Privacy Policy

Product Nerve AI Operated by Product Nerve AI Limited, a company incorporated under the laws of the Federal Republic of Nigeria, with its principal business location in Lagos, Nigeria, trading as Product Nerve AI and Product Nerve ("Product Nerve", "PNAI", "we", "us", "our") Effective date: 24 August 2026 · Last updated: 24 August 2026 Contact: [privacy@productnerve.com]

1. Who we are and what this covers

Product Nerve AI is a venture intelligence platform that helps founders validate startup ideas and generate business documents. This policy explains what personal data we collect, why, who we share it with, how long we keep it, and the rights you have. It covers productnerve.com, app.productnerve.com, our mobile applications, and every service we operate under the Product Nerve AI name.

We are currently incorporated in Nigeria. We plan to incorporate a United States entity (Delaware) and, if the operating entity changes, this policy will be updated and you will be notified before the change takes effect. Your rights under this policy will not be reduced by any such change.

This platform is for adults. You must be at least 18 years old to create an account. We do not knowingly collect personal data from anyone under 18, and identity verification is required for every account, which enforces this. If we learn we hold data on a person under 18, we delete it.

2. The data we collect

Account data. First name, last name, email address, password (stored only as a secure hash by our authentication provider), and profile settings. If you sign in with Google or Apple, we receive your name and email from that provider.

Identity verification data (KYC). A government issued identity document (national ID, driver's license, or passport) and the verification result. This is collected through our verification provider and is subject to the strictest handling in our systems, described in section 6 and in our Data Handling Policy.

Business verification data (KYB). If you verify a business, its registration documents and the review outcome. Reviewed manually by our staff.

Workspace and project content. Everything you create or upload to do the work: workspace details, project names and descriptions, your answers to validation questions, files and links you add to a project knowledge base, generated reports and documents, tasks, decisions, and comments. This content can contain personal data if you put it there. You control what you upload.

Payment data. Your payments are processed by Paystack, Paddle, or RevenueCat depending on your market and platform. We never receive or store your full card number. We hold your subscription state, invoices, the identifiers those providers give us, and, for purchases handled by Paddle, Paddle acts as merchant of record for the transaction.

Usage and device data. Product analytics events (pages, features used, generation activity), device and browser type, approximate location derived from IP, and technical logs including IP address, timestamps, and error diagnostics.

Communications. Support tickets, emails you send us, newsletter subscription status.

Where GDPR or similar laws apply, our legal bases are shown in brackets.

  1. To provide the service: accounts, workspaces, projects, validation, document generation, storage, support [contract].
  2. To verify identity and prevent fraud: KYC on every account, KYB where business features require it [legal obligation and legitimate interests].
  3. To process payments, subscriptions, and refunds [contract and legal obligation].
  4. To operate AI features: your project content and validation answers are sent to our AI providers to produce your reports and documents [contract].
  5. To secure the platform: rate limiting, abuse detection, audit logging [legitimate interests and legal obligation].
  6. To improve the product: analytics on how features are used [legitimate interests, and consent where required for cookies and similar technologies].
  7. To communicate with you: transactional email always; marketing and newsletters only with your consent, withdrawable at any time [consent].
  8. To comply with law: tax, accounting, lawful requests from authorities [legal obligation].

We do not use automated decision making that produces legal or similarly significant effects on you. Validation scores are analytical outputs about a business idea, not decisions about you as a person, and no account level decision (such as suspension) is made without human involvement.

4. AI processing, stated plainly

When you run validation or use a studio tool, the relevant content you provided (answers, project knowledge base excerpts, prior documents in the same project) is sent to third party AI providers to generate the output. Our current providers are Anthropic and Google AI. Under our agreements with these providers, your content is processed to deliver the service and is not used to train their models. Your identity documents are never sent to any AI provider under any circumstances. Generated outputs are analysis, not professional advice; see the Terms of Service.

