Nenbase Privacy Policy

Version 1.4 · Effective September 26, 2026.

Nenbase is operated by Info Ops LLC, a California limited liability company, 3217 E Carson St PMB 1011, Lakewood, CA 90712, United States. Privacy questions and requests: support@nenbase.ai.

This policy explains what personal information we collect through the Nenbase application (nenbase.ai) and our website, how we use and share it, how long we keep it, and the choices and rights you have. It also explains our role when our customers use Nenbase to manage information about their contacts.

1. Two roles: our customers’ data, and our own

Nenbase is a business platform. Most of the personal information inside it belongs to our customers’ businesses — their leads, clients, contacts, call recordings and messages. Our role differs depending on whose data it is:

  • Information about you as a Nenbase user or customer (your account, your login, billing, support conversations, security logs, our emails to you). For this we decide how and why the data is used, so we are the “controller” (or “business” under California law).

  • Information our customers put into Nenbase — “Customer Data” — such as their contacts’ names, phone numbers, form answers, bookings, recordings and messages. For this the customer decides what to collect and why; we process it on their instructions as their service provider (“processor”). The customer’s own privacy notice governs that data. If you are a contact of one of our customers and want to access, correct or delete information they hold about you, contact that business; if you contact us instead, we will pass your request to them and help them respond, rather than act on it ourselves.

The sections below cover both roles and say which applies.

2. What we collect

Account and profile. Name, email address, password (stored as a hash — we never see it), two-factor authentication settings, role, which accounts you belong to, language and display preferences, and profile photo if you add one.

Billing. Subscriptions are paid through Whop and wallet top-ups through Stripe. They handle your card and send us the details we need to run your account: what was bought, when, for how much, the payment status, the last four digits and card brand if the provider shares them, and the email used at checkout. We do not receive or store full card numbers or bank credentials.

Customer Data (processed for our customers). Contact and lead records (name, email, phone, company, tags, notes, pipeline stage); answers to forms and applications; booking details; sales-call records; call recordings and transcripts; text messages and emails sent and received through the account; payment and revenue records the customer connects or enters; content the customer creates (forms, funnels, automations, dashboards); and data imported from third-party services the customer connects (see Section 6). Attribution data — UTM parameters, page visits and form-session events — that shows a customer where a lead came from.

Communication permissions. When customers collect permissions using Nenbase, we process the recipient address and channel, consent or withdrawal status, exact wording shown, form and policy version, source, timestamps, and the country the recipient provides. These records help the customer demonstrate permission and respect communication preferences. Platform Terms acceptance and permission to receive a coach’s messages are separate records.

Technical and security data. IP address, browser and device type, timestamps, pages and features used, error reports, authentication events (sign-ins, password resets, two-factor challenges, invitations accepted), and records of important actions in an account (for example who changed a setting, who accepted our Terms and when).

Support. What you send us when you contact support, including attachments.

Applying or booking a call with us. When you fill in our application form or book a call with our team, we collect what you enter — your name, email address, mobile number, Instagram handle if you give it, and your answers — along with the details of the call you book and technical details of your visit (such as your IP address, browser and the steps you completed). We save your answers as you go, so what you enter is kept even if you do not finish. The booking itself is made through Calendly, embedded in the form. We use this information to review your application, arrange and hold the call, and follow up with you about it.

Texts from Nenbase. If you agree to receive texts from Nenbase itself (see Section 5), we keep your mobile number, the exact wording you agreed to, when and where you agreed (the date and time and the form you used), any later opt-out, and the texts we exchange with you.

Website. Our marketing website is hosted on Framer and uses Framer’s cookie-free, aggregate analytics; it does not set tracking cookies or use advertising pixels. Its “Book a call” buttons lead to our own application form, described above.

We do not knowingly collect information from anyone under 18; Nenbase is for adults using it for a business.

3. How we use information

As controller (your account, billing, support):

  • To create and run your account, authenticate you, and keep the account secure — to perform our contract with you.

