Last updated: 1 August 2026
This policy is a working legal draft and should be reviewed by a qualified data-protection lawyer before it is relied upon.
The controller responsible for the processing of personal data through nod. (usenod.io) is:
Mesper SH.P.K.
Rruga Lot Vaku 37
62000 Kamenicë, Kosovo
hello@usenod.io
For any privacy matter, contact hello@usenod.io.
We do not sell your personal data.
Paid plans are sold and processed by Dodo Payments as our Merchant of Record. Card and payment details are entered with and handled by Dodo Payments, nod. never sees or stores your card data. Dodo Payments processes the personal data needed to take payment, invoice you, and calculate and remit tax/VAT, under its own privacy policy. We receive only limited billing metadata (e.g. plan, status, country, and a transaction reference) to manage your subscription.
The roles below depend on the data flow. Core and optional providers help us deliver nod. Dodo Payments acts as an independent controller and Merchant of Record for purchases. Customer-connected services receive or provide data only when you connect or instruct the relevant integration, under their own terms.
| Service | Purpose | When used |
|---|---|---|
| Supabase | Database, authentication & file storage in the EU Ireland region | Core service |
| Vercel | Application hosting & CDN | Core service |
| Sentry | Error diagnostics & performance monitoring; session replay is disabled | Core service |
| Resend | Transactional email & notification delivery | Core service |
| Anthropic | AI agent, strategy, copy, brand and campaign-builder features | Optional feature |
| Google (Gemini API) | Paid Gemini API for AI copy, feedback, creative checks and help features; prompts are processed under Google's data-processing terms | Optional feature |
| Black Forest Labs | AI image generation from prompts and optional reference images; standard FLUX API terms allow inputs and outputs to be used to improve and train Black Forest Labs services | Optional feature |
| Dodo Payments | Checkout, payment, invoicing and tax as Merchant of Record | Independent controller |
| Google Tag Manager / Google Analytics | Website measurement under Google Consent Mode | Consent-controlled |
| Meta | Advertising data, account sync, publishing and conversion APIs | Only when connected |
| Google connected services | Google Ads, GA4, Search Console, Sheets, Merchant Center and Business Profile | Only when connected |
| Shopify / Klaviyo / TikTok / ChatGPT Ads / Canva | Commerce, email, advertising, and creative-tool data sources | Only when connected |
| CRM / booking / payment / notification services | HubSpot, GoHighLevel, Zoho, Calendly, YouCanBookMe, Cal.com, Stripe, Slack, Microsoft Teams, Google Chat, and browser push services | Only when connected |
Google API data. When you connect a Google service, nod. uses OAuth to access only the permissions you approve. Depending on the service, this may include account identifiers; Google Ads campaigns, ads, budgets, performance and conversion data; GA4 reports; Search Console queries and page metrics; Sheets cell values and workbook titles; Merchant Center product and account data; and Business Profile data. We use this data for the reporting, attribution, profitability, campaign-building, publishing, and account-management features you request. OAuth tokens are encrypted; connected and derived data is stored per workspace in our EU database for the period described in section 8. It is shared only with our infrastructure providers and, when you deliberately invoke an AI feature that needs this context, the named AI provider. We do not sell it, use it to serve unrelated advertising, or use it to train a general-purpose model. Disconnecting removes the stored credential and stops future collection; you can request deletion under section 9. nod.'s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Some service providers and connected services may process data outside the EU/EEA, including in the USA. Where required, transfers are safeguarded by an applicable adequacy decision, the EU Standard Contractual Clauses, or another lawful transfer mechanism. You may request more detail on the safeguards in place at hello@usenod.io.
We retain account, workspace, and derived reporting data while your account is active and as needed to provide the Service. Raw pixel events are retained for the Journey horizon configured for the workspace, plus a limited correction buffer for late-arriving conversions. When you submit a verified deletion request, we delete or anonymise associated personal data without undue delay unless we must retain limited records for legal, security, fraud-prevention, or billing purposes. Restricted backup copies age out under the relevant provider's backup cycle. You can request deletion at any time (see section 9).
You have the right to:
To exercise any of these rights, contact hello@usenod.io. You also have the right to lodge a complaint with your local data-protection supervisory authority.
If you connected Meta, you can also request deletion through Facebook under Settings & Privacy > Settings > Apps and Websites > nod. > Send Request. Meta sends nod. a signed request, and the confirmation link shows the deletion status.
nod. uses essential storage required for authentication, session management, security, and your saved consent choice. Google Tag Manager loads in Advanced Consent Mode with analytics and advertising storage denied by default. Before consent, Google tags may send limited cookieless consent-status or measurement pings, but analytics and advertising cookies and full measurement storage remain disabled. They are enabled only for the categories you accept in the cookie banner. Sentry error diagnostics run as an essential security and reliability service; session replay is disabled. You can change your choices at any time through the cookie settings button.
Questions about this policy, or to exercise your rights? Contact hello@usenod.io.
We may update this policy from time to time. Material changes will be communicated with reasonable notice, and the "Last updated" date above will reflect the latest version.