← noctive

privacy policy

Effective September 7, 2026

Noctive is a campaign planning and execution tool for independent musicians. This describes how the product actually works today — not what it might do later.

Who we are

Noctive operates the Noctive web application and is based in the United States. Reach us at support@noctive.io.

What we collect

Your account. Email address and artist name. Authentication is handled by our infrastructure provider — we never see or store your password.

What you tell us. Your onboarding answers: career stage, goals, genre, strengths, constraints, reference artists, working style. This is what lets Noctive plan a campaign that fits you.

Your campaigns. Releases, tracklists, tasks, schedules, the text Noctive generates for you, and records of creators you track.

Technical data. Standard server logs — IP address, browser, device and session information — kept to run the service and diagnose problems.

Payment. Stripe processes payments. We store your Stripe identifiers and subscription status. We never receive your card number.

Accounts you connect

Nothing is connected by default. When you connect an account, we store its access token and the identifiers needed to act on your behalf.

Meta. An access token plus your ad account, Facebook Page, Instagram account and pixel identifiers — used only to build and manage advertising you ask for. Noctive creates every campaign, ad set and ad paused; nothing is activated and no money is spent without your explicit confirmation. We do not post to your Page or Instagram, and we do not read your personal Facebook profile, messages, or friends.

Spotify. Access and refresh tokens and your artist identifier, used to read performance data about your own music.

Disconnect any of them inside Noctive and the stored token is deleted immediately. You can also revoke access from the service itself — for Meta, under Settings & privacy → Settings → Business Integrations.

How we use it

To run the product, act on services you have connected when you ask, manage your subscription, contact you about your account, and keep the service secure.

We do not sell your personal information, do not share it with advertisers or data brokers, and do not use your campaign content to train AI models.

AI processing

Noctive uses a third-party AI model provider to generate campaign plans and draft text. The relevant parts of your profile and campaign are sent to that provider to produce the output, and processed only to return it. Under our agreement with them, your data is not used to train their models.

AI output is a draft — always saved to your account and shown to you first.

Who else handles your data

Where your own money or your own connected account is involved, we name the provider:

  • Stripe — payments
  • Meta — advertising, if you connect it
  • Spotify — artist data, if you connect it

We also rely on providers for cloud hosting and database, music performance metrics, and the AI generation described above. Email us and we will name them.

We may also disclose information where legally required, or in a merger or acquisition — in which case this policy continues to apply to your data.

Cookies

We use cookies only to keep you signed in and to keep the app working. We do not run advertising or tracking cookies, and we do not use third-party analytics. Blocking cookies will stop you being able to sign in.

Where your data is processed

Noctive is operated from the United States, and our providers may process data in other countries. Wherever it is processed, it is handled under this policy.

Keeping and deleting your data

We keep your data for as long as your account exists. Tokens are deleted when you disconnect an account.

To delete everything: email support@noctive.io from your account address and ask. We delete your profile, campaigns, generated content and stored tokens, and confirm when it is done.

Data may persist briefly in routine backups after deletion, and we keep what tax and accounting rules require.

Your rights

You can access, correct, export or delete your personal data, restrict or object to how we use it, and withdraw consent at any time. Depending on where you live you may have further rights, including the right to ask us not to sell your data — which we do not do.

Email support@noctive.io to exercise any of these and we will act on it.

Security

Data is encrypted in transit. Access is restricted to your own account through database-level row security, and tokens for connected services are stored server-side, never exposed to the browser.

No system is perfectly secure. If we become aware of a breach affecting your information, we will tell you.

Children

Noctive is not intended for anyone under 16 and we do not knowingly collect their information. If you believe a child has given us data, email us and we will delete it.

Changes

If we change this policy we will update the effective date above, and tell you directly if the change is significant.

Contact

Questions, requests, or complaints: support@noctive.io.

noctive