Privacy Policy
Last updated: 2026-08-12Who we are
Nodo is a WhatsApp-based productivity assistant built and operated by Value Add Capital LLC. Questions? Email hello@getnodo.ai.
What we collect
- Phone number — required to send and receive WhatsApp messages.
- Name and (optional) email — collected at signup so Nodo can address you and send admin notifications.
- Message content — everything you text Nodo and everything we send back, so the assistant can remember context across conversations.
- Timezone and schedule preferences — to deliver morning briefs and weekly reviews at the right local time.
- Usage events — timestamps of inbound/outbound messages, opt-in changes, and feature interactions, used to operate and improve the service.
How we use it
- To run the service: capture your tasks, ideas, and reminders, and reply to your messages.
- To send proactive WhatsApp messages you've opted into (daily briefs, weekly reviews, reminders).
- To improve Nodo — diagnose issues, refine prompts, and prioritize features.
WhatsApp specifically
WhatsApp messages are delivered through Meta's WhatsApp Business Platform. Meta processes message metadata and content for delivery as described in Meta's WhatsApp Business Policy. We do not control Meta's infrastructure or retention.
Google Workspace (Calendar & Gmail)
Connecting your Google account is optional. If you do, Nodo can manage your calendar and send email for you from WhatsApp. Nodo works fully without it, and you can disconnect any time.
What we access — only the narrow permissions you grant: creating, viewing, and editing events on your Google Calendar, and sending email on your behalf through Gmail. We do not read your inbox, your existing emails, your contacts, or any other Google data.
How we use it — solely to carry out what you ask for in chat: adding or changing a calendar event, telling you what's on your schedule, checking availability for a reminder, and sending an email you have reviewed. We never send an email without your explicit confirmation.
AI processing — when you ask Nodo about your calendar or to write an email, the relevant details are passed to our AI provider (see the Sharing list below) solely to generate your reply. Our AI providers do not use this data to train or improve their models.
What we store — while you're connected we store the Google access tokens needed to perform these actions, encrypted at rest, plus the email address of the connected Google account so we know which account is linked. We do not copy your calendar or email content into our systems beyond what is needed to complete the action you requested.
Disconnecting — say "disconnect google" in WhatsApp, or use your profile page, to revoke Nodo's access and delete the stored tokens and connected-account email. You can also revoke access anytime from your Google Account permissions.
Nodo's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Sharing
We do not sell your data. We do not share the content of your messages with other Nodo users. We use trusted infrastructure providers — these providers process data on our behalf under their own terms:
- Meta / WhatsApp Business Platform — message delivery
- 360dialog — WhatsApp Business Solution Provider (BSP)
- Anthropic — Claude AI models that generate replies
- OpenAI — language models for select internal tasks
- Supabase — database hosting
- Railway — application hosting
- Resend — transactional email
- Google — Calendar and Gmail APIs, only when you connect your Google account (calendar-event management + sending email you approve). We do not use your Google data for advertising or to train AI/ML models.
Sensitive information
Nodo does not request payment card numbers, financial account numbers, government ID numbers, or health information. Please do not share these via WhatsApp. If you do send sensitive information by accident, contact us and we will delete it.
Retention and deletion
We retain your data for as long as it serves a purpose tied to operating Nodo for you. Specifically:
- Active and paused accounts — kept while the account is in use, so the assistant has the context it needs across conversations.
- Opted-out accounts (you replied STOP) — kept for 90 days, then purged. The 90-day window lets you change your mind and resume by replying START without losing your items.
- Cold-inbound numbers (you texted us once but never activated) — kept for 30 days, then purged.
- Waitlist signups that never activate — kept for 365 days, then purged.
Logs (operational, not message content) are kept for up to 30 days on Railway and rotated automatically.
Your rights — access, correction, deletion
You can request at any time:
- Access — a copy of the data we hold about you (your account fields, items, messages, and feedback).
- Correction — fix incorrect information.
- Deletion — permanent removal of your account and all associated data, ahead of the retention windows above.
- Portability — your data exported in a machine-readable format (JSON).
Email hello@getnodo.ai from the address on file or from the phone number registered with Nodo. We aim to respond within 7 days. If we need to verify your identity (for sensitive deletion requests), we may ask you to confirm via WhatsApp from the registered phone number.
Opt-out
Reply STOP to any Nodo WhatsApp message to opt out of all messages. You'll receive a single confirmation, then nothing further. Reply START or ACTIVATE at any time to come back.
Updates to this policy
If we make material changes, we'll update the "Last updated" date above and, where appropriate, notify you via WhatsApp.
Contact
Privacy questions, deletion requests, or anything else: hello@getnodo.ai.