  • To take payments, send receipts and renewal reminders, and handle billing questions — contract and legal obligations.

  • To send service emails: sign-in and password emails, invitations, billing notices, alerts about your account, changes to our terms — contract and legitimate interest in running the service. These are not marketing and you cannot opt out of them while you have an account. Text messages are separate: you can stop them at any time by replying STOP.

  • To answer support requests — contract.

  • To detect and prevent abuse, fraud and security incidents, and to troubleshoot — legitimate interest and legal obligations.

  • To send occasional product news to account administrators — legitimate interest / consent where required. Every such email has an unsubscribe link.

  • To review applications, arrange the calls people book with us, and follow up with them about those calls — steps taken at your request before a contract, and our legitimate interest in running our sales process.

  • To send the texts you have agreed to receive from Nenbase — about your account, calls you’ve booked with us and anything you’ve asked us to send you — and to act on STOP and HELP replies — consent.

  • To comply with law and enforce our terms — legal obligation and legitimate interest.

As processor (Customer Data): only to provide the features the customer uses — storing records, running forms and bookings, placing and recording calls, sending messages and emails, running automations, syncing connected services, producing transcripts and summaries, and showing the customer its own reports — and as otherwise instructed by the customer or required by law. We do not use Customer Data for our own purposes, do not sell it, do not use it for advertising, and do not use it to train general-purpose AI models.

We may produce statistics about how Nenbase is used (for example how many forms are submitted platform-wide) in a form that does not identify any customer or person, to operate and improve the product.

4. Calls, recordings and AI features

Calls and messages placed through Nenbase are carried by Twilio (voice, SMS and phone numbers) and, for iMessage/SMS where a customer has enabled it, Sendblue. Call metadata (numbers, times, duration, outcome) is stored in the customer’s account.

Recording. Calls made through the Nenbase dialer are recorded by default. Our customer chooses the recording notice played on its calls and is responsible for giving the notice and obtaining the consent that the law requires where it and its contacts are located. Recordings are stored in our own cloud storage (Supabase, on Amazon Web Services in the United States) inside the customer’s account, and are available only to that account’s authorized users. Booked calls carry a link that lets the other participant stop the recording of that call, or ask for it to be deleted after the call; a deletion requested that way is carried out within minutes.

Transcription and analysis. When a customer uses call transcription or call analysis, the recording is sent to a speech-to-text provider (Deepgram or OpenAI) to produce the transcript, and the transcript may be sent to an AI model provider (OpenRouter, OpenAI or Anthropic) to produce a summary or analysis. Other AI features (for example generating dashboard cards, funnel copy, or the in-app assistant) send the relevant content from the customer’s account to those providers. We use these providers under terms that do not permit them to train their models on the content. AI output can be inaccurate and is meant to be reviewed by a person; we do not make automated decisions with legal or similarly significant effects about individuals.

5. Who we share information with

Service providers (subprocessors). We use the following companies to run Nenbase. They process data only to provide their service to us, under contracts that restrict what they may do with it.

Provider · What it does · Where

  • Supabase (on Amazon Web Services) — Database, file storage (including call recordings), authentication, server functions — United States

  • Vercel — Hosting and delivery of the Nenbase application — United States

  • Cloudflare — DNS, network security and content delivery — Global network, US-based

  • Sentry — Error monitoring for the application — United States

  • Whop — Subscription checkout and payments — United States

  • Stripe — Wallet top-up payments — United States

  • Twilio — Phone numbers, calling, SMS, call recording, carrier registration — United States

  • Sendblue — iMessage/SMS sending where enabled by a customer — United States

  • Resend — Sending Nenbase’s own service emails (sign-in, billing, notifications) — United States

  • Mailgun — Sending email that customers send to their contacts from Nenbase — United States

  • ZeroBounce — Checking whether an email address entered on a form is deliverable — United States

  • Deepgram, OpenAI — Speech-to-text transcription of call recordings — United States

  • OpenRouter, OpenAI, Anthropic — AI analysis, summaries and generation features — United States

  • Google Workspace — Our support and business mailboxes — United States

  • Calendly — Scheduling the calls people book with Nenbase’s own team — United States

  • Framer — Hosting of our marketing website — Netherlands, with a global content network

We update this list when we add or change a provider. Customers with a Data Processing Addendum are told of changes in advance.

