Log in
2026-09-16
Document language English 中文

Privacy Policy

Version: v3   Last updated: 2026-09-16   Language: English


1. Introduction

noddock ("we", "us") provides a node-flow style project editor. This Privacy Policy explains how we collect, use, disclose, transfer, retain and protect personal data when you use our website, desktop application and related services (the "Service").

It is written to meet the requirements of the GDPR, UK GDPR, CCPA/CPRA and other applicable privacy laws. If you are in the EEA, the UK or California, the rights in Section 9 apply to you.

2. Data controller and contact

The data controller is <company name>. Privacy contact: [email protected].

3. Data we collect

3.1 Information you provide

  • Account profile: email address, phone number (optional), username, display name, bio, avatar.
  • Login credentials: email password (stored as a bcrypt hash — we cannot recover the plaintext), and the user identifier plus verified email returned by Google sign-in (we never receive your Google password).
  • Transaction and billing information: billing country/region, postal code and tax ID (if you provide them at checkout).
  • Communications: support, refund and legal requests, and any files you attach.

3.2 Information we generate or log

  • Account records: user ID, registration time, account status and role, store country/region and region-change time, notification and privacy preferences, session version.
  • Entitlements and billing relations: the entitlements you hold and their expiry, unit counts, provider subscription identifier and current billing period.
  • Transaction records: payment/refund/dispute amounts and currencies, product-name snapshot, payment-provider object IDs (payment_intent, invoice, charge, dispute), and tax records (tax amount, tax code, billing address, invoice number, reporting period).
  • Security and log data: IP address, device and browser type, operating system, approximate location derived from IP, pages visited and error logs, rate-limiting and anti-abuse records, captcha (Turnstile) verification results.

3.3 What we do not collect

  • We do not store full card numbers or CVVs (handled by the payment provider).
  • We do not collect biometric data, do not run advertising profiles, and do not sell personal data.

3.4 Cookies and local storage

We use only strictly necessary cookies and browser local storage:

Name Purpose Type
Session cookie Login state (JWT with a session version so logout/deletion invalidates old sessions) Necessary
Language preference Remembers the interface language you chose Necessary
Cookie consent state Remembers your consent choice Necessary

We use Cloudflare security and captcha services (including Turnstile), which may set necessary security cookies. We use no advertising or cross-site tracking cookies; if we introduce non-essential cookies in future we will ask for your consent first.

You can delete or block cookies in your browser, but core features such as login may then stop working.

4. How we use data

We use personal data to:

  • create and manage accounts, verify identity and protect login security;
  • provide, maintain, troubleshoot and improve the editor, website and store;
  • process payments, subscriptions, one-off purchases, refunds, chargebacks and tax compliance;
  • calculate and grant entitlements and display billing and expiry information;
  • provide customer support and respond to legal requests;
  • prevent fraud, abuse, refund abuse and violations of our agreements;
  • send product updates and service notices where you consent or the law permits;
  • comply with applicable law and assert or defend legal claims.
  • Performance of a contract: providing the Service, processing transactions and granting entitlements.
  • Legitimate interests: security, anti-fraud and anti-abuse, service improvement, customer support and legal claims.
  • Legal obligation: tax, accounting, financial-record retention and regulatory requirements.
  • Consent: optional communications (such as product and marketing emails); you may withdraw consent at any time.

6. Sharing and disclosure

We do not sell personal data and do not use it for cross-context behavioural advertising. We disclose it only:

  • to service providers (processors) under data-processing agreements:
    • Stripe: payment processing, subscription billing, tax calculation and chargeback handling;
    • Cloudflare: CDN, security, captcha and email delivery;
    • Google: Google sign-in;
    • hosting and database providers: infrastructure necessary to run the Service.
  • to professional advisers (audit, legal, accounting) where necessary;
  • to public authorities where required by law or to protect our rights, safety and property;
  • in a business transfer: in a merger, acquisition or asset sale, data may transfer as an asset, and we will require the recipient to remain bound by this Policy.

7. International transfers

We may process data outside your country (including outside the EEA/UK). Where GDPR applies to a transfer, we rely on adequacy decisions, the Standard Contractual Clauses (SCCs) or another legally recognised mechanism, and require recipients to provide an equivalent level of protection.

8. Retention

Data category Retention period
Account profile and login credentials While the account exists; deleted or anonymised immediately on account deletion
Verification codes and records Deleted after use or expiry
Entitlements and billing relations While the account exists; handled under financial-record requirements after deletion
Transaction, tax and invoice records Retained as long as required by applicable tax, accounting and anti-fraud law (typically 6–10 years)
Security and access logs Up to 90 days, then deleted or anonymised
Backups Rolled over within 30 days

When you delete your account we delete your login identities, verification codes and profile fields and invalidate your sessions; the financial ledger and tax records are retained as legally required records, kept only for the statutory period, to the minimum extent necessary, and never used for marketing or profiling.

9. Your privacy rights

9.1 GDPR / UK GDPR

You have the right to access, rectify, erase, restrict processing, data portability and to object to processing, and not to be subject to decisions based solely on automated processing. You also have the right to lodge a complaint with your supervisory authority.

9.2 CCPA/CPRA (California)

You have the right to know, access, correct and delete personal data, to opt out of the sale/sharing of personal data (we do not sell or share it), and to exercise your rights without discrimination. We honour Global Privacy Control (GPC) signals sent by browsers.

9.3 How to exercise your rights

  • Use "Export my data" in account settings (produces a JSON file containing your account, login methods, entitlements, subscriptions and payment records);
  • use "Delete my data" in account settings (requires your password or typing DELETE to confirm; cancel any active subscription first);
  • email [email protected] for any other request.

We respond within 30 days after verifying your identity (complex requests may be extended, and we will tell you). Exercising your rights will not result in discriminatory treatment or affect entitlements you have purchased.

10. Security

We apply appropriate technical and organisational measures, including:

  • TLS encryption in transit across the site;
  • passwords stored as bcrypt hashes, never logged in plaintext;
  • session tokens with version control so logout, password change or account deletion immediately invalidates old sessions;
  • least-privilege access control, audit logs and anomaly monitoring;
  • payment data handled by a PCI DSS compliant provider — we do not store card numbers.

No system is perfectly secure. If a data breach is likely to affect your rights and freedoms, we will notify you and the competent authority without undue delay as required by law.

11. Automated decision-making

We do not make automated decisions that produce legal effects or similarly significantly affect you. Anti-fraud, refund and dispute handling are reviewed by humans.

12. Children

The Service is not directed at anyone under 18, and we do not knowingly collect children's personal data. If you believe a child has provided us with data, contact [email protected] and we will delete it promptly.

The Service lets you connect third-party APIs, local models and payment providers, and import projects shared by other users. This Policy does not cover third-party services; their own privacy policies govern their processing. Please read them before use.

14. Changes to this Policy

We may update this Policy. Material changes will be announced on the website or by email in advance, and the date at the top will be updated. Continued use means you accept the updated Policy; if you disagree, you may stop using the Service and delete your account.

15. Contact

<company name> Privacy: [email protected] Legal: [email protected] Website: noddock

To exercise your privacy rights, use the export/delete tools in account settings or email the address above.

← Back to Home

We use cookies and similar technologies to remember your language preference and keep the site secure. By clicking accept you agree to our privacy policy. Privacy