. Asking Claw to do something on a phone means the model has to see that phone. During a run — and only during a run you started — the screen goes to whichever provider you configured: OpenRouter using your own key, or Anthropic using your own Claude subscription. It goes to them, not to us; it is not stored on our servers.

    That means the readable contents of the screen at that moment, including a picture of it. If the phone is showing a conversation, the model sees the conversation. This is the same exchange any assistant needs in order to act on your behalf, but it is worth knowing before you point Claw at an app holding something private. Nothing is sent when Claw is not running, and a routine that was already learned replays without asking a model at all.
  • Google Analytics on the website, our own analytics in the app. noisey.ai loads Google Analytics 4. It sets cookies and sends Google your page views, the link that referred you, your approximate location and your device — and, because Google’s enhanced measurement is switched on, also how far down a page you scroll, which outbound links you click, and the files you download. All of it happens when you arrive, without asking you first. There is no advertising pixel and no fingerprinting.

    The signed-in app at my.noisey.app carries no Google tag. It is measured instead by WOW WEE, which is our own product running on our own servers in Europe — so that data goes to us, not to a third party. It records the pages you open and nine named actions: linking a phone, creating an automation, routine, flow, profile or schedule, connecting a source, minting a webhook token, and installing something from the store. Those are tied to your account, your name and your email address. It sets no cookie; it keeps one identifier in your browser’s session storage, which your browser discards when you close the tab.

    What it does not record is content. Not what your automations or flows actually do, not what you wrote in a profile or a brief, not your media, not the token itself, and never the screen of a phone — only that the action happened, and when. The “analytics” on your dashboard are a different thing entirely: your own automation results, shown to you.
  • No data brokers, no scraping. We do not buy, enrich or scrape data about you or anyone else.

5. Why we use it, and the legal bases

Under data protection law — the UK and EU GDPR set the standard we hold ourselves to — each use needs a legal basis. Ours:

  • Running the service you signed up for (contract): accounts, sessions, media storage and delivery, executing your automations, showing your activity, naming your phones, billing.
  • Keeping the service safe (legitimate interests): session IP records, server logs, rate limiting, investigating abuse and fraud, enforcing plan limits.
  • Support and product quality (legitimate interests): answering your emails, reading the bug reports you send, fixing what they describe.
  • Paying affiliates fairly (legitimate interests and contract): referral attribution, commission and payout records.
  • Legal obligations: tax and accounting records for payments and payouts.

We do not send marketing email. If that ever changes it will be opt-in, with consent as its basis, and every message will unsubscribe in one click.

We do not make automated decisions with legal or similarly significant effects about you.

What is required and what is optional: a name, email and password (or Google sign-in) are needed to have an account at all — without them we cannot provide the service. Everything else — media, profiles, phone names, a bug report’s contact address — is provided if and when you choose to use the feature it belongs to.

6. Cookies

In plain words

One cookie to keep you signed in, and two more only if you arrive through an affiliate link. The website also runs Google Analytics, which sets two of its own. There is no cookie banner: those load when you arrive rather than waiting for you to agree.

  • Session cookie (my.noisey.app) — keeps you signed in. Strictly necessary; the app cannot work without it.
  • noisey_ref — set only when you land on a link containing a referral code. Holds the code for 60 days so the affiliate who sent you is credited if you sign up.
  • noisey_vid — set in the same moment: a random identifier (not derived from anything about you) that lets a click and a later signup be matched. Kept for 12 months.
  • _ga and _ga_<id> (noisey.ai) — Google Analytics. They tell one browser from another, so that ten visits from you are not counted as ten people. Set the moment you arrive on the website, and kept for up to 2 years.

That is the complete list, and all of them are first-party. The session and affiliate cookies do nothing beyond the jobs described above, and no third party can read them. The two Google Analytics cookies are the exception worth naming plainly: they are first-party as well, but what they measure is sent to Google, who process it for us as described under “Who we share it with”. None of these are used for advertising or profiling. The desktop app stores preferences (like your theme) on your own machine.

7. Where your data lives

Our servers and database run on Amazon Web Services infrastructure in Europe. Your media is stored there too.

Some providers we rely on process data in the United States — chiefly Stripe (payments) and Google (sign-in, and analytics on the website). Those transfers are protected by recognised safeguards: the EU–US Data Privacy Framework and its UK extension where the provider is certified under them, and otherwise standard contractual clauses. You can ask us for a copy of the safeguard that applies.

