Privacy Policy
Last updated: June 9, 2026
This Privacy Policy explains how Noodal ("we", "us", "our") collects, uses, and protects your personal information when you use our service. We've tried to write this in plain language. If anything is unclear, contact us at help@noodal.app.
1. Who We Are
Noodal is a creative operations application provided by Noodal, LLC, a Delaware limited liability company. We're based in California, USA. We're the data controller for the personal information you provide to us.
2. What Information We Collect
Information you give us directly
When you sign up, we collect:
- Your email address
- Your name (first and last)
- A password (stored as a hashed, salted value; we never see your actual password)
When you complete your profile, you may optionally provide:
- A profile photo
- Your role or job title
- Your working style preferences
- Marketing communication preferences
When you use Noodal, you create:
- Projects, documents, mind maps, and the content within them
- Comments and collaboration data
- Files and images you upload
- AI chat conversations
- Assets you save via the "Add to Noodal" browser extension (images, videos, source URLs, page titles).
Information we collect automatically
When you use Noodal, we automatically collect:
- IP address (used for security and approximate location)
- Browser type and version
- Device type and operating system
- Pages and features you access
- Time spent in the application
- Approximate timezone (for date display)
- Approximate locale (for language defaults)
Information from third parties
If you sign in with Google, we receive your email, name, and profile photo from Google. We don't access anything else from your Google account.
If you make a payment, our payment processor (Stripe) handles your payment information. We don't store your full credit card details. We receive and store: your billing email, your subscription tier, your subscription status, and the last four digits of your card.
3. How We Use Your Information
We use your information to:
- Provide the service: Create your account, save your projects, deliver AI features
- Communicate with you: Send transactional emails (invites, password resets, billing)
- Improve the service: Understand how features are used, identify bugs
- Process payments: Charge subscriptions, send receipts, handle refunds
- Keep the service safe: Detect abuse, prevent fraud, enforce our Terms
- Comply with the law: Respond to legal requests, retain records as required
- Send marketing (only if you opt in): Newsletters, product updates, promotional offers
4. AI Features and Your Content
Noodal uses Anthropic's Claude API to power AI features. When you use AI features, your messages, attachments, and project context are sent to Anthropic's servers for processing.
Important:
- Anthropic does NOT train AI models on data sent through their API (per their commercial terms)
- Your content is not used by Noodal to train AI models
- AI conversations are stored in your account so you can resume sessions and review history
- You can delete AI conversations anytime
- We retain AI usage logs (token counts, tool calls, costs) for billing and abuse prevention
- We only send content to Anthropic when you actively use AI features. Content you don't engage AI with is never sent to Anthropic.
5. Who We Share Your Information With
We share your information only when necessary to operate the service. We do NOT sell your personal information to anyone. Ever.
We share information with:
- Supabase: Database hosting and authentication. Shared: account data, projects, content
- Lovable: Application hosting. Shared: page requests, technical data
- Webflow: Marketing site hosting. Shared: page requests, technical data
- Anthropic: AI features (when you use them). Shared: AI chat messages, project context
- Stripe: Payment processing (when you subscribe). Shared: billing email, subscription details
- Liveblocks: Real-time collaboration (when in shared projects). Shared: document content, presence data
- Sentry: Error monitoring. Shared: error reports, technical metadata
- Resend: Transactional email delivery. Shared: email address, message content
- PostHog: Product analytics (anonymized usage data). Shared: click events, navigation, scroll behavior; all text content and inputs are masked in your browser before transmission
- Microsoft Clarity: Marketing-site analytics and session replay. Shared: page interactions on the marketing site, with content masked
- Google: Sign-in (if you use Google sign-in). Shared: auth tokens (we receive your profile info)
- Google AI (Gemini): Image classification for Library search tags when you save assets. Shared: image content for the sole purpose of generating descriptive tags. Per Google's API terms, your content is not used to train AI models.
These vendors are contractually required to protect your data and only use it for the purpose of providing services to us. Most are based in the US; a few in the EU.
We may also disclose information:
- In response to a valid legal request (subpoena, court order)
- To protect Noodal, our users, or the public from harm or fraud
- In connection with a merger, acquisition, or sale of Noodal (you'll be notified)
- With your explicit consent
6. Collaborators and Shared Content
When you invite collaborators to a project, those collaborators see:
- Your name and profile photo
- Content within shared projects
- Comments and edits you make in shared projects
- Folder context you set is visible to everyone with access to projects in that folder. Don't put sensitive personal information in folder context.
When you create a public share link, anyone with the link can access that project. We log share link access for security purposes.
7. How Long We Keep Your Information
Account data: While your account is active
Projects and content: While your account is active; deleted within 30 days of soft-deletion
AI chat history: While your account is active; you can delete anytime
Usage logs: 12 months for product analytics, longer for billing/audit
Payment records: 7 years (legal requirement)
Trash: 30 days, then permanently deleted
Marketing email preferences: Until you unsubscribe or delete account
Backups: Up to 90 days
When you delete your account, we delete or anonymize personal data within 30 days, except where retention is required by law (e.g., billing records for tax purposes).
8. How We Protect Your Information
We use industry-standard security practices:
- Data encrypted in transit (TLS/HTTPS for everything)
- Data encrypted at rest (Supabase default encryption)
- Row-level security on all database tables
- Authentication tokens with short expiry
- Two-factor authentication available for accounts
- Regular security audits
Despite these measures, no system is 100% secure. We can't guarantee absolute security, but we work hard to protect your data.
If a breach occurs, we'll notify you within 72 hours of becoming aware, as required by GDPR.
