Privacy Policy
- Effective
- 2026-08-26
- Last updated
- 2026-08-26
- Version
- privacy-v4
WishWell LLC, a Virginia limited liability company doing business as Noet (“WishWell,” “Noet,” “we,” “us,” or “our”), provides creator software and creator-controlled public gear pages.
This Privacy Policy explains how we collect, use, disclose, retain, and protect information when you visit Noet, create an account, connect Google or YouTube, submit or upload material, purchase a subscription, publish a page, use a public creator page, or contact us.
It should be read with the Terms of Service. If this Policy and the Terms conflict on a privacy point, this Policy controls for that point.
Noet uses YouTube API Services. Use of YouTube-connected features is also subject to the YouTube Terms of Service at https://www.youtube.com/t/terms . Google’s processing is described in the Google Privacy Policy at https://policies.google.com/privacy .
Noet’s use of information received from Google APIs will adhere to the Google API Services User Data Policy at https://developers.google.com/terms/api-services-user-data-policy , including the Limited Use requirements.
1. Who this Policy covers
This Policy covers creators who create accounts, connect services, upload material, or subscribe; visitors to public Noet pages, including public creator storefronts; and reporters who submit a rights, privacy, or image report.
Paid subscriptions are offered only in the United States. Incidental visits from elsewhere do not expand the paid launch and do not, by themselves, mean WishWell is established in that place.
Depending on how you use Noet, we may collect the following categories of personal information:
- Identifiers: name, email, Google user ID, IP address, account IDs. Sources: you, Google, automatic. Typical recipients: providers listed in the Service providers section; you, if you publish.
- Commercial information: plan, allowance, invoices, payment outcome. Sources: you, Stripe. Typical recipients: Stripe; hosting and database providers.
- Internet or network activity: logs, security events, requested pages, limited outbound-link events. Source: automatic. Typical recipients: hosting, bot protection, database.
- User content: transcripts, review decisions, Uploaded Images, page copy. Source: you. Typical recipients: hosting and storage; OpenAI for normalized transcript only; the public if you publish.
- Professional information: channel name, video identifiers you connect. Sources: you, YouTube API. Typical recipients: Google/YouTube; the public if you publish.
- Inferences: automated product candidates and confidence. Source: derived from your content. Stored for your review; public only if you publish.
We do not collect Social Security numbers, government ID images, precise geolocation for advertising, or payment-card PAN/CVC into Noet systems. Stripe may collect payment details under its policy.
2. Information you provide
- Account and profile information: name, email address, authentication identifier, creator or channel name, settings, and communications.
- Creator-authorized content and instructions: channel and video identifiers, URLs, transcript text, product selections, approvals, corrections, ordering, page settings, and publication choices.
- Transcript files: if you upload a supported caption or transcript file (for example .vtt, .srt, .sbv, .ttml, or .txt), we receive the file. Launch processing normalizes the text and is designed to discard original uploaded bytes and filenames. Normalized evidence and minimal audit metadata remain until the applicable video or account deletion process.
- Product-card images: if you upload a photo or other image for a product card, we collect the image file, file type, size, a content hash, the uploading account, the related card, timestamps, and the required ownership attestation. We store the file to display it on your cards and related Service pages, to secure and troubleshoot the Service, and to handle rights reports. We delete or hide it with the card or account lifecycle, subject to the retention section. We do not use Uploaded Images to train a general-purpose model. We do not treat Amazon listing images or other retailer Program Content as your photo.
- Affiliate-network identifiers you supply so Noet can build creator-controlled links. Product records store a bare product identifier (for example an ASIN). Your affiliate identifier is applied in application code when a link is generated. Affiliate identifiers are not sent to language models.
- Support, privacy, billing, rights, and security reports and the supporting information you choose to provide. Do not send passwords, complete payment-card numbers, or unnecessary government identity documents.
- Attestations and consents: 18-or-older attestation, Terms acceptance, Privacy acknowledgment, upload attestations, and Checkout acknowledgments, with version, time, and account context.
We do not ask for your YouTube, Google, Amazon, or Stripe password. We do not need to store complete card numbers or card security codes; Stripe processes those.
