Privacy Policy
Last updated · 2026-09-11
This Privacy Policy explains how Noli LLC (“we,” “us,” “our,” or the “Company”), operating under the Noli AI brand (“Noli” or “Noli AI”), collects, uses, stores, and shares information when you use our websites, our applications, our AI agents, and any related services (the “Services”).
By accessing or using the Services, you agree to the practices described in this Privacy Policy. If you do not agree, please do not use the Services. This Privacy Policy is incorporated into our Terms & Conditions by reference.
1. Who we are
Noli AI is a product offered by Noli LLC, a Wyoming limited liability company, 30 N Gould St, Ste 100, Sheridan, WY 82801. Noli LLC is the controller of the personal information described in this policy. Contact: privacy@noliai.com for privacy matters; support@noliai.com for general inquiries; security@noliai.com for security matters.
The Launch Pad (thelaunchpadincubator.com and launchpad.noliai.com) is a program offered by Noli LLC, the same company that operates Noli AI. A Launch Pad membership is a Noli account: one sign-in, one controller, and this policy and the Noli Terms govern both, alongside the Launch Pad's own terms for the program itself.
2. Information we collect
2.1 Account information
When you create an account, we collect information necessary to authenticate you and provision the Services: your name, email address, password (stored only as a salted hash, or not stored at all if you use a third-party identity provider such as Google or Apple), workspace name, and any organization details you provide.
2.2 Subscription and billing information
To purchase a subscription, our payment processor collects billing information on our behalf, including card or bank details, billing address, and tax identifiers. We don't store full card numbers on our servers; we keep a token plus the last four digits for receipts and renewals. We also store the tier you selected, the subscription start date, the renewal date, and your invoice history.
2.3 Workspace content
To do its job, your AI team needs context about your business. The Services collect, store, and process the content you choose to upload, capture, generate, or connect, including:
- Notes, documents, voice memos, and transcripts captured in Noli KB;
- Customer records, deal pipelines, calls, and follow-ups in Noli CRM;
- Marketing assets, drafts, campaigns, and analytics in Noli AMS;
- Goals, projects, milestones, and reflections in Noli PM;
- Briefings, approvals, to-dos, and conversation history with your Chief of Staff;
- Prospects, campaigns, drafts, and replies in the GTM Engineer (see Section 2.8 for how Prospect Data is handled);
- Calls, voicemails, transcripts, text conversations, and caller phone numbers handled by the AI Receptionist, if you add it;
- Transactions, categorizations, and forecasts in Noli CFO, and read-only data from any payment, bank, or accounting account you connect for it;
- Property records, comparable sales, adjustments, and client presentations in the real estate tools;
- Credentials you connect so your team can act for you (for example an OAuth grant, a mailbox app password, or an API key), which are stored encrypted and used only for the work you asked for;
- Content from third-party integrations you authorize (e.g., Google Drive files, Notion pages, and calendars), strictly within the scope you grant.
We refer to the above collectively as “Workspace Content.” Workspace Content is treated as your User Content under our Terms.
2.4 AI interaction data
When you (or another agent) ask an AI agent to do something, we collect and process the prompt, the relevant context retrieved from your Workspace Content, the model's response, and metadata about the interaction (timestamp, tokens used, latency, error states). This allows us to provide the Services, enforce usage limits, debug, and improve quality.
2.5 Usage data
We automatically collect basic information about how you use the Services, including device, browser, IP address, pages and features accessed, performance metrics, and crash diagnostics. We use this to debug, improve performance, prioritize what to build, and detect abuse. Our analytics may include session replay of how you move through the Services; text you type into forms is masked before it is recorded.
2.6 Communications
When you contact us (email, support form, in-app chat), we keep the communication, your contact details, and any attachments you send, so we can respond and improve our support.
2.7 Cookies and similar technologies
We use cookies and similar technologies for authentication, session management, security, preference storage, and limited analytics. See Section 7 below for details.
2.8 GTM Engineer prospect data
GTM Engineer helps a business customer identify potential business buyers and, for supported consumer use cases, public places where potential buyers may gather or express demand. Those places can include communities, forums, groups, posts, threads, online or in-person events, and creator audiences. When an approved source returns it, Noli may also show a public author, organizer, or participant as secondary context. At the customer's direction, Noli may obtain public or licensed information about these prospects and demand opportunities. We call this “Prospect Data.” Prospect Data may include a name, job title, employer, company website and attributes, work email address, business phone number, public profile URL, public post or event URL, visible audience or engagement metrics, and public professional or consumer-demand signals.
