Privacy Policy
This Privacy Policy explains how Nodal Data, Inc. ("Nodal," "we," "us") collects, uses, and shares information when you visit nodaldata.io or docs.nodaldata.io (the "Sites"), create an account, or use the Nodal hosted service (the "Service"). Capitalized terms not defined here have the meaning given in our Terms of Service.
1. Our Role
For information about your account, billing, and your use of the Sites, Nodal is the controller (or "business") and this Policy applies.
For the contents of the repository you connect to the Service and the requests your Users send to your endpoint ("Customer Content"), Nodal processes that data on your behalf as a service provider, under your instructions and our Terms of Service. If someone else's Nodal account processes information about you, contact that organization; we will refer requests to them.
2. Information We Collect
Account information. When you create an account we collect your name, work email address, company name, and a password. Authentication is handled by AWS Cognito; passwords are stored by Cognito in hashed form and are not visible to us.
Billing information. Payments are processed by Stripe. Stripe collects your payment card details directly; we do not receive or store full card numbers. We receive your name, billing email, billing address, the last four digits and brand of your card, and transaction records.
Repository access. To serve your context repository you provide a GitHub access token. We store it encrypted and use it only to read the connected repository. We store a copy of the repository contents as needed to serve them.
Usage logs. When Users query your endpoint, the Service logs the request (including the text of the request and the tool called), a User identifier, timestamps, response status, and errors. This is how the Service provides usage visibility to account administrators and how we troubleshoot and secure it. Depending on what your Users ask, these logs may contain business information from your organization.
Site data. When you visit the Sites we automatically collect standard server log data: IP address, browser type, device type, pages viewed, referring URL, and timestamps. We use Google Analytics to understand Site traffic; see Section 7.
Communications. If you email us, fill out a form, or contact support, we keep the correspondence.
We do not knowingly collect information from anyone under 18, and the Sites and Service are not directed to them.
3. How We Use Information
We use the information above to:
- provide, operate, secure, and support the Service and the Sites;
- create and manage your account and authenticate Users;
- process payments, send invoices and receipts, and manage subscriptions;
- show account administrators how their endpoint is being used;
- respond to your requests and provide customer support;
- send transactional messages (receipts, security notices, changes to terms) and, with the ability to opt out, product updates;
- analyze usage in aggregate to improve the Service, including performance, reliability, and features;
- detect, investigate, and prevent fraud, abuse, and security incidents;
- comply with legal obligations and enforce our agreements.
We do not use Customer Content to train machine-learning or AI models, and we do not sell personal information.
4. How We Share Information
We share information only as described here.
Service providers (subprocessors). We use third parties to run the Service and the Sites. They process data only on our instructions. Our current subprocessors are:
| Provider | Purpose | Location |
|---|---|---|
| Amazon Web Services | Hosting, storage, authentication (Cognito), secrets management | United States (us-east-1) |
| Stripe | Payment processing, invoicing, tax calculation | United States |
| GitHub | Code hosting for the Sites; source of connected repositories | United States |
| Google Workspace | Email and support correspondence | United States |
| Google Analytics | Site analytics | United States |
We will update this list when we add or replace a subprocessor and, for the Service, will notify account administrators by email.
Model providers you choose. The hosted Service does not send Customer Content to any AI model provider. If you enable optional AI features by placing your own API key in your repository, those features run as workflows in your repository and send data directly to the provider you selected, under your agreement with that provider. Nodal does not receive or store that key and is not a party to those requests.
Legal and safety. We may disclose information if required by law, subpoena, or legal process, or when we believe disclosure is necessary to protect the rights, property, or safety of Nodal, our customers, or others.
Business transfers. If Nodal is involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction, subject to this Policy.
With your direction. We share information when you ask us to, including with your own Users through the Service.
5. Data Retention
- Account and billing information: retained while your account is active and for 90 days after it closes, then deleted, except for transaction records we must keep for tax, accounting, and legal purposes.
- Repository contents and tokens: deleted within 30 days after you disconnect the repository or terminate your subscription, except for routine backups deleted on their normal schedule.
- Usage logs: retained for 12 months from creation, then deleted or de-identified.
- Site logs: retained for 90 days.
- Communications: retained as long as needed to handle your request and for our records.
6. Security
We use administrative, technical, and physical safeguards designed to protect information, including encryption in transit (TLS) and at rest, encrypted storage of access tokens, least-privilege access to production systems, and logging of administrative access. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If you believe your account has been compromised or you have found a vulnerability, contact security@nodaldata.io.
7. Cookies
The Sites use cookies and similar technologies that are strictly necessary to operate, such as session cookies for signed-in users. We also use Google Analytics, which sets cookies to help us understand how the Sites are used; Google may process this data in the United States. You can disable these cookies in your browser settings or install the Google Analytics opt-out browser add-on, and the Sites will still work. We do not use advertising cookies and do not respond to browser "Do Not Track" signals, because there is no industry standard for them.
8. Your Rights and Choices
You may access, correct, or delete your account information by signing in or by emailing info@nodaldata.io. You may cancel your subscription through the billing portal. You may opt out of product-update emails using the link in those emails; we will still send transactional and security messages.
California residents. The California Consumer Privacy Act gives you rights to know what personal information we collect and how we use and share it, to request deletion or correction, and to not be discriminated against for exercising those rights. We do not sell or share personal information for cross-context behavioral advertising. To exercise your rights, email info@nodaldata.io; we may need to verify your identity. You may designate an authorized agent to make a request on your behalf.
European Economic Area, United Kingdom, and Switzerland. The Service is offered primarily to organizations in the United States. If you are located in the EEA, UK, or Switzerland, we process your personal data to perform our contract with you, to comply with legal obligations, and for our legitimate interests in operating, securing, and improving the Service. You have rights to access, rectify, erase, restrict, port, and object to processing of your personal data, and to lodge a complaint with your supervisory authority. Data is transferred to and processed in the United States; where required, we rely on standard contractual clauses, which are available on request. Contact info@nodaldata.io to exercise these rights.
Other jurisdictions. If your local law provides additional rights, email us and we will honor them where they apply.
9. International Transfers
Nodal is based in the United States and processes information there. If you access the Sites or Service from elsewhere, your information will be transferred to and processed in the United States, where privacy laws may differ from those in your jurisdiction.
10. Changes to This Policy
We may update this Policy. We will post the revised Policy with a new "Last updated" date and, for material changes affecting the Service, notify account administrators by email before the changes take effect.
11. Contact
Nodal Data, Inc. 228 Park Ave S, PMB 152020 New York, New York 10003-1502 US info@nodaldata.io Security reports: security@nodaldata.io