9. Your Rights
You have the right to:
- Access: Request a copy of the data we have about you
- Correction: Fix inaccurate or incomplete information
- Deletion: Ask us to delete your data ("right to be forgotten")
- Portability: Get your data in a machine-readable format
- Restriction: Limit how we use your data
- Objection: Object to specific uses (like marketing)
- Withdraw consent: Revoke any consent you've given (e.g., marketing emails)
- Lodge complaint: Contact your local data protection authority if you believe we're not handling your data correctly
To exercise any of these rights, email help@noodal.app. We'll respond within 30 days.
You can also handle most things directly in your account settings: delete projects, export data, update profile, manage email preferences.
10. International Data Transfers
We're based in the United States. If you're outside the United States, your data is transferred and processed in the United States.
For users in the European Economic Area (EEA), United Kingdom, or Switzerland, we use Standard Contractual Clauses with US-based vendors to ensure your data has GDPR-equivalent protection.
11. Children's Privacy
Noodal is not intended for children under 16. We don't knowingly collect data from children under 16. If you believe a child has created an account, contact us at help@noodal.app and we'll delete it.
12. Cookies and Tracking
Noodal uses cookies and similar technologies for:
- Authentication: Keep you signed in. Required: yes (essential)
- Preferences: Remember settings (theme, language). Required: no (functional)
- Analytics: Understand product usage. Required: no (analytics)
- Website analytics (Clarity): Understand marketing-site usage and session replay. Required: no (analytics)
You can control cookies through your browser settings. Disabling essential cookies will break the service.
We don't use advertising cookies. We don't share data with ad networks. We don't track you across other websites.
Session Analytics
We use PostHog to understand how Noodal is used so we can fix bugs and improve the product. PostHog records anonymized interaction signals like clicks, scrolls, page navigation, and time on page.
All text content, form inputs, document bodies, canvas items, mind map nodes, and comments are masked in your browser before any data leaves your device. We cannot read your document content, project names, comments, or anything you type into Noodal through session analytics. This masking runs locally on your computer and cannot be bypassed by anyone at Noodal.
On our marketing website (not the app) we use Microsoft Clarity to understand how visitors use the site, including aggregated heatmaps and session replay. Clarity runs only on the marketing site, sees anonymous visitor interactions, and has content masking enabled.
We use this data only to improve the product. We do not share it with advertisers or use it for marketing.
13. Marketing Communications
We send marketing emails only if you opt in (during signup or in your account settings). You can unsubscribe anytime via the "unsubscribe" link in marketing emails or in your account settings.
We always send transactional emails (account-related, billing, security) regardless of your marketing preferences. You can't opt out of these because they're required to operate the service.
14. Changes to This Policy
We may update this policy occasionally. When we do, we'll update the "Last updated" date at the top. For material changes, we'll notify you via email or in-app notification at least 14 days before the change takes effect.
If you don't agree with the updated policy, you can delete your account before the changes take effect.
15. Contact Us
For privacy questions, requests to exercise your rights, or any concerns:
Email: help@noodal.app
Mailing address: Noodal, LLC, 8 The Green, Suite #16544, Dover, DE 19901, USA
If you're in the EU and feel we haven't addressed your concern, you can file a complaint with your local data protection authority.
By using Noodal, you acknowledge you've read this Privacy Policy.
16. The "Add to Noodal" Browser Extension
The "Add to Noodal" Chrome extension lets you save images and videos from any website directly to your Noodal Library. This section explains how the extension specifically handles your data.
What the extension accesses
The extension uses the following browser permissions:
- Active tab access: Reading images on the page you're currently viewing, only when you click the extension icon or use the right-click "Save to Noodal" menu.
- Local storage: Storing your authentication session locally so you stay signed in across browser restarts.
- Context menus: Adding the right-click "Save to Noodal" option to images on web pages.
- Identity: Used only for the Google sign-in flow.
- Host permissions: Granted by you per-site on first use; used to fetch image bytes when CORS restrictions block direct access.
What the extension does NOT do
- It does NOT read or transmit any data from web pages other than the images you actively choose to save.
- It does NOT track your browsing history.
- It does NOT inject scripts into pages unless you trigger a save or scan.
- It does NOT access cookies, passwords, form data, or any sensitive content on websites you visit.
- It does NOT run in the background when you are not actively saving.
What we send to our servers when you save an asset
When you choose to save an image or video, we transmit:
- The image or video bytes downloaded by the extension from the source URL you selected.
- The source URL of the asset and the URL of the page you saved it from.
- The page title, used for organization in your Library.
- A perceptual hash of the image, used to detect when you save the same image twice and skip the duplicate.
- The bucket or buckets you chose to save it to.
What we do NOT send
- The full DOM or HTML of the page you are saving from.
- Any other content on the page besides the asset you selected.
- Your browsing history, cookies, or any session data from the source site.
Where the saved data goes
Saved assets are stored in Supabase as described in Section 5. They become part of your personal Library. Auto-tagging of saved images uses Anthropic's Claude API under their commercial terms described in Section 4, and Google's Gemini API for image classification. In both cases, images are sent for the sole purpose of generating descriptive tags for your own search, are not used to train any AI model, and tag generation results are stored only in your account.
Authentication
The extension signs in via the same authentication as the Noodal app: either Google sign-in or email and password. Your session is stored locally in the browser's secure extension storage and is used only to authenticate API calls to Noodal. Signing out of the extension or revoking access removes the session immediately.
Uninstalling
Uninstalling the extension removes all locally stored session data immediately. Your Library data in your Noodal account is unaffected; manage or delete it from the Noodal app at any time.