Legal
Privacy Policy
Nouly is a news bot that runs inside Telegram. This policy explains what information Nouly uses, why, who else sees it, how long it stays, and the choices you have. It is written to match what the software actually does, and we update it when the software changes. Nouly collects little — there is no account to create beyond your Telegram one, no email, no password — but it does process your messages and your reading, and you should know how.
Words like “we” and “us” mean the operator of Nouly (see Who runs Nouly). Words like “the app” mean the Nouly app that opens inside Telegram.
What Nouly uses
- Your Telegram user ID, @username and language. A numeric ID so we know which chat to send your digest to, your @username so a person can recognise you if you write in for support, and your language so we know which language to write in. We do not store your real name. Telegram sends your first and last name with every message; we discard them after replying.
- Your feed preferences. The country, topics and keywords you choose, so we can tailor your daily stories. Topics are subjects you tap from a list; keywords are phrases you type yourself, and we keep both what you typed and the cleaned-up form Nouly matches stories against. You set these in the app; where the chat still offers them, they are the same settings, stored once.
- Messages you send the bot. The text you type — a keyword, a country name, a question about a story, a request to draft a post, a support message — is processed to respond to you. Questions and answers with the assistant are also kept for a while as the assistant’s memory of your conversation, so it can follow on.
- Basic usage signals. Which stories you open, which buttons you tap, the digest you received and how you rate it, stored as simple events so we can understand what works.
- Stories you like. When you tap the heart on a story — in the chat or in the app, they are the same heart — we record which story and when, so we can show it back to you in your liked list. Tapping the heart again removes that record straight away.
- Which stories you have read. When you open a story we record that you opened it, and when. It is what puts the tick beside a headline you have already read wherever you pick Nouly up. Nobody but you sees it.
- Delivery time. Your digest is sent at 05:00 in the time zone of the country you chose, worked out from that choice alone. We never ask for or receive your location or your device’s time zone.
- How you found Nouly. If you arrived through an invite link, a campaign link or a referral, we keep the campaign name, the referring user’s ID, which story was shared with you if it was a story link, and — if you came through an advertisement — the advertising network’s click identifier (see Advertising attribution).
- The waiting list. When sign-ups are paused, finishing setup puts you on a waiting list. The record is the same as an account — the preferences above and the date you joined — so we can open the door in order and start you with the feed you asked for.
- Purchase records. If you buy Nouly Premium, we keep a record of the transaction — Telegram’s payment identifier, the amount in Stars, what it bought, when it happened, and whether it was refunded — so we can grant what you paid for, honour refunds, and keep our accounts. Refund requests you send, and our answer, are kept with them. We never see or store card or payment details; Telegram handles the payment itself.
- Codes and gifts. If you redeem a discount code or a gift link, or send one, we record who issued it and who used it, so a code cannot be used more times than intended.
Who can see your messages
If you send feedback, answer a survey, or open a support or payment ticket, that message is forwarded as you wrote it, with your @username (or, if you have none, your user ID) and a ticket number, to our internal Telegram support group, so a person can read and reply. Please don’t include anything you would not want a human to read. Our replies go back to you through the bot. Nouly also posts a short note in that group when someone new starts the bot; it carries your @username and ID, not your name.
Artificial intelligence
Nouly’s stories are written by AI, and so are its translations, its answers, and the posts it drafts. That means some of what you send is processed by AI providers on our behalf: what you type to the assistant (with its memory of your recent conversation and the story you are asking about), the keywords and country names you type so they can be understood and cleaned up, and a story when you ask for a post to be drafted from it. We send the text and the story; we do not send your name, your Telegram ID, your @username or anything that identifies you to those providers. They process it to return a reply and, under their published API terms, do not use it to train their models.
Each AI call costs us money, so Nouly counts how many you make and enforces the limits shown in the app. Those counters are part of the usage signals above.
The Nouly app inside Telegram
When the app opens, Telegram sends it a signed introduction so we can be sure the request really came from you: it contains your Telegram user ID and the profile basics Telegram attaches to it — your first and last name, your @username, your language, and your profile photo link. We read the ID and store only that; the rest is discarded, exactly as with a message you send in the chat. To make the app work inside Telegram it loads Telegram’s own web-app script from telegram.org, which is subject to Telegram’s privacy policy.
Setting up in the app writes the same country, topics and keywords as setting up in the chat, and liking a story there writes the same record — one account, whichever way you use it. The posts the app drafts for you are kept on our servers with the story they were written from, so they are still there when you come back, and go when the story goes. If you have never messaged Nouly before, finishing setup in the app creates your account.
The app is served from the same servers as the rest of Nouly, in the European Union, at nouly.app. Cloudflare sits in front of that host as a content delivery network and DDoS shield: it sees the request (your IP address, the page you asked for, and — when the app is open — the signed introduction Telegram sends) and forwards it to us. Local testing may instead use a tunnelling provider, which likewise passes traffic between your phone and us.