Prospect Data comes from approved public sources and contracted data services. Availability, source coverage, and providers can change. Noli records available source, observation-time, confidence, and provider-operation evidence so a customer can review the basis for a result. Noli does not use sensitive personal information, sensitive life events, protected characteristics, or information about children to create GTM audiences or qualify leads. A public source does not override these restrictions.
2.8.1 How Prospect Data is used
Noli uses Prospect Data to source and de-duplicate prospects, evaluate customer-defined fit criteria, show the evidence and public source for a result, identify public demand opportunities, find or verify business contact points, prepare outreach or participation suggestions for customer review, process business-email replies, and enforce retention, suppression, and removal requests. For a consumer opportunity, Noli may recommend that the customer read a public discussion, attend an event, contact an organizer, or contribute a useful response. Noli does not automate outreach to a person identified through a consumer play: it does not join a group, register for an event, follow a person, post, comment, or message a consumer for the customer. Separately, where a customer connects a social publishing service, Noli can publish content the customer has approved to the customer's own accounts. Prospect Data is isolated to the customer organization that requested it and is not used to train a general-purpose AI model.
2.8.2 Customer outreach and mailing addresses
Automated email in GTM Engineer is limited to supported United States business-to-business outreach. A customer may research and qualify those prospects without entering a mailing address. Before the customer can approve or send a commercial email, the customer must provide its own valid physical postal address. Noli freezes that address into the reviewed campaign version and adds it to each email footer with an unsubscribe mechanism. Outreach is sent from a mailbox the customer connects and authorizes. The customer is the sender and remains responsible for the message, audience, and compliance obligations that apply to its outreach.
For a supported, non-sensitive consumer audience, Noli may show a public community, conversation, event, creator audience, or other demand opportunity, the evidence explaining the match, and a public destination. Noli may also show a named public person and draft a message or response for the customer to review. The customer must review the destination's rules and personally perform any consumer participation or outreach outside Noli. Noli does not automate consumer email, text messages, calls, direct messages, follows, event registration, posting, or commenting and does not record a copied draft or opened link as sent.
2.8.3 Scope, retention, and removal
Provider sourcing is limited by audience, geography, source rights, customer access, and product controls. Automated outreach remains limited to supported United States business-to-business email. A never-promoted prospect receives a 90-day retention deadline. A manual consumer message draft receives a 30-day retention deadline. Routine retention sweeps hard-delete eligible expired records and their associated evidence and contact points. Records that become customer contacts or durable outreach history follow the customer's workspace-retention rules. Suppression hashes are retained so an opted-out or removed address is not sourced or contacted again through Noli.
A person who believes their information appears as Prospect Data can submit the public form at noliai.com/prospect-removal. The form accepts a business email address or exact public LinkedIn profile URL, removes matching records, stops pending matching outreach, and applies platform-wide suppression without revealing whether Noli previously held a record. For access, correction, source, or other verified privacy requests, email privacy@noliai.comwith “Prospect Data Request” in the subject line.
2.9 Information about your customers, callers, and contacts
Much of what you put into the Services is information about other people: your contacts and deals in the CRM, the people who call or text your AI Receptionist, subscribers to your newsletters, buyers of your courses, and the prospects described in Section 2.8. For that information you decide what is collected and why, and we process it only on your instructions to provide the Services to you. If you are subject to laws that treat you as the controller or business and us as a processor or service provider, that is the relationship we intend, and a data processing agreement is available on request from privacy@noliai.com.
If you are one of those people and want to know what a Noli customer holds about you, please contact that customer directly, since they control that data. If you contact us instead, we will pass your request to them where we can identify them and help them respond. For GTM Prospect Data specifically, Section 2.8.3 describes a removal form you can use yourself.
When the AI Receptionist answers a call or a text on a customer's behalf, it identifies itself as an AI assistant at the start of the conversation. If the customer has turned on call recording, callers are told before the recording begins. The customer is responsible for confirming that recording with that disclosure is lawful in every state where they and their callers are located, including states that require the consent of every party, and for any consent required before a text message is sent. We process caller information on the customer's instructions and only to provide the feature to them. Where you interact with an AI agent rather than a person, we tell you: our agents identify themselves as AI and will confirm it if asked.
