Nabil Semaan
Privacy Policy
This policy explains what information is collected through nabilsemaan.com and Social Intelligence OS, why it is collected, how it is used and shared, how long it is kept, and the choices available to you.
- Effective date
- 14 August 2026
- Applies to
- nabilsemaan.com and Social Intelligence OS
Introduction
Nabil Semaan respects the privacy of everyone who visits this website or uses Social Intelligence OS. This Privacy Policy describes the personal information involved, the purposes it is used for, and the controls available to you.
It is written to be read rather than skimmed past. Where a limit or a caveat applies, it is stated in the relevant section instead of being buried in general language.
If anything here is unclear, or if you would like more detail about a specific processing activity, please contact privacy@nabilsemaan.com.
Service operator
This website and Social Intelligence OS are operated by Nabil Semaan, an individual developer and operator. Nabil Semaan is responsible for the decisions described in this policy about why and how personal information is processed.
Contact details are published on the Contact page and repeated in the final section of this policy.
Social Intelligence OS is a product developed by Nabil Semaan. It is not presented as, and should not be taken to be, a separately incorporated company.
Scope
This policy covers two distinct things.
- This website — the public pages at nabilsemaan.com. The website is a static, informational site. It has no accounts, no login, no contact form, no database and no advertising or behavioural tracking.
- Social Intelligence OS — the social media management, content intelligence, analytics and workflow platform described on this site. Most of the processing described below happens there, in the context of a workspace created by a customer.
Where a section applies only to one of the two, it says so. This policy does not cover the practices of third-party social platforms, which handle your data under their own policies.
Availability of specific Social Intelligence OS capabilities depends on the provider, the account type, the permissions granted and the level of API access held at the time. Some capabilities described here may not be active for a given workspace.
Information users provide
Information provided directly by a user of Social Intelligence OS may include:
- Details supplied when creating or configuring a workspace, such as an organisation or brand name and workspace settings.
- Content uploaded for processing, planning or publication — video, audio, images, documents and written copy.
- Campaign, planning and strategy information such as content pillars, ideas, briefs and scheduling preferences.
- Configuration of approval rules, roles and workflows.
- Correspondence sent to the operator, including support and privacy enquiries.
Visiting this website requires no information to be provided at all. There is no form to complete; enquiries are made by email, at your choice.
Account and profile information
Social Intelligence OS keeps the account information necessary to identify a user, control what they can access, and maintain an accurate record of who authorised what.
- Identifiers such as a name, email address and display name.
- Workspace membership, role and permission assignments.
- Authentication information, including credential material stored in hashed or otherwise protected form.
- Records of significant account actions, such as membership changes and approvals given.
Separation of duties and approval workflows only mean something if the identity of the person who approved an action is recorded reliably. That is the principal reason account activity is retained.
Authorisation and access credentials
When a social account is connected, the provider issues access credentials — typically an access token and, where applicable, a refresh token. Social Intelligence OS stores these credentials in encrypted form and uses them solely to carry out the functions the user has asked for through the platform.
- Credentials are used to perform requested publishing, analytics, account-management and, where supported and enabled, public-comment operations.
- Credentials are not sold, rented or shared for any independent purpose.
- Credentials are not used to access anything beyond the scopes the user granted.
- Credentials are held for as long as the connection remains active, and are invalidated or removed when the connection is disconnected.
Social Intelligence OS does not ask for, store or use social-platform passwords, and does not rely on credential sharing to operate a connected account.
User content and media
Content uploaded to a workspace — source video, audio, images, documents and written copy — is stored so that it can be processed, planned, approved, published and reported on.
Processing of that content may produce derived material, which is stored alongside it:
- Transcripts and time-coded text derived from audio and video.
- Structured analysis of visual, audio and contextual characteristics of a piece of content.
- Rendered outputs such as clips, reframed versions, subtitle files and platform-specific variants.
- Draft copy and captions prepared for a specific platform.
Uploaded content may contain personal information about people other than the uploader — for example people appearing or speaking in a video. Responsibility for holding the necessary rights, consents and permissions for that content rests with the customer, as set out in the Terms of Service.
Posts and publishing information
When content is prepared for or published to a connected account, records are kept of what was published, where, when and on whose authority:
- The payload that was authorised — the text, media references and platform options as approved.
- The identity of the person who approved the action, and when.
- The outcome reported by the provider, including any identifiers it returned and any errors.
- Idempotency and reconciliation records used to avoid duplicate publication and to confirm the true state of an action.
- Whether the action was carried out against a live provider connection or in a simulated environment.
These records exist to make external actions accountable and auditable. They are described further under Data retention.
Analytics and performance information
Where a provider makes analytics available for a connected account, that information may be retrieved and stored so that performance can be assessed over time.
- Metrics supplied by the provider for posts and, where available, for the account.
- The time at which each metric was retrieved, and the state of that retrieval.
- Assessments and comparisons derived from the account's own history.
Metric availability is recorded explicitly. Where a provider does not return a value, that absence is stored as an absence — it is never silently recorded or displayed as zero.
