How it works The handoff Use cases FAQ
Log in Sign up

Privacy Policy

Last updated: [DATE]

This policy explains what nodalo does with personal data. It is written to satisfy the GDPR, which applies to us because we offer nodalo to people in the European Union, as well as applicable United States privacy law.

1. Controller and contact

The controller is [LEGAL ENTITY NAME], [ADDRESS]. For any privacy matter, including the rights described in section 8, write to [PRIVACY EMAIL].

Our representative in the European Union under Article 27 GDPR is [EU REPRESENTATIVE — name and address, or delete this paragraph if you have established that none is required].

2. What we collect

Account data

Your first name, last name, email address and a securely hashed password. We never see your password in plain text. If you sign in with Google, we receive your name and email address from Google.

Content you create

The graphs you build: titles, node definitions, notes, connection labels, links, and any images or files you attach. If you use the voice feature, the resulting transcript and the definition written from it are stored with the node.

Technical data

Our hosting provider records standard server logs for each request: IP address, time, requested address, referrer and browser identification. These are used to operate and secure the service.

Stored in your browser, not on our servers

Some things stay on your device and never reach us: your AI provider API key, your connector token, your theme and language choice, and your session token. We use no tracking cookies, no analytics and no advertising technology — which is why nodalo shows no cookie banner.

3. Why we process it, and on what legal basis

PurposeLegal basis (GDPR Art. 6)
Providing your account and storing your graphs Performance of a contract, Art. 6(1)(b)
Sending account emails (confirmation, password reset) Performance of a contract, Art. 6(1)(b)
Keeping the service secure, preventing abuse, rate limiting Legitimate interests, Art. 6(1)(f)
Complying with legal obligations Legal obligation, Art. 6(1)(c)

We do not use your data for profiling or automated decision-making with legal effect, and we do not use your content to train machine-learning models.

4. Who receives data

These providers process data on our behalf:

ProviderPurposeLocation
Vercel Inc.Hosting, delivery, server logsUnited States
Supabase Inc.Account data, graph storage, authentication emails [REGION OF YOUR SUPABASE PROJECT]

These receive data only when you choose to trigger it:

  • Your AI provider (for example OpenAI) — when you use the voice or AI-definition features, your browser sends the recording or text directly to that provider using your own API key. We are not part of that transmission.
  • The AI assistant you connect — when you use the handoff, the synced board becomes retrievable by that assistant (for example Claude, ChatGPT, Copilot, Cursor or Codex) through your connector address.

We do not sell personal data and we do not share it for cross-context behavioural advertising.

5. International transfers

Data is processed in the United States and, depending on the region of our database, possibly elsewhere. Where data leaves the European Economic Area, we rely on the European Commission’s Standard Contractual Clauses with our providers, supplemented by encryption in transit and at rest.

6. How long we keep it

  • Account data — until you delete your account.
  • Graphs — until you delete them, or until your account is deleted.
  • Synced handoff boards — 30 days after the last sync, after which they are no longer served.
  • Server logs — for the retention period of our hosting provider, currently [e.g. 30 days].

7. How we protect it

  • All traffic is encrypted in transit (HTTPS with HSTS).
  • Separation of user data is enforced in the database itself through row-level security, so a row can only ever be read by its owner — not merely filtered in application code.
  • Connector tokens are stored only as a SHA-256 hash; the database never holds the token itself.
  • A Content Security Policy restricts what the application may load and where it may send data.
  • Public endpoints are rate limited to prevent abuse.

8. Your rights

Under the GDPR you have the right to access your data, to rectification, to erasure, to restriction of processing, to data portability, and to object to processing based on our legitimate interests. Where processing rests on consent, you may withdraw it at any time without affecting prior processing.

If you are a California resident, you have the right to know what personal information we collect and how we use it, to request deletion or correction, and not to be discriminated against for exercising those rights. We do not sell or share personal information as those terms are defined under the CCPA.

To exercise any of these rights, write to [PRIVACY EMAIL]. You can export your graphs at any time from within the app. You also have the right to lodge a complaint with your local data protection authority.

9. Children

nodalo is not intended for children under 16. We do not knowingly collect their data; if you believe a child has provided us data, contact us and we will delete it.

10. Changes to this policy

We may update this policy. Material changes will be announced by email or in the app before they take effect. The date above always shows the current version.

11. Contact

Privacy questions: [PRIVACY EMAIL].

nodalo — graph engineering for AI
Graph engineering Loop engineering Terms Privacy Open the canvas