3. How we use your information
We use the information we collect to:
- Provide, maintain, secure, and improve the Services;
- Operate AI agents on your behalf, scoped to your own workspace data;
- Route relevant Workspace Content to AI agents through the cross-product memory layer so the agents can coordinate;
- Process payments, manage subscriptions, and send transactional and account communications (which you can't opt out of while your account is active);
- Send product updates, tips, and offers you can opt out of via the unsubscribe link in any such email;
- Enforce our Terms, prevent fraud and abuse, and respond to legal process;
- Comply with legal obligations.
Legal bases under GDPR (if you are in the EEA/UK): performance of a contract (to deliver the Services you purchased); legitimate interests (security, abuse prevention, basic analytics, and improvement of the Services); consent (for marketing emails and non-essential cookies); and legal obligation (compliance, tax, and accounting).
4. AI models and training
4.1 We do not use your data to train AI models
We do not use your User Content, Workspace Content, prompts, or AI Output to train, fine-tune, or otherwise improve any AI model owned or operated by us, nor do we permit our model providers to do so under our enterprise API contracts.
4.2 Third-party model providers
To generate AI Output, the Services route prompts and the relevant context to large language model providers, currently including Google, OpenAI, Anthropic, and xAI, and may include other comparable providers in the future. We use API tiers under which the provider contractually disallows training on data submitted through the API. If a provider changes those terms in a way that would permit training, we will (a) notify affected customers and (b) seek a comparable alternative provider where commercially feasible.
4.3 Bring Your Own API Key (BYO API Key)
If you elect to provide a BYO API Key, your prompts and context are sent directly to that provider under your account, governed by the provider's terms, not ours. Please review your provider's data-handling and training policies before enabling BYO.
4.4 Aggregated and anonymized data
We may use aggregated and anonymized data (data from which all personal and identifying details have been removed) to publish benchmarks, improve the Services, and report on platform-level trends.
4.5 Google user data: Limited Use
When you choose to connect a Google account (for example, to sync your calendar through Noli CRM), the Services access Google APIs. Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
We request only the scopes needed for the calendar features you enable: reading your calendar availability so booking pages and the AI Receptionist do not double-book you (calendar.readonly), creating and updating booking appointments on your calendar (calendar.events), and identifying your email address for account linking (userinfo.email, openid). You connect Google Calendar once, in Noli CRM; your Chief of Staff reads your calendar through that one connection and does not hold a Google grant of its own. If you sign in to Noli with Google, we receive only your name, email address, and profile picture from that sign-in.
We use Google user data exclusively to provide those features. We do not sell or lease it; we do not use it for advertising, ad targeting, or to build advertising profiles; and we do not allow humans to read it except with your explicit consent for a specific message, for security or abuse investigation, to comply with law, or when it has been fully aggregated and anonymized. Google OAuth tokens are stored encrypted, and you can disconnect Google at any time from the settings of the product where you connected it, which immediately revokes our access and deletes the stored tokens.
4.6 Google user data and AI models
Some Noli features use AI models to process information you connect, including Google Workspace data such as calendar events. We do not use, transfer, or sell Google user data, whether raw, aggregated, derived, or anonymized, to create, train, fine-tune, or improve any generalized or foundational AI or machine learning model, and we do not permit our providers to do so.
Where Google user data is processed by a third-party AI provider, we use only paid or enterprise API tiers whose terms prohibit training on customer data. Those providers are Google (Gemini API, paid tier), Anthropic (Claude API) and OpenAI (API). None of these tiers use API inputs or outputs for model training. Where you supply your own provider key, that provider processes your data under the terms of the plan attached to your key, and we surface this so you can choose accordingly.
The same applies when you connect an outside AI assistant to your Noli account, for example Claude or ChatGPT. When you do that, you are directing us to send the information you ask for to that assistant, and it is then handled under your agreement with whoever provides it rather than under our provider terms. Consumer plans differ from the paid API tiers described above, and some may use what you send them to improve their models. This includes any Google Workspace data you ask that assistant to work with, such as calendar events. You choose which assistant to connect and which parts of your account it can reach, you can limit a connection to specific products, and you can disconnect it at any time.
Our use of raw or derived user data received from Google Workspace APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
4.7 Meta Threads data
If you use GTM Engineer, you can connect your own Threads account so that Noli can search recent public Threads posts by keyword on your behalf. When you connect it, Meta provides us with your Threads user ID, username, and display name, together with an access token that we store encrypted under your workspace key. When you run research, the Threads keyword search returns public posts: the post ID, permalink, text, media type, publication time, and the author's public username. We call this “Threads Data.”
