Legal

Privacy Policy

Last updated: September 13, 2026

1. What we collect

When you create an account we store your email address. If you sign in with GitHub we also store your GitHub username and profile image URL, provided by GitHub during OAuth.

Your projects, nodes, edges, and specifications are stored in our database to provide the Service. This includes node titles, descriptions, positions, statuses, and any AI-generated content.

API keys you generate are stored as hashed values. The raw key is shown once at creation and is not retained.

When you use the AI editing features (split, tighten, error states), the content you send is processed by Anthropic. We store the results but not the raw prompts beyond what is needed to fulfil the request.

2. Why we collect it

We collect only what is needed to operate the Service: your email for authentication, your project data for the graph editor, and AI usage records for metering your plan's edit allowance.

3. Who we share data with

Anthropic processes your AI editing requests. Node and project content you send to the AI features is transmitted to Anthropic to generate responses.

Stripe processes subscription payments. Stripe receives your email and payment method details at checkout. We do not store your card number.

Neon hosts our Postgres database. All data stored by the Service sits in a Neon database.

Vercelhosts the application. Requests to the Service pass through Vercel's infrastructure.

We do not sell your data. We do not share your data with advertisers.

4. Cookies and local storage

We use one cookie: the NextAuth session token, which keeps you signed in. It is httpOnly, secure, and sameSite lax. We do not use analytics cookies, tracking pixels, or third-party advertising cookies today. The service worker caches static assets for offline support but does not cache API responses or authenticated requests.

5. Data retention

Your data is kept for as long as your account exists. We do not run a scheduled deletion job, so nothing is removed automatically when a subscription ends. To have your account and its project data deleted, email us using the address in section 9 and we will delete it.

6. Your rights

You can request export or deletion of your data at any time by emailing hello@nodeon.app. We will action the request and confirm by email.

7. Security

API keys are hashed before storage and cannot be recovered. Sessions are managed by NextAuth with secure, httpOnly cookies. All traffic is served over HTTPS. We use Content Security Policy headers to restrict resource loading.

8. Changes to this policy

We may update this policy from time to time. Material changes will be posted on this page with an updated revision date, and where the change materially affects active subscribers we will notify those subscribers by email.

9. Contact

Questions about this policy can be sent to hello@nodeon.app.