Privacy Policy
Effective date: June 8, 2026 Controller: The Palaz Company LLC, 1209 Mountain Road PL NE STE N, Albuquerque, NM 87110, USA. Contact: [email protected]. EU/UK representatives (GDPR / UK GDPR Art. 27): representatives in the EU and UK will be appointed; in the meantime, EU/UK residents can reach us about their data at [email protected].
This policy explains what personal data NodePad (“we”) collects, why, and your rights. It covers node-pad.com (marketing) and app.node-pad.com (the product).
1. The data we collect
Information you provide
- Account data — email, display name, password (stored only as a hash). If you use social sign-in (Apple or Google), the identifier and email from that provider.
- Profile/preferences — avatar, default model, system prompt, UI settings.
- User content — the workspaces, branches, nodes, messages, text notes, and attachments you create. This includes the prompts you send to AI models.
- Payment data — name and billing details you enter at checkout. Card details are processed by Stripe; we never receive or store your full card number.
- Support communications — anything you email us.
Information collected automatically
- Usage & device data — actions in the app, tokens/messages used (for billing and limits), browser/device info, approximate location, and (with consent in the EU/UK, opt-out elsewhere) analytics and masked session replay via PostHog. See our Cookie Policy.
- Log/security data — IP address, timestamps, and similar, for security and reliability.
2. How we use it, and our lawful bases (GDPR)
| Purpose | Lawful basis (GDPR Art. 6) |
|---|---|
| Provide the service (accounts, workspaces, AI generation) | Performance of a contract |
| Process payments, subscriptions, usage metering & limits | Performance of a contract |
| Security, fraud prevention, abuse handling | Legitimate interests / legal obligation |
| Product analytics & session replay | Consent (EU/UK) / legitimate interests (opt-out regions) |
| Service emails (verification, billing, security) | Performance of a contract |
| Comply with tax/accounting/legal obligations | Legal obligation |
We do not sell your personal data. We never use your private workspace content to train AI models of our own. On paid plans, we access model providers under commercial API terms pursuant to which API inputs are not used to train their models. The Free plan’s open models are served through OpenRouter and its downstream hosting providers, which may retain submitted content and use it under their own terms (see Section 3); the no-training commitment above therefore applies to our paid plans.
3. AI processing & third parties
When you use AI features, the content you submit is sent to the LLM provider that serves your chosen model (Anthropic, OpenAI, or Google for the frontier models; OpenRouter and its downstream hosting providers for the Free plan’s open models) to generate a response. These providers act as our sub-processors. Anthropic and OpenAI process this content in the United States, and Google processes it in the US or other regions, so using AI features involves a transfer of your submitted content outside the EU/UK.
Free plan retention notice. The open models available on the Free plan are routed through OpenRouter to third-party hosting providers that may retain prompts and responses and use them under their own terms, including for service improvement. We show a notice in the app whenever a retaining model is selected. If you do not want your content retained by these hosts, use a paid plan’s models. The full list of sub-processors and locations is at Sub-processors.
4. Where your data is processed & international transfers
Our core application data (accounts, workspaces, content) is hosted in the EU (Finland, with a planned database move to AWS Frankfurt), object storage is in the EU (Cloudflare R2, Eastern Europe), email is sent via AWS SES (Frankfurt), and analytics data is in PostHog’s EU region.
Transfers outside the EEA/UK occur for: AI generation (LLM providers, US), payments (Stripe, US/global), and network/CDN (Cloudflare, global). Where we transfer EU/UK personal data abroad, we rely on appropriate safeguards such as the EU Standard Contractual Clauses (and the UK International Data Transfer Addendum).
5. Retention
We keep account and content data while your account is active. Content you delete is moved to trash and permanently purged after 30 days. When you delete your account, your sign-in methods are removed and your email address is anonymized immediately; the remainder of your profile details is anonymized within 30 days. Your workspace content is retained in anonymized form so that it can be restored if you return, unless you select “also delete my content” when deleting your account, in which case it is permanently deleted at the 30-day mark. You can also request earlier or fuller deletion anytime at [email protected]. Limited records we must retain by law (e.g. invoices for tax/accounting) are kept for the required period. Backups are purged on a rolling basis. Content submitted to the Free plan’s open models may additionally be retained by the third-party hosting providers described in Section 3 under their own retention terms; deleting your NodePad account does not delete copies those providers retained.
6. Your rights
Depending on where you live (GDPR/UK GDPR, CCPA/CPRA, and others), you may have the right to: access, correct, delete, port, restrict, or object to processing, and to withdraw consent. EU/UK users may lodge a complaint with a supervisory authority. California residents have rights to know, delete, correct, and to opt out of “sale”/“sharing” (we do not sell or share for cross-context advertising).
How to exercise:
- Export / delete your account & data — you can delete your account in the app (Settings → Security); for a copy of your data, email [email protected]. We honor requests within 30 days.
- Other requests — email [email protected].
We will not discriminate against you for exercising your rights.
7. Business customers
If you use NodePad on behalf of an organization, that organization may be the controller of the data it processes through NodePad, and we act as its processor for that content; a separate Data Processing Agreement is available on request at [email protected].
8. Children
NodePad is not directed to children under 13. We do not knowingly collect data from children under that age. In some EU member states the digital-consent age is higher (up to 16); the higher local age applies.
9. Security
We use measures including encryption in transit and at rest, hashed passwords, and access controls. No system is perfectly secure; we will notify you and regulators of breaches as required by law.
10. Changes
We will post updates here with a new effective date and, for material changes, notify account holders.
11. Contact
The Palaz Company LLC, 1209 Mountain Road PL NE STE N, Albuquerque, NM 87110, USA — [email protected].