Privacy
policy

Effective September 20, 2026 ยท Version 1.0

Summary

Provided for convenience; the formal policy below governs.

We collect and process the information described below to provide, secure, support, bill, and improve NoBS. Brief content is disclosed only to authorized service providers for the stated purposes, is not sold or used for advertising, and is not used by Padoca LLC to train general-purpose AI models. Authorized personnel may access content only where reasonably necessary for support, security, abuse investigation, legal compliance, or service repair. In plain terms: we do not read your briefs in the ordinary course of running the Service. You can export or request deletion of eligible information, subject to the retention exceptions below.

01โ€” Who We Are and Scope

Padoca LLC operates NoBS from the United States and determines how account administration, security, direct-user communications, product operations, billing records received by Padoca, support, analytics, and legal-compliance information are handled. Contact: hello@mynobs.co.

NoBS is currently a self-service beta focused primarily on individual users and organizations using the standard product. The standard Service is not designed for regulated-data processing, custom enterprise security commitments, or uses requiring a negotiated DPA. An organization that requires a DPA, specialized security terms, or other enterprise commitments must contact Padoca before submitting content and enter a separate signed agreement. Any signed agreement supplements this Privacy Policy and controls to the extent of a conflict.

U.S.-focused scope. This Policy describes Padoca's practices for the U.S.-focused Service. Technical accessibility from another location does not, by itself, mean Padoca affirmatively directs or offers the Service in every jurisdiction. Nothing in this Policy limits a right or obligation that applicable law does not permit Padoca or a user to waive.

02โ€” Information We Collect

(a) Account and profile information. Email address, first and last name, company, professional background (the discipline you select), country, date-format and display preferences, avatar, invitation code, tier and entitlement information, account timestamps, verification status, password hash, password-reset and authentication events, and administrative security records. We do not store plaintext passwords.

(b) User Content. Briefs you type, paste, or upload; project and organization names; versions; checklists; files; exports; share settings; and outputs such as translations, tension cards, references, reports, and differences between versions. User Content may include confidential information and personal information about people who are not account holders. Under the Terms, users are responsible for ensuring that they are authorized to submit information to NoBS, including compliance with their employer's or organization's applicable artificial-intelligence, confidentiality, information-security, data-governance, procurement, approved-vendor, and approved-technology policies. Padoca does not determine whether a user's employer, organization, client, customer, or other third party has authorized that use.

(c) Usage and analytics information. Number of briefs and updates, feature-interaction events (including page views, page paths, and referrers), usage-cycle information, export and share events, service-performance and error events, and aggregate or de-identified statistics. Events may be linked to an account identifier before aggregation. We do not include brief text in analytics or error reports. We do not attempt to re-identify de-identified information or disclose aggregate statistics in a form that identifies a user, an organization, or a brief and its content.

(d) Payment and subscription information. Stripe and/or its affiliates, including the merchant of record identified at checkout, collect payment-method and transaction information directly under Stripe's applicable terms, conditions, and privacy notice. Padoca may receive customer and subscription identifiers, plan, billing dates, currency, tax status, invoices, receipts, transaction status, refunds, disputes, cancellations, and webhook events. Padoca does not receive or store your full card number.

(e) Technical and security information. Depending on the request and provider configuration, this may include IP address, browser and device information, user-agent, request date and time, URL or referrer, approximate location derived from IP, cookie or session identifiers, authentication events, rate-limit events, and security logs.

(f) Consent, acceptance, and transaction records. The applicable Terms, Privacy Policy, cookie notice, checkout or plan terms, and consent language; account or customer identifier; plan, price, currency, and billing frequency where relevant; timestamp; IP address; user-agent; acceptance event; cookie preference; and other evidence reasonably needed to demonstrate assent, authorization, notice, or compliance.

(g) Communications and support information. Emails, contact-form messages, support requests, bug reports, attachments, and delivery, bounce, or complaint events received from email and support providers.