3. Google identity information
Identity login and YouTube authorization are separate.
When you sign in with Google, we receive the information Google provides for that identity flow, typically an email address, name, Google user identifier, and tokens needed to keep the session authenticated. We use that information to create and authenticate your Noet account, contact you, and secure the Service.
We request only scopes used by the shipped product. We do not use Google identity data for advertising, credit decisions, or training a general-purpose model.
4. YouTube information (YouTube API Services)
Noet uses YouTube API Services to verify the creator’s channel and to confirm that a submitted video belongs to that channel. At launch, that connection uses read-only YouTube authorization. Owner-caption access through YouTube OAuth is disabled unless separately approved, implemented, and disclosed.
4.1 What we access, collect, and store
Within the permissions you grant, Noet may access and store channel identifiers and names needed to verify control of the channel; video identifiers, titles, and related metadata needed to confirm that a submitted video belongs to that channel and to display authorized video references; OAuth tokens required to maintain or refresh that authorization; and timestamps and other API data strictly required for the feature you request.
Noet does not obtain or store your YouTube password. Launch extraction does not pull captions through YouTube. It uses text you paste or a transcript file you upload.
If Noet later displays YouTube thumbnails or channel art retrieved through the API, those assets are YouTube API Data. They will be retrieved through official APIs, identified as YouTube-sourced where required, stored as identifiers or authorized URLs rather than as a substitute YouTube service, and refreshed or deleted under YouTube’s storage rules.
4.2 How we use, process, and share it
We use YouTube Authorized Data only to provide the user-facing features you request: verify channel and video ownership, show authorized video references on your private review tools and, if you publish, on your creator-controlled pages, and secure the account.
We do not sell YouTube API Data. We do not use it for advertising. We do not use it to train a general-purpose model. We do not send YouTube audiovisual content or YouTube-downloaded caption files to OpenAI. Launch model input is normalized creator-supplied transcript evidence, with affiliate identifiers, account email, internal account IDs, provider credentials, and private URLs excluded.
If we later enable owner-caption access or any other new use of YouTube API Data that this Policy did not cover when you authorized the connection, we will update this Policy and ask you to consent before that use.
4.3 Revocation, Google settings, and deletion
You may revoke Noet’s access through available Noet connection controls or through Google’s security settings page at https://security.google.com/settings/security/permissions .
After you revoke consent through that page, or after you delete your Noet account, we delete stored YouTube Authorized Data that was accessed or stored pursuant to that consent as soon as possible and within seven calendar days, except where a specific legal requirement requires a longer hold.
If an authorization token cannot be refreshed, we delete associated API Data as soon as possible and within thirty calendar days, consistent with YouTube’s stored-data rules.
You may also request deletion of stored data related to you by emailing privacy@takenoet.com or using available in-product deletion controls. We will delete that stored data as soon as possible and within seven calendar days, subject to the lawful-retention exceptions in the retention section.
Deleting data from Noet does not delete data maintained by YouTube or Google.
We periodically reconfirm that authorization tokens remain valid.
4.4 YouTube player and third-party content
If a Noet page embeds a YouTube player, YouTube or Google may collect device and playback information, set cookies or similar technology, and serve advertisements according to their policies, including in connection with playback. WishWell does not control YouTube’s player, ads, or cookies. That is third-party content served on or through the page.
Noet does not use third-party advertising cookies of its own at launch.
4.5 Optional Noet browser extension
If Noet makes its browser extension available and you invoke it on a supported YouTube video tab, the extension temporarily reads the active tab’s URL locally, accepts only supported HTTPS YouTube video URLs, extracts one validated 11-character YouTube video ID, and transfers only that ID to Noet through HTTPS navigation.
The extension does not transfer the complete URL, other query parameters, fragments, credentials, ports, page content, captions, transcripts, browser-history database, clipboard, unrelated tabs, identity, cookies, or extension analytics. It does temporarily handle the active-tab URL after your click and is not described as handling “no data.”
