nod.

Privacy Policy

Last updated: 1 August 2026

This policy is a working legal draft and should be reviewed by a qualified data-protection lawyer before it is relied upon.

1. Who we are (controller)

The controller responsible for the processing of personal data through nod. (usenod.io) is:

Mesper SH.P.K.
Rruga Lot Vaku 37
62000 Kamenicë, Kosovo
hello@usenod.io

For any privacy matter, contact hello@usenod.io.

2. What data we collect

  • Account data - your name and email address when you register, and authentication data.
  • Usage data - brands, campaigns, comments, approval statuses, and settings you create in the Service.
  • Uploaded creatives - images, videos, and copy you upload for review.
  • Reviewer details - email addresses of people you invite to review creatives, and their feedback.
  • Performance & connected-source data - account and campaign identifiers, ad and creative metadata, spend, impressions, clicks, conversions, search queries, store/order records, CRM leads, bookings, and related metrics received from services you connect.
  • Pixel & journey data - pseudonymous visitor and session identifiers, consent state, sanitised page URLs and referrers, campaign parameters and click IDs, event timestamps, session duration, active time, scroll depth, interactions, milestones, and conversion identifiers and values. The pixel stores a one-way, secret-peppered IP hash for security and matching; it does not store the raw IP address.
  • AI prompts & inputs - briefs, prompts, brand or performance context, and optional reference images you submit to AI features.
  • Technical data - IP address, browser/device information, and timestamps collected automatically by our infrastructure for security and operation.

3. Legal bases for processing

  • Art. 6(1)(b) GDPR - performance of our contract with you (providing the Service, including AI features you invoke).
  • Art. 6(1)(a) GDPR - your consent (e.g. non-essential cookies / analytics, marketing communications).
  • Art. 6(1)(c) GDPR - compliance with legal obligations (e.g. tax records held by our Merchant of Record).
  • Art. 6(1)(f) GDPR - our legitimate interests in operating, securing, and improving the Service.

4. How we use your data

  • To provide, operate, and secure the Service.
  • To send transactional emails and review/approval notifications.
  • To generate AI suggestions from the inputs you submit.
  • To publish creatives to Meta when you connect and instruct that integration.
  • To improve the product based on aggregated usage.
  • To comply with legal and accounting obligations.

We do not sell your personal data.

5. Payments (Merchant of Record)

Paid plans are sold and processed by Dodo Payments as our Merchant of Record. Card and payment details are entered with and handled by Dodo Payments, nod. never sees or stores your card data. Dodo Payments processes the personal data needed to take payment, invoice you, and calculate and remit tax/VAT, under its own privacy policy. We receive only limited billing metadata (e.g. plan, status, country, and a transaction reference) to manage your subscription.

6. Service providers & connected services

The roles below depend on the data flow. Core and optional providers help us deliver nod. Dodo Payments acts as an independent controller and Merchant of Record for purchases. Customer-connected services receive or provide data only when you connect or instruct the relevant integration, under their own terms.

ServicePurposeWhen used
SupabaseDatabase, authentication & file storage in the EU Ireland regionCore service
VercelApplication hosting & CDNCore service
SentryError diagnostics & performance monitoring; session replay is disabledCore service
ResendTransactional email & notification deliveryCore service
AnthropicAI agent, strategy, copy, brand and campaign-builder featuresOptional feature
Google (Gemini API)Paid Gemini API for AI copy, feedback, creative checks and help features; prompts are processed under Google's data-processing termsOptional feature
Black Forest LabsAI image generation from prompts and optional reference images; standard FLUX API terms allow inputs and outputs to be used to improve and train Black Forest Labs servicesOptional feature
Dodo PaymentsCheckout, payment, invoicing and tax as Merchant of RecordIndependent controller
Google Tag Manager / Google AnalyticsWebsite measurement under Google Consent ModeConsent-controlled
MetaAdvertising data, account sync, publishing and conversion APIsOnly when connected
Google connected servicesGoogle Ads, GA4, Search Console, Sheets, Merchant Center and Business ProfileOnly when connected
Shopify / Klaviyo / TikTok / ChatGPT Ads / CanvaCommerce, email, advertising, and creative-tool data sourcesOnly when connected
CRM / booking / payment / notification servicesHubSpot, GoHighLevel, Zoho, Calendly, YouCanBookMe, Cal.com, Stripe, Slack, Microsoft Teams, Google Chat, and browser push servicesOnly when connected

Google API data. When you connect a Google service, nod. uses OAuth to access only the permissions you approve. Depending on the service, this may include account identifiers; Google Ads campaigns, ads, budgets, performance and conversion data; GA4 reports; Search Console queries and page metrics; Sheets cell values and workbook titles; Merchant Center product and account data; and Business Profile data. We use this data for the reporting, attribution, profitability, campaign-building, publishing, and account-management features you request. OAuth tokens are encrypted; connected and derived data is stored per workspace in our EU database for the period described in section 8. It is shared only with our infrastructure providers and, when you deliberately invoke an AI feature that needs this context, the named AI provider. We do not sell it, use it to serve unrelated advertising, or use it to train a general-purpose model. Disconnecting removes the stored credential and stops future collection; you can request deletion under section 9. nod.'s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

7. International transfers

Some service providers and connected services may process data outside the EU/EEA, including in the USA. Where required, transfers are safeguarded by an applicable adequacy decision, the EU Standard Contractual Clauses, or another lawful transfer mechanism. You may request more detail on the safeguards in place at hello@usenod.io.

8. Data retention

We retain account, workspace, and derived reporting data while your account is active and as needed to provide the Service. Raw pixel events are retained for the Journey horizon configured for the workspace, plus a limited correction buffer for late-arriving conversions. When you submit a verified deletion request, we delete or anonymise associated personal data without undue delay unless we must retain limited records for legal, security, fraud-prevention, or billing purposes. Restricted backup copies age out under the relevant provider's backup cycle. You can request deletion at any time (see section 9).

9. Your rights (GDPR)

You have the right to:

  • Access - request a copy of the personal data we hold about you.
  • Rectification - request correction of inaccurate data.
  • Erasure - request deletion of your data ("right to be forgotten").
  • Restriction - restrict processing in certain circumstances.
  • Portability - receive your data in a structured, machine-readable format.
  • Objection - object to processing based on legitimate interests.
  • Withdraw consent - at any time, where processing is based on consent.

To exercise any of these rights, contact hello@usenod.io. You also have the right to lodge a complaint with your local data-protection supervisory authority.

If you connected Meta, you can also request deletion through Facebook under Settings & Privacy > Settings > Apps and Websites > nod. > Send Request. Meta sends nod. a signed request, and the confirmation link shows the deletion status.

10. Cookies

nod. uses essential storage required for authentication, session management, security, and your saved consent choice. Google Tag Manager loads in Advanced Consent Mode with analytics and advertising storage denied by default. Before consent, Google tags may send limited cookieless consent-status or measurement pings, but analytics and advertising cookies and full measurement storage remain disabled. They are enabled only for the categories you accept in the cookie banner. Sentry error diagnostics run as an essential security and reliability service; session replay is disabled. You can change your choices at any time through the cookie settings button.

11. Contact & changes

Questions about this policy, or to exercise your rights? Contact hello@usenod.io.

We may update this policy from time to time. Material changes will be communicated with reasonable notice, and the "Last updated" date above will reflect the latest version.