Privacy Policy
Last updated: 9/8/2026
This policy explains how NiceCode collects, uses and protects your data when you use the website, the Automation Labs — Auto Flow extension and Scene Studio. The guiding principle: we collect only what is needed to run your account and payments; your creative content stays on your machine.
1. Data we collect
To run your account, quotas, credits and payments, NiceCode stores:
- Email address — encrypted with AES-256-GCM at rest; lookups use a hash of the email, never the readable address.
- Device ID and device name generated by the extension or Scene Studio, plus each device's last activity time.
- Jobs used per day (a count only, with no job content).
- Credit balance and credit transaction history (grants, deductions, refunds) — character counts only, no text.
- Payment orders: order code, plan, amount, status and timestamps. NiceCode never receives or stores card details — the payment provider handles that entirely. For domestic bank transfers the money arrives directly in NiceCode's bank account, so we do see the sender name and transfer note supplied by the bank.
- Display preferences: language and currency (the lang and al_cur cookies).
- When an OTP is sent, your IP address is salted, hashed and kept for at most 1 day to prevent abuse; the readable IP is not stored.
2. Data we do NOT collect
NiceCode does not receive, store or have any database table for: your prompts, the images or videos you generate, project IDs or the contents of Google Flow pages, or the scripts, images and audio you load into Scene Studio. The extension runs entirely in your browser; Scene Studio processes everything on your machine.
Text you send for voice-over goes directly from Scene Studio to the TTS engine to produce audio and is not stored by NiceCode. NiceCode's server only records the character count to deduct credits.
3. Cookies and local storage
Your website sign-in token is kept in the browser's localStorage to maintain your session; the extension and Scene Studio keep their tokens in their own storage. Signing out deletes the token.
The website uses two preference cookies: lang (language) and al_cur (currency). There are no advertising cookies and no third-party trackers.
To pick the right display currency, your browser calls a third-party IP geolocation service (identify.tpro.vn) and uses only the returned country code. NiceCode does not receive or store your IP address from this step; you can change the currency with the switcher in the footer.
4. Third parties that process data
NiceCode shares data only with the providers needed to run the service, and only the minimum each one needs:
- Payment providers — SePay reads balance-change notifications on NiceCode's bank account to confirm domestic orders; PayPal processes international payments (order code, amount, short description, and your email where the provider requires it). USDT payments involve no third party — NiceCode reconciles the transaction on the public blockchain.
- Email delivery provider — sending OTP codes to your email address.
- Hosting and database infrastructure (Vercel, Neon) — running the server and storing the data listed in section 1.
- TTS engines — receiving text to generate voice-over, as described in section 2.
NiceCode does not sell user data and does not share it for advertising purposes.
5. Retention and deletion
Daily job counts older than 90 days and expired OTP codes are purged periodically. Device records are deleted when you remove a device or sign out.
You can request deletion of your entire account by emailing nicecode2025@gmail.com from your registered address. Any remaining credits and Pro time are lost with the account and are not refunded.
Payment records are retained for as long as accounting and tax obligations require, including after an account is deleted.
6. Security
Sign-in tokens are stored on the server only as SHA-256 hashes; email addresses are encrypted at rest; TTS engine API keys are encrypted at rest and wrapped in an additional layer of encryption in transit to Scene Studio. All connections use HTTPS. No measure is absolute, but NiceCode designs the system so that as little data as possible could be exposed in an incident.
7. Your rights
You have the right to access, correct and delete your data. Devices, plan and credit history are available on your Account page; for other requests (data export, account deletion, complaints) email nicecode2025@gmail.com — NiceCode responds within 30 days.
8. Children
The service is not intended for anyone under 16. If we learn that an account belongs to a child under 16, NiceCode will delete the account and the associated data.
9. Changes to this policy and contact
This policy may be updated; the new version is posted on the website with its update date. Material changes to how data is used will be announced by email.
Privacy questions: nicecode2025@gmail.com. In case of any discrepancy between the Vietnamese and English versions, the Vietnamese version prevails.