Orange Nuts, developed by KheniTech ("we", "our", or "us"), is a social content creation app that helps you build brands, generate social media posts with AI, and manage your business projects. This Privacy Policy explains what information we collect, how we use it, and your rights over your data.
1. Information We Collect
- Account information: When you sign in with Google or Apple, we receive your name, email address, and profile photo. We do not receive your password.
- Content you create: Projects (ventures), brand profiles, AI-generated social posts, uploaded images, and captions you create within the app are stored in your account.
- Profile photo: If you change your profile picture inside the app, the image is uploaded to Firebase Storage and linked to your account.
- Device & usage data: We use Google Analytics for Firebase to collect aggregated usage data — app opens, screen views, feature usage events, a random app-instance identifier, device model and OS version, and approximate (city-level) location derived from your IP address. This data helps us understand how the app is used and improve it. It is not linked to your name or email and is never used for advertising. On iOS, we do not access the advertising identifier (IDFA). On Android, a separate identifier — the Google Advertising ID — is shared with Meta for app-install attribution; see the next item.
- Advertising identifiers (Meta app-install attribution): To measure how effective our app-install ads are, Orange Nuts uses Meta's SDK. On Android, this SDK reads your device's Google Advertising ID (GAID) and shares it with Meta Platforms, Inc. for app-install attribution — this is real, device-level ad data shared with a third party. On iOS, we do not collect the IDFA and do not show Apple's App Tracking Transparency prompt; attribution instead uses Apple's SKAdNetwork, which does not identify you or your device. On iOS, the Meta SDK also sends app install and launch events to Meta using an app-scoped identifier that is not the IDFA. You can opt out on Android at any time via Settings → Google → Ads → "Delete advertising ID."
2. Camera and Photo Library Access
Orange Nuts requests access to your camera and photo library solely to let you upload images for your social posts, brand logos, project icons, and profile picture. We do not scan, analyze, or share your photos. Images you choose to upload are stored in Firebase Storage under your account and are only used to display within the app.
3. How We Use Your Information
- To authenticate your identity and maintain your session.
- To store and display the content you create (posts, brands, projects).
- To generate AI-assisted content using the details you provide about your brand.
- To understand aggregate app usage and improve features (anonymous analytics).
We do not sell or rent your personal information. Firebase Analytics data (see Section 1) is not shared with third parties for advertising or marketing purposes. The one exception is app-install attribution: on Android, the Google Advertising ID is shared with Meta Platforms, Inc. for this purpose (see "Advertising identifiers" in Section 1). On iOS, no advertising identifier is collected or shared.
4. AI Content Generation
Orange Nuts uses the Base44 AI service to generate post captions, brand profiles, and images based on prompts you provide. Input you submit to the AI (brand names, descriptions, tone) is processed by Base44's servers to generate output. Please do not include sensitive personal information in AI prompts.
5. Data Storage and Security
- All data is stored in Google Firebase (Firestore database and Cloud Storage), hosted in the United States (us-central multi-region).
- Access to your data requires authentication — other users cannot read your private posts, brands, or projects.
- Posts you explicitly mark as public are visible to other signed-in users in the Feed.
- Uploaded images are stored in Firebase Storage, which uses Google-managed encryption at rest.
6. Third-Party Services
- Google Firebase — authentication, database, storage, and cloud functions.
- Google Sign-In — sign-in authentication (scopes: profile, email).
- Apple Sign-In — sign-in authentication on iOS (scopes: name, email).
- Google Analytics for Firebase — aggregated, anonymous usage statistics (see "Device & usage data" above).
- Base44 — AI text and image generation.
- Meta Platforms, Inc. (Meta Ads SDK) — app-install ad attribution. On Android, shares your device's Google Advertising ID with Meta. On iOS, no advertising identifier is collected and no App Tracking Transparency prompt is shown; the Meta SDK also sends app install and launch events to Meta using an app-scoped identifier that is not the IDFA.
- Firebase Crashlytics — We use Firebase Crashlytics to collect crash reports and error diagnostics, including device model, OS version, and the sequence of events leading to a crash. These reports are associated with your account so we can investigate issues you report to us. They are never used for advertising.
None of these services receive your posts, brand details, captions, or other content for advertising or profiling purposes. On Android, the Meta Ads SDK receives a device-level advertising identifier (the Google Advertising ID) for install-attribution purposes. On iOS, the Meta Ads SDK also sends app install and launch events to Meta using an app-scoped identifier that is not the IDFA — never your account content, on either platform.
7. Data Retention
Your data is retained for as long as your account is active. When you delete your account (see below), all your data is permanently deleted. We do not retain backups of deleted user data.
8. Account and Data Deletion
You can permanently delete your account and all associated data directly within the app:
- Go to Profile (bottom navigation bar, rightmost tab).
- Scroll to the bottom and tap Delete Account.
- Confirm the deletion in the dialog.
This action permanently deletes your sign-in account, all your projects, brands, posts, uploaded images, and profile photo. It cannot be undone. If deletion fails due to a session expiry, sign out and sign back in before trying again.
9. Children's Privacy
Orange Nuts is intended exclusively for adults aged 18 and over. It is not directed at children, and we do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us information, please contact us and we will delete it and terminate the account.
10. Your Rights
You have the right to access, correct, or delete your personal information. You can:
- Edit your display name and profile photo directly in the app.
- Delete individual posts from the app.
- Delete your entire account and all data in-app (see Section 8).
- Revoke Google or Apple sign-in access from your respective account settings.
- On Android, opt out of the Google Advertising ID used for Meta attribution any time via Settings → Google → Ads → "Delete advertising ID."
- Contact us at the address below for any other data requests.
11. Changes to This Policy
We may update this Privacy Policy from time to time. The "Last updated" date at the top reflects any changes. Continued use of the app after changes constitutes acceptance of the updated policy.