NodiTalk to us

In effect 16 August 2026

Privacy policy

This is about hellonodi.com: the questionnaire, the email step, and the web checkout. It says what we collect, why we are allowed to, who helps us handle it, and how to get it deleted.

Short version: we collect the answers you type, your email, and first-party analytics about how the funnel is going. We never sell your data and there are no advertising trackers on this site.

Who is responsible

Nodi is a sole proprietorship based in the Netherlands. That is the data controller for everything described here, and a person, not a bot, reads the support inbox.

Write to hello@hellonodi.com for anything on this page: a copy of your data, a correction, a deletion, our full registered details, or a question you would rather ask a person.

What we collect and why

Your questionnaire answers

Goals, how much experience you have, how your face feels in the morning, gender and age range. We use them to build the plan you see, and to hand that plan to the app when you open it.

Legal basis: taking steps at your request before a contract, and performing it (GDPR Art. 6(1)(b)).

Your email address, and your first name if you give it

So your plan is saved, so we can send your claim code, your receipt, and the occasional message about your subscription. First name is optional and only used to greet you.

Legal basis: performing our contract with you (Art. 6(1)(b)).

Your claim code and redemption status

The code is what carries your answers from this site into the iOS app. We store it, and whether it has been used, so the handoff cannot lose your plan or be redeemed twice by someone else.

Legal basis: performing our contract with you (Art. 6(1)(b)).

A short lived hint so the app can find your plan

While you use the questionnaire we keep a hashed version of your IP address plus a few coarse details about your device: timezone, language, and the major version of your operating system. It is only there so the app can tell that the phone opening it is the one that just finished the questionnaire, instead of making you type a code.

Legal basis: performing our contract with you (Art. 6(1)(b)): the plan you built has to actually reach your app.

Payment details, if you buy on the web

Stripe handles the card. We never see or store your card number. We receive the result: whether the payment worked, the card brand and last four digits, the country, and your subscription status.

Legal basis: performing our contract with you (Art. 6(1)(b)), and our legal duty to keep tax records (Art. 6(1)(c)).

How you use the site

Which steps you view and finish, which buttons you press, your device type, browser, referring page, and any campaign tags in the link you arrived on. Your IP address gives an approximate country or city, and is not used to identify you.

Legal basis: our legitimate interest in understanding and fixing our own funnel (Art. 6(1)(f)). You can object at any time, see Your rights.

Security and delivery logs

Our hosting and DNS providers keep short-lived request logs, including IP address and browser, to serve the site and to block abuse.

Legal basis: our legitimate interest in keeping the site up and safe (Art. 6(1)(f)).

We do not ask for health data, we do not ask for anything sensitive, and we do not make automated decisions that have a legal effect on you. The plan you see is tailored from your answers, and that is the whole of it.

How the app finds your plan

The website and the app are two separate things, so something has to connect them. Rather than making you copy a code across, we keep a small hint while you use the questionnaire, and the app looks for it the first time you open it. If the app restores your plan this way, we also store an identifier for that device so your plan cannot be claimed twice by someone else.

The hint is a hashed form of your IP address, plus coarse device information: your timezone, your language, and the major version of your operating system. The hash is one way and mixed with a secret only our server holds, so the raw IP address is never stored, and none of those details are precise enough to pick you out on their own.

It is first party and it goes nowhere else. We never share it, never sell it, and never use it for advertising. It stops being usable 48 hours after your last visit and is erased by a daily cleanup, so it is gone within 72 hours at the latest, whether the app found your plan or not. Your claim code and your email stay as the fallback.

Cookies and similar storage

Two cookies keep your saved plan attached to your browser. One handles analytics. One remembers an invite code, if you arrived on somebody else’s link. Two exist only to run the cookie question itself. Stripe sets its own during payment. That is the full list: no advertising networks, no social pixels, no cross-site tracking.

  • nodi_fsFunctional

    Remembers which saved plan belongs to this browser, so your answers are still there if you come back or refresh.

    Set by Nodi (first party). Lasts: 30 days, reset each time you come back.

  • nodi_fssFunctional

    A secret that proves this browser owns that saved plan. Without it, nobody else can read or change your answers.

