In effect 3 August 2026
Privacy policy
This is about hellonodi.com: the questionnaire, the email step, and the web checkout. It says what we collect, why we are allowed to, who helps us handle it, and how to get it deleted.
Short version: we collect the answers you type, your email, and first-party analytics about how the funnel is going. We never sell your data and there are no advertising trackers on this site.
Who is responsible
Nodi is built and run by Thomas Abbott, sole proprietor, Kerkstraat, 1017 GD Amsterdam, the Netherlands. That is the data controller for everything described here, and the person who reads the support inbox.
Write to hello@hellonodi.com for anything on this page: a copy of your data, a correction, a deletion, or a question you would rather ask a person.
What we collect and why
Your questionnaire answers
Goals, how much experience you have, how your face feels in the morning, gender and age range. We use them to build the plan you see, and to hand that plan to the app when you open it.
Legal basis: taking steps at your request before a contract, and performing it (GDPR Art. 6(1)(b)).
Your email address, and your first name if you give it
So your plan is saved, so we can send your claim code, your receipt, and the occasional message about your subscription. First name is optional and only used to greet you.
Legal basis: performing our contract with you (Art. 6(1)(b)).
Your claim code and redemption status
The code is what carries your answers from this site into the iOS app. We store it, and whether it has been used, so the handoff cannot lose your plan or be redeemed twice by someone else.
Legal basis: performing our contract with you (Art. 6(1)(b)).
Payment details, if you buy on the web
Stripe handles the card. We never see or store your card number. We receive the result: whether the payment worked, the card brand and last four digits, the country, and your subscription status.
Legal basis: performing our contract with you (Art. 6(1)(b)), and our legal duty to keep tax records (Art. 6(1)(c)).
How you use the site
Which steps you view and finish, which buttons you press, your device type, browser, referring page, and any campaign tags in the link you arrived on. Your IP address gives an approximate country or city, and is not used to identify you.
Legal basis: our legitimate interest in understanding and fixing our own funnel (Art. 6(1)(f)). You can object at any time, see Your rights.
Security and delivery logs
Our hosting and DNS providers keep short-lived request logs, including IP address and browser, to serve the site and to block abuse.
Legal basis: our legitimate interest in keeping the site up and safe (Art. 6(1)(f)).
We do not ask for health data, we do not ask for anything sensitive, and we do not make automated decisions that have a legal effect on you. The plan you see is tailored from your answers, and that is the whole of it.
Analytics, in plain terms
We use PostHog to count things: how many people start the questionnaire, which step loses the most people, whether the download step works. It runs first-party through hellonodi.com, so it does not follow you around other websites, and PostHog is our processor rather than an advertiser.
Your IP address reaches PostHog so it can estimate a rough location and catch abuse. We do not use it to work out who you are, and we do not combine analytics with your email to build a profile for advertising.
We keep analytics events for up to 84 months, which is 7 years. That is deliberate: it lets us see whether Nodi is actually working for people over years rather than over a single quarter. It is longer than we keep your saved plan, which goes after 12 months.
We run this on legitimate interest, not consent, because it is first-party measurement of our own site with no ad tech attached. If you would rather not be counted, email hello@hellonodi.com and we will delete your analytics profile and leave you out. You can ask at any time, at any point in those 7 years, and we do it.
Who else touches your data
These companies process data for us, under contract, only on our instructions. Nobody else gets it, and none of it is sold.
- SupabaseThe database that holds your answers, email and claim code.EU (Frankfurt)
- VercelHosts and serves the site.EU (Frankfurt) with US company
- CloudflareDNS and network protection in front of the site.Global network, US company
- StripeTakes the payment and manages web subscriptions. Card details go to Stripe, never to us.EU and US
- RevenueCatSyncs a web purchase to your app access, using a random session id and the purchase record.US
- ResendSends the transactional emails: claim code, receipt, sign-in codes.EU region
- PostHogProduct analytics for the funnel.US Cloud
If you buy inside the iOS app instead, Apple handles that payment as its own controller under Apple's privacy policy, and we only learn that a subscription exists.
Data leaving the EU
Your answers, your email and your claim code live in the EU. Some of the services above are American, so a few things travel: analytics events to PostHog US Cloud, purchase records to RevenueCat, and parts of payment processing to Stripe.
Those transfers run on the European Commission's standard contractual clauses, plus the EU-US Data Privacy Framework where the provider is certified, along with the usual technical safeguards like encryption in transit. Ask us and we will tell you which one covers a given provider.
How long we keep things
- Your saved plan (answers, email, claim code): kept until you redeem it in the app, then 12 months, then deleted. If it is never redeemed, we delete it 12 months after your last activity.
- Sign-in codes sent by email: 15 minutes, then discarded.
- A log of which emails we sent you: 12 months, so we never send the same thing twice.
- Payment and subscription records: as long as tax and accounting law requires, which in most EU countries is up to 10 years.
- Analytics events: up to 84 months, which is 7 years. Longer than the rest on purpose, so we can read long-term product trends. They sit under a random id, not your name, and you can have your analytics profile deleted at any time by emailing hello@hellonodi.com.
You do not have to wait for any of that. Ask and we delete what we are not legally required to keep.
Your rights
Under the GDPR you can ask us to:
- give you a copy of the data we hold about you (access);
- fix anything that is wrong (rectification);
- delete it (erasure);
- pause what we do with it while something is disputed (restriction);
- hand it over in a machine readable file, or send it somewhere else (portability);
- stop processing that runs on legitimate interest, analytics included (objection).
Email hello@hellonodi.com. Include your claim code if you have one, since it is the fastest way for us to find your record. We answer inside 30 days and usually within two business days. We do not charge for this.
If we get it wrong, you can complain to the data protection authority in the EU country where you live or work.
The Nodi app
This policy covers the website. The iOS app collects a little more, because it does more. It can take a selfie to show you a projection of how your face might look after weeks of routine. That image is processed on a server, its retention is disclosed inside the app before you take the photo, and the whole feature is optional.
The app's own privacy details live in the App Store listing and in the app's settings. If you have already installed it, the same address works for questions: hello@hellonodi.com.
Children
hellonodi.com and the web checkout are not aimed at anyone under 16, and we do not knowingly collect data from them. If you are under 16, please do not use the checkout on this site.
If you are a parent or guardian and think your child has entered something here, email hello@hellonodi.com and we will delete it.
How we protect it
Everything travels over HTTPS. The database is locked to server-side access with keys that never reach your browser, and your saved plan can only be read by a browser holding the matching secret cookie, or by the app with your claim code. Card numbers never touch our systems. Access on our side is limited to the founder.
If a breach ever puts you at real risk, we will tell you and the relevant authority, quickly and in plain words.
Changes
If we change this policy we update the date at the top. When a change actually matters to you, and we have your email, we send you a note rather than hoping you check.
Contact
Data questions, deletion requests, or anything that feels off: hello@hellonodi.com. A person answers.
See also our terms of service and the support page.