Privacy
policy

Last updated: July 16, 2026

Draft for legal review โ€” not for publication

This document contains two policies: Terms of Service and Privacy Policy. Sections marked "[LAWYER REVIEW]" flag clauses where qualified legal counsel must confirm, refine, or replace placeholder language before publication.

Operating entity: Padoca LLC, a Delaware limited liability company (in formation). [LAWYER REVIEW: Confirm final registered name, formation date, and registered agent before publication. If formation is not complete at publish date, do not publish.]

Product status at drafting (July 2026): Live, invitation-only. Real user accounts, real briefs stored and processed. Paid subscriptions via Stripe are imminent; this draft is written paid-ready โ€” billing sections take effect when paid tiers activate.

Primary domain: mynobs.co

Last updated: [DATE TO BE INSERTED AT PUBLICATION]
Effective: [DATE TO BE INSERTED AT PUBLICATION]

Summary

Provided for convenience; the formal policy below governs.

We collect the minimum needed to run NoBS: your account info, the briefs you upload, the outputs generated from them, usage counters, and payment status (handled by Stripe โ€” we never see your card number). Briefs are sent to our AI provider's API solely to generate your outputs and are not used to train AI models. We don't sell data. We don't share briefs. You can export your data or permanently delete your account, yourself, at any time.

01Who We Are

The data controller is Padoca LLC, a Delaware limited liability company, operating NoBS at mynobs.co. Contact: [CONTACT EMAIL]. [LAWYER REVIEW: Whether an EU representative under GDPR Art. 27 and/or UK representative is required given user base.]

02What We Collect

(a) Account data. Email address, password (stored only as a bcrypt hash โ€” we cannot see your password), display name, invitation code used, tier and entitlement data, account timestamps.

(b) User Content. Briefs you paste or upload, project and client names you enter, brief versions, deliverable checklists, and the AI outputs generated from them (translations, tension cards, references, reports, diffs).

(c) Usage data. Brief and update counters per usage cycle, feature interaction events, and aggregate statistics (e.g., cumulative BS-cut metrics) used to power your reports.

(d) Payment data. Handled by Stripe. We receive and store only: subscription status, plan, billing-cycle dates, and Stripe customer/subscription identifiers. We never receive or store your full card number.

(e) Technical data. IP address, browser user-agent, and approximate country โ€” collected transiently for security, rate limiting, and consent logging.

(f) Consent records. A log of your acceptance of these policies (timestamp, IP, user-agent, policy version), kept as legal evidence of consent.

(g) Communications. Emails you send us; bug reports and contact-form submissions.

We do not collect data from third-party sources, and we do not run third-party advertising or tracking pixels.

03How We Use Your Data

Purpose Data used Legal basis (GDPR)
Provide the Service (translate briefs, generate outputs, track versions)Account data, User ContentContract performance
Authentication and account securityAccount data, technical dataContract performance; legitimate interest
Billing and subscription managementPayment dataContract performance
Transactional email (verification, receipts, account notices)Email addressContract performance
Quotas, entitlements, and abuse preventionUsage data, technical dataLegitimate interest
Legal compliance and consent evidenceConsent recordsLegal obligation
Service improvement (aggregate, non-content analytics)Usage dataLegitimate interest

We do not use your data for advertising, profiling for marketing, or automated decisions with legal effect. We do not sell or rent personal data. [LAWYER REVIEW: CCPA "sale/share" definitions โ€” confirm no disclosure qualifies; add CCPA notice section if California users are in scope.]

04AI Processing

(a) To generate outputs, brief content and related context are transmitted to OpenAI, L.L.C. via its API and processed by OpenAI's models.

(b) Under OpenAI's API terms, content submitted via the API is not used to train OpenAI's models. [LAWYER REVIEW: Confirm current OpenAI API data-usage and retention terms at publication; state the applicable API retention window accurately, and update this section if a Zero Data Retention arrangement is in place.]

(c) We design our systems to minimize what leaves our infrastructure: only the content necessary to produce your requested output is sent.

(d) Our internal operational logs are redacted so that brief content does not persist in plaintext operator logs.