Services our customers connect. When a customer connects a third-party service to its account — such as GoHighLevel, Close, Calendly, Cal.com, Google Calendar and YouTube, Meta and Instagram, TikTok, Zoom, Typeform, Tally, Webflow, ClickFunnels, WebinarJam, Kit, Airtable, Fathom, Discord, Slack, Whop, Fanbasis or Stripe — data flows between Nenbase and that service as the customer has configured. Each connection is authorized by the customer (usually through the service’s own sign-in screen), is limited to the permissions shown there, and can be disconnected at any time from the Integrations page in Nenbase or from the service’s own settings. Data received from a connected service is used only to provide the connected feature to the account that authorized it and is never shared with other accounts. These services are not our subprocessors; they act for the customer under their own terms.

People in the customer’s account. Administrators and team members of a Nenbase account can see Customer Data according to the permissions the customer gives them.

Legal and safety. We disclose information when the law requires it (for example a valid subpoena), to protect the security of the service or the rights and safety of people, or to professional advisers under confidentiality. If Nenbase is sold or merged, information may be transferred to the new owner under this policy.

We do not sell personal information and do not share it for cross-context behavioral advertising.

Mobile information and text messaging

Mobile opt-in information. No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. We do not share, sell, or provide your mobile phone number or messaging consent data to third parties or affiliates for marketing or promotional purposes. All the above categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties, excluding aggregators and providers of the text message services.

Texts from Nenbase. If you give us your mobile number and agree to receive texts from Nenbase, we use your number and your consent record only to send you the texts you agreed to — about your account, calls you’ve booked with us, and anything you’ve asked us to send you — and to keep proof that you agreed. Message frequency varies. Message and data rates may apply. Reply STOP to any of our texts to opt out, or HELP for help, or email support@nenbase.ai. Agreeing to receive texts is not a condition of any purchase. The full program terms are in Texts from Nenbase in our Terms of Service.

Communication choices. To stop texts from Nenbase itself, reply STOP to any of our texts or email support@nenbase.ai. To stop a customer’s texts, reply STOP to that sender or contact that business directly. For help, reply HELP where supported or use the sender’s published support details. Use the unsubscribe link in its marketing emails or ask that business to stop calling. Contact support@nenbase.ai for platform privacy requests.

6. Disclosures required by connected platforms

Google user data (Limited Use). Nenbase’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We use Google user data only to provide the user-facing features the customer connected; we do not transfer it except as necessary to provide those features, with consent, or for security or legal reasons; we do not use it for advertising; and we do not allow humans to read it except with permission, for security, or where the law requires. Gmail connections. When you connect Gmail, Nenbase uses your Google identity and email address to identify your mailbox, sends one-to-one emails you compose, and reads message content and headers to synchronize replies to conversations started in Nenbase. Google grants mailbox-wide read permission; Nenbase limits the messages it imports to those related conversations and does not import unrelated conversations or attachments. Stored messages become Customer Data in the selected Nenbase account, accessible to its authorized team members and through account-authorized integrations, including AI assistants where enabled. Personal Gmail connections are not used for campaigns or automated sequences. Disconnecting removes stored access credentials and stops future synchronization; an email already sending may finish. Disconnecting or deleting a contact does not erase stored email history. That history follows account retention and deletion rules; you can request deletion through the account administrator or support@nenbase.ai. You can also revoke Nenbase access in your Google Account settings. The Google Limited Use restrictions above apply to this data.