Opening Noet does not itself submit, store, identify, process, consume allowance for, or bill a video. You must explicitly continue through authenticated intake. Ordinary Noet authentication and account activity after navigation are separate from the extension’s narrow extraction. Extension distribution remains unavailable until the Store listing, in-product disclosure, data category, Limited Use statement, package, and installed flow match the shipped behavior.
5. Information generated through the Service
- Authentication sessions, security events, consent and attestation records, and account-lifecycle state.
- Automated product candidates, categories, source relationships, timestamps, evidence, model and prompt-version provenance, creator review decisions, and publication state.
- Subscription plan, allowance, qualification, renewal, invoice, refund, payment outcome, and Stripe customer or subscription references.
- Operational request, diagnostic, abuse-prevention, and job information needed to secure and run the Service.
- Public referral reporting, if offered, is aggregate and does not disclose creator identities, emails, IP addresses, or private activity to a referrer.
To prevent reuse of a consumed one-time trial, Noet may retain a protected keyed value derived after successful trial use. It does not contain the raw channel ID, account ID, email, transcript, content, referral identity, or provider token, and it is not available to creators or referrers. We retain it only for that anti-abuse purpose.
6. Visitors to public pages
If you visit a public Noet page without an account, we may collect IP address, browser and device type, timestamps, requested URLs, and security or bot-protection signals; limited outbound-link or page-request events needed to render, secure, and measure a creator-controlled page; and information you choose to submit on /rights, /report-image, or a contact form.
We do not use visitor information for cross-context behavioral advertising at launch. We do not sell it. Creator pages may contain affiliate links; those links send the visitor to the retailer. The retailer has its own privacy policy.
7. How we use information
- Authenticate users, verify creator authority, and provide private review tools.
- Process creator-authorized evidence and propose products and supporting provenance.
- Host and display Uploaded Images and published pages you choose to make public.
- Operate subscriptions, allowance, cancellation, export, deletion, customer service, and required notices.
- Send transactional email when that feature is enabled (for example account, security, billing, or Founding welcome messages).
- Secure Noet, prevent fraud and repeat trial abuse, troubleshoot failures, preserve audit evidence, and enforce agreements.
- Comply with law and protect users, WishWell, providers, and third parties.
We do not use personal information for cross-context behavioral advertising at launch. We do not sell personal information for money.
8. Automated processing and Limited Use
Noet uses automated systems, including the OpenAI API, to analyze one creator-authorized video’s normalized evidence at a time and propose product information for the creator’s review. Requests disable optional Responses API application-state storage with store: false. That setting does not promise zero provider retention. Provider processing and abuse-monitoring terms still apply. OpenAI states that API data is not used to train its models unless the customer opts in; standard abuse-monitoring logs may retain customer content for up to 30 days unless different approved data controls apply.
Noet excludes affiliate identifiers, account email, internal account IDs, provider credentials, private URLs, and raw affiliate destinations from language-model input. Automated output remains private until the creator’s page and eligible products are separately published.
Limited Use. Noet’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. That means, among other things: we use Google and YouTube user data to provide or improve prominent user-facing features in Noet (authentication, channel and video verification, and authorized display of creator-controlled pages); we do not use that data for serving ads, including retargeting, personalized, or interest-based advertising; we do not use it to determine credit-worthiness; we do not transfer it except as needed to provide those features, for security, to comply with law, or as part of a business transaction as described below; and we do not use it to train a general-purpose or non-personalized AI/ML model.
WishWell does not use creator-identifiable content or review decisions to train a general-purpose model. No optional improvement program is represented as available unless Noet separately presents an initially-off control and disclosure that match the shipped scope, retention, exclusions, withdrawal, and deletion behavior.
9. When information is disclosed
- To service providers that process data for us, limited to what they need for the Service, as listed in the Service providers section.
- To Google or YouTube for requested API, player, or authorization features.
- To Stripe for authorized payment and billing activity.
- At your direction, after separate overall-page and product-publication requirements are satisfied (your published page is public).
- For lawful process, safety, rights protection, fraud prevention, or a merger, financing, acquisition, reorganization, or sale of assets, subject to appropriate confidentiality and, where required, notice or consent.
- With your consent.