05Sub-Processors

We share personal data only with the service providers below, only as needed to run NoBS, each bound by its own data-protection terms:

Provider Role Data touched
Vercel Inc.Hosting and serverless computeAll data in transit through the application
Upstash, Inc.Primary datastore (Redis)Account data, User Content, usage data
OpenAI, L.L.C.AI model APIBrief content and generation context
Stripe, Inc.Payment processingPayment and billing data
Resend, Inc.Transactional email deliveryEmail address, email content
ConvertAPI (UAB "Baltsoft")Document export conversion (PDF/PPT)Content of exports you request, transiently

[LAWYER REVIEW: Confirm DPAs / SCCs are executed or incorporated with each provider; confirm ConvertAPI legal entity name and retention behavior.]

We will update this list when providers change. We do not share data with any other third parties except as required by law (e.g., valid legal process), in which case we will notify you where legally permitted.

06Security

Measures currently in place, as built:

  • Passwords stored only as bcrypt hashes; plaintext passwords are never stored or logged.
  • Sessions via httpOnly cookies; session tokens are not exposed to client-side scripts.
  • Server-side tenant isolation: every read and write verifies the authenticated user against the data owner; quotas and entitlements are enforced server-side.
  • Transport encryption (HTTPS/TLS) on all connections.
  • Operator log redaction: brief content is redacted from operational logs.
  • Secrets held server-side in environment configuration, never in client code or the repository.
  • Rate limiting and single-redemption guards on sensitive operations.

No system is perfectly secure. If we become aware of a personal-data breach creating risk to you, we will notify affected users and regulators as required by applicable law (including GDPR Art. 33/34 timelines). [LAWYER REVIEW: Breach-notification wording per applicable state and EU law.]

07Data Retention

  • Account data and User Content: retained while your account exists.
  • After free-tier expiry or subscription cancellation: your data is retained and remains viewable/exportable; only generation stops. Your work is never deleted by expiry.
  • After account deletion: all account data, briefs, versions, outputs, and indexes are permanently deleted in a full cascade at the time of deletion. [LAWYER REVIEW: State backup/replica purge window if datastore replicas retain data transiently.]
  • Consent records: retained after account deletion as legal evidence of consent, for the period required by applicable law. [LAWYER REVIEW: Retention period.]
  • Billing records: retained as required by tax and accounting law, held by Stripe and in our billing records.
  • AI provider retention: API inputs/outputs are retained by OpenAI per its API policy for abuse monitoring and then deleted. [LAWYER REVIEW: State the current window accurately; update if ZDR is granted.]

08Your Rights

You can exercise most rights directly, in the product, without asking us:

  • Access / portability: export your complete data from your account at any time.
  • Deletion: permanently delete your account and all associated data from your account settings. This is immediate and irreversible.
  • Rectification: correct your account information in settings.

Additionally, depending on your jurisdiction (GDPR, UK GDPR, CCPA/CPRA, and similar laws), you may have rights to object to or restrict processing, to withdraw consent, to non-discrimination for exercising rights, and to lodge a complaint with a supervisory authority. To exercise any right you cannot complete in-product, contact [CONTACT EMAIL]. We respond within the timelines required by applicable law. [LAWYER REVIEW: Add named supervisory-authority guidance for EU users; CCPA-specific disclosures if in scope.]

09Cookies and Local Storage

We use only the cookies and browser storage necessary to operate the Service:

  • Session cookie (httpOnly): keeps you signed in. Strictly necessary.
  • Functional local storage: interface preferences and non-sensitive state.
  • Consent record storage: your cookie/consent choices.

We do not use third-party advertising or cross-site tracking cookies. A cookie notice within the Service itemizes current keys and lets you manage functional storage. [LAWYER REVIEW: Whether current consent-banner mechanics satisfy ePrivacy requirements for the functional category.]

10International Data Transfers

Our infrastructure providers are U.S.-based; data is processed in the United States. If you access the Service from the EU/EEA/UK, your data is transferred to the U.S. under our providers' safeguards, including EU-U.S. Data Privacy Framework participation and/or Standard Contractual Clauses as applicable to each provider. [LAWYER REVIEW: Verify each sub-processor's current transfer mechanism.]

11Children

The Service is not directed to anyone under 18, and we do not knowingly collect data from anyone under 18. If we learn we have done so, we will delete it.

12Changes to This Policy

We may update this Privacy Policy. For material changes we will give at least 14 days' notice via the Service or email. The "Last updated" date at the top reflects the current version. Prior versions are available on request.

13Contact

Padoca LLC โ€” [REGISTERED ADDRESS TO BE INSERTED]
Email: [CONTACT EMAIL]

NoBS โ€” "We don't share briefs. We cut them."