Gmail connections. When you connect Gmail, Nenbase uses your Google identity and email address to identify your mailbox, sends one-to-one emails you compose, and reads message content and headers to synchronize replies to conversations started in Nenbase. Google grants mailbox-wide read permission; Nenbase limits the messages it imports to those related conversations and does not import unrelated conversations or attachments. Stored messages become Customer Data in the selected Nenbase account, accessible to its authorized team members and through account-authorized integrations, including AI assistants where enabled. Personal Gmail connections are not used for campaigns or automated sequences. Disconnecting removes stored access credentials and stops future synchronization; an email already sending may finish. Disconnecting or deleting a contact does not erase stored email history. That history follows account retention and deletion rules; you can request deletion through the account administrator or support@nenbase.ai. You can also revoke Nenbase access in your Google Account settings. The Google Limited Use restrictions above apply to this data.

YouTube API Services. Nenbase uses YouTube API Services. When a customer connects a YouTube account we access and store the channel’s identity (channel name and ID), video metadata and analytics metrics to display that customer’s own channel performance in its account. Stored YouTube API data is refreshed or deleted at least every 30 days. By using the YouTube connection you also agree to be bound by the YouTube Terms of Service; Google’s handling of your data is described in the Google Privacy Policy. You can revoke Nenbase’s access at any time from the Google security settings page or by disconnecting the integration in Nenbase.

Meta Platforms (Instagram). When a customer connects an Instagram professional account, we receive data from Meta’s APIs in accordance with the permissions granted on Meta’s consent screen and Meta’s Platform Terms. We read the connected account’s profile, posts and stories, the insights Instagram reports about them (reach, views, saves, shares, interactions) and aggregated follower demographics, to show that account its own performance. If the account uses the Nenbase DM inbox, we read the account’s Instagram conversations to display them and send messages, reactions and images from that account when a team member chooses to. We do not store the content of messages received; we do store the text of messages sent from Nenbase with the recipient’s Instagram-scoped ID, and which conversations were opened and when. Images sent from Nenbase are stored at a publicly readable URL because Instagram’s messaging API fetches images from our servers rather than accepting an upload; anyone with the URL can open the image. You can revoke access from your Instagram or Meta account settings (Apps and Websites) or by disconnecting in Nenbase; when the app is removed, Meta notifies us and we delete the stored access tokens, the imported Instagram content and metrics, and the direct-message records described above. Deletion requests relayed to us by Meta are carried out automatically and we keep a record of each request and its outcome.

TikTok. When a customer connects a TikTok account we receive profile information and video and audience metrics in accordance with the scopes approved on TikTok’s consent screen and TikTok’s Terms of Service and Developer Guidelines, solely to display the connected account’s own metrics to the account that authorized it. We do not share it without consent and do not sell it. You can revoke access in the TikTok app under Settings → Security & permissions → Manage app permissions, or by disconnecting in Nenbase, and can request deletion as described in Section 8.

Zoom. When a customer connects a Zoom account we receive webinar data — titles and schedules, registrants (name, email and registration answers) and attendance — in accordance with the scopes shown on Zoom’s consent screen. The connection is read-only: Nenbase cannot create, change or delete anything in a Zoom account, and cannot start, join or access meetings or recordings. We use the data solely to show the connected account’s own webinar performance and to add registrants to the authorizing account’s CRM. You can disconnect from the Integrations page in Nenbase or by removing the app in Zoom under Settings → Installed Apps; on removal Zoom notifies us and we delete the stored access tokens and the imported webinar records.

7. Where data is stored and international transfers

Info Ops LLC is based in the United States, and Nenbase’s data is stored and processed in the United States by the providers listed above. If you use Nenbase from outside the United States — including the European Economic Area, the United Kingdom or Australia — your information is transferred to the United States. Where the law of your country requires safeguards for that transfer, we rely on the data-processing terms of our providers (which, for EEA and UK data, incorporate the standard contractual clauses approved for such transfers) and, for customers who need one, our Data Processing Addendum. We do not claim certification under the EU-US Data Privacy Framework. You can ask us at support@nenbase.ai for more information about the safeguards that apply.

8. How long we keep information

  • Your account while it is active: for as long as the account exists.

