NichoAI

Status: Draft — Not Legal Advice. Requires Review By A Qualified Lawyer Before Publication.

This is a first-pass draft written by an AI assistant based on product requirements and a direct code review of the NichoAI codebase (see Section 6, Cookies, for what was actually checked vs. assumed). It has not been reviewed by legal counsel, has not been checked against Swedish/EU data protection law in detail, and must not be published or relied upon as-is.

Every [PLACEHOLDER] below marks a question that requires a legal decision or additional product decision — none of them have been guessed at.

NichoAI — Privacy Policy (Draft v0.1)

Last updated: [DATE — not yet published]

This Privacy Policy should be read together with NichoAI’s Terms of Service, in particular Section 2 (Partner Responsibility), which governs how responsibility is split between NichoAI and Partners for data Partners submit about their own customers or creators.

1. What Data We Collect

Account data (Partners):

  • Name, email address, and password — collected and stored by Base44, NichoAI’s underlying application platform, which handles authentication. If a Partner signs up via OAuth (e.g., Google), Base44 receives the relevant profile data from the OAuth provider instead of a password.

[PLACEHOLDER: does Base44 also collect anything beyond name/email/password by default, e.g. login timestamps, IP address at signup? Needs confirmation directly from Base44’s own data processing documentation, not assumed here.]

Payment data (Partners):

  • Handled entirely by Stripe. NichoAI does not receive or store raw card numbers, CVV, or full payment credentials — only what Stripe returns via its API (e.g., transaction status, last 4 digits of a card, subscription/billing status).

Third-party data Partners submit about others:

  • Creator Build: creator profile links, screenshots, captions, and other basic info about a creator that a Partner enters into the Platform in order to generate a product pitch.
  • Web Build: a business’s publicly available contact information (used to generate a website for that business).
  • This data is provided by the Partner, about a third party who is not themselves a NichoAI user.

[PLACEHOLDER: this raises a real question of whose “data subject” this is under GDPR — the creator/business is the data subject, but NichoAI’s direct relationship is with the Partner, not them. Needs explicit legal treatment (see Section 2, legal basis) — do not assume the standard “we collect data from users about themselves” framing applies here.]

Content generated on the Platform:

  • Websites (Web Build) and product pitches/recommendations (Creator Build) generated from the above inputs.

2. Why We Process This Data (Legal Basis)

[PLACEHOLDER — REQUIRES LEGAL CONFIRMATION FOR EACH ROW BELOW. Nothing in this section should be treated as settled; it is a starting list of categories that need a lawyer’s sign-off on the correct GDPR Article 6 basis, not a determination.]

Data categoryLikely candidate basis (unconfirmed)Why it needs legal confirmation
Partner account data (name, email, password)Contract (Art. 6(1)(b)) — necessary to provide the serviceShould be straightforward, but confirm login/security logging isn’t collected under a different basis.
Payment data (via Stripe)Contract (Art. 6(1)(b))Standard, but confirm Stripe’s own role as processor vs. controller for parts of this data.
Third-party data Partners submit (creator info, business contact info)Legitimate interest (Art. 6(1)(f))? Or does it rest on the Partner’s own basis for having collected/submitted it?This is the least settled item in the whole document. The data subject (creator/business) has no direct relationship with NichoAI and has not consented to NichoAI processing their data — this needs a lawyer to determine whether NichoAI is a processor acting on the Partner’s instructions, or an independent controller, since the answer changes NichoAI’s entire compliance obligation here.
AI/LLM processing of submitted data to generate outputContract (Art. 6(1)(b)), tied to the aboveDepends on resolving the row above first.
Marketing use of generated content (per ToS Section 5)Legitimate interest, with opt-outFlagged in the ToS draft too — opt-out may not be sufficient basis if content contains identifiable personal data; needs legal confirmation, possibly requires opt-in instead.

