Legal
Privacy Policy
Last updated: 27 August 2026
1. Information we collect
- Account information: the email address and display name you provide when you sign up, handled by our authentication provider, Supabase.
- Workspace and Nodi content: the workspace name, Nodi titles, destinations, and any profile details, links, or images you add to a Connect page.
- Verify records: if your workspace publishes a Nodi Verify record, we store the name, role/title, display ID, verification status, and an optional photo supplied by your workspace, together with your workspace name. The public verification page shows only this information — never a phone number, home address, date of birth, personal email, or government ID. A Verify record confirms only that the publishing workspace currently maintains it; it does not independently verify the person's legal identity.
- Scan and click analytics: when a Nodi is scanned or a Connect page element is clicked, we record which Nodi/element it was and when. We do not store your visitors' raw IP addresses in this analytics data. Click events include a short-lived, salted hash derived from the request's IP address, used only to prevent automated abuse of the click counter for a few seconds after each click; this hash cannot be reversed to reveal the original IP address and is not used to identify or track visitors.
- Session cookies: used to keep you signed in, managed by Supabase Auth.
2. How we use this information
To operate the service (create and resolve your Nodis), keep your account secure, show you scan/click counts, prevent automated abuse, and improve the product. We do not sell your personal information.
3. Who we share data with
We use the following infrastructure providers to run NODI, and your data passes through their systems as a result:
- Supabase — authentication, database, and file storage.
- Vercel — application hosting.
We do not otherwise share your personal information with third parties except where required by law.
4. Data retention and deletion
We retain your account and workspace data while your account is active. We do not currently offer a self-service way to delete your account or data from within the app. To request deletion, contact us using the details in Section 7 and we will act on the request manually.
5. Your rights
You can request a copy of the personal information we hold about you, ask us to correct it, or ask us to delete it, by contacting us using the details in Section 7.
6. Children's privacy
NODI is not directed at children and we do not knowingly collect personal information from children.
7. Contact
Questions about this policy, or requests about your data: [insert support contact email].
8. Changes to this policy
We may update this policy as NODI changes. We will update the “Last updated” date above when we do. See our Terms of Service for the governing jurisdiction for disputes about this policy.