03โ€” How We Use Information

PurposeInformation usedWhy we use it
Provide and personalize the Service; generate outputs; track versions; create exports and sharesAccount information, User Content, usage informationPerform the service and actions requested by the user
Authentication, account separation, service security, incident investigation, fraud and abuse preventionAccount, technical/security, and usage information; limited User Content where necessaryProtect users, Padoca, and the Service
Billing, subscriptions, taxes, refunds, disputes, and account reconciliationPayment/subscription and account informationAdminister purchases and meet payment, tax, and recordkeeping obligations
Transactional and service communications, verification, receipts, policy notices, and supportAccount, communications, and payment/subscription statusOperate accounts and respond to users
Plan quotas, troubleshooting, performance, and service improvementUsage, technical, aggregate, or de-identified informationOperate, measure, troubleshoot, and improve the Service
Enforce Terms, protect rights, establish or defend legal claims, and comply with lawful requestsRelevant account, User Content, security, consent, and communications informationProtect legal rights and comply with law
Corporate transactions subject to confidentiality and appropriate safeguardsRelevant account, contract, and operational informationEvaluate or complete a financing, reorganization, acquisition, or sale
Product news and notices about NoBSEmail address, name, country, professional background, tier, invitation codeKeep users informed about the Service; every news email carries an unsubscribe link

We do not sell or rent personal information. We do not use personal information for cross-context behavioral advertising or promotional profiles, and we do not make solely automated decisions that produce legal or similarly significant effects.

We may send product news and notices to the email address on your account. Every such email includes an unsubscribe link, and an unsubscribe is honored immediately and is not reversed by later account activity. Unsubscribing does not stop transactional messages about your account, billing, security, or changes to these policies.

04โ€” AI and Search Processing

(a) To generate outputs, User Content and related context โ€” the text of your brief, a document you upload (sent for text extraction), and, for an update, the previous translation โ€” may be transmitted to OpenAI. OpenAI processes the information to provide the requested AI functions under Padoca's provider agreement and its own applicable service terms and privacy disclosures.

(b) Padoca uses OpenAI's API, whose data is not used to train OpenAI's models by default. Padoca has not opted in to data sharing for model improvement, and each request asks OpenAI not to store it beyond what is needed to respond. OpenAI may retain limited information for abuse monitoring and security under its contract and technical settings.

(c) We design requests to minimize information sent outside Padoca's infrastructure and send only the content and context reasonably necessary for the requested function. We seek to minimize personal, organization, and project identifiers in operational logs and search queries.

(d) Logging and support access. Padoca is designed not to write full brief text to ordinary operational logs. Limited metadata may be recorded for diagnostics, security, and rate limiting. Where feasible, Padoca uses pseudonymous internal identifiers instead of organization or project names. Production access is restricted to authorized operational purposes.

(e) Reference verification. To verify a reference example, NoBS may send a short, brief-derived query to Brave Search, such as a title, organization, product, person, source, award, or related term. We do not intentionally send the full brief and seek to minimize confidential or personal information before transmission. Brave Search's applicable terms and privacy notice govern its independent search service and do not replace Padoca's obligations under this Policy.

05โ€” Service Providers and Other Disclosures

Current material service providers include Vercel (hosting, serverless compute, and cookieless site traffic measurement; application data in transit and technical or runtime data, including page views, referrers, country, and device class); Upstash (data storage; account information, encrypted User Content, usage information, and configured backups); OpenAI (AI processing; User Content, generation context, outputs, and API metadata); Brave Search (reference verification; minimized search queries and API metadata); Stripe and its affiliates (payment processing, merchant-of-record functions, tax, fraud, disputes, and transaction support; payment, billing, subscription, and transaction information); Resend (transactional email; email addresses, message content, and delivery events); Loops (product news and notices; email address, name, country, professional background, tier, invitation code, and subscription status); Sentry (error monitoring; error reports with the page or endpoint, browser and device information, and technical context, with brief content and account identity removed before sending); ConvertAPI, operated by UAB Baltsoft (document conversion; requested export content and conversion metadata); and Hostinger (mailbox hosting for NoBS email).

Our pages also load resources from Google Fonts (typefaces), Sentry's content delivery network (the error-monitoring script), Vimeo (the video embedded on the What is NoBS page, with do-not-track enabled), and jsDelivr (an audio library used by the arcade). When a resource loads, that provider receives your IP address and browser information under its own privacy notice; none of them receives User Content.

Each provider's own terms, conditions, privacy notice, and/or customer agreement govern that provider's independent service or processing where applicable. Those documents do not replace this Privacy Policy for Padoca's handling of information. Users may be required to accept Stripe's checkout terms directly. When a provider processes information on Padoca's behalf, Padoca's contract with that provider governs the processing. Providers and configurations may change as the Service evolves; a current list is available from hello@mynobs.co.