The app also keeps a small amount of information on your own device, in your browser’s local storage, so it can pick up where you left off: which stories you have opened and liked, which day you last finished, the sort order you chose, whether you prefer a light or dark appearance, and a copy of your topics and keywords for the first paint. This never leaves your device — we cannot read it, and it is not sent to us or anyone else. It stays until you clear Telegram’s or your browser’s storage for the app, and clearing it costs you nothing but the read marks. It is not used to track you, and there are no advertising or analytics cookies anywhere in the app or on this website.
Sharing a story
When you share a story from Nouly — to Telegram, X, WhatsApp or anywhere else — the link carries a short random code that stands for your account, never your Telegram ID or name. The link opens a small public page at nouly.app showing the story’s headline, one line of summary, its sources and a button into Nouly; the full story stays inside Telegram. If someone opens that page, we record that the page was viewed, which story it was, and that the code was yours; if they then set up Nouly, we record that they came through your link. We use this to see which stories travel and to credit you for the readers you bring. The person who opened your link is not identified to you or to us: the page sets no cookies and the view record holds the story, the time and your code, nothing about them. Like every event on your account it is mirrored to our product analytics (see Who else processes your data) and kept until you delete your account; a link whose code matches no account records nothing. We also record which share you used and which story, as an event on your account, like any other tap. That value says only whether the link went to your phone’s own share menu, to Telegram, or to your clipboard — when you share through your phone’s menu, it does not tell us which app you then chose, and we do not try to find out. The page is shown in the language you use Nouly in, so someone opening your link can tell which that is.
For the person opening the link: the request passes through Cloudflare and our servers like any visit to nouly.app (see The Nouly app inside Telegram for what they see, and How long it’s kept for server logs), and nothing else is stored about you unless you go on to set up Nouly.
Advertising attribution
We may from time to time pay an advertising network to show Nouly to new people. If you started Nouly from one of those advertisements, the link carries a click identifier chosen by the network. We store it with your account, and we send it back to the network twice — once when you finish setting up, and once when you are still with us on the second day — as a signal that the advertisement led to a real user. The signal carries the click identifier only: no name, no Telegram ID, no messages, no preferences. Its purpose is to tell the network which advertisements were worth paying for; it is not used to build a profile of you, and Nouly itself shows no advertisements. Our legal basis is our legitimate interest in knowing whether our advertising works. Which network, if any, we are using changes with our campaigns; a network may process the signal outside the EU (see Where your data goes). If you did not arrive through an advertisement, none of this applies to you.
What Nouly does not collect
No real name, no email address, no phone number, no precise location, no contacts, no device identifiers, no advertising profile, and no tracking of you across other websites or apps beyond the single click identifier described above. Nouly shows no ads and does not sell your data to anyone.
How your information is used
- To send your daily digest and the stories you ask for, in your language, at a sensible hour.
- To answer your questions, follow your keywords, and draft posts when you ask.
- To reply when you write in for support, and to handle payments, codes and refunds.
- To remind you when a digest is waiting, if you have not opened one in a while (reminders stop the moment you come back).
- To enforce usage limits, detect abuse, and keep the service running and secure.
- To understand, in aggregate, which features people use, so we can improve Nouly.
- To know whether our advertising brings real users, as described above.
- To meet legal obligations, such as keeping records of purchases.
If you are in the EU, EEA or UK: our legal bases are the performance of our agreement with you (delivering the service you asked for and any purchase you make), our legitimate interests (understanding use, improving the product, preventing abuse, measuring advertising, keeping the service secure), and legal obligation (accounting records). We do not make decisions about you with legal or similarly significant effects by automated means; choosing which stories to show you is not one.
Who else processes your data
We use a small number of service providers, each bound by a contract to process data only on our instructions. We do not sell data and we do not share it for anyone else’s advertising.
- Telegram carries every message between you and Nouly, delivers the app, and processes Premium payments. Telegram’s own privacy policy governs what Telegram does.
- Hosting — Hetzner (Germany) runs the bot and this website; Supabase (Ireland) hosts the database. Both in the EU.
- Cloudflare sits in front of nouly.app and sees requests to it, as described above.
- AI providers — Groq and OpenRouter, which route requests to models from several vendors — receive the text described under Artificial intelligence. A chart Nouly attaches to a story may be rendered by QuickChart from the story’s figures; nothing about you is sent with it.
- Product analytics — PostHog, hosted in the EU. Nouly sends it events such as “opened a story” or “changed country”, tagged with your Telegram ID, your language, your country, whether you are Premium, and the feature involved. It never receives what you typed, a story’s text, or any code you redeemed. We use it to see how Nouly is used in aggregate; it does not track you elsewhere.