We use Threads Data only to show you public conversations that may be relevant to your business, for your manual review. Noli never publishes, replies, follows, or messages on your behalf through Threads, and it never contacts the authors of public posts automatically. We do not sell Threads Data, use it for advertising or ad targeting, build advertising profiles from it, or use it to train, fine-tune, or improve any AI or machine learning model, and we do not permit our providers to do so. Threads Data is not shared with third parties except the infrastructure and AI providers described in Sections 4.2 and 6, strictly to provide the feature.
Public posts returned by a search are retained for up to ninety (90) days and then removed by our routine retention sweeps. Your connection details and encrypted token are retained until you disconnect. You can disconnect at any time from the GTM Engineer Setup screen, or by removing Noli from your Threads account settings; either action revokes our access and deletes the stored token immediately. Our use of Threads Data adheres to the Meta Platform Terms and Developer Policies.
5. When we share information
We don't sell your personal information. We share it with:
5.1 Service providers (sub-processors)
We use trusted vendors to operate the Services. They process personal data only on our behalf, only for the purposes we direct, and under written contracts that include confidentiality and security obligations. They fall into these categories: identity and authentication; payment processing; cloud hosting, databases, and storage; AI model providers; telephony, text messaging, and carrier registration; email and notification delivery; social publishing; analytics and error reporting; customer support tooling; and the data services described in Section 2.8. We may add or replace sub-processors at our discretion; where a law that applies to you requires notice of a change, we will provide it. Our current sub-processors, what each one does, and where it processes data are listed at noliai.com/legal/sub-processors, and business customers can accept our Data Processing Addendum, which gives 30 days' notice before a new sub-processor is added.
5.2 Other workspace members
Information you put into a shared workspace is accessible to other members of that workspace at the access level you grant.
5.3 Aggregated information
We may publish or share information that has been aggregated or de-identified so that it cannot reasonably be used to identify you, your workspace, or any individual, for example platform-level benchmarks and usage trends. We will not attempt to re-identify it and we will require anyone we share it with to make the same commitment. We never aggregate or de-identify Google user data, Meta Threads data, or the contents of a connected mailbox for this purpose.
5.4 Business transfers
If we're involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, your information may be transferred as part of that transaction. We'll notify you (e.g., by email and a prominent notice on the Services) of any change in ownership or use of your information.
5.5 Legal requirements and requests from public authorities
We may disclose information if we believe in good faith it is necessary to comply with a law, regulation, or legal process; to enforce our Terms; to detect, prevent, or address fraud, security, or technical issues; or to protect the rights, property, or safety of the Company, our users, or the public.
Requests from governments, law enforcement, courts, and other public authorities are handled under our Government and Legal Request Policy, which commits us to the following. We disclose personal information to a public authority only when the law requires it. Every request is reviewed for legality before anything is disclosed: it must be in writing from a verifiable authority, cite the legal authority it relies on, be within that authority's jurisdiction, and identify the specific accounts, data, and period it covers. We refuse requests that fail that review, object to requests that are broader than necessary, and may challenge a request in court. When we do disclose, we disclose only the data the request specifically covers, through a secure channel, and we never disclose access tokens, app secrets, or other credentials. We tell the affected customer before we disclose, giving them time to object, unless the law prohibits notice, a court orders otherwise, or notice would create a risk of death or serious injury, in which case we notify them as soon as the restriction ends. We may make an emergency disclosure without legal process only where we reasonably believe there is an imminent risk of death or serious physical injury. We keep a record of every request, our review, and our response for seven years. Requests to us must be sent to support@noliai.comwith “Legal request” in the subject line.
6. International transfers
We are a United States company. Personal data is processed in the United States and, for some Services, in the European Union and other countries where our providers operate. Noli CRM and the GTM Engineer currently run on infrastructure located in Germany. Your information may be transferred to, processed, and maintained on servers and systems located outside of your state, province, or country, where the privacy laws may not be as protective as those in your jurisdiction. By using the Services, you consent to such transfer, processing, and storage in the United States and elsewhere.
For transfers from the EEA/UK to the United States, we rely on appropriate safeguards (such as the European Commission's Standard Contractual Clauses) where required.
7. Cookies and similar technologies
We use the following categories of cookies and similar technologies:
- Essential: required for authentication, session management, security, and core functionality. These cannot be disabled.
- Preferences: remember your settings (theme, language).
- Analytics: measure how users interact with the Services so we can improve them. Where required, we ask for consent before setting these.
Most browsers let you block or delete cookies via their settings. Blocking essential cookies will break the Services. Authentication cookies are scoped to .noliai.com so a single sign-in works across all our subdomains.
