Last updated: August 2025
When you create an account we collect your email address, display name, and a hashed copy of your password. We also store the content you create inside Nodlen — spaces, cards, and any associated data — so we can sync it across your devices.
We collect standard server logs (IP address, browser, pages visited, timestamps) to operate and secure the service.
We use your information to provide Nodlen, send transactional emails (account verification, password reset), and improve the product. We do not sell your data to third parties or use it to serve you targeted advertising.
If you delete your account, your data is soft-deleted immediately (your account becomes inaccessible) and permanently purged after 30 days. You may request early permanent deletion by contacting us.
Passwords are stored as bcrypt hashes — we never store your password in plain text. Access tokens are short-lived; refresh tokens are rotated on each use and revoked on password change or sign-out. All traffic is encrypted in transit via TLS.
We use a single HttpOnly cookie to maintain your session (the refresh token). We do not use third-party tracking cookies.
Questions about this policy? Reach us at privacy@nodlen.app.