Nory AI Nory ← Back to home

Privacy Policy

Last updated: July 3, 2026

This Privacy Policy explains how Nory AI ("we", "us", "our") collects, uses, and protects information when you use our review-management platform (the "Service"). By using the Service you agree to the practices described here.

1. Information we collect

  • Account information — your name, email address, password (stored hashed), and the restaurant/business details you provide.
  • Google Business Profile data — when you connect your Google account, we access your business locations and customer reviews through Google's official API, using OAuth tokens you authorize. We only request the business.manage scope needed to read reviews and post replies.
  • Review content — reviews, ratings, reviewer display names, and the AI-generated and published replies associated with your locations.
  • Billing information — subscription plan and payment status. Card details are handled entirely by our payment processor, Stripe; we never see or store full card numbers.
  • Usage data — basic technical logs (IP address, browser type, actions taken) used to operate and secure the Service.

2. How we use your information

  • To import your Google reviews, classify their sentiment, and generate on-brand reply drafts using AI.
  • To post replies to Google on your behalf when you approve them.
  • To send transactional emails (trial reminders, payment notices, review alerts, support replies).
  • To provide, maintain, secure, and improve the Service.
  • To process subscription payments through Stripe.

3. AI processing

Review text and your configured brand voice are sent to our AI provider to classify sentiment and draft replies. This data is used only to generate the response for your account and is not used to train third-party models where the provider offers an opt-out. Generated drafts are only published to Google after you review and approve them.

4. Google API disclosure

Nory AI's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We access Google user data solely to provide the review-management features you request and never sell it or use it for advertising.

5. Sharing your information

We do not sell your personal data. We share information only with service providers who help us operate the Service — namely Google (reviews), Stripe (payments), our AI provider (reply drafting), and our email delivery provider — each bound to process data only on our instructions. We may disclose data if required by law.

6. Data retention

We retain your account and review data for as long as your account is active. You may disconnect any Google location at any time, which removes its stored OAuth tokens. If you delete your account, we remove your personal data within 30 days, except where retention is required for legal or accounting purposes.

7. Security

OAuth tokens and sensitive settings are encrypted at rest. Passwords are hashed. Access to production data is restricted. No system is perfectly secure, but we take reasonable measures to protect your information.

8. Your rights

You may access, correct, export, or delete your personal data by managing your account or contacting us. Depending on your location, you may have additional rights under laws such as GDPR or CCPA.

9. Changes to this policy

We may update this policy from time to time. Material changes will be communicated by email or an in-app notice. Continued use of the Service after changes take effect constitutes acceptance.

10. Contact

Questions about this policy? Email us at hello@nory.cloud.

© 2026 Nory AI. All rights reserved.
Privacy Policy Terms of Service Contact