Draft — not final

This document is a working draft pending legal review. Highlighted passages are unresolved placeholders. It does not yet state Nemali’s final position and should not be relied on.

Nemali
  1. Home
  2. /
  3. Privacy Policy

Privacy Policy

On this page

  • 1. Information You Provide
  • 2. Information Collected Automatically
  • 3. How We Use Information
  • 4. Communication Choices
  • 5. Analytics Choices
  • 6. How We Share Information
  • 7. Data Retention
  • 8. Security
  • 9. Your Requests and Choices
  • 10. Children
  • 11. International Processing
  • 12. Third-Party Links
  • 13. Changes to This Policy
  • 14. Contact

Draft for founder and legal review Effective date: [INSERT EFFECTIVE DATE] Last updated: [INSERT LAST UPDATED DATE]

This Privacy Policy explains how [INSERT LEGAL ENTITY OR OPERATOR NAME], operating as Nemali (“Nemali,” “we,” “us,” or “our”), collects, uses, shares, and protects personal information when you visit https://nemali.io, join the Nemali waitlist, communicate with us, or otherwise interact with the launch website.

This policy currently covers the public Nemali website and waitlist. It does not yet cover authenticated product accounts, creative projects, scripts, prompts, generated media, collaboration features, payments, or other future product functionality. We will update this policy before those features become publicly available.


1. Information You Provide

When you join the waitlist, you may provide:

  • Email address — required;
  • Name — optional;
  • Project type — optional;
  • Location — optional;
  • Note — optional, up to 1,000 characters.

You may also provide information when you contact us, reply to an email, request support, unsubscribe, or make a privacy-related request.

When you submit the waitlist form, the details you provide (including the optional note) may be included in an internal notification email that we send to ourselves through our email provider, Resend, to alert us to a new signup. See Section 6.

Please do not submit confidential creative material, scripts, financial information, government identification numbers, health information, or other sensitive personal data through the waitlist form.


2. Information Collected Automatically

2.1 Optional analytics

We use optional analytics only after you choose Allow analytics.

When analytics are allowed, we may collect limited information such as:

  • pages visited;
  • waitlist call-to-action source;
  • referral source;
  • UTM campaign information;
  • general viewport or device-size group;
  • selected project type (the chosen category, not free text);
  • anonymous analytics identifier;
  • interaction events such as opening or submitting the waitlist form.

We do not intentionally send your name, email address, location, waitlist note, or complete waitlist form submission to our analytics provider.

You may continue using the website and join the waitlist without allowing optional analytics. You can change your analytics choice later through the privacy or analytics-preferences link provided on the website.

2.2 Technical and security information

We may process limited technical information required to operate and protect the website, including:

  • request identifiers;
  • route, response status, timing, and error category;
  • application environment and release information;
  • technical error and performance information;
  • temporary abuse-prevention information used for rate limiting.

For rate limiting, an IP address may be transformed using a server-side salt and temporarily stored as a hash in Redis. Similarly, a hash derived from the submitted email address may be temporarily stored in Redis to enforce a per-email submission limit. These temporary hashes expire automatically, and we do not use them as analytics or user identifiers. We do not intentionally store raw IP addresses in the Nemali waitlist database.

Our production logs are designed not to include waitlist form bodies, names, email addresses, locations, notes, raw IP addresses, email content, cookies, authorization headers, or creative project content.


3. How We Use Information

We use information for the following purposes:

  • to create and manage waitlist entries;
  • to confirm that a waitlist submission was received;
  • to send occasional launch, early-access, and related Nemali updates;
  • to respond to questions, replies, unsubscribe requests, and privacy requests;
  • to understand interest in Nemali and the types of projects potential users are considering;
  • to improve the website and launch experience;
  • to prevent spam, automated abuse, and misuse;
  • to diagnose technical problems and monitor reliability;
  • to protect the security and integrity of our systems;
  • to comply with applicable legal obligations and enforce our rights.

We do not use waitlist information for automated decision-making that produces legal or similarly significant effects.


4. Communication Choices

By joining the waitlist, you agree to receive updates about Nemali’s launch and early access.

You can stop future waitlist updates by:

  • replying to a Nemali email and asking to unsubscribe; or
  • contacting us at [INSERT MONITORED PRIVACY OR SUPPORT EMAIL].

When you unsubscribe, we may retain the minimum information necessary to record and respect your choice, such as your normalized email address, unsubscribe status, and unsubscribe date.

A duplicate waitlist submission will not automatically reactivate an unsubscribed or suppressed address.


5. Analytics Choices

Optional analytics are disabled unless you choose Allow analytics.

If you choose Continue without analytics:

  • PostHog will not be initialized for optional analytics;
  • optional analytics events will not be sent;
  • the website and waitlist will remain usable.

We may store a limited preference value in your browser so we can remember whether analytics were allowed or declined.

You can change your choice later using the analytics-preferences link available on the website.

Strictly necessary technical storage may still be used to operate, secure, or remember essential website choices.


6. How We Share Information

We do not sell personal information.

We use service providers to operate the website and waitlist. They process information on our behalf or provide infrastructure required for the service.

Current providers include:

ProviderPurpose
VercelHosts and delivers the public Next.js website.
RailwayHosts the FastAPI backend, PostgreSQL database, Redis, and Celery worker.
CloudflareProvides domain-name services, DNS security, and email routing.
PostHogProvides optional, consent-based website analytics.
ResendSends the acknowledgment email to you and an internal notification email to us (which includes your submitted waitlist details, including the optional note), and reports delivery outcomes.
SentryProvides technical error and performance monitoring.