- Uptime monitoring — Healthchecks.io receives a periodic “still alive” ping from our servers that carries nothing about any user.
- Advertising attribution — the advertising network whose link you arrived through, if any, as described above.
Beyond those providers, we share personal data only if the law requires it — a valid request from an authority, or to establish or defend a legal claim — or, if Nouly is ever transferred to a company or a successor, to that successor under this same policy. We would tell you about such a transfer.
Where your data goes
Nouly’s servers and database are in the European Union, and so is our analytics provider. Some providers are in, or route through, the United States: the AI providers (Groq, OpenRouter and the model vendors behind it), QuickChart, Cloudflare’s global network, and the advertising network. Telegram operates worldwide. Where personal data leaves the EEA, we rely on the European Commission’s Standard Contractual Clauses in our contracts with those providers, and on the EU–US Data Privacy Framework where a provider is certified under it. As explained above, what reaches the AI providers is the text of a request without your identity attached.
How long it’s kept
- Stories live for 14 days, then are deleted along with every read mark, like and drafted post attached to them. A liked story stays in your liked list for up to 30 days if it is still there.
- What you typed and the assistant’s memory — the text of events such as keywords you searched, questions you asked and the assistant’s replies — is cleared after 60 days. The bare event (“asked a question”, with its date) stays, without the text, for aggregate use.
- Weekly digests and your reading history are kept for 8 weeks while your feed is active; a paused feed keeps its last digests so you can pick up where you left off.
- Support, payment and refund messages, survey answers and suggestions are kept for as long as your account exists, because they are the history a person needs to help you next time and, for payments, part of the accounting record. They are deleted with your account, except purchase records (below). The copy forwarded to our support group stays there as long as that group’s history does.
- Your account and preferences — ID, @username, language, country, topics, keywords, settings, your share code, how you found us — are kept until you ask us to delete them (see Your choices). Blocking the bot stops all messages but does not by itself delete the record, because people often come back.
- Purchase records are kept for as long as tax and accounting law requires — in Italy, ten years — even after you delete your account. They hold the payment identifier, the amount, the product and the dates; nothing you wrote.
- Server logs are kept for 30 days on our own servers, then deleted. They record what the bot did, and can include a message you sent while it was being handled; they exist for debugging and security and nobody reads them routinely.
- Backups of the database are kept by our database host for a short rolling window and expire on their own; a deleted account may persist in a backup for a short time after deletion.
Your choices
- Change what you get. Country, topics, keywords, language, delivery and pausing are all under Settings in the app or the chat. Change them any time.
- Stop messages. Block or delete the chat in Telegram. Everything stops, including reminders.
- Delete your data. Ask by messaging the bot (send
/helpand write “delete my data”) or by emailing [email protected] from any address, quoting your @username or Telegram ID. We delete your account and everything attached to it within a month and tell you in the chat when it is done. What remains: purchase records (accounting law), the copies of support messages in our internal group, and server logs until they rotate out — all described above. - See your data. Ask the same way and we will send you what we hold about you.
- Correct, restrict, object, port. If you are in the EU, EEA or UK you can also ask us to correct data, to restrict or object to processing based on our legitimate interests (including advertising attribution), and to receive the data you gave us in a portable form. Ask the same way. You may also complain to your data protection authority — in Italy, the Garante per la protezione dei dati personali, or the authority of the country where you live.
Some of these rights depend on where you live; we honour them for everyone where we reasonably can. We may ask you to confirm the request from the Telegram account it concerns, so that nobody can delete or read your data by claiming to be you.
Children
Nouly is not for children. You must be at least 16 to use it (or the age your country sets for consenting to services like this online), and we do not knowingly collect data from anyone younger. We cannot verify age; if you believe a child is using Nouly, tell us and we will delete the account.
Security
Traffic between Telegram, you and Nouly is encrypted in transit; the database is encrypted at rest by its host; access to servers and data is limited to the people who run Nouly; and our logs mask secrets before they are written. No system is perfectly secure, and we cannot promise that yours will never be affected — if a breach touches your data, we will tell you, and the authorities where the law requires it, as soon as we can.
Changes to this policy
When the software changes what it does with your data, this policy changes with it. The date at the top is the date of the current version. For a change that matters to you — new data, a new purpose, a new kind of recipient — we tell you in the app or the chat before it takes effect. Continuing to use Nouly after that means you have read it.
Who runs Nouly
Nouly is an independent project whose operator is established in Italy and is the data controller for everything described here. They will identify themselves on request through the contact routes below, and this section will name them once Nouly operates as a legal entity. Nouly is not affiliated with Telegram.
Contact
Questions or requests about your data? Email [email protected], or message us on Telegram through the bot.
See also our Terms of Service.
← Back to Nouly