The specific cookies we set, their purpose, and their lifetime are listed in our Cookie Policy.
We do not currently respond to the “Do Not Track” browser setting. We do honor opt-outs you make through our preference controls and unsubscribe links, and because we do not sell or share personal information, a Global Privacy Control signal changes nothing about how we treat your data.
8. Your choices and rights
8.1 Email preferences
You can unsubscribe from marketing emails at any time using the unsubscribe link in any such email or by contacting privacy@noliai.com. You will continue to receive transactional and account communications (e.g., receipts, security alerts, service notices) while your account is active.
8.2 Access, correction, and deletion
You can access and update most account information directly within the Services, and you can download a copy of your account, plan and Chief of Staff data at any time from the Plan page in your account. To request a wider copy, a correction, or deletion of personal information beyond what you can change yourself, email privacy@noliai.com. We may need to verify your identity. After deletion, some information may remain in our archives and back-up systems until overwritten or deleted in the ordinary course of business.
8.2.1 Data deletion instructions
To delete the data Noli holds about you, including data received from a connected third-party account such as Google or Meta Threads: (1) sign in and disconnect the account from the product where you connected it (for Threads, the GTM Engineer Setup screen), which deletes the stored access token immediately; (2) to delete your Noli account and all Workspace Content, email privacy@noliai.comfrom the address on your account with the subject “Delete my data”. We confirm receipt within two (2) business days and complete deletion within thirty (30) days, subject to the retention exceptions in Section 10. If you removed Noli from your Threads account, Meta also notifies us and we delete the connection automatically; the confirmation code Meta shows you can be checked at the status page we return to Meta.
How we handle requests. We confirm receipt within ten (10) business days. We respond to a request under California law within forty-five (45) calendar days, extendable once by a further forty-five (45) days, and to a request under the GDPR or UK GDPR within one (1) month, extendable by two (2) further months for a complex request. We will tell you if we need an extension and why. To protect your information we will verify your identity, normally by confirming that you control the email address on the account and by matching details we already hold; for a request to delete or to receive a copy of specific pieces of information we may ask for more. We do not charge for a request unless it is manifestly unfounded or excessive, and we will tell you before we charge. If we decline a request, we will tell you why, and you may appeal by replying to our decision with “Appeal” in the subject line. We will decide the appeal within forty-five (45) days and tell you how to complain to your state attorney general or your supervisory authority if you are still unsatisfied.
8.3 EEA/UK (GDPR) rights
If you are in the EEA/UK, you have the right to: access the personal data we hold about you; correct inaccurate data; request deletion; restrict or object to certain processing; data portability; and where we rely on consent, withdraw your consent at any time. You also have the right to lodge a complaint with your local data protection authority. To exercise these rights, contact privacy@noliai.com.
8.4 California (CCPA / CPRA) rights
California residents have the right to request: (a) access to the categories and specific pieces of personal information we collect; (b) deletion of personal information; (c) correction of inaccurate personal information; (d) information about the categories of third parties with whom we share personal information; and (e) to opt out of any “sale” or “sharing” of personal information for cross-context behavioral advertising. We do not sell personal information as defined by the CPRA, nor do we share it for cross-context behavioral advertising. If this changes, we will update this policy and provide a “Do Not Sell or Share My Personal Information” link.
To exercise California rights, email privacy@noliai.comwith “California Privacy Request” in the subject line. We may need to verify your identity. You may use an authorized agent if they provide proof of authorization and we can verify your identity. You will not be discriminated against for exercising these rights.
8.4.2 Categories of personal information
In the last twelve months we have collected the following categories of personal information, from the sources and for the purposes shown, and have disclosed each of them for a business purpose to the categories of service providers listed in Section 5.1. We have not sold or shared any of them.
| Category | Examples | Source | Retention |
|---|---|---|---|
| Identifiers | Name, email, account ID, IP address, phone number | You, your identity provider, your connected accounts | Life of account plus the periods in Section 10 |
| Customer records | Billing address, payment token, last four digits | You, our payment processor | Life of account plus tax and accounting retention |
| Commercial information | Plan, purchases, usage, invoice history | You, our systems | Life of account plus tax and accounting retention |
| Internet or network activity | Pages viewed, features used, device, browser, crash and performance data | Automatic collection | Up to 24 months |
| Geolocation (coarse) | City or region inferred from IP | Automatic collection | Up to 24 months |
| Audio and electronic information | Voice memos, call recordings where you enable them, transcripts, text conversations, email contents from a mailbox you connect | You and your connected accounts | Life of account; recordings up to 30 days at our telephony provider |
| Professional or employment information | Job title, employer, work email, business phone for prospects you instruct us to source | Public sources and contracted data services, at your instruction | 90 days for a never-promoted prospect; otherwise your workspace rules |
| Inferences | Fit scores, summaries, and recommendations produced by AI agents | Derived from the above | Life of account |
| Sensitive personal information | Account credentials and connected access tokens; contents of email and text messages where we are not the intended recipient | You and your connected accounts | Life of the connection |
We do not knowingly collect personal information about anyone under 18. We use sensitive personal information only to provide the Services you asked for, and we do not use or disclose it for any purpose that would give rise to a right to limit its use.