Because our internal new-signup notification is delivered through Resend, the waitlist details it contains — including the optional note — are processed by Resend as email content. We do not send this notification content to our analytics provider.

These providers may process information in countries other than the country where you live. We use provider contracts and available data-processing terms as appropriate, subject to final legal review.

We may also disclose information:

  • when required by law or a valid legal process;
  • to protect the rights, security, or safety of Nemali, our users, or others;
  • in connection with a merger, acquisition, financing, reorganization, or sale of assets, subject to appropriate protections;
  • with your direction or consent.

7. Data Retention

We retain waitlist information while:

  • the waitlist and launch process remain active;
  • we continue to have a defined launch or early-access purpose;
  • you remain subscribed to relevant communications;
  • retention is reasonably necessary for security, dispute resolution, or legal obligations.

We plan to review stale waitlist records no later than 12 months after Nemali’s broad product launch.

When information is no longer needed, we may delete or anonymize it. For unsubscribed, bounced, or complaint-marked addresses, we may retain minimum suppression information to prevent unwanted future messages.

Temporary rate-limit records in Redis expire automatically according to configured time limits.

Backups may retain information for a limited additional period until they are overwritten or expire under our backup schedule.


8. Security

We use technical and organizational measures intended to protect information, including:

  • HTTPS;
  • environment-separated credentials;
  • restricted infrastructure access;
  • multi-factor authentication for key providers;
  • request validation and size limits;
  • rate limiting and honeypot protection;
  • authenticated email-provider webhooks;
  • structured logging designed to exclude personal form data;
  • error-monitoring scrubbing;
  • database backups and controlled deployment practices.

No method of transmission or storage is completely secure. We cannot guarantee absolute security.

Publish gate (not part of the public copy): several controls above (provider MFA, database backups, production TLS) must be verified as actually enabled before this policy is published as final. Do not set LEGAL_PAGES_PUBLISHED=true until they are.


9. Your Requests and Choices

Subject to applicable law, you may be entitled to ask us to:

  • confirm whether we hold personal information about you;
  • provide access to certain information;
  • correct inaccurate information;
  • delete information;
  • withdraw consent for certain processing;
  • stop launch or early-access communications;
  • raise a concern about how we handle information.

To protect your information, we may verify that you control the email address associated with the request before providing, changing, or deleting data.

Send requests to:

[INSERT MONITORED PRIVACY EMAIL — RECOMMENDED: privacy@nemali.io]

We aim to acknowledge privacy requests within seven calendar days and handle straightforward waitlist requests within 30 days. These are internal service targets and do not limit any rights or timelines provided by applicable law.

Legal review required: Final rights language should be checked against the laws applicable on the effective date, including the Digital Personal Data Protection Act, 2023 and the provisions of the Digital Personal Data Protection Rules, 2025 then in force.

Publish gate (not part of the public copy): the rights promised here require a working fulfillment path (the waitlist:export/:delete-personal-data/:unsubscribe/:suppress commands, or a documented owned manual runbook) before this policy is published as final.


10. Children

The launch website and waitlist are not intended for children under [INSERT AGE — RECOMMENDED: 18].

We do not knowingly seek personal information from children through the waitlist. If you believe a child has submitted personal information, contact us so that we can review and take appropriate action.

Legal review required: Confirm the age threshold and any parental-consent obligations before publication.


11. International Processing

Our service providers may store or process information outside India or outside your country of residence.

Where required, we will use appropriate contractual, organizational, or legal safeguards for cross-border processing.

Legal review required: Confirm applicable transfer requirements and execute or accept appropriate data-processing agreements with relevant providers.


12. Third-Party Links

The website may contain links to external websites or services. Their privacy practices are governed by their own policies, not this Privacy Policy.


13. Changes to This Policy

We may update this policy as Nemali develops, legal requirements change, or our data practices change.

We will update the “Last updated” date when changes are made. For material changes, we may provide additional notice through the website or by email where appropriate.

Before authenticated accounts, creative-content storage, payments, or media-generation features launch, this policy must be reviewed and expanded.


14. Contact

Nemali Operated by: [INSERT LEGAL ENTITY OR OPERATOR NAME] Address: [INSERT BUSINESS OR CONTACT ADDRESS IF REQUIRED] Privacy email: [INSERT MONITORED PRIVACY EMAIL] General contact: hello@nemali.io


Review Status

This draft is intended to accurately describe the current Nemali launch implementation. It is not a substitute for legal advice.

Before publication, founder/legal review must confirm:

  • the legal entity or operator;
  • effective date;
  • contact and business address requirements;
  • age threshold;
  • user-rights wording;
  • international transfer language;
  • applicable grievance or complaint mechanism;
  • provider DPAs and subprocessor disclosures;
  • any jurisdiction-specific disclosures.

Reference Sources for Review

  • Government of India, Ministry of Electronics and Information Technology — Digital Personal Data Protection Act, 2023.
  • Government of India, Ministry of Electronics and Information Technology — Digital Personal Data Protection Rules, 2025 and enforcement timeline.
  • PostHog — privacy, trust, subprocessor, and data-processing documentation.
  • Resend — Privacy Policy, Data Processing Addendum, Terms, and subprocessor documentation.
  • Vercel, Railway, Cloudflare, and Sentry — current privacy and data-processing documentation.