    Set by Nodi (first party, httpOnly). Lasts: 30 days, reset each time you come back.

  • nodi_refReferrals

    Only set if you arrived through somebody's invite link. It holds their six character code so they get credit if you subscribe. It says nothing about you.

    Set by Nodi (first party). Lasts: 1 year, or only until you close the browser if you are in the UK or the EEA and have not said yes to cookies.

  • nodi_geoNecessary

    A one or two letter flag saying whether your connection looks like it is in Europe, worked out from your IP address as the page is served and then thrown away. It is what lets us ask about cookies where we have to and leave everyone else alone. It holds no id and cannot be traced back to you.

    Set by Nodi (first party). Lasts: 30 days.

  • nodi_ccNecessary

    Your answer to the cookie question, so we honor it and stop asking. One letter: yes or essential only.

    Set by Nodi (first party). Lasts: 6 months, then we ask again.

  • ph_[project key]_posthogAnalytics

    Holds a random analytics id and the current session id, so we can count how many people finish each step. It carries no name, no email, no address.

    Set by PostHog (served from hellonodi.com/ingest). Lasts: up to 12 months (the cookie itself; the events it labels are kept longer, see how long we keep things).

  • __stripe_mid, __stripe_sidNecessary for payment

    Stripe's fraud checks. They only appear if you open the checkout on the web.

    Set by Stripe (only on the payment step). Lasts: 1 year (mid), 30 minutes (sid).

Those are cookie lifetimes, not how long we keep the data behind them. Your saved plan goes after 12 months; analytics events are kept a lot longer. Both are set out in how long we keep things.

The heading says similar storage, so here is that half, in full. Your answers live in your browser’s own storage while you are filling in the questionnaire and are dropped when you close the tab. The analytics id described above is kept there as well as in its cookie, and so is an invite code if you arrived on one. Our app-download helper page, the one an Instagram or TikTok link sends you through, keeps its own random id so we can count how often it manages to open the App Store. A countdown on one promotional page is the last of it. Clearing your site data removes all of it at once.

You can clear or block all of them in your browser settings. The two Nodi cookies are the ones doing real work: block those and the site will forget your answers between visits.

Your choice. In the UK and the EEA we ask before any analytics is written, and nothing analytics related is written until you answer. An invite code, if you arrived on one, is held only until you close the browser and becomes the year-long version only if you say yes. Everywhere else analytics runs on legitimate interest, explained just below, and you can still switch it off. Whichever applies to you, changing your mind takes one tap and we act on it straight away, including deleting what was already stored. And if your browser sends a Do Not Track signal we skip the whole thing without asking, the question included: no analytics, and no cookie banner either.

Analytics, in plain terms

We use PostHog to count things: how many people start the questionnaire, which step loses the most people, whether the download step works. It runs first-party through hellonodi.com, so it does not follow you around other websites, and PostHog is our processor rather than an advertiser.

Your IP address reaches PostHog so it can estimate a rough location and catch abuse. We do not use it to work out who you are, and we do not combine analytics with your email to build a profile for advertising.

We keep analytics events for up to 84 months, which is 7 years. That is deliberate: it lets us see whether Nodi is actually working for people over years rather than over a single quarter. It is longer than we keep your saved plan, which goes after 12 months.

On this website we run it on legitimate interest, not consent, because it is first-party measurement of our own site with no ad tech attached. If you would rather not be counted, email hello@hellonodi.com and we will delete your analytics profile and leave you out. You can ask at any time, at any point in those 7 years, and we do it.

Inside the app it runs for everyone. There is no consent screen for it and no switch to turn it off. It is the same thing as on this website and for the same reason: first-party product analytics, so we can see how people move through the app and fix what is not working. The app talks to PostHog directly rather than through hellonodi.com, because the reason for that detour is browser extensions and an app has none.

What the app sends: which screens you open and finish, which steps of setup you complete, which guides you start and how far through them you get, when a session begins and when it ends, your streak day, and purchase events like a paywall shown, a purchase started, a purchase finished or a purchase canceled. Your setup answers travel as ranges rather than details: an age band, not a birthday. Like any request to any server, it carries your device's network address, which PostHog turns into a rough location and we do not use to work out who you are.

