Privacy Policy
Last updated: September 15, 2026
This policy explains how NudeBot (app.nudebot.net, the “service”) handles user data. The service is intended for adults aged 18 and over only. By using the service you agree to this policy and the Terms of Service.
Data we collect
- Account data: email address and a password hash (the password itself is never stored), your Telegram ID if you sign in with Telegram, your Google account ID and email if you sign in with Google, and your interface language.
- Purchase data: order number, package, amount, status and token transaction history. Card details are handled by the payment provider; the service never receives or stores them.
- Generation data: chosen scene, status, cost, time, and a technical fingerprint of the uploaded image (for abuse prevention).
- A partner code, if you arrived through a partner link.
- Technical data: IP address (to protect against password guessing and abuse), browser and device type.
Sign in with Google
When you sign in with Google, the service requests only basic data: your account ID, email address and whether it is verified. This data is used solely to sign you in and to contact you about your account. We do not access your emails, files, contacts or any other Google account data, we do not sell Google user data, and we do not share it with third parties except where required by law. Our use of this data complies with the Google API Services User Data Policy, including the Limited Use requirements.
Uploaded photos and results
- An uploaded photo is sent to an AI processing provider only to perform the generation you requested.
- Original uploads are kept on temporary file storage for no longer than 72 hours and are deleted automatically.
- A generation result is available for download for 3 hours; the history entry and an archived copy of the result are kept for up to 14 days and then deleted.
- The service never publishes your photos or results and never uses them for advertising.
Cookies and analytics
- kadr_session — keeps you signed in.
- kadr_lang — your chosen language (1 year).
- kadr_ref — partner code (90 days).
- kadr_gstate — protects the Google sign-in flow (10 minutes).
- Yandex Metrica (including Session Replay), Google Analytics 4 and Google Tag Manager — aggregated visit statistics. Areas showing uploaded photos or results, and password fields, are excluded from session recordings.
Who we share data with
- The AI processing provider — the uploaded photo and generation settings.
- The payment provider — the data needed to process a payment.
- Telegram — if you sign in with Telegram or receive a result in the bot.
- Google — if you sign in with Google.
- Hosting, CDN (Cloudflare) and analytics providers — to the extent needed to run the service.
We do not sell personal data.
Retention and your rights
Account data is kept for as long as the account exists. You can request a copy of your data, its correction, or deletion of your account together with all associated data.
Changes to this policy
We may update this policy; the current version is always available on this page with its update date.