WishWell does not sell personal information as “sale” is commonly understood (disclosure for money). WishWell does not share personal information for cross-context behavioral advertising at launch. If that changes, this Policy and any required opt-out will be updated first.
If a rights or image report is filed, we may share limited information with the authenticated creator who published the material, unless that would be prohibited or unsafe, so they can respond or remove it.
10. Retention, offboarding, and deletion
WishWell retains each category only as reasonably necessary for the disclosed purposes, including providing and securing the Service, administering billing, resolving disputes, preventing fraud, and meeting legal obligations.
- Account, profile, private catalog, published pages, and Uploaded Images: while needed to provide the active Service; then deactivation, hiding, and provider-removal under the implemented lifecycle.
- Normalized transcript evidence: until the related video or account is deleted under this Policy.
- YouTube Authorized Data after revocation or account deletion: as soon as possible and within 7 calendar days, unless a specific legal requirement requires a longer hold.
- YouTube API Data associated with tokens that cannot be refreshed: as soon as possible and within 30 calendar days.
- Stripe billing, invoice, tax, dispute, and similar financial records: for the operationally justified or legally required period applicable to those records.
- Security, fraud-prevention, legal-hold, and rights-report evidence: for the period needed to investigate, defend, or comply, then deletion or secure archival.
- Trial anti-abuse keyed value: only for the documented anti-abuse purpose.
- Backups: until expiration under the production backup cycle. This Policy does not invent a backup-day count until that cycle is operationally verified.
Voluntary deletion is designed to deactivate the account, hide public material, stop processing, and proceed through provider-removal and backup handling. Signing in alone does not restore a deactivated account.
Exact universal restoration clocks, other than the YouTube Authorized Data periods above, are not promised until those production paths are verified. If a specific additional deadline is later proven, this Policy will be updated to match it.
11. Service providers
- Hosting: Vercel processes site requests, IP/device, and diagnostic data.
- Database, object storage, and authentication: Supabase processes account, creator, content, Uploaded Images, entitlement, consent, and security data.
- Payments: Stripe processes billing contact, location, subscription, invoice, tax, and payment data. Stripe processes full card details.
- Automated extraction: OpenAI API receives one normalized transcript and generated product candidates per request with store: false; abuse-monitoring may retain content up to 30 days.
- Background jobs: Inngest processes opaque job/event identifiers and minimum task data.
- Bot protection: Cloudflare Turnstile processes network, browser, and challenge data when that public Auth method is enabled.
- Identity and YouTube: Google / YouTube API Services process OAuth tokens and authorized identity, channel, and video data, and embedded playback if used.
- Transactional email: Resend, when that feature is enabled, processes destination address, message content, and delivery events (sent, bounce, complaint). Marketing tracking pixels are not used unless this Policy is updated first.
We may replace a provider with a successor that performs the same function. A material new category of recipient will be added to this Policy before that use is represented as current.
Human access to user content is limited to providing the Service, security and abuse investigation, complying with law, or as otherwise allowed under Limited Use and this Policy.
12. Cookies and browser signals
Noet uses cookies or similar storage that are necessary to authenticate a session, maintain security, and complete a payment flow.
Noet does not currently use cookies to persist optional UI preferences or to attribute referrals across visits. If those cookies are later added, this Policy will be updated first.
Noet does not use third-party advertising cookies at launch. If nonessential tracking is later added, this Policy and any required consent or opt-out will be updated before that use begins.
If a page embeds a YouTube player, YouTube/Google may set their own cookies as described in the YouTube player section.
Noet does not currently treat a browser “Do Not Track” signal as a request to disable the strictly necessary authentication, security, or payment-flow functions described above. Noet does not represent that it collects browsing activity over time across unrelated third-party sites. If Noet begins processing a legally recognized browser-based privacy signal for an applicable opt-out right, this Policy and the implemented control will be updated together before that processing is represented publicly.
California residents: this section is intended to describe our Do Not Track posture as required for a posted policy.
13. Your choices and privacy rights
- Access or correct account and creator-controlled information.
- Approve, reject, correct, reorder, publish, or unpublish eligible creator material.
