Privacy Policy
Last updated: August 2026. What we collect, why, and the rights you keep.
01What we collect
- Account data — email address, display name, country, and authentication identifiers.
- Search inputs — the countries, skills, interests, and capital constraints you provide to power discovery.
- Usage and wallet data — ACU purchases, consumption ledger, generated-asset history, and device/browser telemetry.
- Payment data — processed by our payment providers, Stripe (card) and KODA (mobile money). We never store full card numbers. For mobile-money payments we may receive a mobile-money identifier such as your phone number and operator (e.g. Orange Money, M-Pesa) to confirm the payment.
- Referral data — if you join the Growth Partner programme, your invite code and the referrals and commission attributed to it.
02How we use it
To operate the platform (running searches, generating documents, maintaining your wallet and repository), to improve scoring quality, to prevent fraud and welcome-credit abuse, to meet legal obligations, and — with your consent — to send product updates. Search inputs are sent to our AI providers solely to generate your results and are not used by us to build advertising profiles.
03Where your data lives
Your account, ACU wallet balance and consumption ledger, and generated documents are stored on our servers, tied to your account, so they persist across sessions and devices. Sensitive stores (wallet and account data) are encrypted at rest. Some working state — drafts, interface preferences, and cached copies of your documents — is also kept locally in your browser for speed; clearing your browser data removes only those local copies, not your account. Deleting your account removes your profile and wallet from our systems.
04Sharing
We share data only with processors that run the service (cloud hosting, AI model providers, payment processors, analytics), under contracts limiting use to our instructions. We do not sell personal data. We may disclose data where the law requires it.
05Retention and security
Account and ledger data are retained while your account is active and for the period required by tax and accounting law. Generated assets are retained until you delete them. The platform is end-to-end encrypted: data is encrypted in transit (TLS 1.3) and at rest (AES-256), generated venture documents are encrypted with per-user keys, and access to production systems is role-restricted and logged.
Human-only access. Registration and sign-in are restricted to human users. Automated agents, bots, and scripted clients are blocked at signup and login by layered controls — CAPTCHA challenge, behavioural analysis, honeypots, and device signals — and blocked attempts are logged as security events. Legitimate machine access exists only through the keyed partner API programme, never through user accounts.
06Your rights
Depending on your jurisdiction (including UK/EU GDPR), you may request access, correction, deletion, portability, or restriction of processing, and you may object to marketing at any time. Contact privacy@nichefinderhq.com — we respond within 30 days. You may also complain to your data-protection authority (in the UK, the ICO).