Privacy policy
Version September 9, 2026
Controller and purposes
Jonathan Amsellem, 124 boulevard de Rochechouart, 75018 Paris, France, is the contact responsible for Nocha’s data processing: contact@nocha.world.
Account information, access rights, creations, saved content and requested operations are used to provide the service. Security logs, decisions and reports are used to prevent abuse and handle appeals. Purchase information and supporting records are used to allocate credits and meet applicable accounting obligations.
Legal bases depend on the purpose: performance of the requested service, legal obligations, legitimate interests in securing the service and handling abuse, or consent where required for an optional transfer or permission. Refusing an optional feature does not authorise another transfer.
Data and recipients
Watchirl provides identity, the wallet, provider access and shared assets; Tripirl handles some media. These are platform services. Your public profile contains your opaque identifier and your chosen handle, public name and avatar, never a name inferred from your email address.
Preparation and Studio use OpenRouter with the selected agent and model: Codex with OpenAI, Claude with Anthropic, or OpenCode with Z.AI. Your conversation limit covers discussion, plan preparation, repairs and context compaction. AI and media features use the providers actually selected by Watchirl. Before a transfer requiring your agreement, the Nocha dialogue specifies the data categories, purpose and actual recipients. A relevant change requires renewed confirmation.
Nocha stores your age range to apply access restrictions. If you enter a date of birth in your Watchirl account, it remains private: it is not sent to public profiles, experiences or payment providers.
Purchases are verified by Watchirl with the channel provider: Stripe on the web, Apple for iOS packs, and Google with RevenueCat on Android. Historical mobile subscriptions may be tracked by RevenueCat. Transaction data is used to confirm entitlements, reconcile operations and process refunds.
A shared experience may show your actions to other participants. Blocking relationships, consent records and billing data are not exposed to hosted content. Avoid including third-party data without permission.
Camera, microphone and location permissions are separate from consent to a transfer and spending authorisation. The consent record does not retain a copy of prompts or media. Revocation blocks the relevant new transfers; it does not recall data already transferred.
The contractual list of hosting providers, processors, countries and transfer safeguards must be verified before commercial launch. Data location commitments cannot be inferred solely from the presence of development servers in France.
Retention
Experiences and saved content are retained for use, then deleted on request through the erasure process. The initial policy provides for: detailed technical traces for 72 hours; a seven-day withdrawal period for account deletion; security and administration for six months; closed report files for twelve months with data minimisation.
Minimal acceptance records are retained for five years after the relationship ends. Accounting records subject to a retention obligation are kept for ten years under that obligation. Exceptional retention must have a reason, a deadline and an audit trail.
The target for erasing active data is thirty days after the request; backups should expire no later than thirty days after that erasure. These targets require verification of the storage actually deployed. Deleting a logical volume does not certify physical erasure. Processing status and any copies not covered must be distinguished.
While the service is being prepared, general purges remain disabled pending this verification. Requested deletions are tracked separately. Historical copies and backup policies that have not yet been attested prevent these periods from being presented as an already effective guarantee.
Your rights
You may request access, rectification, erasure, restriction and portability where applicable, object to processing based on legitimate interests, and withdraw consent for the future. Contact: contact@nocha.world. Proportionate verification of your identity may be necessary.
You may lodge a complaint with the CNIL, including at cnil.fr. Closing Nocha does not automatically close your access to other products. Legal obligations may justify retaining certain minimal records after content has been erased.