- Replace or remove an Uploaded Image using available product-card controls.
- Cancel through the Stripe Customer Portal.
- Revoke Google or YouTube authorization as described in the YouTube deletion section.
- Request a portable export before the applicable cutoff.
- Request account and personal-data deletion, subject to lawful retention.
- If you have opted into a separately offered improvement program, withdraw that consent.
Depending on applicable law, you may also have rights to know, access, correction, deletion, portability, restriction, objection, withdrawal of consent, appeal, or to opt out of sale or sharing. WishWell does not sell personal information or share it for cross-context behavioral advertising at launch, so there is no separate “Do Not Sell or Share” control at this time.
Send requests to privacy@takenoet.com. WishWell may verify a request proportionately (for example by requiring that it come from the account email or an authenticated session). We will respond within the period required by applicable law and will not discriminate against you for exercising a privacy right.
If we deny a request and applicable law provides an appeal, email privacy@takenoet.com with the subject “Privacy appeal,” explain why you disagree, and we will review and respond.
We cannot fulfill a request that would interfere with another person’s rights, with a legal hold, or with records we must keep for billing, tax, security, or fraud prevention.
California “Shine the Light”: we do not disclose personal information to third parties for their own direct marketing. If that changes, this Policy will be updated.
14. Export scope
An authenticated, short-lived export may include creator-owned catalog and storefront data, videos, timestamps, approved excerpts, normalized transcript evidence, account and storefront settings, affiliate identifiers, consent and entitlement history, and aggregate analytics. It excludes passwords, cookies, tokens, provider credentials, service secrets, internal security logs, other people’s data, and raw Uploaded Image binaries except where an available export actually includes them. If image files are included, the export will say so.
15. Children
Noet creator accounts and paid subscriptions are only for people at least 18 years old. Noet is not directed to people under 18 and does not knowingly collect personal information from children under 13.
If WishWell learns that a creator is a minor, the account is suspended and renewal is stopped. Personal information is then deleted as appropriate, subject to lawful billing, security, fraud-prevention, backup, and record-retention requirements. If you believe a child provided personal information, contact privacy@takenoet.com.
Public pages may be viewed by anyone. They are general-audience pages, not directed to children. If Noet embeds a video designated “Made for Kids,” the implementation must apply YouTube’s required tracking restrictions. That embedding path is not represented as available until it is implemented and this Policy is updated if needed.
There is no kids-product-card photo path. Uploaded Images are part of an 18+ creator account.
16. International use
Paid subscriptions are offered only in the United States at launch. We do not market or sell paid subscriptions outside the United States until tax, privacy, consumer-contract, transfer, and local-representative requirements are reviewed.
Information may be processed in the United States by WishWell and its providers. If you access Noet from another country, you understand that your information is processed in the United States.
17. Security
WishWell uses administrative, technical, and organizational measures designed to protect information, including access controls, encryption in transit for the public site, and least-privilege provider access where configured. No method of storage or transmission is completely secure. We cannot guarantee absolute security.
Report suspected account compromise or a security concern to legal@takenoet.com.
18. Changes
WishWell may update this Policy prospectively. Material changes will be communicated through Noet or email to the address on the account before they take effect. If we start to access, collect, or use Google or YouTube user data in a way this Policy did not cover, we will update this Policy and prompt consent before that use.
The Last updated date identifies the current version.
19. Contact
Questions about this Policy, privacy practices, or data requests:
Privacy and data requests: privacy@takenoet.com
Security reports: legal@takenoet.com
Support: support@takenoet.com
Rights and copyright: /rights and legal@takenoet.com
Product-card photos: /report-image or legal@takenoet.com with subject “Report this image”
Mailing address: WishWell LLC d/b/a Noet, 9480 Main St #1162, Fairfax, VA 22031
This mailing address is a public mailing and contact address. It is not WishWell’s physical office, headquarters, operating location, registered office, or a residence.
If you have questions about Noet’s privacy practices and cannot reach us through the contacts above, YouTube’s policies provide that YouTube may share a developer contact with users in some cases. The contacts in this section are the intended channel.
Privacy and data requests: privacy@takenoet.com