Legal

Privacy Policy

What Nodlume collects, why we need it, and the choices you have over your information.

Effective: August 27, 2026

About 6 minutes to read

Our privacy commitments

Your data is not for sale

We do not sell your personal information or build advertising profiles for third parties.

Your projects stay private

We do not use your project content to train AI models.

Analytics is your choice

Analytics and advertising tools only load after you accept.

This summary is for convenience. The complete policy below explains our practices in detail.

What we collect

  • Account information: your email address and display name, used to create and secure your account.
  • Project content: the pages, components, graphs, and settings you create on the canvas, stored so your projects persist and can be shared with collaborators.
  • Usage and billing data: plan tier, token-credit balance and consumption, and basic usage needed to enforce plan limits and meter AI generation.
  • Technical data: the session cookie described below, and standard server logs (timestamps, request paths, IP addresses) kept for security and debugging.
  • Analytics and advertising data, only if you accept: which pages you visit and when, whether you signed up or subscribed after arriving from one of our ads, and how you interact with pages — clicks, scrolling, and session replays in which your project content and anything else you author is masked before it leaves your browser, so replays show layout and interaction, never your work. Share-link addresses are stripped of their access token before being recorded, so a page view never carries the credential that opens the project, and share pages are excluded from session replay entirely.

How we use it

We use this information to operate Nodlume: authenticating you, saving your projects, managing project access and sharing, processing payments, enforcing plan limits, and improving the product. We do not sell your personal information, and we do not use your project content to train AI models.

Cookies

  • Essential: a single first-party authentication cookie, __session, keeps you signed in. It is httpOnly and required for the app to function, so it is set without asking.
  • Analytics and advertising: if you accept, Google and Microsoft set cookies to measure how Nodlume is used and to measure the effectiveness of our advertising — specifically, whether an ad led to a sign-up or a subscription. Nothing is requested from either until you accept, and declining is remembered. You can change your choice at any time via 'Cookie settings' in the footer.
  • Accepting covers both purposes together. We do not sell advertising on Nodlume and we do not use these cookies to build advertising profiles for third parties; they measure our own campaigns.

Service providers

  • Google Firebase (Google Cloud) — authentication, hosting, and project data storage.
  • Google Analytics — usage measurement, only if you accept analytics and advertising cookies.
  • Google Ads — measuring which advertising campaigns lead to sign-ups and subscriptions, only if you accept. We share that a conversion happened, not your account details or project content.
  • Microsoft Clarity — session replay and heatmaps, only if you accept. Replay reconstructs how a page behaved during a visit — clicks, scrolling, and where a layout went wrong. Because that recording is a reconstruction of the page, everything you author is masked before it leaves your browser — project names, canvas node labels, data-model fields, AI conversations, generated code, and the contents of dialogs and menus all appear as blocks, never as readable text. Pages reached through a share link are never recorded at all.
  • Liveblocks — managing access to projects shared with collaborators.
  • Sentry — error monitoring and performance diagnostics. Reports may include technical request data, but we disable default collection of personally identifiable information and redact authentication cookies, credentials, share-link tokens, and sensitive request fields before sending them.
  • Stripe — payment processing. Card details go directly to Stripe; we never see or store your full card number.

Each provider processes data only as needed to provide its service to us.

Sharing and collaboration

When you invite collaborators or create a share link, the invited people — or anyone holding the link — can see the shared project content and your display name. Nothing else about your account is exposed to them.

Retention and deletion

We keep your data while your account is active. If you delete a project, it is removed from the application. If you delete your account (or ask us to via support), we delete your account data and project content, except where we must retain records — such as billing history — to meet legal obligations.

Your rights

Depending on where you live, you may have rights to access, correct, export, or delete your personal information. To exercise them, contact us through the support page and we will respond within a reasonable time.

Changes to this policy

If we make material changes to this policy, we will notify you by email or in the app before the changes take effect. The effective date above always reflects the current version.

Want to exercise a privacy right?

Contact us for help with access, correction, export, or deletion requests.

We'd like to use Google cookies to understand how Nodlume is used and to measure our advertising. Nothing loads until you choose, and declining does not affect anything in the app.