Privacy Policy

Last updated: October 4, 2026

This Privacy Policy explains how information is collected, used, shared, and safeguarded when you use the Nodey mobile application (the "App"), getnodey.com, and related services (the "Service").

Better Brain Lab LLC operates the Google Play edition of Nodey. Skin Kins Co. operates the iOS edition. In this policy, "we," "us," and "our" refer to the operator of the edition you use. Skin Kins Co. operates the website.

This policy is the same Privacy Policy linked from the App Store, Google Play, the App, and getnodey.com. By installing, accessing, or using the Service, you acknowledge that you have read and understood this Privacy Policy.

If you have questions about this policy or want to exercise any of your privacy rights, contact us at privacy@getnodey.com .


1. Who we are

For the iOS edition, Skin Kins Co. is a Delaware C-corporation. Its registered office is 1201 Orange Street, Wilmington, DE 19801. Its mailing address is 1521 Alton Road, Miami Beach, FL 33139.

For privacy inquiries, contact privacy@getnodey.com or call (888) 441-3005.

For users in the European Economic Area, the United Kingdom, or Switzerland: the operator of the edition you use is the controller of your personal data within the meaning of the GDPR and the UK GDPR. We have not appointed an EU or UK representative at this time; for any questions, please contact us using the email address above.


2. What Nodey does and what it means for your data

Nodey is a mobile companion app for n8n, the workflow automation platform. The App connects to n8n instances that you control — either self-hosted n8n servers you operate yourself, or n8n.cloud accounts that belong to you — and lets you monitor workflows, view executions, trigger runs, diagnose failures with AI assistance, and back up workflow definitions.

This means three things matter for understanding your data:

  1. Most operational data stays between your device and your n8n instance. When the App fetches your workflows, executions, or logs, that data flows directly from your n8n server to your phone. We do not receive a copy of it.
  2. Some data flows to AI providers when you use AI features. AI features (such as Workflow Explainer, Error Diagnosis, Security Hardening) send the relevant workflow content to an AI model so it can analyse and respond. This is described in detail in Section 5.
  3. Some technical data flows to our infrastructure and to operational vendors. This includes account-level information, subscription state, crash reports, pseudonymous usage analytics, push notification tokens, and similar operational data. This is described in Section 4.

3. Information we collect

We collect three categories of information.

3.1 Information you provide to us

Category Examples Why we have it
Account contact details Email address (when you contact support, request a refund, or sign up for marketing communications) To respond to you and provide the Service
Connection configuration The name you give an n8n instance, its base URL (e.g., https://n8n.example.com), and configuration of any triggers (geofence coordinates, NFC tag identifiers, webhook URLs) To let the App connect to your n8n instance and fire your triggers
Credentials n8n API keys, AI provider API keys you choose to use ("BYOK" — Bring Your Own Key) To authenticate against the services you direct the App to call
Subscription information Your subscription tier, purchase receipts, and product entitlements To grant you access to paid features
Support communications Anything you choose to include in an email, support request, or feature request To assist you

Where credentials and connection configuration are stored. API keys you enter (n8n keys, BYOK keys for Claude/Gemini/Mistral) are stored in the iOS Keychain (or Android Keystore-backed storage) on your device and are not transmitted to our servers. They are transmitted only to the service the key is associated with — your n8n instance, or the AI provider whose key you provided — for the connections, monitoring, and actions you configure.

Private review access. An optional reviewer code is stored securely on the device and sent only to Nodey’s authenticated AI relay for verification. It is separate from n8n and AI-provider keys, does not create a store purchase, and can be removed in AI Settings.

Sharing from other apps. If you configure sharing webhooks, Nodey stores their destination URLs on your device. After you confirm Send in the share sheet, the shared text or URL is sent directly to those destinations as a JSON payload. It does not pass through the Nodey AI relay. The receiving service controls its retention. Nodey does not persist the shared text after the sharing session.