8.5 Other U.S. state privacy rights
Residents of states with comprehensive privacy laws (including Colorado, Connecticut, Virginia, Utah, Texas, Oregon, and others as enacted) may have rights similar to those described above. Contact us at privacy@noliai.comto exercise applicable rights under your state's law. We do not sell personal information or process it for targeted advertising, so there is nothing to opt out of; we honor universal opt-out preference signals where a state requires it, and they change nothing about how we treat your information.
9. Security
We use technical and organizational safeguards designed to protect your information, including encryption of data in transit using TLS, encryption of stored data at the storage layer by our hosting and database providers, additional encryption of connected credentials, access tokens, and API keys, role-based access controls, managed secret storage, vendor review, and periodic review of our security practices. No method of transmission or storage is completely secure and we cannot guarantee absolute security. If we become aware of a breach of security leading to the unauthorized access, disclosure, or loss of your personal information, we will notify you and any regulator without undue delay and within the timeframes applicable law requires. If the affected information belongs to your customers, contacts, or callers rather than to you, we will notify you so that you can meet your own notification obligations, and we will provide the information you reasonably need to do so. We do not collect or use voiceprints, faceprints, or other biometric identifiers.
10. Data retention
We retain your information for as long as your account is active or as needed to provide the Services. After you cancel or terminate your account: (a) Workspace Content is retained for thirty (30) days so you may export it, we email the account owner seven (7) days before the deletion date, and you may download a copy at any time from the Plan page in your account, after which the Workspace Content is deleted from active systems; (b) account and billing information is retained for the period required by tax, accounting, and regulatory rules; (c) communications and support records are retained as needed to resolve disputes, enforce agreements, and comply with legal obligations; (d) backups containing your information are deleted in the ordinary course of business as backup tiers expire.
AI Receptionist recordings. Call recording is off unless you turn it on. If you do, callers are told, and the recording is kept by our telephony provider for up to 30 days. Call summaries, transcripts, and text conversations are Workspace Content and follow the rules above.
GTM Prospect Data. Never-promoted prospect records receive a 90-day retention deadline and are deleted by the GTM retention process when eligible. Manual consumer message drafts receive a 30-day retention deadline. A record retained as a customer contact or as durable outreach history follows the applicable workspace and legal-retention rules. A one-way suppression hash may be kept indefinitely for the sole purpose of honoring an opt-out or removal request.
You can request earlier deletion of certain categories of information by emailing privacy@noliai.com; we'll honor the request to the extent we're not required to retain the information by law.
11. Children's privacy
The Services are for businesses and are not directed to anyone under 18. We do not knowingly collect personal information from anyone under 18, and we do not knowingly collect personal information from a child under 13 as defined by the Children's Online Privacy Protection Act. If we learn that we have collected personal information from a child under 13, we will delete it promptly. If you believe a child has provided us with personal information, email privacy@noliai.com and we will delete it. Our Terms prohibit you from uploading personal information about a child under 13 into the Services, and our GTM Engineer does not target, source, or build audiences from information about minors.
12. External websites and integrations
The Services may contain links to, or allow you to connect, external websites and services not operated by us. We don't control and are not responsible for the privacy practices or content of those third parties. When you authorize an integration (e.g., Slack, Google Drive, your calendar, a mailbox, a payment account, or a social account), the third party's privacy policy and terms govern its handling of your data; we receive only the scope of access you grant and use it as described in this Privacy Policy.
13. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes to our practices or for legal, operational, or regulatory reasons. If we make material changes, we will update the “Last updated” date and, where required, provide additional notice (in-app banner, email, or both). Your continued use of the Services after the change takes effect constitutes acceptance. Previous versions of this policy are available on request.
14. Contact us
Questions, requests, or concerns? Email privacy@noliai.com.
© 2026 Noli LLC. All rights reserved. Noli AI is a product offered by Noli LLC.