Public comment and community information
Where a provider supports it and the capability is enabled for a workspace, publicly visible comments on a connected account's posts may be retrieved so that they can be reviewed and responded to through a governed workflow.
- This may include the public comment text, its identifier, its timestamp and the public author identifier the provider supplies.
- Drafted replies, the review decisions taken on them and the outcome of any reply that was published.
Social Intelligence OS does not offer private direct-message inboxes, and this policy makes no claim to process private messages.
Transcripts and AI-assisted analysis
AI-assisted functionality is used to help people work with their own content. Depending on the features in use, this may include transcription, analysis of what a piece of content contains, planning and storyboard suggestions, drafting of copy, summarisation and assistance in preparing reports.
The material produced — transcripts, structured analyses, suggestions and drafts — is stored in the workspace alongside the content it relates to, so that it can be reviewed and reused.
Nabil Semaan does not use social-platform content, or customer content, to train or fine-tune a general-purpose or foundation AI model.
AI output is advisory. It does not by itself authorise anything, and it does not replace the human authorisation required before a governed external action is carried out. See How AI-assisted processing works.
Creator information and rights evidence
Where a workspace works with creators or uses user-generated content, records may be kept about the permission obtained to use that content:
- Creator records, including the identifiers and contact details needed to request and manage permission.
- Rights requests and the responses to them.
- The scope of any permission granted — for example which content, which platforms, whether organic use only or paid promotion as well, and for how long.
- Evidence supporting the grant, such as the wording used and the time at which agreement was given.
- Any subsequent expiry or revocation.
This information is used to validate rights at the point of publishing and to demonstrate, afterwards, that permission existed at the time content was used. Its retention is explained under Data retention.
Client reporting information
Where a workspace produces reports for its own clients, the following may be processed:
- Client records and the contact details needed to give a client access to a report.
- Report snapshots — fixed records of the figures and evidence as they stood when the report was produced.
- Branding supplied by the workspace for white-label presentation.
- Records of report access and export.
Report snapshots are deliberately immutable, and each carries the provenance of the evidence behind it, including whether that evidence was live, simulated or a mixture of the two.
Technical and log information
This website
nabilsemaan.com is a static site. It runs no analytics product, no advertising tags and no session-replay tooling. As with any website, the hosting provider may record ordinary server request logs — such as IP address, request time, requested path and user agent — for the purposes of serving the site and maintaining its security. Those logs are handled under the hosting provider's own arrangements.
Social Intelligence OS
The platform records technical information necessary to operate it safely and diagnose problems, including request and error logs, security-relevant events, and an audit history of significant actions taken within a workspace.
How information is used
Information is used to:
- Provide the features a user has asked for — ingestion, analysis, creation, planning, approval, publishing, measurement, engagement and reporting.
- Carry out authorised actions on connected social accounts within the scopes granted.
- Enforce roles, permissions, separation of duties and approval rules.
- Validate creator and usage rights before content is published.
- Maintain an audit history of governed actions and the authorisations behind them.
- Produce analytics, assessments and client reports with accurate evidence provenance.
- Keep the service secure, prevent abuse and investigate suspected misuse.
- Diagnose faults, and maintain and improve the reliability of the service.
- Respond to enquiries and support requests.
- Meet legal obligations and to establish, exercise or defend legal claims.
Social-platform data is not sold. It is not shared with data brokers, and it is not used to build advertising profiles.
AI-assisted processing
Where a feature is AI-assisted, content that the user has authorised for that purpose may be processed to produce the requested result — a transcript, an analysis, a plan, a draft, a recommendation or reporting assistance.
Two principles govern this.
- AI output is advisory. A suggestion, analysis or draft carries no authority of its own. It becomes an action only when a person with the necessary permission authorises it.
- Human authorisation remains required for governed external actions. Publishing to a connected account, replying publicly and comparable outward-facing actions require an explicit human authorisation, and that authorisation is bound to the specific payload being authorised.
An approval also does not override machine validation: if a platform-level or rights-level check fails, the action is refused regardless of who approved it.
Social-platform content is not used by Nabil Semaan to train a general-purpose foundation model.
Third-party AI and service providers
Social Intelligence OS relies on third-party infrastructure and, for AI-assisted features, on third-party model providers. Categories of provider include hosting and infrastructure, storage, media processing, transactional email, error monitoring and AI model services.
Where content is sent to such a provider in order to deliver a requested feature, that provider processes it under its own applicable terms and under the configuration selected for the service.
No promise is made here on behalf of a third party about how it configures its own systems. What is stated is what the operator does: providers are selected for the purpose, sent only what the feature requires, and engaged on terms intended to restrict use of the content to delivering that feature.
If you require the current list of processors used for a particular workspace, request it from privacy@nabilsemaan.com.
Data sharing
Information may be shared:
- With the social platforms a user has connected, in order to carry out the actions the user authorised.
- With service providers acting on the operator's behalf for the purposes described above.
- Within a workspace, with the members and clients whom the workspace's own administrators have granted access.
- Where required by law, or where reasonably necessary to protect rights, safety, property, or to establish, exercise or defend a legal claim.
