This document contains two policies: Terms of Service and Privacy Policy. Sections marked "[LAWYER REVIEW]" flag clauses where qualified legal counsel must confirm, refine, or replace placeholder language before publication.
Operating entity: Padoca LLC, a Delaware limited liability company (in formation). [LAWYER REVIEW: Confirm final registered name, formation date, and registered agent before publication. If formation is not complete at publish date, do not publish.]
Product status at drafting (July 2026): Live, invitation-only. Real user accounts, real briefs stored and processed. Paid subscriptions via Stripe are imminent; this draft is written paid-ready โ billing sections take effect when paid tiers activate.
Primary domain: mynobs.co
Last updated: [DATE TO BE INSERTED AT PUBLICATION]
Effective: [DATE TO BE INSERTED AT PUBLICATION]
Provided for convenience; the formal policy below governs.
We collect the minimum needed to run NoBS: your account info, the briefs you upload, the outputs generated from them, usage counters, and payment status (handled by Stripe โ we never see your card number). Briefs are sent to our AI provider's API solely to generate your outputs and are not used to train AI models. We don't sell data. We don't share briefs. You can export your data or permanently delete your account, yourself, at any time.
The data controller is Padoca LLC, a Delaware limited liability company, operating NoBS at mynobs.co. Contact: [CONTACT EMAIL]. [LAWYER REVIEW: Whether an EU representative under GDPR Art. 27 and/or UK representative is required given user base.]
(a) Account data. Email address, password (stored only as a bcrypt hash โ we cannot see your password), display name, invitation code used, tier and entitlement data, account timestamps.
(b) User Content. Briefs you paste or upload, project and client names you enter, brief versions, deliverable checklists, and the AI outputs generated from them (translations, tension cards, references, reports, diffs).
(c) Usage data. Brief and update counters per usage cycle, feature interaction events, and aggregate statistics (e.g., cumulative BS-cut metrics) used to power your reports.
(d) Payment data. Handled by Stripe. We receive and store only: subscription status, plan, billing-cycle dates, and Stripe customer/subscription identifiers. We never receive or store your full card number.
(e) Technical data. IP address, browser user-agent, and approximate country โ collected transiently for security, rate limiting, and consent logging.
(f) Consent records. A log of your acceptance of these policies (timestamp, IP, user-agent, policy version), kept as legal evidence of consent.
(g) Communications. Emails you send us; bug reports and contact-form submissions.
We do not collect data from third-party sources, and we do not run third-party advertising or tracking pixels.
| Purpose | Data used | Legal basis (GDPR) |
|---|---|---|
| Provide the Service (translate briefs, generate outputs, track versions) | Account data, User Content | Contract performance |
| Authentication and account security | Account data, technical data | Contract performance; legitimate interest |
| Billing and subscription management | Payment data | Contract performance |
| Transactional email (verification, receipts, account notices) | Email address | Contract performance |
| Quotas, entitlements, and abuse prevention | Usage data, technical data | Legitimate interest |
| Legal compliance and consent evidence | Consent records | Legal obligation |
| Service improvement (aggregate, non-content analytics) | Usage data | Legitimate interest |
We do not use your data for advertising, profiling for marketing, or automated decisions with legal effect. We do not sell or rent personal data. [LAWYER REVIEW: CCPA "sale/share" definitions โ confirm no disclosure qualifies; add CCPA notice section if California users are in scope.]
(a) To generate outputs, brief content and related context are transmitted to OpenAI, L.L.C. via its API and processed by OpenAI's models.
(b) Under OpenAI's API terms, content submitted via the API is not used to train OpenAI's models. [LAWYER REVIEW: Confirm current OpenAI API data-usage and retention terms at publication; state the applicable API retention window accurately, and update this section if a Zero Data Retention arrangement is in place.]
(c) We design our systems to minimize what leaves our infrastructure: only the content necessary to produce your requested output is sent.
(d) Our internal operational logs are redacted so that brief content does not persist in plaintext operator logs.
We share personal data only with the service providers below, only as needed to run NoBS, each bound by its own data-protection terms:
| Provider | Role | Data touched |
|---|---|---|
| Vercel Inc. | Hosting and serverless compute | All data in transit through the application |
| Upstash, Inc. | Primary datastore (Redis) | Account data, User Content, usage data |
| OpenAI, L.L.C. | AI model API | Brief content and generation context |
| Stripe, Inc. | Payment processing | Payment and billing data |
| Resend, Inc. | Transactional email delivery | Email address, email content |
| ConvertAPI (UAB "Baltsoft") | Document export conversion (PDF/PPT) | Content of exports you request, transiently |
[LAWYER REVIEW: Confirm DPAs / SCCs are executed or incorporated with each provider; confirm ConvertAPI legal entity name and retention behavior.]
We will update this list when providers change. We do not share data with any other third parties except as required by law (e.g., valid legal process), in which case we will notify you where legally permitted.
Measures currently in place, as built:
No system is perfectly secure. If we become aware of a personal-data breach creating risk to you, we will notify affected users and regulators as required by applicable law (including GDPR Art. 33/34 timelines). [LAWYER REVIEW: Breach-notification wording per applicable state and EU law.]
You can exercise most rights directly, in the product, without asking us:
Additionally, depending on your jurisdiction (GDPR, UK GDPR, CCPA/CPRA, and similar laws), you may have rights to object to or restrict processing, to withdraw consent, to non-discrimination for exercising rights, and to lodge a complaint with a supervisory authority. To exercise any right you cannot complete in-product, contact [CONTACT EMAIL]. We respond within the timelines required by applicable law. [LAWYER REVIEW: Add named supervisory-authority guidance for EU users; CCPA-specific disclosures if in scope.]
We use only the cookies and browser storage necessary to operate the Service:
We do not use third-party advertising or cross-site tracking cookies. A cookie notice within the Service itemizes current keys and lets you manage functional storage. [LAWYER REVIEW: Whether current consent-banner mechanics satisfy ePrivacy requirements for the functional category.]
Our infrastructure providers are U.S.-based; data is processed in the United States. If you access the Service from the EU/EEA/UK, your data is transferred to the U.S. under our providers' safeguards, including EU-U.S. Data Privacy Framework participation and/or Standard Contractual Clauses as applicable to each provider. [LAWYER REVIEW: Verify each sub-processor's current transfer mechanism.]
The Service is not directed to anyone under 18, and we do not knowingly collect data from anyone under 18. If we learn we have done so, we will delete it.
We may update this Privacy Policy. For material changes we will give at least 14 days' notice via the Service or email. The "Last updated" date at the top reflects the current version. Prior versions are available on request.
Padoca LLC โ [REGISTERED ADDRESS TO BE INSERTED]
Email: [CONTACT EMAIL]
NoBS โ "We don't share briefs. We cut them."