Skip to content

We do not train models on your screenplay. Not the scenes, not the treatment, not your synopses or notes, not your conversations, and not drafted text once it is part of your script. Not verbatim, not “anonymized,” not in aggregate. When AI features need outside models, we send your content only to providers whose terms, published data-use commitments, or settings on our account exclude it from model training.

1. Scope

This Privacy Policy explains how Nabu ("Nabu," "we," "us," and "our") collects, uses, discloses, and protects information when you visit nabu.page or use the Nabu application at app.nabu.page.

Nabu is in private alpha. Some product details will change, but this policy is meant to describe the commitments that matter most: your creative work is yours, and we do not use it to train models.

2. The no-training promise

We do not train models on your screenplay or creative content. This includes scenes, treatments, outlines, synopses, notes, conversations with Nisaba, accepted AI-drafted text once it is part of your script, and embeddings or other text-derived representations.

We do not use that creative content for model training, fine-tuning, shared training datasets, advertising, or resale. We send it only to model providers whose terms, published data-use commitments, or settings on our account exclude it from model training. Section 5 names each provider and the basis we rely on.

While the structure and choice signals setting is on (it is on by default), Nabu records structure and choice signals: numbers and decisions about your work, such as when you export a draft, in which format, and how many scenes it has. These signals are linked to your account, contain no screenplay or conversation text, and are used only in aggregate. You can turn them off in Settings. That setting does not cover the usage data described in Section 3, or the record of your decisions that Nabu keeps so the product works, such as which suggestions you accepted.

3. Information we collect

We collect information needed to provide, secure, bill for, and improve Nabu:

  • Account information: email address, display name, avatar, sign-in method, workspace membership, and authentication/session information.
  • Creative content: projects, scenes, characters, treatments, outlines, notes, conversations, imports, exports, and other material you choose to put in Nabu.
  • AI request context: the project excerpts, instructions, and conversation context needed to answer your request or run the feature you selected.
  • Voice input: audio you dictate in the editor, and the text made from it.
  • Working preferences: short notes about how you like to work, drawn from your conversations with Nisaba and used in your later requests across your projects. You can review them in Settings and remove individual entries. A summary made from earlier entries can keep informing responses after an entry is removed.
  • Usage, security, and diagnostics: feature interactions, AI credit usage, timestamps, logs, device/browser information, error reports, and fraud or abuse-prevention signals.
  • Structure and choice signals: the optional metadata described in Section 2.
  • Billing information: Stripe customer, subscription, invoice, and payment-event identifiers. Stripe handles card numbers, CVVs, and full payment credentials.
  • Communications: messages you send to us and transactional emails we send to you.

4. How we use information

We use information for the following purposes:

  • to provide, maintain, personalize, and improve Nabu;
  • to save, organize, analyze, edit, import, and export your projects at your direction;
  • to send AI requests to model providers when you use AI features;
  • to process payments, manage subscriptions, and enforce credit limits;
  • to detect abuse, debug failures, secure the service, and prevent fraud;
  • to send service, account, billing, security, and support communications;
  • to comply with law, enforce our terms, and protect rights, safety, and property;
  • to improve Nabu using aggregate usage data and optional structure and choice signals, not screenplay prose.

5. AI providers

When you use AI features, Nabu may send creative content and instructions to third-party AI providers so they can generate, classify, summarize, revise, or otherwise respond to your request. We send the content a feature needs. Some features, such as full-draft coverage and screenplay import, send the whole screenplay.

We currently use these providers:

  • Anthropic, OpenAI, Google (Gemini API, paid tier), Mistral (paid platform), and Moonshot (Kimi) for text features such as writing, conversations with Nisaba, and coverage. Google also computes the embeddings that power search and continuity inside your project.
  • OpenRouter, which passes some requests to other companies that host open models, currently including Z.AI and Cloudflare.
  • OpenAI and AssemblyAI for voice features, such as turning dictated audio into text. For live dictation, AssemblyAI also receives a short list of words from your project, such as character and location names, to recognize them.

For each provider, the no-training commitment rests on one of three things: the provider's API terms (Anthropic, OpenAI, and Google's paid services); settings on our account (our Mistral account, on its paid platform, has model improvement turned off; our OpenRouter account excludes hosts that may train on prompts; and our AssemblyAI account is opted out of its model training); or, for Moonshot, its published API data-security statement that API inputs and outputs are not used to train its models. Moonshot's platform terms reserve broader rights to use content unless otherwise agreed in writing.