What the app does not send: your payment as money, so no revenue figures, no receipts and no transaction ids; your email address; your first name; your referral code, which belongs to the person who invited you rather than to you; and nothing at all about the feathers, rewards and gifts you earn or spend. There is no session replay either: no recording of your screen and no map of your taps. RevenueCat holds the money side, and it is a separate record.

The basis for app analytics is our legitimate interest in improving and securing our own product (Art. 6(1)(f)), not consent, because there is no consent gate in the app any more. If you are in the EU or the UK and you would rather not be part of it, email hello@hellonodi.com and say so. We delete your analytics profile and leave you out from then on.

If you built your plan here and then opened the app, the two are joined up so we can see that as one journey rather than as two strangers. That link is made with a random analytics identifier and nothing else: your email address and your name are never sent to PostHog from either side.

Who else touches your data

These companies process data for us, under contract, only on our instructions. Nobody else gets it, and none of it is sold.

  • SupabaseThe database that holds your answers, email and claim code.United States (AWS us-west-2, Oregon), under its data processing agreement
  • VercelHosts and serves the site.United States (Portland, Oregon), under its data processing agreement
  • CloudflareDNS and network protection in front of the site.Global network, US company
  • StripeTakes the payment and manages web subscriptions. Card details go to Stripe, never to us.EU and US
  • RevenueCatSyncs a web purchase to your app access, using a random session id and the purchase record.US
  • ResendSends the transactional emails: claim code, receipt, sign-in codes.EU region
  • MuxStreams the routine videos to the app. Sees your device's network address while a video plays, nothing more.United States, under its data processing agreement
  • AnthropicWrites the swan's chat replies in the app, and turns the face scan's measurements into your scores. Receives the messages you type in the chat, and the numbers worked out from the scan on your phone. Never the photograph, and nothing else about you. Does not train its models on any of it.United States, under its data processing agreement
  • PostHogProduct analytics, for this website and for the app.US Cloud

If you buy inside the iOS app instead, Apple handles that payment as its own controller under Apple's privacy policy, and we only learn that a subscription exists.

Data leaving the EU

Most of the services above are American, so your data crosses the Atlantic: your answers, email and claim code sit with Supabase in the United States, analytics events go to PostHog US Cloud, purchase records to RevenueCat, parts of payment processing to Stripe, routine videos stream from Mux, and what you type to the swan in the app is answered by Anthropic. If you take the optional face scan, the numbers worked out from it on your phone go the same way, to Anthropic, for as long as it takes to score them. The photograph itself never crosses anything, because it never leaves your phone.

Those transfers run on the European Commission's standard contractual clauses, plus the EU-US Data Privacy Framework where the provider is certified, along with the usual technical safeguards like encryption in transit. Ask us and we will tell you which one covers a given provider.

How long we keep things

  • Your saved plan (answers, email, claim code): kept until you redeem it in the app, then 12 months, then deleted. If it is never redeemed, we delete it 12 months after your last activity.
  • The hint that lets the app find your plan (hashed IP address, timezone, language, operating system version): unusable after 48 hours, erased by a daily cleanup within 72 hours at the latest.
  • Sign-in codes sent by email: 15 minutes, then discarded.
  • A log of which emails we sent you: 12 months, so we never send the same thing twice.
  • Payment and subscription records: as long as tax and accounting law requires, which in most EU countries is up to 10 years.
  • What you ask the swan in the app, and what it answers: 12 months, then deleted by the same daily cleanup. The log exists so we can review what the swan actually said if an answer ever looks wrong, and you can have yours deleted sooner by emailing hello@hellonodi.com.
  • The photograph the app's optional face scan takes: never uploaded, so never kept by anybody but you, and deleted on your phone as soon as it has been read. The numbers worked out from it: not stored at all, by us or by Anthropic. They exist for the seconds it takes to turn them into your scores, and the scores are kept on your iPhone.
  • Analytics events, from this website and from the app alike: up to 84 months, which is 7 years. Longer than the rest on purpose, so we can read long-term product trends. They sit under a random id, not your name, and you can have your analytics profile deleted at any time by emailing hello@hellonodi.com.

You do not have to wait for any of that. Ask and we delete what we are not legally required to keep.