  • After a subscription is cancelled: the account’s data (including Customer Data, recordings and transcripts) is kept for 90 days after the cancellation takes effect so the customer can restore it, then deleted permanently. While an account is on a paid pause, its data is kept.

  • When a customer deletes an account: immediately, or after the seven-day undo period for a scheduled deletion, the account’s data is deleted permanently.

  • Individual records: customers can delete contacts, recordings and other records at any time; a recording deleted through the booked-call opt-out link is removed within minutes.

  • Billing and tax records: kept for as long as tax and accounting law requires (generally seven years) even after an account is deleted.

  • Aggregate financial totals: after an account is deleted we keep platform-wide totals of payments processed, in a form that does not identify any person or customer.

  • Security and authentication logs, error reports and support conversations: for a limited period appropriate to security, troubleshooting and dispute handling, then deleted.

  • Platform Terms acceptance records (who accepted which version of our terms, when, and from what address): kept for as long as we may need them to demonstrate the agreement, including after the account is deleted.

  • Your agreement to receive texts from Nenbase (and any later opt-out): kept for as long as we may need it to show what you agreed to and when, including after you opt out.

  • Backups: copies of deleted data can remain in encrypted backups for a limited period before they are overwritten.

  • Legal holds: we may keep information longer when a law, court order or active dispute requires it.

Lead communication-consent records are Customer Data and follow the account retention and deletion rules above; customers should retain any separate evidence they are legally required to keep.

9. Security

We protect information with measures appropriate to its sensitivity: encryption in transit (TLS) and at rest through our hosting providers; account-level isolation so that one customer cannot see another’s data; role-based permissions inside each account; optional two-factor authentication; hashed passwords; signed and verified webhooks and email hooks; restricted access to production systems; and logging of security-relevant events. No system is perfectly secure, and you are responsible for keeping your own credentials safe. If we become aware of a breach affecting your personal information, we will notify you and any authorities as the law requires.

10. Your rights and choices

Depending on where you live, you may have the right to ask for access to the personal information we hold about you, a copy of it, correction, deletion, restriction of or objection to its processing, portability, and to withdraw consent where processing is based on consent. Residents of California and other US states with privacy laws may have rights to know, access, correct and delete information, to opt out of sale, sharing and targeted advertising (we do none of these), and to appeal a decision we make about a request. Residents of the EEA and the UK may also complain to their data-protection authority; residents of Australia may complain to the Office of the Australian Information Commissioner. We have not appointed an EU or UK representative or a data protection officer.

To make a request, email support@nenbase.ai from the address on your account. We will verify your identity in proportion to the request, respond within the time the applicable law allows (and tell you if we need an extension), and explain any exception we rely on. We will not treat you differently for exercising your rights. If your request concerns information one of our customers holds about you, we will refer it to that customer and help them respond.

Marketing and texts. Use the unsubscribe link in any product email, or email us; service notices continue while you have an account. To stop texts from Nenbase, reply STOP to any of them.

11. Cookies and browser storage

The Nenbase application uses only strictly necessary cookies and browser storage: to keep you signed in, remember preferences such as language and selected account, and support two-factor authentication. It does not use advertising or cross-site tracking cookies, and there is nothing to opt out of. Our marketing website uses Framer’s cookie-free analytics. Because we do not sell or share personal information, browser “Global Privacy Control” and “Do Not Track” signals do not change how the site behaves. If we ever add optional cookies we will ask for consent first where required.

12. Changes to this policy

We will post any changes here with a new version number and effective date. For material changes we will email account administrators before the changes take effect and, where the law requires, ask for your consent. Earlier versions are available on request.

13. Contact

Info Ops LLC (Nenbase) · 3217 E Carson St PMB 1011, Lakewood, CA 90712, United States · support@nenbase.ai

Nenbase

Built for the business behind your offer.

Help

FAQ

@jonas.rorwick@JonasRorwick

Info Ops LLC · 3217 E Carson St PMB 1011, Lakewood, CA 90712, United States

© 2026 Info Ops LLC. Nenbase. All rights reserved.