3. How Data Is Shared — Sub-Processors

The following third parties process data on NichoAI’s behalf as sub-processors:

  • Base44 — application platform; handles authentication (account data) and underlying infrastructure/hosting for the Platform. Base44’s Data Processing Agreement is part of its Terms of Service rather than a separately executed document — confirmed by reading base44.com/dpa directly, which states SOC 2 Type II and ISO 27001 certification. Base44’s own sub-processors are listed at base44.com/dpa/exhibitc.
  • Data residency — verified 2026-07-31 directly in the Base44 workspace (Settings → Overview → Data hosting → “View app data residency”): NichoAI’s data region is US, not EU/UK.

[PLACEHOLDER: where personal data is transferred from the EEA/UK to the United States, this transfer relies on Standard Contractual Clauses / the EU-US Data Privacy Framework — hold as placeholder until Base44 confirms directly which mechanism actually applies to NichoAI’s account.]

[PLACEHOLDER — UNRESOLVED, do not guess: Base44’s own DPA pages name two different contracting entities. base44.com/dpa states the DPA is part of the Terms of Service “governing the services provided to you by Base44, Inc.”, while base44.com/dpa/exhibitc states it is part of the Terms of Service “governing the services provided to you by Wix.com Ltd (including its subsidiaries and affiliates), which operates the Base44 branded services.” Do not state which entity is NichoAI’s actual data processor (Base44, Inc. vs Wix.com Ltd.) until Base44 confirms — this affects the SCC reference jurisdiction and which entity’s DPA execution status applies to NichoAI’s account.]

[PLACEHOLDER: base44.com/dpa/exhibitc currently contains two different sub-processor listings within the same page — a visible card grid and a separately structured table present in the page’s markup but not rendered on screen, listing an overlapping but not identical set of vendors (e.g. Langfuse and Logfire appear only in the non-visible table, not the visible cards). Do not treat either list as final; re-check the live page, and if the discrepancy persists, ask Base44 directly which listing is authoritative before publication.]

  • Stripe — payment processing; handles all payment card data and billing.
  • Pexels — image API used to source background/hero photos for generated websites (Web Build). No standalone Pexels DPA was found publicly — only a general Privacy Policy and Terms of Service, which describe contractual necessity as their processing basis but do not offer a dedicated GDPR DPA document to link or reference.

[PLACEHOLDER remains open: confirm directly with Pexels whether a DPA can be requested/executed, and separately confirm exactly what, if any, personal data is sent to Pexels in an API request (likely just a search/keyword query) — this affects whether the absence of a DPA is even a real gap.]

  • AI/LLM provider — gpt_5_mini, accessed via Base44’s OpenAI integration — powers both Leo/Bosse (Web Build assistant) and MAX (Creator Build assistant). OpenAI publishes a Data Processing Addendum at openai.com/policies/data-processing-addendum, but it must be actively executed by the party with a direct OpenAI account/contract.

[PLACEHOLDER — unresolved architectural question, not just a formality: NichoAI accesses gpt_5_mini through Base44’s integration, not through a direct OpenAI account. This means the DPA chain is likely NichoAI → Base44 → OpenAI, not NichoAI → OpenAI directly. It must be confirmed with Base44 whether Base44’s own OpenAI agreement covers this processing as NichoAI’s sub-processor (in which case Base44’s DPA, not OpenAI’s, is the operative document), or whether NichoAI needs its own separate arrangement with OpenAI. Do not publish this policy claiming a direct NichoAI–OpenAI DPA without resolving this.]

[PLACEHOLDER: standard sub-processor list boilerplate — does NichoAI commit to notifying Partners before adding new sub-processors? Not yet decided.]

No data is sold to third parties.

[PLACEHOLDER: confirm this claim is actually true given the marketing-use clause in ToS Section 5 — “not sold” and “used for marketing with an opt-out” are different things and both need to be accurately described, not just the more favorable one.]

4. Data Retention

[PLACEHOLDER: no retention periods have been defined for any data category — account data, third-party data submitted via Creator Build/Web Build, or generated output. This needs an explicit product decision (how long is data kept after a Partner stops being active, or after a specific generated site/pitch is created) before legal can assess GDPR storage-limitation compliance (Art. 5(1)(e)).]

5. Data Subject Rights

Under GDPR, data subjects have the right to:

  • Access — request a copy of personal data held about them.
  • Rectification — request correction of inaccurate data.
  • Erasure — request deletion of their data (“right to be forgotten”), subject to legal exceptions.
  • Data portability — receive their data in a structured, commonly used format.
  • Object — object to processing based on legitimate interest, including marketing use.

