Privacy Policy
Effective date: 2026-08-10
This policy explains what Nodeboard does with your data. The controller is Teralabs LLC, 1111B S Governors Ave STE 52993, Dover, DE 19904, USA. For anything in this document, write to privacy@nodeboard.ai.
We have tried to describe what the system actually does rather than what is convenient to claim. Two things in particular are worth reading: Section 3, on what happens to the content you send to AI providers, and Section 6, where we tell you plainly that data requests are handled by hand rather than by a button.
1. What we collect
| What | Details |
|---|---|
| Account | Your email address. Credentials are handled by Supabase Auth; we never see your password. |
| Google identity — when you sign in with Google | Your email address, name, profile picture and Google account identifier. These are received from Google at sign-in; we do not collect them from you separately, and we request no other Google data. |
| Boards and projects | The canvas state: nodes, connections, prompts, settings, titles, and the collaborative editing history. |
| Assets | Images, video, audio and 3D files you upload, and those generated through your workflows. |
| AI provider API keys | Stored encrypted at rest. Used only to run generations you initiate. Never displayed back to you in full and never shared. |
| Error telemetry | Sent to Sentry when something breaks. Session replay is enabled at a very low rate (0.5% of sessions, 50% of sessions with an error) and all text is masked before it leaves your browser. We have disabled the setting that would attach personal data and request headers to error reports. |
| Operational logs | Records of generation jobs, estimated costs, and calls made through our REST, MCP and CLI surfaces. |
| Access requests | If you request access through our website, we receive your email address and your message. These are not stored in a database — they are delivered to us by email, through Resend, and live in our mailbox. |
| Support communications | Messages sent to support@, info@, feedback@ or billing@nodeboard.ai, including their headers and attachment metadata. They are delivered to our Microsoft 365 Operations mailbox. A restricted server-side working copy may be used to classify the request and prepare a human-reviewed reply. Addresses for security, privacy, legal and DMARC matters remain in a human-only mailbox and are not ingested by the support automation. |
We do not run third-party analytics, advertising or tracking. There is no analytics script on the site.
2. Why we process it
To create and secure your account; to store and serve your boards and assets; to run the generations you ask for; to keep the Service working and diagnose failures; to communicate with you about the Service; and to comply with legal obligations.
Where the GDPR or the Swiss FADP applies, our legal bases are the performance of our contract with you (providing the Service), our legitimate interests (security, abuse prevention, keeping the Service reliable) and, where relevant, legal obligation.
3. AI providers, and what leaves Nodeboard
This is the section that matters most, because it is the part people usually assume rather than read.
Generation with your own key. When you run a generation node, we transmit your prompt, your selected media and your settings to the AI provider you chose, using your own API key. Your relationship with that provider is direct: their privacy policy and their data-retention practices govern what happens to that content once it reaches them. If you care what a provider may keep or learn from your content, check the settings of your account with them.
Features that run on our accounts. Three features do not use your key, and send content to providers under Nodeboard's own accounts instead:
- the Lula assistant — receives the context of your board and your messages;
- prompt translation — receives the text being translated;
- automatic image description — receives the image being described.
The providers involved are listed on the Sub-processors page.
Training. We do not train AI models on your content, and we do not provide it to anyone else for that purpose. Third-party providers apply their own policies to content you send them under your own account.
4. Who else processes your data
We use a small number of infrastructure providers to run the Service. They process data on our instructions and are listed, with what each one does, on the Sub-processors page.
Google appears there in two separate roles, and it is worth not confusing them: as an identity provider, when you choose to sign in with Google, and as an AI provider, for prompt translation and automatic image description. Different purposes, different data.
5. Where your data is processed
Nodeboard runs on infrastructure located in the United States. If you are in the European Economic Area, the United Kingdom or Switzerland, your data is transferred there. We rely on the transfer mechanisms our providers make available, including standard contractual clauses where applicable. We do not claim any certification we have not verified.
6. Your rights, and how we handle them
Depending on where you live, you may have the right to access your data, correct it, delete it, receive a copy in portable form, object to or restrict processing, and complain to a supervisory authority.
How to exercise them: write to privacy@nodeboard.ai. We will verify that the request comes from you and respond within 30 days.
We want to be straightforward about the mechanism: there is no self-service export or account-deletion button in the product today. Requests are handled by a person. That is a real limitation, not a formality — it means the address above is the way, and we treat it accordingly.
You can, without writing to us, delete your provider API keys at any time in Settings → API Keys, and delete individual projects and assets from within the product.
7. How long we keep things
| Data | Retention |
|---|---|
| Account, projects, assets | For the life of your account. Deleted when the account is deleted. |
| Manual board snapshots (Time Machine) | Kept until you delete them. |
| Automatic board snapshots | 30 days |
| Generation job records, once finished | 7 days |
| Operational metrics | 30 days |
| Cron heartbeats | 7 days |
| Error telemetry (Sentry) | According to our Sentry plan's retention. |
| Access requests received by email | Kept in our mailbox until they are no longer needed. |
| Support messages in the Microsoft 365 Operations mailbox | 12 months from the message date, unless a legal hold or legal obligation requires longer. |
| Local support working copy | Readable message and draft content for 90 days after the conversation's last activity, then irreversibly redacted. Residual operational records are deleted after 12 months. An unresolved import failure is retained only until it is repaired or dismissed, after which the same retention clock applies. |
Backups may hold data for a short period after deletion, and expire on their own cycle.
8. Security
Provider API keys are encrypted at rest. Access to production data is restricted. Database rows are protected by row-level security so that one account cannot read another's. Error reports are configured not to carry personal data or request headers.
No system is perfectly secure. If we become aware of a breach affecting your personal data, we will notify you and the relevant authority where the law requires it.
9. Cookies
We use only cookies that are strictly necessary to run the Service: the session cookies that keep you signed in. We do not use advertising, profiling or analytics cookies, and there is no third-party tracking script on the site.
Because of this, there is no consent banner. If we ever add anything beyond strictly necessary cookies, we will ask for your consent first.
10. Children
The Service is not intended for anyone under 18, and we do not knowingly collect data from children. If you believe a child has created an account, write to privacy@nodeboard.ai and we will remove it.
11. Changes
We will publish any update to this policy with a new effective date. If a change materially affects how we handle your data, we will ask you to accept the updated version the next time you sign in.
12. Contact
Teralabs LLC 1111B S Governors Ave STE 52993 Dover, DE 19904 USA