Your rights

Under the GDPR you can ask us to:

  • give you a copy of the data we hold about you (access);
  • fix anything that is wrong (rectification);
  • delete it (erasure);
  • pause what we do with it while something is disputed (restriction);
  • hand it over in a machine readable file, or send it somewhere else (portability);
  • stop processing that runs on legitimate interest, analytics included (objection).

Email hello@hellonodi.com. Include your claim code if you have one, since it is the fastest way for us to find your record. We answer inside 30 days and usually within two business days. We do not charge for this.

If we get it wrong, you can complain to the data protection authority in the EU country where you live or work.

If you are in the United States

Most of the page above is written against European law, which is the strictest version of the promise. If you are in California, Colorado, Connecticut, Virginia or any other state with its own privacy act, here is the same story in the words those laws use.

What we collect and why. Identifiers, meaning your email address and first name if you give them, plus a random analytics id. Internet activity, meaning which pages and questionnaire steps you saw and what browser you used. Approximate location, worked out from your IP address and never more precise than a region. Commercial information, meaning whether you started a subscription, which Stripe holds rather than us. We collect it to build and hand over your plan, to answer your emails, to keep the site working, and to measure how the questionnaire performs. We keep it for the periods set out in how long we keep things.

We do not sell your personal information, and we do not share it for cross-context behavioral advertising. Not in the everyday sense and not in the specific sense California gives those two words. There is no advertising pixel and no ad network on this site, nothing about you goes to one, and there never has been. That is also why you will not find a Do Not Sell or Share My Personal Information link here: there is nothing for it to switch off. If that ever changes, this section changes first and the link arrives with it.

We do not collect sensitive personal information as those laws define it, so there is nothing to limit. We do not use your data to profile you in a way that produces legal or similarly significant effects, and we do not knowingly collect anything from anyone under 16.

Your rights. You can ask what we hold, ask for a copy, ask us to correct it, and ask us to delete it. Email hello@hellonodi.com and include your claim code if you have one. We answer inside 45 days. You can send somebody else to do it on your behalf; we will just need to confirm they are authorized. We will never charge you, refuse you service, or give you a worse price for asking. If we say no to a deletion request, we tell you which legal exception we are relying on.

Do Not Track and Global Privacy Control. If your browser sends a Do Not Track header, our analytics does not start. That is a real switch in the code, not a sentence in a policy. Global Privacy Control is a signal about selling and sharing, and since we do neither, there is nothing for us to apply it to. If we ever start, we will honor it.

You can also turn analytics off outright, wherever you live, with the button in cookies and similar storage.

The Nodi app

This policy covers the website. The iOS app is a separate piece of software, and most of what it holds never leaves the phone it is installed on.