We do not add your account email address, payment details, or sign-in credentials to requests to model providers. Personal information you write into your content, such as contact details, can be sent with that content. Some requests include your project's title and its author name, which by default is the display name on your account.

Provider terms may also allow them to process or retain requests for safety, security, abuse prevention, debugging, legal compliance, or service operation. That is different from model training. If a provider materially changes its terms, we review the provider before continuing to route creative content there.

Provider references: Anthropic, OpenAI, Google Gemini API, Mistral, Moonshot, OpenRouter, AssemblyAI.

6. Third-party services

We use third-party services to operate Nabu, including AI providers, OpenRouter, Stripe for payments, Google for sign-in, Railway for hosting, Cloudflare for DNS/CDN/security and for storing project files and backups, Resend for transactional email, Discord for internal alerts to our team (which can include the category, severity, and a short title of a bug report you send us), and privacy-filtered analytics and error-monitoring tools such as PostHog and Sentry.

We do not sell your personal information. We do not share it for cross-context behavioral advertising. We may disclose information to service providers, affiliates, professional advisers, authorities when legally required, or parties involved in a merger, financing, acquisition, or similar business transaction, subject to appropriate safeguards.

7. How we store information

Your account and your projects are stored on servers and storage run by our hosting providers, Railway and Cloudflare. That includes your screenplay, its version history, your conversations with Nisaba, and files you import.

We encrypt sensitive records in our database, such as the email address on your account and the access tokens we receive when you sign in with Google. Some sign-in, invitation, and billing records keep an email address unencrypted so they can work.

Sign-in sessions use secure, HTTP-only cookies. Sessions expire, and you can sign out of any device from Settings.

Our scheduled backups are encrypted before they leave our servers and are kept with a different storage provider from our main database. Our database host also keeps its own recovery backups.

8. How long we keep information

We keep information for as long as we need it for the purposes in Section 4, or as the law requires. We keep your account information and your projects while your account is open. Your conversations with Nisaba are stored with the project they belong to and are kept until you delete that project. When you delete a project, it is removed from your dashboard, and we then delete its content, version history, and conversations from our live systems. That cleanup can take some time.

Some information is kept apart from your projects and can outlast them: billing, payment, and credit records; security and audit logs, which include IP addresses and browser details; records of AI requests, which can include the text a model returned; usage statistics; and the working preferences described in Section 3, with the summary made from them, which stay with your account.

Copies of deleted information can remain in backups and archives after it is removed from our live systems.

9. Your controls and rights

You can export your screenplay from Nabu in supported formats such as Fountain, Final Draft (FDX), and PDF. You can also turn off structure and choice signal collection in Settings.

In Settings you can download a copy of your account data, review the working preferences Nabu keeps and remove individual entries, and sign out of Nabu on other devices. You can delete a project from your dashboard. To stop optional emails, use the unsubscribe link in any of them. Some emails are always sent, such as sign-in, security, billing, and policy notices.

Depending on where you live, you may have rights to access, correct, delete, export, or restrict the use of your personal information; to object to certain processing; to withdraw consent where processing is based on consent; and to appeal or complain to a privacy regulator.

You may request account deletion or deletion of associated personal information by contacting us. We will process deletion requests within a reasonable period and as required by applicable law, subject to exceptions for billing records, security, fraud prevention, legal compliance, dispute resolution, backups, and content that must remain available to other collaborators or workspace members.

11. Security

We use technical and organizational safeguards intended to protect personal information, including encryption in transit, encryption for sensitive records where appropriate, access controls, logging, rate limiting, and operational review. No online service can guarantee absolute security.

12. International processing

Nabu and our service providers process information in the United States and in other countries, where data-protection laws may differ from those where you live.

13. Children

Nabu is not intended for children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided personal information to Nabu, contact us and we will take appropriate action.

14. Changes and contact

We may update this policy as Nabu changes. If we make material changes, we will provide notice through the service, by email, or by another reasonable method. We will not use your creative content for model training by quietly changing this policy.

Privacy questions and requests: privacy@nabu.page.