This policy explains what personal data Nodra processes when you visit nodranotes.com, use the web app at app.nodranotes.com or use the Nodra plugin for Obsidian; why we process it; who receives it; how long we keep it; and the rights you have under the EU General Data Protection Regulation (GDPR) and Spain's Organic Law 3/2018 (LOPDGDD).
In short: we process only what we need to run the service. We do not sell your data, show ads, run analytics or track you, and this website sets no cookies.
1. Who is responsible for your data
- Controller
- Alex Fernández Sabaté, an individual entrepreneur trading as Nodra
- Tax ID (NIF)
- 21764200J
- Address
- Carrer de Bruc, 149, 08037 Barcelona, Spain
- Privacy contact
- legal@nodranotes.com
We are not required to appoint a Data Protection Officer. For anything about your personal data, write to legal@nodranotes.com.
2. How your notes are protected: Managed and Private
Every Nodra account uses one of two protection modes. The mode decides who can decrypt the content of your vault, so it matters for this policy.
Managed mode (the default)
Every account starts in Managed mode. Your vault content is encrypted in transit and at rest. Our server keeps an escrow of the key that unlocks your account's encryption keys. That escrow is what lets you get back into your account with just your login email, and it also means that Nodra can technically decrypt the content of a Managed vault.
The escrow is used when you sign in on a device: our server unwraps that key for an instant, re-encrypts it for your device and does not store or log it. Your notes are then decrypted on your device. We do not decrypt or look at the content of Managed vaults in the normal running of the service, and Nodra has no feature that does. We would access it only if the law required us to, for example under a valid court order, and we would tell you unless the law forbids it. Because we hold the escrow, a compromise of our servers could also expose Managed content.
Private mode (optional, on every plan)
In Private mode, your vault is encrypted on your device before it reaches our servers, and Nodra cannot read your notes. Private mode keeps no escrow: your keys are protected by your Encryption Password and Secret Key, which we never store. Private mode is end-to-end encrypted, within the limits described in our Terms of Service.
If you switch from Managed to Private, the content you write after the switch is out of our reach straight away. Older content and history only leave our reach once Nodra has finished re-encrypting them, and we could technically have copied them while they were readable.
In both modes our servers see the metadata listed in section 3, because the service cannot work without it.
3. What data we process and why
| Data | What it includes | Why we need it | Legal basis |
|---|---|---|---|
| Account | Your email address, your password (stored only as a hash by our authentication provider), sign-in times, and a copy of your contact email kept with your Nodra account. | To create your account, sign you in, let you reset your password and recover a Managed account, and to send you security notifications. | Performance of our contract with you (Art. 6(1)(b) GDPR) |
| Vault content and history | The files of the vaults you sync and their earlier versions, stored encrypted. File names and folder paths are encrypted too. | To sync your vault between devices, open it in the browser and keep its version history. | Contract (Art. 6(1)(b)) |
| Keys and devices | Your account's encrypted keys and public keys, the signed list of your devices and trusted browsers with the label each device gives itself (for example "Web browser" or "Obsidian:" followed by the vault name), and, in Managed mode only, the escrow described in section 2. | To encrypt and decrypt your vaults on your devices, let you add and remove devices, and recover your account. | Contract (Art. 6(1)(b)) |
| Service metadata | What our servers necessarily see: the number of files, changes and versions; the size of the encrypted data; when and how often you make changes; encryption key generations; your devices; and your storage use against your plan's limits. | To run sync, enforce plan limits and quotas, and prevent abuse. | Contract (Art. 6(1)(b)); our legitimate interest in keeping the service working and free of abuse (Art. 6(1)(f)) |
| Security events | A record of security-relevant actions on your account (for example a new device, a removed device, a password or Secret Key change, a recovery, a scheduled deletion, or a change of protection mode), with the time and the device involved. | To show you what happened on your account and email you about it, so you can react to anything you did not do. | Our legitimate interest in protecting your account (Art. 6(1)(f)); contract (Art. 6(1)(b)) |
| Billing | Your Paddle customer, subscription and transaction identifiers, your plan, price and currency, the subscription status and renewal dates. We never receive your card details. The country of your request is used once to pick the currency of your checkout and is not stored. | To give you the plan you pay for and apply its limits. | Contract (Art. 6(1)(b)) |
| Emails | Transactional emails we send you: sign-up confirmation, password reset and security notifications, with a record of each notification sent. We do not send marketing emails. | To operate your account and warn you about security events. | Contract (Art. 6(1)(b)); legitimate interest in protecting your account (Art. 6(1)(f)) |
| Technical data | Your IP address, browser details and request times, as our hosting and authentication providers process them to deliver and protect the service. Nodra does not store IP addresses in its own database. | To deliver web pages and API requests, and to protect the service against attacks. | Legitimate interest in running a secure service (Art. 6(1)(f)) |
| Messages to us | What you tell us when you email us. | To answer you and handle your request. | Contract (Art. 6(1)(b)) or legitimate interest in answering you (Art. 6(1)(f)); legal obligation when you exercise your rights (Art. 6(1)(c)) |
Where we rely on legitimate interest, we have weighed it against your rights, and you can object to it (section 9). Providing your email address and a password is necessary to have an account; without them we cannot provide the service.
4. What we do not do
- We do not sell or rent your personal data, and we do not share it for advertising.
- We do not use analytics, tracking pixels, advertising networks or session recording, on this website or in the app.
- We do not profile you or make decisions about you based solely on automated processing.
- We do not use the content of your notes for any purpose other than storing and syncing it for you.