- In connection with a transfer of the service, in which case any recipient would be bound by terms no less protective than these; users would be notified before their information became subject to a different policy.
Personal information and social-platform data are not sold, and are not shared for the independent marketing purposes of a third party.
Data retention
Information is kept for as long as it is needed for the purpose it was collected for, and then deleted or reduced — except where a longer period is genuinely necessary.
- Content and derived material is retained while the workspace requires it, and is removed on deletion of the workspace or of the item, subject to the exceptions below.
- Access credentials are retained while a connection is active and invalidated or removed on disconnection.
- Audit and authorisation records may be retained after the underlying content is removed, because their purpose is to evidence what was authorised and by whom.
- Creator-rights evidence may be retained for longer, because it is the proof that permission existed at the time content was used.
- Report snapshots are immutable by design and are retained as records of what was reported.
- Security and abuse-prevention records are retained for as long as necessary for that purpose.
In practice, a record is retained past the deletion of the material it describes only where that is reasonably necessary for security, fraud prevention, audit, dispute resolution, a legal obligation, or as evidence of a historical authorisation or right.
This policy does not promise that every historical record is erased on request. Where a record exists to evidence an authorisation, a right or a security event, retaining it may be necessary — and the reason will be given if you ask.
Disconnecting a social account
A connected social account can be disconnected from a workspace at any time.
- Disconnecting prevents further access to that provider through that connection.
- The stored credentials for that connection are invalidated or removed.
- No further publishing, analytics retrieval or comment retrieval takes place through that connection.
Access can also be withdrawn from the provider's own side, using the connected-application controls the provider offers. Doing so takes effect according to that provider's behaviour.
Disconnection stops future access. It does not, by itself, delete material already published to the platform, or historical records retained for the reasons set out above. The Data Deletion page explains both routes in full.
Data deletion
You can ask for a workspace and its associated data to be deleted. Requests are made by email to privacy@nabilsemaan.com, and the process — including what is deleted, what may be retained and why — is set out on the Data Deletion page.
The request will be acknowledged and, once identity and authority to make it have been established, actioned without undue delay.
Reports that have already been downloaded or exported cannot be recalled. Once a file has left the service, it is in the recipient's possession.
Security
The service is designed with a set of security principles rather than a single control:
- Social accounts are connected only through provider-operated authorisation flows; social-platform passwords are never requested or stored.
- Access credentials are stored in encrypted form.
- Workspaces are isolated from one another, and access is granted through explicit membership.
- Roles, permissions and separation of duties constrain who can do what.
- Governed external actions require human authorisation, bound to the specific payload authorised.
- Significant actions are recorded in an audit history.
- Data is transmitted over encrypted connections.
No system can be guaranteed to be completely secure, and no claim to a formal security certification is made here. The Security page describes these principles in more detail, and is equally explicit about what is not claimed.
International processing
The service and the providers it relies on may process and store information in more than one country. Where information is transferred to a country other than the one it was collected in, appropriate safeguards are used, taking into account the legal basis available for that transfer.
Connecting a social platform necessarily involves that platform processing information in the locations it operates in, under its own arrangements.
If you need to know the processing locations relevant to a particular workspace, ask privacy@nabilsemaan.com.
Your rights
Depending on where you live, you may have rights over your personal information, including the right to:
- Ask what personal information is held about you and obtain a copy of it.
- Ask for inaccurate information to be corrected.
- Ask for information to be deleted.
- Ask for processing to be restricted, or object to certain processing.
- Receive certain information in a portable form.
- Withdraw a consent you have given, without affecting processing that already took place on that basis.
- Complain to your local data protection authority.
To exercise a right, contact privacy@nabilsemaan.com. You will be asked for enough information to confirm your identity and, where relevant, your authority to make the request on behalf of an organisation.
Where a request cannot be met in full — for example where a record must be retained to evidence an authorisation or to meet a legal obligation — you will be told which part could not be met and why.
Children
Social Intelligence OS is a professional tool intended for use by businesses and by adults acting in a professional capacity. It is not directed at children, and it is not intended for use by anyone under the age required by the social platforms they wish to connect.
If you believe a child has provided personal information through the service, contact privacy@nabilsemaan.com so that it can be investigated and removed where appropriate.
Changes to this Privacy Policy
This policy will be updated when the service changes, when new processing is introduced, or when a description here could be made clearer.
The effective date at the top of the page always reflects the version currently published. Where a change materially affects how personal information is handled, reasonable steps will be taken to bring it to users' attention rather than relying on a silent update.
Contact
Privacy questions, access requests and deletion requests should be sent to privacy@nabilsemaan.com.
Postal correspondence details are not published on this site. The Contact page lists the current channels in use.
Operator: Nabil Semaan · Website: https://nabilsemaan.com (opens in a new tab)
20Social-platform providers
Connected social platforms are independent services with their own terms and privacy policies. When an account is connected, information flows between that platform and the workspace in both directions, within the limits the platform sets.
Current integration positions are described honestly on the Integrations page, including where a capability is dependent on approval or activation.