We may also disclose information at your direction; to professional advisers under confidentiality; in connection with a financing, reorganization, acquisition, merger, or sale subject to appropriate safeguards; to protect the rights, safety, and security of Padoca, users, or others; or in response to valid legal process. Where legally permitted and appropriate, we will notify the affected user or organization before compelled disclosure.

06โ€” Security and Incident Response

Padoca uses administrative, technical, and organizational safeguards designed to protect User Content and personal information. No system is perfectly secure, and we cannot guarantee absolute security. Current safeguards include:

  • account-scoped storage and authenticated, server-side ownership checks designed to separate each user's User Content;
  • restricted administrative and production access for authorized operational purposes;
  • password hashes or authentication-provider controls rather than plaintext password storage;
  • httpOnly session cookies so session tokens are not ordinarily exposed to client-side scripts;
  • server-side authorization, quota, and entitlement checks;
  • HTTPS/TLS for all connections, enforced with HTTP Strict Transport Security, including the connection to the primary datastore;
  • per-record AES-256-GCM encryption of brief content and generated outputs before they are written to the datastore, with the encryption key held only in server-side configuration;
  • log minimization designed to exclude full brief text from ordinary operational logs;
  • server-side management of application secrets rather than intentional inclusion in client code or public repositories; and
  • rate limiting and anti-abuse controls on selected sensitive operations.

Security incidents may include malicious attacks, unauthorized access, data loss or corruption, service-provider failures, or other events affecting the confidentiality, integrity, or availability of information. Incident response. We maintain procedures to investigate, contain, and remediate suspected security incidents. If we determine that a breach of personal information requires notice, we will notify affected users, organizations, and authorities as required by applicable law. We may delay or tailor notice where permitted by law or requested by law enforcement. Notice may be provided through email, an in-product message, mynobs.co, or another method permitted by applicable law.

07โ€” Data Retention

  • Account information and User Content are retained while the account is active and as otherwise needed to provide the Service, resolve disputes, enforce agreements, meet legal obligations, and complete deletion.
  • After limited invitation access expires or a paid subscription is cancelled, User Content generally remains viewable and exportable while the account remains open; generation and paid or limited-access features may stop. We may later adopt an inactive-account retention limit after advance notice.
  • After account deletion, we remove your briefs, versions, outputs, share links, profile details, and indexes from active production systems promptly, cancel any active subscription, remove your contact from our news-and-notices tool, and instruct other providers to delete information where their services allow. Caches, logs, replicas, and backups are deleted or overwritten on their ordinary cycles; the primary datastore's automated backup is kept for one day. Deletion does not affect copies exported or shared by the user, the deletion record described in the next bullet, or records retained for billing, fraud prevention, disputes, legal claims, legal holds, or other lawful exceptions.
  • Deletion record. When you delete your account, Padoca keeps a limited record so that it can later show what you agreed to and when: your first and last name, email address, account identifier, country, plan tier, the number of briefs held, signup and deletion dates, and your consent and acceptance records (policy version, timestamp, IP address, country, user-agent, and the event). This record contains no briefs, outputs, or other profile details. It is kept for five years after deletion, or longer only while a dispute, claim, or legal hold is pending; it is used solely to demonstrate compliance and to establish, exercise, or defend legal claims, never for marketing or any other purpose; and access to it is restricted to authorized personnel. Recurring-billing authorization, billing, refund, tax, and dispute records are retained for the period reasonably necessary to meet accounting and payment obligations and resolve disputes.
  • Usage events (event name, page path, country, and a random account identifier) contain no name, email address, or brief content. They are retained while useful for product analytics and reviewed periodically; after account deletion the identifier no longer corresponds to any account.
  • Share links expire 90 days after creation and are removed earlier when the brief or the account is deleted.
  • An account whose email address is not verified within 7 days is deleted automatically. Signed-in sessions last up to 30 days or until you log out; verification and password-reset links expire after 60 minutes.
  • Limited security and suppression records may be retained for as long as reasonably necessary to prevent repeated fraud or serious abuse, subject to restricted access and periodic review.
  • Service providers retain information under their contracts, technical configurations, and applicable legal obligations. Current provider-retention information is available from hello@mynobs.co.

