NōD

Privacy Policy

Last updated: 18 August 2026

NōD (“Company”, “we”, “us”, “our”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal data when you use the NōD application (“App”) and the website at nod-ai.com.

This policy is intended to comply with the EU General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA/CPRA), and other applicable privacy laws.

1. Data controller

NōD
Email: privacy@nod-ai.com
Data Protection Officer: privacy@nod-ai.com

2. Personal data we collect

2.1 Information you provide

2.2 Information from connected services

2.3 Information collected automatically

3. Legal basis for processing (GDPR Article 6)

4. How we use your data

5. AI data processing

5.1 Your data may be processed by AI models to generate summaries, suggestions, and automated actions.

5.2 When using NōD-provided AI features, relevant content may be processed by OpenAI or other subprocessors we use to provide the service.

5.3 When you configure external AI providers with your own API keys, your data is sent to those providers under their privacy policies.

5.4 We do not use your personal data to train AI models.

5.5 You can opt out of AI personalization in the App’s settings.

6. Data sharing and disclosure

We do not sell your personal data.

6.1 Third-party service providers: we share data with service providers who assist in operating the App, bound by data processing agreements where applicable. These providers include OpenAI (AI processing), Stripe (payments), Supabase (database/auth infrastructure), Upstash (Redis rate limiting), Cloudflare (network/security infrastructure), Resend (transactional email), and Sentry (diagnostics/error monitoring).

6.2 Connected services: when you connect your accounts (Google, Microsoft, Apple), data flows between those services and the App as you direct.

6.3 External AI providers: only when you explicitly configure and enable them with your own API keys.

6.4 Legal requirements: we may disclose data when required by law, court order, or government request.

6.5 Business transfers: in the event of a merger, acquisition, or sale of assets, your data may be transferred. We will notify you beforehand.

7. Data retention

7.1 Account data: retained while your account is active and for 30 days after deletion.

7.2 Messages and content: retained while your account is active. Deleted within 30 days of account deletion.

7.3 Usage logs: retained for 12 months, then automatically purged.

7.4 AI usage logs: retained for 6 months for billing and service improvement.

7.5 Legal hold: data may be retained longer when required by law.

8. Your rights

Under GDPR (EU residents) and CCPA (California residents), you have the right to:

To exercise these rights, contact us at privacy@nod-ai.com or use the in-app controls.

9. California residents (CCPA/CPRA)

9.1 Categories of personal information collected: identifiers, internet activity, geolocation, professional information, inferences.

9.2 We do not sell personal information.

9.3 We do not share personal information for cross-context behavioral advertising.

9.4 You have the right to know, delete, correct, and opt out.

9.5 You may designate an authorized agent to make requests on your behalf.

10. International data transfers

10.1 Your data may be processed in countries other than your country of residence.

10.2 For transfers from the EEA/UK, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission.

10.3 We ensure that any international transfer is subject to appropriate safeguards.

11. Data security

11.1 We implement industry-standard technical and organizational measures to protect your data.

11.2 Passwords are hashed using bcrypt.

11.3 OAuth tokens are encrypted at rest.

11.4 API communications use TLS/HTTPS encryption.

11.5 Access to personal data is restricted to authorized personnel on a need-to-know basis.

11.6 Upstash Redis stores rate-limit counters for security and abuse prevention, including hashed normalized-email keys for password reset and verification resend throttles and IP/user-derived keys for route throttles.

11.7 Sentry receives crash and error telemetry for diagnostics. Password, token, Authorization, cookie, JWT, and API-key fields are scrubbed before events are sent.

11.8 Despite our measures, no method of transmission or storage is 100% secure.

12. Children’s privacy

The App is not intended for users under 13 years of age, or under 16 in the European Union where required by applicable law. We do not knowingly collect data from children below those ages. If you believe a child has provided us with personal data, contact us at privacy@nod-ai.com.

13. Cookies and tracking

13.1 The App does not use traditional web cookies.

13.2 We may use local storage and secure storage for authentication tokens and preferences.

13.3 We do not engage in cross-app or cross-site tracking.

13.4 The marketing website at nod-ai.com may use strictly necessary cookies required to operate the site. It does not use advertising cookies.

14. Automated decision-making

14.1 The App uses AI to generate content summaries, suggestions, and prioritize information.

14.2 These automated processes do not produce legal effects or similarly significant effects on you.

14.3 You can override or dismiss any AI-generated suggestion.

15. Changes to this policy

15.1 We may update this Privacy Policy from time to time.

15.2 We will notify you of material changes at least 30 days in advance via in-app notification or email.

15.3 Continued use of the App after changes take effect constitutes acceptance.

16. Complaints

If you believe your privacy rights have been violated:

17. Contact

Privacy: privacy@nod-ai.com
Data Protection Officer: privacy@nod-ai.com
General support: help@nod-ai.com