8. How long we keep things

In plain words

Media expires on a clock set by your plan — 24 hours free, 90 days paid. Most everything else lives as long as your account does.

DataKept for
Media24 hours from upload on the free plan, 90 days on the paid plan, then deleted automatically. Deleting a file or folder yourself deletes it immediately.
Account, automations, phones, profilesUntil you delete them or your account.
Notification contents72 hours, then deleted automatically. This one is short on purpose: it is the contents of your notifications, and there is no reason for us to keep it once the flows that react to it have run.
Community posts & reportsUntil you delete them. Content removed by moderation, and the reports about it, are kept internally as the moderation record — the terms’ community section explains why.
Activity recordsPer your plan’s history window, then pruned.
SessionsUntil they expire or you revoke them in Settings.
Billing, commissions, payoutsSix years, as tax and accounting rules require.
Bug reportsKept as service records. If you delete your account, the report stays but its link to you is removed.
Referral clicksThe attribution window plus bookkeeping — hashed IPs, never raw.
Server logsA short rolling window, then overwritten.

To delete your account entirely, email support@noisey.app from your account address. We remove the account and everything hanging off it — media, automations, phones, profiles — except records we are legally required to keep (billing) and the anonymised service records above.

9. Who we share it with

In plain words

Infrastructure providers under contract, and nobody else. We do not sell data — there is no version of this product where you are the product.

We share personal data only with processors who help us run NOISEY:

  • Amazon Web Services — hosting and storage (Europe).
  • Stripe — payments, subscriptions and affiliate payouts.
  • Google — sign-in with Google, if you choose it, and Google Analytics on the website.

Each processes data only on our instructions and under its own data processing terms. Beyond that, we disclose personal data only if the law genuinely requires it, or as part of a sale or restructuring of the business — in which case this policy continues to apply to it.

We never sell personal data, and never share it for advertising.

10. People in your profiles

In plain words

If you manage accounts for clients, the briefs and handles you save describe real people. Have their permission — that data is your responsibility as well as ours.

Profiles can carry a name, handles, notes and a brief about the person who holds a social account — often your client rather than you. When you save that, you are giving us someone else’s personal data, and you must have the right to: their permission, or a contract with them that covers it.

We use profile data for exactly one thing — running the automations you point at it — and never for our own purposes. If an account holder contacts us directly about data in your profiles, we will refer the request to you where lawful, and honour their legal rights where we must.

11. Your rights

Under data protection law (including the UK and EU GDPR) you can ask us to:

  • tell you what personal data we hold about you, and give you a copy (access);
  • correct it (rectification);
  • delete it (erasure);
  • limit what we do with it (restriction);
  • hand it over in a portable format (portability);
  • stop processing based on legitimate interests (objection).

Email support@noisey.app from your account address and we will act on it within a month, free of charge. Much of it you can do yourself, faster, in Settings — name, email, password, avatar and sessions are all self-serve.

If you think we have handled your data badly, you can complain to the data protection authority where you live — in the UK that is the Information Commissioner’s Office at ico.org.uk — though we would rather you told us first, and we take it seriously when you do.

12. How we protect it

  • Everything travels over HTTPS.
  • Passwords are hashed with a modern algorithm; webhook tokens are stored hashed, with the copyable value encrypted at rest.
  • Access to production systems is limited to the people who run NOISEY.
  • Plan limits, roles and every admin action are re-checked on the server, never trusted from the browser.

No internet service can promise perfect security, and we do not. If a breach ever puts your data at risk, we will tell you and the relevant authorities as the law requires — directly and without spin.

13. Children

NOISEY is for adults. You must be at least 18 to hold an account, and we do not knowingly process children’s data. If you believe a child has an account, tell us and we will remove it.

14. Changes to this policy

When the product changes what it collects, this page changes with it, and the date at the top moves. For material changes we will tell you — by email or in the app — before they take effect. The current version always lives at noisey.ai/privacy.

15. Contact

support@noisey.app — for privacy requests, use the email address your account is registered to, so we can verify it is you without asking for more data than we hold.

Read alongside the terms of service. Questions — support@noisey.app.

What’s new, when it ships

One email when something worth knowing lands — new features, new platforms. No noise.

NOISEY

AI agents for real phones. Automate anything.

support@noisey.app

Sitemap

  • Home
  • Blog
  • Docs
  • Terms of service
  • Privacy policy

Product

  • Download for Mac
  • Open the app
  • Community

Account

  • Sign in
  • Create account
© 2026 NOISEYNot affiliated with TikTok, Instagram or any other platform.