We determine retention periods based on the nature of the information, the purpose for which it is used, account status, security and fraud-prevention needs, provider backup cycles, legal obligations, and applicable limitation periods. We delete or de-identify information when it is no longer reasonably needed, subject to the exceptions above.

08โ€” Your Privacy Choices and Rights

You can exercise several choices directly in the product:

  • Access / portability: the Download my data control in your account exports, as a JSON file, the account information and brief data available to your browser at that moment; each brief can also be exported as a PDF or PPT file where your plan includes it. An export may exclude security logs, fraud signals, trade secrets, other users' information, and records controlled independently by payment or other providers.
  • Deletion: request account deletion through account settings. Deletion is irreversible after completion and cancels active access, subject to the retention exceptions in ยง07.
  • Correction: correct eligible account information in settings or contact us for information that cannot be corrected in-product.

To the extent an applicable U.S. state privacy law grants additional rights, you may also have rights to access, correct, delete, or obtain a portable copy of personal information; opt out of certain processing; use an authorized agent; appeal a denied request; and receive non-discriminatory treatment. We may verify identity and authority and may deny or limit a request where an applicable exception permits. Because we do not sell personal information or use it for cross-context behavioral advertising, related opt-out rights may not apply. For personal information contained in an organization's brief, contact that organization first; Padoca will reasonably assist where required.

09โ€” Cookies and Local Storage

We use cookies and browser storage for the functions below. You can manage optional choices through any cookie control made available in the Service.

Strictly necessary

  • Session cookie (nobs_session): keeps you signed in and protects the authenticated session; httpOnly and secure; expires after 30 days or when you log out.
  • Cookie-preference storage (nobs_cookie_consent, in your browser's local storage): remembers your cookie choices and records them in our consent trail.
  • Error monitoring (Sentry): if a page or request fails, a scrubbed error report is sent so we can fix the failure. It contains no brief content and no account identity.

Functional

  • Interface state in your browser's local and session storage: a cached copy of your profile fields for faster page loads, arcade scores and preferences, and โ€” while a page is loading a translation โ€” the brief text and its outputs, held in session storage and cleared when the tab closes.

Analytics

  • First-party product events on Padoca's own infrastructure (which features are used, page paths and referrers, country), collected only after you accept analytics in the cookie control. They never include brief text.
  • Site traffic measurement by Vercel, our hosting provider, runs on every page: page views, referrers, country, and device class, with no cookies, no cross-site tracking, and no stored IP address. It is part of operating the Service and is not switched by the cookie control, which covers our own product events. We do not use advertising cookies, cross-site behavioral tracking, or session recording.

Optional categories are disabled until an affirmative choice where applicable law requires consent. Where a consent interface is offered, reject and accept controls are intended to be comparably accessible.

10โ€” U.S. Operations and International Access

NoBS is operated from the United States and is primarily directed to U.S. users. Padoca and its service providers may process information in the United States and in other countries where they operate. If you access the Service from outside the United States, you do so on your own initiative and acknowledge that information may be transferred to and processed in the United States, where privacy laws may differ from those in your location. Technical accessibility does not mean Padoca affirmatively offers the Service in every jurisdiction. Where a non-waivable law directly requires a particular transfer safeguard or other protection, Padoca will use an appropriate lawful mechanism.

11โ€” Children

The Service is not directed to account holders under 18, and we do not knowingly permit them to create accounts. If we learn that an underage person created an account, we will take appropriate steps to delete or restrict it. Briefs concerning products, services, or projects intended for children may be permitted, but users must not upload personal dossiers, unsupported sensitive information, or unlawfully collected personal information about children and must have lawful authority for any permitted processing.

12โ€” Changes to This Policy

We may update this Privacy Policy. For material changes, including a new purpose, material information category, recipient, or retention practice, we will publish notice on mynobs.co and announce the update on the official NoBS Instagram profile, @nobriefshit, before the change takes effect. Instagram is an additional public announcement channel and does not replace any individual notice, retainable notice, or consent required by applicable law. Where required, we will also use an appropriate direct or in-product method and obtain consent. The current and prior versions will be maintained with their effective dates.

13โ€” Contact

Padoca LLC
hello@mynobs.co