5. Who we share data with

We share personal data only with the processors and partners needed to run the service, under contracts that restrict their use of it:

| Category | Provider | What they process | |---|---|---| | Database and authentication | Supabase | Account data, workspace and project content, structured records | | File storage | Cloudflare (R2) | Uploaded files; identity documents in a separate restricted store | | Backend hosting | Render | Application processing, technical logs | | Web hosting | Vercel | Website and app delivery, technical logs | | Caching and rate limiting | Upstash | Short lived technical identifiers | | AI processing | Anthropic, Google AI | Project content and validation answers, never identity documents | | Identity verification | Didit | KYC identity documents and verification results | | Payments | Paystack, Paddle, RevenueCat | Payment and subscription data; card data is held by them, not us | | Email | Resend | Email address, message content | | Analytics | PostHog; Google Analytics and Meta (landing pages only) | Usage events, device data | | Error monitoring | Sentry | Technical error data, request context |

We also disclose data where the law requires it, to enforce our terms, or as part of a corporate transaction such as the planned incorporation, in which case this policy continues to apply. We do not sell personal data. The use of Google Analytics and Meta Pixel on our marketing pages may qualify as "sharing" for cross context behavioral advertising under California law; you can decline this entirely through the cookie banner or the "Your Privacy Choices" link, and these tags never run on the logged in application.

6. International transfers

We operate globally. Our providers process data in the United States, the European Union, and other regions. Where data moves out of a jurisdiction that restricts transfers (including the EU, UK, and Nigeria), we rely on appropriate safeguards: the European Commission's Standard Contractual Clauses or equivalent contractual mechanisms with each provider, and provider certifications where available. Details per provider are in the Data Handling Policy. [Counsel: confirm transfer mechanism inventory and whether an EU/UK Article 27 representative will be appointed at launch.]

7. Retention

We keep data only as long as needed for the purposes above. In outline: account and content data for the life of the account plus 90 days after deletion (30 day soft delete recovery, then purge from live systems, then backup cycle expiry); identity documents only for the minimum period necessary to complete verification and any required fraud or compliance review, set by counsel against applicable Nigerian anti money laundering and fraud prevention obligations, then deleted (the verification result itself, without the document, is kept longer, see the Data Handling Policy); payment records for the period tax and accounting law requires (6 years); logs on short rotation, security audit records longer. We may retain personal data beyond these periods where reasonably required to comply with legal, tax, accounting, fraud prevention, security, dispute resolution, or regulatory obligations; once a period expires, data is deleted, anonymised, or irreversibly de-identified. The full retention table lives in the Data Handling Policy.

8. Your rights

Depending on your location, you have the right to access, correct, delete, or receive a copy of your personal data, to restrict or object to certain processing, to withdraw consent at any time, and to not be discriminated against for exercising rights.

Nigeria (NDPA 2023): the rights above, plus the right to lodge a complaint with the Nigeria Data Protection Commission. EU and UK (GDPR): the rights above, plus complaint to your supervisory authority. Legal bases are listed in section 3. California (CCPA/CPRA): the rights to know, delete, correct, and opt out of sale or sharing (see section 5), exercisable via [privacy@productnerve.com] or the Your Privacy Choices link. We honor Global Privacy Control signals on the marketing pages. Canada (PIPEDA): access and correction rights, and complaint to the Office of the Privacy Commissioner of Canada.

To exercise any right, email [privacy@productnerve.com] from your account email or use the in app controls. We verify the request, respond within the period the applicable law sets (one month under GDPR and NDPA, 45 days under CCPA), and never charge for a first request unless the law permits it.

9. Security

Encryption in transit and at rest, row level access isolation between workspaces, strict separation of identity documents from all other data, signed short lived file access, role restricted staff access with audit logging, and rate limiting throughout. No system is perfectly secure; if a breach creates risk to you, we will notify you and the relevant authorities within the timelines the applicable law requires (72 hours to the supervisory authority under GDPR and NDPA where thresholds are met).

10. Cookies

Covered in full in the Cookie Policy. Essential cookies run the service; analytics and marketing tags run only with consent and only on marketing pages.

11. Changes and contact

We will post changes here and, for material changes, notify you by email or in app before they take effect. Questions, requests, or complaints: [privacy@productnerve.com]. Data protection contact: Joshua Theophilus, our Data Protection Officer / Privacy Lead, reachable at [privacy@productnerve.com]. Product Nerve is not yet classified as a Data Controller or Processor of Major Importance under the Nigeria Data Protection Act, and this role is not a statutory DPO appointment under that Act; we may appoint a dedicated or external Data Protection Officer as the company grows.