[PLACEHOLDER: process not yet defined. Who receives these requests (a support email? a dedicated privacy inbox?), what is the response timeframe (GDPR default is one month), and — critically — how are requests handled for the creator/business third-party data submitted by Partners, given NichoAI has no direct relationship or contact channel with those individuals? This last point connects back to the unresolved legal-basis question in Section 2 and needs to be resolved together with it, not separately.]

6. Cookies

This section is based on an actual review of the NichoAI codebase on 2026-07-25, not an assumption. Findings:

  • No analytics or advertising trackers were found. A search of the codebase and package.json dependencies found no Google Analytics, Google Tag Manager, Meta/Facebook Pixel, Hotjar, Mixpanel, PostHog, Microsoft Clarity, or similar tracking scripts anywhere in the app.
  • No cookies are set on the Landing page itself.
  • One cookie-setting function exists in the codebase (src/components/ui/sidebar.jsx, a UI-library component that stores sidebar open/collapsed state in a cookie), but it is not imported or used anywhere in the app — confirmed via a codebase-wide search for references to that component. It is inert boilerplate, not active on any page including Landing.
  • The app does use browser localStorage (not cookies) app-wide, via src/lib/app-params.js, to persist the Base44 authentication access token and a few app configuration parameters. This runs as part of the global app shell, not something specific to a logged-in area — so technically active on every page load, including Landing. This is a functional/strictly-necessary storage mechanism (authentication), not tracking or marketing.
  • Stripe’s checkout flow (hosted on Stripe’s own domain during payment) will set its own cookies under Stripe’s domain, outside NichoAI’s direct control — this is disclosed via Stripe’s role as a sub-processor (Section 3), not as a NichoAI first-party cookie.

[PLACEHOLDER: strictly-necessary storage (like the auth-token localStorage use above) is generally exempt from cookie-consent-banner requirements under the EU ePrivacy Directive, but “generally exempt” is not the same as “confirmed exempt for this specific implementation” — a lawyer should confirm this classification holds, and whether localStorage (as opposed to HTTP cookies specifically) is treated identically under Swedish implementation of the ePrivacy rules. Do not assume no cookie banner is needed without this confirmation.]

7. Contact

For questions about this Privacy Policy or to exercise a data subject right, contact: privacy@nichoai.com

[PLACEHOLDER — NOT VERIFIED, DO NOT PUBLISH UNTIL CONFIRMED: I could not check whether the nichoai.com domain is actually configured to receive mail at this address — the sandbox this draft was written in has no outbound DNS/network access to query MX records, so this is unconfirmed, not confirmed. Before publishing, send a test email to privacy@nichoai.com and confirm it’s received (or set up mail routing for it first if it isn’t). If it turns out the mailbox doesn’t exist, replace with a working address rather than leaving this one live in a legal document.]

[PLACEHOLDER: does NichoAI, given its size and processing activities, need to appoint a Data Protection Officer (DPO) under GDPR Art. 37? Likely not mandatory at current scale, but this is a legal determination, not a product one — flag for legal review rather than assuming “no.”]


Summary of open items requiring a decision or legal confirmation before this can go to legal review:

Legal basis for processing third-party data submitted by Partners (the central unresolved question — see Section 2) · whether NichoAI is a controller or processor for that third-party data · whether Base44’s OpenAI agreement covers NichoAI’s use of gpt_5_mini as a sub-processor arrangement, or whether NichoAI needs its own direct DPA with OpenAI · confirmation that Base44’s DPA is actually executed/in force for NichoAI’s account, and whether EU/UK data residency is enabled · whether a Pexels DPA can be obtained despite none being published, and whether Pexels API calls transmit any personal data · sub-processor change-notification policy · the “not sold” vs. “used for marketing” distinction · data retention periods for all categories · data subject request process, including for third parties with no direct NichoAI relationship · confirmation that strictly-necessary localStorage use is exempt from cookie-consent requirements under Swedish ePrivacy implementation · verify privacy@nichoai.com actually receives mail before publishing · DPO requirement determination.