NMRD
Back to Sign In

Privacy Policy

Last updated: May 3, 2026Effective immediately

This Privacy Policy explains how NMRD (“NMRD”, “we”, “us” or “our”) collects, uses, shares and protects personal data in connection with the NMRD social-media scheduling, publishing, analytics and team-collaboration platform (the “Service”) and the websites at nmrd.lol and related sub-domains (the “Site”). It applies to visitors to the Site, account holders, members of customer workspaces, prospects, event attendees, and anyone else who interacts with us. By using the Site or the Service you acknowledge this Policy. For our contractual terms, see our Terms of Service.

1. Who We Are (Data Controllers)# Link

NMRD is operated by NR LLC. References in this Policy to “NMRD”, “we”, “us” or “our” mean NR LLC.

NR LLC is the primary data controller for account, billing, customer-support, marketing, and Service-usage data. NR LLC also processes the OAuth credentials, scopes, and platform-side metadata required to publish on your behalf on connected third-party networks.

For all privacy-related questions, requests, and complaints, please contact us through our website’s support channels or your account settings.

2. The Service in Brief# Link

NMRD lets you connect 28+ social-media and chat channels and centrally schedule, publish, analyse and collaborate on content. The platform includes a calendar and scheduling engine, a media library, a publishing queue, analytics, AI-assisted content generation, team and workspace management, and integrations with third-party platforms. Some features depend on your plan and on the platforms you choose to connect.

3. The Data We Collect# Link

3.1 Account & Identity Data

Name, email address, password (stored as a salted hash), profile picture, organisation name, role, language, and timezone preferences. If you sign in via a social-login provider (e.g. Google), we collect the basic profile fields and email returned by that provider. We also store workspace and team membership, invitations sent and accepted, and permissions granted.

3.2 Connected Platform Data

When you connect a third-party social or messaging account to NMRD we receive and store, via that platform’s API:

  • OAuth access & refresh tokens (encrypted at rest), granted scopes, platform username and identifier, and account-level metadata (profile picture, follower counts, page/channel IDs).
  • Content and engagement data needed to provide the Service: posts created or scheduled, published posts, comments, replies, direct messages (where explicitly enabled), and post-level analytics (impressions, clicks, reach, video retention, aggregate metrics).

For YouTube specifically, the Service uses YouTube API Services. Your use of those features is subject to the YouTube Terms of Service and the Google Privacy Policy. You can revoke NMRD’s access to your Google data at any time in your Google Security Settings.

3.3 Content You Upload

Text, images, video, audio, captions, links, hashtags, schedules, prompts, comments, approval notes, calendar metadata, and any other content you upload to or generate within the Service.

3.4 Billing Data

Plan, subscription status, invoice history, billing email, billing address, and tax identifiers. Card details and bank-account details are collected and stored directly by our payment processors (e.g., Stripe, Paddle); NMRD only receives a tokenised reference, the last four digits, the card brand, and the expiry date.

3.5 Logs, Usage & Device Data

IP address, user-agent, browser type and version, operating system, device identifiers, referrer URL, language preference, and approximate location derived from IP (country/region). We also track application telemetry: pages visited, features used, posts created/published/failed, API calls made, performance metrics, and session activity (login timestamps, MFA enrolment, etc.).

3.6 Communications & Support Data

Messages you send us by email, in-app support chat, support tickets, or community channels; surveys, feedback, and engagement metrics for our transactional and marketing emails.

3.7 Cookies & Similar Technologies

We use cookies, local storage, pixels, and SDKs for authentication, security, preferences, analytics, and marketing attribution. You can manage non-essential cookies through your browser settings or consent banner (where applicable). Disabling strictly-necessary cookies will break parts of the Service.

4. How We Use the Data & Legal Bases# Link

We process personal data for the following purposes and legal bases:

  • Provide the Service: Authenticating users, managing workspaces, publishing content, returning analytics, and providing customer support. (Performance of contract.)
  • Bill and Collect Payment: Issuing invoices, managing subscriptions, preventing fraud, and complying with tax law. (Performance of contract; Legal obligation.)
  • Secure the Service: Detecting and preventing abuse, fraud, spam, infrastructure attacks, and enforcing our Terms. (Legitimate interests in safety; Legal obligation.)
  • Operate and Improve: Uptime monitoring, debugging, performance measurement, A/B-testing features, and compiling aggregate usage analytics. (Legitimate interests in running a reliable Service.)
  • Communicate with You: Sending service-related notices (billing receipts, post-failure alerts) and opt-in marketing communications. (Performance of contract; Consent or Legitimate interests.)
  • Comply with Law: Responding to lawful requests, defending legal claims. (Legal obligation; Legitimate interests.)

We do not use your scheduled posts, connected-platform content, or private messages for advertising, and we do not sell your personal data.

5. AI-Assisted Features# Link

The Service offers optional AI features that generate or rewrite captions, hashtags, image prompts, video scripts, and analytics summaries. To provide them we transmit your prompts and the inputs you choose to include to third-party model providers (for example Anthropic, OpenAI, and similar) acting as our sub-processors. We instruct those providers not to use your inputs or outputs to train their models. AI outputs are generated probabilistically and may be inaccurate; you remain responsible for reviewing them before publishing.