  • Your practice stays on the device. The routines you finish, your streak, the feathers you earn and spend, your reminder times and the rest of your settings are kept on your iPhone. There is no account to log into and we hold no copy of any of it.
  • Claiming or restoring your plan. The one thing the app sends us is what it takes to find the plan you built here: your claim code, or your email address and the six-digit code we email back when you restore. The quieter version of the same lookup is how the app finds your plan. None of your answers or your progress travel with it.
  • Reminders. The app sets them on your phone, at the times you pick, and iOS delivers them. We run no push service, so we never learn whether one arrived or what you did about it.
  • The face scan. Setup offers you an optional face scan, and you can skip it. If you take it, the app opens the camera, you take one picture of yourself, and that picture is read by a model built into the app, on your phone. The photograph is never uploaded and it is never stored. It does not go to us, it does not go to any other company, and the app deletes it as soon as it has been read. What leaves your phone is a short list of numbers worked out from the picture, things like how open your eyes are and how even the two sides of your face are. We send those numbers to our server, which passes them to Anthropic, whose Claude model turns them into the six scores you are shown, and that is the only thing they are used for. We do not keep them: they are held in memory while the answer is worked out and then they are gone. They carry no name, no email address and no picture, and there is no way to work out who somebody is from them. The scores that come back are stored on your iPhone, the same as the rest of your practice, and we hold no copy.
  • Asking the swan. The chat tab is answered by an AI model. When you send a message, the app sends the conversation and its random billing identifier to our server; the server checks that your subscription is active, then passes the conversation text, and only the text, to Anthropic, whose Claude model writes the swan's reply. Anthropic never receives your email, your name, or any identifier, and under our agreement it does not use your messages to train its models. Questions that look medical are answered by a standing note we wrote ourselves, telling you to see a doctor, and never reach the model at all. We keep a log of questions and replies for 12 months so we can review what the swan actually said; to have yours deleted sooner, email hello@hellonodi.com. The chat is for the routines, so the plain advice is to type nothing into it you would not put in an email to us.
  • Usage data. The app measures how it is used, for everybody, and there is no switch to turn that off. It sends which screens you reach and finish, which guides you play and how far through them you get, when a session starts and ends, which plan you were shown and whether you bought it, plus the answers you gave in setup as ranges rather than details: an age band, not a birthday. It carries no name, no email address, no photograph and nothing measured off your face, and no amount of money, no receipt and no transaction id. PostHog processes this for us, the same processor described in analytics, in plain terms, which sets out the full list and how to object to it.
  • Erasing what is on the phone. Profile has an "Erase my data" button. It clears your streak, your feathers, your check-ins, your setup answers and your preferences from the phone, and it drops the random analytics id with them, so the app counts from a fresh one afterwards. It does not switch analytics off, because there is no off, and it does not cancel a subscription. To have the events already sent deleted too, email hello@hellonodi.com.
  • Advertising, and the permission iOS asks about. The app carries no advertising SDK and no attribution or install-tracking SDK. It does ask iOS for permission to track, because we are starting to run adverts and we want to know which one brought you here. What that permission covers, and how to change your answer, is in the tracking permission. The other outside code in the app is the code that makes it work: Apple's own frameworks, video playback, and RevenueCat, which tells the app whether your subscription is active.

The app asks for your camera once, for the optional face scan described above, and it never asks for your photo library. There is no picture of you on our servers and there never has been: the one the scan takes is read on your phone and deleted there. Nothing else in the app takes a photograph.

A subscription bought inside the app is billed by Apple, and how it renews and cancels is in the terms of service.

The app's own privacy details live in the App Store listing and in the app's settings. If you have already installed it, the same address works for questions: hello@hellonodi.com.

The tracking permission

Early on, the app shows you a short screen about tracking and then iOS shows its own permission sheet on top of it. Ours explains why we are asking. Apple's is where the answer is recorded, and both buttons on our screen lead to it.

What allowing it permits: your iPhone carries an advertising identifier, a random id Apple gives the device. With permission granted, that identifier may be used to work out which advert brought you to Nodi, so we can tell which advertising is worth paying for. We are starting to run adverts on Meta and TikTok, and that measurement is the reason the question exists. Refuse and the identifier is not read and not used. Nothing else about the app changes either way, and nothing is withheld from you for saying no.

Today the app asks and no more than that. There is no advertising SDK and no attribution SDK in it yet, so the identifier is not being used while that stays true. If it changes, this page changes with it.

You can change your answer at any time, in either direction. Open the iOS Settings app, go to Privacy & Security, then Tracking, and find Nodi in the list. Nodi's own page in Settings carries the same switch.

This is a separate thing from the product analytics above. Those are our own measurements of our own app, they run whatever you answer here, and they never touch the advertising identifier.

Children

hellonodi.com and the web checkout are not aimed at anyone under 16, and we do not knowingly collect data from them. If you are under 16, please do not use the checkout on this site.

If you are a parent or guardian and think your child has entered something here, email hello@hellonodi.com and we will delete it.

How we protect it

Everything travels over HTTPS. The database is locked to server-side access with keys that never reach your browser, and your saved plan can only be read by a browser holding the matching secret cookie, or by the app with your claim code. Card numbers never touch our systems. Access on our side is limited to the founder.

If a breach ever puts you at real risk, we will tell you and the relevant authority, quickly and in plain words.

Changes

If we change this policy we update the date at the top. When a change actually matters to you, and we have your email, we send you a note rather than hoping you check.

Contact

Data questions, deletion requests, or anything that feels off: hello@hellonodi.com. A person answers.

See also our terms of service and the support page.