Last Updated: August 3, 2026
This page describes the security and data-handling boundaries NADA AI currently publishes for Aippy and other services that link to our policies. It is not a certification report and does not claim controls, audits, or guarantees that are not identified here.
Published assurance status. This page does not make a public claim of SOC 2 or ISO 27001 certification, penetration-test coverage, or a guaranteed vulnerability-response time.
1. Scope
Our security responsibilities cover account information, creative projects, prompts and generated outputs, service operations, and the infrastructure used to deliver the Services. Security is shared across NADA AI, the service providers we use, and users who control their own devices and login methods.
No internet service can guarantee absolute security. If you believe an account or system has been exposed, report it using the process below.
2. Data Boundaries
The Services handle different kinds of information in different ways:
- Account and profile data may include email, username, profile details, and provider-specific login identifiers.
- Creative data may include prompts, generated code, project files, comments, images, videos, fonts, and other uploads.
- Device and usage data may include IP address, browser, device and app information, activity, logs, and crash reports.
- Published content may be visible to and interacted with by other users when you choose to share it publicly.
For the complete collection, use, sharing, and retention description, see our Privacy Policy.
3. Accounts and Authentication
Where available, Aippy supports third-party sign-in providers such as Google or Apple. Those providers control their own authentication systems and security settings.
Users should secure connected accounts, avoid sharing credentials, sign out on shared devices, and notify contact@nadaai.ai if they suspect unauthorized access.
4. AI Providers
Prompts, inputs, and generated outputs may be sent to third-party AI providers to produce results and operate the Services. Some providers may retain inputs or outputs under their own policies, including for service improvement or model training.
Do not submit passwords, full payment credentials, health information, biometric identifiers, precise location, or other sensitive personal information in prompts or uploads. NADA AI cannot promise deletion from a third-party system beyond the technical and contractual controls available to us.
5. Payments and Deletion
Full payment credentials are processed by payment providers such as Stripe. NADA AI stores transaction records such as order ID, amount, currency, time, and payment channel, but does not store complete card numbers or payment-account passwords.
An Aippy account can be deleted through Settings → Account → Delete Account. Information may remain where needed for security, fraud prevention, legal obligations, dispute handling, or provider-level operational logs, as described in the Privacy Policy.
6. Access and Operations
NADA AI uses cloud infrastructure and specialist providers for hosting, AI models, analytics, crash reporting, authentication, payments, support, and security monitoring.
Access to production systems, user data, and operational tools is restricted to authorized personnel or providers who need it to operate, secure, support, or improve the Services. Operational controls include permission management and monitoring or logging used to investigate reliability and security events.
7. Platform Safety
Automated systems, manual review, or both may be used to identify spam, fraud, account abuse, unauthorized access attempts, malicious content or code, policy violations, misuse of AI features, and attempts to bypass rate limits, payments, or security controls.
Content may be removed and features or accounts may be restricted when necessary to protect users or the Services.
8. Report a Vulnerability
Email contact@nadaai.ai with the subject Security Report. Include:
- the affected product, page, or URL;
- a concise description of the issue and its potential impact;
- reproduction steps or a minimal proof of concept;
- supporting screenshots or logs with personal data removed; and
- a contact method for follow-up.
Please avoid accessing other users’ data, disrupting availability, using destructive tests, or publishing an unresolved issue before we have had a reasonable opportunity to evaluate it. We review submitted reports and may contact you for more information; no guaranteed acknowledgement or resolution timeline is currently published.