6. NMRD as Controller vs Processor# Link

For account, billing, Site analytics, marketing, and security data, NMRD acts as a data controller.

For the content you publish through the Service and the personal data of your audience, followers, customers, and message contacts that flows through NMRD on your instructions, NMRD acts as a data processor on your behalf, and you are the controller. You are responsible for having a lawful basis for that processing. On request we will sign our standard Data Processing Addendum (DPA) incorporating EU Standard Contractual Clauses. Please contact us via our website support channels to request a DPA copy.

7. Who We Share Data With# Link

We do not sell personal data and we do not rent it to third parties. We share data only with:

  • Sub-processors and Infrastructure Providers: Cloud hosting, database management, observability, customer-support tools, transactional email systems, and payment processors. We require these vendors to process data only on our instructions.
  • Connected Third-Party Platforms: Transmitting scheduled posts and retrieve analytics. Each platform’s own privacy policy governs what it does next.
  • Other Members of Your Workspace: Schedules, comments, and approvals are visible to coworkers in your workspace depending on permissions.
  • Professional Advisors & Successor Entities: Accountants, auditors, legal advisors under confidentiality, or in the event of a merger, acquisition, or restructuring.
  • Authorities: When legally required to comply with court orders, regulatory inquiries, or law-enforcement requests.

8. International Data Transfers# Link

NMRD utilizes sub-processors, database nodes, and cloud servers across the United States, the European Union, and other global regions. Personal data may be transferred to, stored in, and processed in jurisdictions outside of your country of residence.

Where personal data subject to the GDPR or UK GDPR is transferred to a country without an adequacy decision, we rely on the European Commission Standard Contractual Clauses (and the UK Addendum) supplemented by technical and organizational protection measures (encryption in transit and at rest, strict database access controls).

9. Data Retention# Link

We retain personal data according to the following schedules:

  • Account Data: Kept for as long as your account is active. Following account closure, data is retained for up to 90 days to allow recovery, then deleted or anonymised (except where accounting/billing logs require longer storage).
  • OAuth Tokens: Kept while your platform connection is active; revoked tokens are deleted promptly. You can disconnect platforms at any time.
  • Billing Records: Retained for the period required by tax and accounting law (typically 7 years).
  • Logs & Backups: Operational logs are kept for up to 12 months. Backups roll off on their normal rotation schedule within 30 to 90 days.

10. Security# Link

We maintain administrative, technical, and physical safeguards designed to protect personal data against accidental destruction, loss, alteration, or unauthorized disclosure. These include: encryption of data in transit (TLS) and at rest, encryption of OAuth tokens, password hashing with modern salted algorithms, role-based access, multi-factor authentication (MFA) for staff access, and regular security commits. No system is fully secure, and we cannot guarantee absolute security.

11. Your Rights# Link

Depending on your jurisdiction, you may have the right to access the personal data we hold about you, receive a copy, request correction, request deletion (subject to legal retention requirements), object to or restrict processing, or withdraw consent.

Most account changes can be handled directly by signing in to your account settings. To exercise rights that cannot be handled in-product, please contact us through our website’s support channels or your account settings. We will respond within the legally required timeframe (typically 30 days). We may verify your identity before acting on a request.

12. California Privacy Rights# Link

If you are a California resident, the California Consumer Privacy Act as amended by the California Privacy Rights Act (together, the “California Privacy Laws”) gives you the right to know what categories of personal information we collect, the purposes of use, the right to delete, the right to correct, the right to limit the use of sensitive personal information, and the right to not be discriminated against.

NMRD does not sell personal information and does not share it for cross-context behavioural advertising. To exercise your California rights, please contact us through our website’s support channels.

13. Children# Link

The Service and the Site are intended for business use and are not directed to children. We do not knowingly collect personal data from children under the age of 18. The platform is not designed for or marketed to children under 13 within the meaning of the U.S. Children’s Online Privacy Protection Act (“COPPA”), the EU GDPR, or comparable laws. If you believe a child has provided us with personal data, please contact us immediately through our support channels and we will delete it.

14. Marketing & Cookies Choices# Link

You can unsubscribe from marketing emails at any time using the unsubscribe link in any such email. Transactional and account-related emails remain mandatory while your account is active. Cookie preferences can be managed via your browser settings.

15. Third-Party Sites and Services# Link

Our Service links to and integrates with third-party networks. Their handling of your data is governed by their own privacy policies. We encourage you to review the privacy policy of any platform you connect to NMRD, including the Google Privacy Policy for YouTube integrations.

16. Changes to this Policy# Link

We may update this Privacy Policy from time to time. If a change is material we will provide reasonable notice (for example by email or in-product notice) before it takes effect. The date the Policy was last updated is shown at the top of this page. We encourage you to review it periodically.

17. Contact Us# Link

If you have any questions, requests, or complaints about this Privacy Policy, please contact us through our website’s support channels or your account settings.

Thank you for reading our Privacy Policy. If you have any inquiries regarding your data, please contact us through our website’s support channels or your account settings.