Privacy Policy
Last updated: April 26, 2026
1. Who we are
Biling ("we", "us", or "our") is a social media management platform operated by the Biling team. Our service is accessible at norbiling.com and helps content creators analyze, edit, and publish video to social platforms.
2. Data we collect
We collect only what is needed to provide the service:
- Account data — your name, email address, and profile picture, provided via Clerk authentication.
- Content you upload — videos, captions, hashtags, and metadata you submit for AI analysis or publishing.
- Social account tokens — OAuth tokens issued by platforms (YouTube, Facebook, Instagram, Threads, TikTok, LinkedIn, X) when you connect an account. Tokens are encrypted at rest.
- Publishing metadata — scheduled times, target platforms, post status, and analytics pulled from connected platforms.
- Usage logs — IP address, timestamps, and basic browser information for security and rate-limiting.
3. How we use your data
- To provide AI video analysis, captioning, and clipping.
- To publish content to social platforms on your behalf when you authorize a publish action.
- To retrieve performance metrics for your published posts.
- To keep your account secure and to comply with applicable law.
We do not sell your personal data, do not use it to train third-party AI models, and do not serve advertising based on it.
4. Data sharing
We share data only with:
- Sub-processors we rely on to operate the service: Vercel (hosting), Supabase (database), Clerk (authentication), Vercel Blob (storage), Google Gemini (video analysis), Deepgram (speech-to-text), and Resend (email). Each is bound by a Data Processing Agreement and EU/US privacy frameworks where applicable.
- Social platforms you explicitly connect — we send your content to the platform you chose to publish to, using the access you granted.
- Legal authorities if required by valid legal process.
5. Data location
Personal data is processed and stored within the European Union (Helsinki, Finland for our publishing infrastructure; eu-central-1 for our database). Some sub-processors may transfer data to the United States under Standard Contractual Clauses.
6. Retention
- Account data: kept while your account is active, and up to 30 days after deletion.
- Uploaded videos and clips: kept until you delete them.
- Social tokens: kept until you disconnect the account or revoke the token.
- Logs: kept for 90 days.
7. Your rights (GDPR)
If you are in the European Economic Area, the United Kingdom, or Switzerland, you have the right to access, correct, delete, export, and restrict processing of your personal data. You can exercise these rights by emailing us at privacy@norbiling.com. You may also disconnect any social account at any time from your Biling Settings.
8. Security
All data is transmitted over TLS. Social platform tokens are encrypted at rest with AES-256-GCM. We follow least-privilege access for our infrastructure and review our security posture continuously.
9. Children
Biling is not intended for children under 16. We do not knowingly collect data from children. If you believe a child has given us data, please contact us and we will delete it.
10. Changes to this policy
We may update this policy as the service evolves. Material changes will be announced by email or in-app at least 14 days before they take effect.
11. Contact
For privacy questions, contact privacy@norbiling.com.