5. Cookies and storage in your browser
nodranotes.com sets no cookies and stores nothing in your browser. The one exception is the checkout page, which loads Paddle's checkout so you can pay; Paddle may use cookies or similar technologies that are necessary for the payment, under Paddle's privacy policy.
app.nodranotes.com sets no cookies. It stores only what it needs to work:
- your sign-in session, in your browser's local storage;
- a local copy of your vault, your device's keys and the sync state, in your browser's IndexedDB, so the app can open your vault and keep it in sync.
The Nodra plugin keeps similar data inside Obsidian on your device. This storage is strictly necessary to provide the service you ask for, so it does not need your consent under Article 22(2) of the LSSI-CE and the ePrivacy Directive, and there is no cookie banner. You can remove it by signing out and clearing the site's data in your browser.
6. Who receives your data
We use a small number of service providers. They process data on our behalf, under data processing agreements, and only to provide their service to us:
| Provider | What they do for Nodra | Where |
|---|---|---|
| Supabase, Inc. | Authentication (sign-in, password reset) and the database that holds account data, encrypted keys, metadata, security events and billing state. | Database hosted in Frankfurt, Germany (EU, AWS eu-central-1); Supabase is based in the United States. |
| Cloudflare, Inc. | Hosting of nodranotes.com and app.nodranotes.com, our server code (Workers), R2 storage of encrypted vault data, DNS, and safekeeping of the escrow key. | Cloudflare's global network, including the United States. |
| Purelymail | Sending our transactional emails from no-reply@nodranotes.com. | The United States. |
Paddle. Payments for paid plans are handled by Paddle.com Market Ltd, our reseller and Merchant of Record. Paddle processes your payment and billing details (such as your name, email, address and payment method) as an independent controller under its own privacy policy, and keeps the invoices and tax records the law requires. Nodra receives from Paddle only the identifiers and plan details listed in section 3.
We may also disclose data to public authorities or courts when the law requires us to. We do not share personal data with anyone else.
7. International transfers
Some of our providers are based in, or may process data in, the United States or other countries outside the European Economic Area. Where they do, the transfer relies on the EU-US Data Privacy Framework for providers certified under it and/or on the European Commission's Standard Contractual Clauses (Art. 46 GDPR), as applicable. Paddle.com Market Ltd is based in the United Kingdom, which benefits from an EU adequacy decision. You can ask us for more information about these safeguards at legal@nodranotes.com.
8. How long we keep your data
| Data | How long |
|---|---|
| Current files of your vaults | For as long as they are in your vault and your account exists. |
| Version history and deleted files | For your plan's history period, counted from the moment a version was replaced or a file was deleted: 7 days on Free, 90 days on Pro and 365 days on Max. After a move to a plan with a shorter history, the longer period keeps applying for 30 more days. Older versions are then removed. |
| Minimal sync records | For each removed version, its identifiers and its place in the file's history (a few dozen bytes, no content), kept while the vault exists so devices can stay in sync. |
| A deleted vault | Deletion is scheduled 14 days ahead, so it can be cancelled. Then its files, history and keys are deleted from our database and storage. |
| Your account | Until you delete it. Deletion is scheduled 14 days ahead, so it can be cancelled; then all its vaults, keys, escrow, devices, security events, billing records and sign-in identity are deleted, and our storage is checked again every 24 hours until no file of the account remains. If your sign-in identity is removed without deleting the account, the account is kept for 90 days and then deleted the same way. |
| Security events and notification records | 180 days. |
| Billing state | While your account exists. After the account is deleted, we keep only the Paddle subscription identifier and the deletion date for 30 days, so that a cancelled subscription cannot be charged again. Paddle keeps invoices and payment records for as long as tax law requires. |
| Provider logs and backups | Our hosting and authentication providers keep short-lived operational logs, and our database provider keeps backups that expire on their regular cycle. Deleted data can remain in those backups until they expire; we do not restore deleted accounts from them. |
| Messages to us | As long as needed to deal with your request and any follow-up. |
9. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you and get a copy of it;
- rectify data that is inaccurate or incomplete;
- erase your data, including deleting your account;
- restrict how we process your data in certain cases;
- data portability: receive the data you gave us in a structured, machine-readable format;
- object to processing based on our legitimate interest;
- withdraw your consent at any time, where we rely on consent (today we do not rely on consent for any processing).
To exercise any of these rights, email legal@nodranotes.com from the email address of your account. We may ask you to confirm your identity, and we answer within one month (extendable by two months for complex requests, in which case we tell you why). Exercising your rights is free.
Your notes always stay in your Obsidian vault as plain Markdown files on your own devices, so you already have a complete, portable copy of them. In Private mode we cannot give you a decrypted copy of your vault, only the encrypted data we hold.
If you think we have not handled your data correctly, you can complain to the Spanish Data Protection Agency (Agencia Española de Protección de Datos, www.aepd.es) or to the data protection authority of the EU country where you live or work. We would appreciate the chance to fix the problem first.
10. Security
We protect your data with encryption in transit and at rest, strict access controls, a separate checkout page so that no payment script runs in the app, and notifications for security-relevant changes to your account. No system is perfectly secure. If a personal data breach puts your rights at risk, we will notify the supervisory authority and, where required, you.
11. Children
Nodra is not intended for children under 14. If you are under 14, please do not create an account. If you believe a child under 14 has given us personal data, contact us and we will delete it.
12. Changes to this policy
We may update this policy as Nodra changes. We will publish the new version on this page with a new date, and if a change is significant we will tell you by email before it takes effect.