Privacy Policy
Nook (“Nook,” “we,” “us”) is a voice assistant for Windows. This policy explains what we collect, why, and your choices.
The short version
- Your microphone audio never leaves your device. Speech is turned into text on your own computer using an offline model. We never receive or store audio.
- The text of your commands and Nook’s replies is sent to our servers (with your account email) so we can run AI features and improve how well Nook understands you.
- Your screen is only captured when you explicitly ask (e.g. “what am I looking at?”). One screenshot is sent to our AI provider to answer that question.
- We never store your password — only a salted one-way hash.
- AI requests go to Anthropic (Claude); optional voice replies go to ElevenLabs. We do not sell your data.
Information we collect
Account information. When you create an account we collect your email address and a salted hash of your password (never the password itself). We assign your account a plan and, for paid plans, a renewal date.
Command and reply text. When you speak or type a request, the transcribed text of that request and Nook’s text reply are sent to our servers, associated with your account. We use this to run AI features and to find and fix cases where Nook mishears or misunderstands.
Usage data. We count how many AI-assisted commands (and, on paid plans, voice and screen-vision requests) you make per day, to enforce plan limits and prevent abuse.
A device identifier. Each installation is assigned a random, anonymous ID so we can count active installs and deliver updates. It is not tied to your real-world identity.
Approximate location — only for weather. If you ask for the weather, we look up your city-level location from your IP address (via a third-party service) to give a local forecast. We do not use precise GPS location and do not otherwise track your location.
Screen content — only on request. If you ask Nook about your screen, Nook captures a screenshot of your active monitor and sends it to our AI provider to answer. This happens only for that request and is not retained by us beyond generating the answer.
Payment information. If you subscribe to a paid plan, payment is handled by our payment processor, Stripe. We do not receive or store your full card details; we receive only a confirmation and limited billing metadata.
What we do not collect
- Microphone audio — transcription happens on your device; audio never leaves it.
- Your password in readable form — only a salted hash.
- Your screen, files, or keystrokes in the background — nothing is captured unless a specific command requires it (a screenshot when you ask about your screen).
- We do not sell your personal information.
How we use your information
- To provide Nook’s features (run commands, hold conversations, answer questions).
- To operate accounts, enforce plan limits, and process subscriptions.
- To improve accuracy and reliability (reviewing missed or misunderstood commands).
- To keep Nook secure and prevent abuse.
- To communicate important service or account notices.
Who we share it with (service providers)
We share only what is necessary with providers who process data on our behalf:
| Provider | Purpose | What they receive |
|---|---|---|
| Anthropic (Claude) | AI reasoning & conversation | Your command text, and a screenshot only when you ask about your screen |
| ElevenLabs | Spoken voice replies (if enabled) | The text of Nook’s reply, to synthesize speech |
| Supabase | Accounts, database, authentication | Your email, hashed password, plan, usage, and command/reply text |
| Stripe | Payment processing (paid plans) | Billing details you enter with them directly |
| IP geolocation (ip-api.com) | City-level weather location | Your IP address, at the moment you ask for weather |
| Weather provider | Weather forecasts | The approximate location for your forecast |
These providers are bound by their own privacy and security terms. We choose them for their security posture but are not responsible for their independent practices.
How your data is stored and protected
- On your device: your settings and any API keys live in a local configuration file on your own PC. Keys you enter are never bundled into the app or shared with us.
- On our servers: account and usage data are stored in Supabase (Postgres) with row-level security, so each account can access only its own data. Passwords are stored only as salted PBKDF2 hashes. Administrative access is restricted.
- No method of transmission or storage is 100% secure, but we take reasonable measures to protect your information.
How long we keep it
- Account data: for as long as your account exists.
- Command/reply text and usage: retained to operate and improve the service, generally for up to 12 months, then aggregated or deleted.
- If you delete your account, we delete or anonymize your associated data within about 30 days, except where we must keep records for legal or billing reasons.
Your choices and rights
- Access, correction, deletion: you can request a copy of your data, or ask us to correct or delete it, by contacting us below.
- Voice and screen features are optional and off by default; you control them in Settings.
- Depending on where you live (for example the EEA/UK or California), you may have additional rights such as objection, restriction, or portability. Contact us to exercise them.
Children’s privacy
Nook is not directed to children under 13. We do not knowingly collect personal information from children under that age. If you believe a child has provided us information, contact us and we will delete it.
Changes to this policy
We may update this policy as Nook evolves. We will change the “Last updated” date above and, for material changes, notify you in the app or by email.
Contact us
Questions or requests about your privacy: nookofficialmail@gmail.com.