Nosy Pup icon
Privacy policy

Nosy Pup

Nosy Pup page·Support·[email protected]

Effective: 10 September 2026 · Operator: dataloup (Luc Mathery), Abu Dhabi, UAE · Contact: [email protected]

Nosy Pup is a social-listening tool. It finds public posts that match keywords a developer chooses, and shows them to that developer so they can decide whether to reply by hand. This policy explains what it collects, why, and what happens to it. It is written to be read, not skimmed.

1. Who this applies to

Two groups of people:

  • Users — developers who run Nosy Pup for their apps. Today that is dataloup itself; a subscription version may follow.
  • Authors — people whose public posts on Threads, Bluesky, Reddit or the App Store match a user’s keywords. Authors have no account with us and never interact with Nosy Pup directly.

2. What we collect

From authors (public content only)

When a public post matches a keyword, we store:

  • the post text and title, as published
  • the author’s public handle or display name
  • the post’s link, timestamp and platform
  • public engagement counts (likes, replies, reposts) where the platform provides them
  • for App Store reviews of a user’s own app: the review text, star rating, reviewer nickname and territory

We collect only content that is already public. We do not access private accounts, direct messages, follower lists, email addresses, locations or any data behind a login other than the user’s own.

From users

  • Account identifiers needed to run the service: platform API tokens the user supplies (stored encrypted as Cloudflare secrets), a Telegram user ID to deliver alerts, and the keywords and app descriptions the user enters.
  • Records of what the user did with each post: claimed, skipped, replied, and the text of any reply the user drafted.
  • Click counts on the user’s own campaign links (country and browser type only — no cookies, no cross-site tracking).

What we do not collect

No cookies. No advertising identifiers. No tracking pixels. No profiles of individual authors. No sale or licensing of any data to anyone.

3. How we use it

  • Triage. Each matched post is sent, together with the user’s app description, to Anthropic’s Claude API, which returns a relevance score and a suggested reply. Anthropic processes this under its API terms and does not train on API inputs. Nothing about the author beyond the public post text is sent.
  • Alerts. Posts judged relevant are delivered to the user’s private Telegram group.
  • Human replies only. Nosy Pup never posts, follows, likes, messages or otherwise acts on any platform. Every reply is written and published by a person, from their own account, under that platform’s rules.
  • Attribution. Campaign-link clicks are counted so the user can see whether replies led to installs.

4. Platform data

  • Threads (Meta). Public post data is accessed through the Threads API under Meta’s Platform Terms and Developer Policies. We request only threads_basic and threads_keyword_search. We do not store Threads data beyond the retention period below, and we honour deletion requests within 10 days.
  • Bluesky. Public posts via the AT Protocol, authenticated as the user’s own account.
  • Reddit. No automated access. Users review Reddit conversations manually through Reddit’s own tools and may log links to threads they replied to.
  • Apple App Store. A user’s own app reviews via the App Store Connect API, using the user’s own credentials.

5. Where it lives

Data is stored on Cloudflare (Workers, D1 and KV) in the European Union region. API tokens are stored as encrypted secrets and are never logged or displayed.

6. How long we keep it

  • Matched posts that a user did not reply to are deleted automatically after 90 days.
  • Posts a user replied to are kept as a record of that reply, and deleted when the user’s account is closed.
  • Users may delete any stored post at any time; authors may request deletion of their content at any time (section 8).
  • Click logs are aggregated after 12 months and the raw records deleted.

7. Who we share with

  • Anthropic (triage, as above), Cloudflare (hosting), Telegram (alert delivery), and Apple, Meta and Bluesky as the platforms the data comes from — each only to the extent needed to provide the service.
  • No advertisers, no data brokers, no resale, ever.
  • We will disclose data if legally required and will tell the affected user unless prohibited.

8. Your rights

Authors: if a public post of yours is stored by Nosy Pup and you would like it removed, email [email protected] with the post link. We delete it within 10 days, no questions.

Users: you can export or delete everything we hold about you by emailing the same address. Deletion closes the account and removes all stored posts, replies and tokens within 10 days.

If you are in the EU/UK you have the rights set out in the GDPR, including access, correction, erasure, restriction and portability, and the right to complain to your data-protection authority. We act as the data controller for the data described here.

9. Children

Nosy Pup is a professional tool for developers and is not directed at anyone under 18.

10. Changes

We will post changes here with a new effective date. Material changes will be announced to users in their alert channel before they take effect.

11. Contact

[email protected] · dataloup, Abu Dhabi, United Arab Emirates