3.2 Information we collect automatically

Category What it includes Source
Device and OS info Device model, OS version, App version, language, time zone App telemetry
Approximate location (derived) Approximate area inferred by service providers from network requests; Nodey disables Amplitude IP-address, city and region analytics Server logs, analytics
Precise location Used only if you enable location-based triggers ("geofences"). Coordinates are processed on-device and inside your geofence trigger configuration; they are not transmitted to us as part of routine operation. When you use the Android map, Google Maps processes the map requests needed to display that area. iOS / Android location services (with your consent)
Diagnostic data Crash logs, performance traces, errors, stack traces, exception messages Firebase Crashlytics
Usage analytics (in-app) Screens viewed, features used, button taps, session start/end, in-app purchase events. We do not collect the content of your workflows, executions, or AI prompts as analytics events. Amplitude
Website analytics (getnodey.com) Pageviews, sessions, referrer, device and browser type — collected only if you accept the analytics cookie banner on the website. See Section 12 for full details. Google Analytics 4
Push notification token An opaque identifier issued by Apple Push Notification Service (APNs) and forwarded to Firebase Cloud Messaging iOS / Firebase
Subscription telemetry Pseudonymous app user identifier, subscription status, transaction events, entitlement state RevenueCat, App Store / Google Play
Remote configuration metadata Installation identifier used by Firebase Remote Config to deliver the correct content variant Firebase

3.3 Information we receive from third parties

In-app privacy controls. Usage analytics and crash reporting are optional and can be disabled in Settings. These records use persistent installation or app-user identifiers and may be linked to subscription records; they are not fully anonymous. Turning them off does not disable the authentication, purchase verification, and app security checks needed for managed Nodey AI.

  • Apple and Google Play: when you make an in-app purchase, we receive a transaction receipt to validate your subscription. We do not receive your full payment card details, only the data Apple or Google passes to developers (transaction ID, product ID, dates, anonymized account identifier).
  • AI providers (when AI features are used): we receive the AI's response to forward back to you. We do not receive payment or account information from AI providers.

3.4 Information we explicitly do not collect

  • We do not collect or transmit the contents of your n8n workflows, execution data, credentials stored inside n8n, or notes inside n8n, except (i) to your own n8n instance, or (ii) to an AI provider when you affirmatively use an AI feature, as described in Section 5.
  • We do not collect your contacts, calendars, photos, or microphone input.
  • We do not use the IDFA (iOS Advertising Identifier) or Android Advertising ID for advertising purposes. Nodey contains no advertising.
  • We do not sell your personal information.
  • We do not share your personal information with data brokers or for cross-context behavioural advertising.

4. How we use information

We use the information we collect for the following purposes, each tied to a lawful basis under GDPR/UK GDPR (where applicable):

Purpose Examples Legal basis (GDPR)
Provide the Service Connect to your n8n instance, fetch workflows, fire triggers, deliver push notifications Contract (Art. 6(1)(b))
Process subscriptions Validate purchases, manage entitlements, prevent fraud Contract (Art. 6(1)(b))
Communicate with you Respond to support, send service notices (e.g., security advisories) Contract / legitimate interests (Art. 6(1)(b)/(f))
Improve the Service Aggregate usage analytics, fix crashes, prioritise features Legitimate interests (Art. 6(1)(f))
Comply with the law Tax records, fraud prevention, response to lawful requests Legal obligation (Art. 6(1)(c))
AI feature delivery Send the workflow content you select to an AI provider so it can be analysed Consent (Art. 6(1)(a)) — see Section 5
Security and abuse prevention Detect unusual activity, rate-limit abuse, protect the Service Legitimate interests (Art. 6(1)(f))

We do not use your personal information for automated decisions producing legal or similarly significant effects, and we do not profile you for advertising.


5. AI features and what gets sent where

This is the most important section of this Privacy Policy. Read it carefully.

5.1 What an AI feature is

Nodey offers AI-powered analysis features (Workflow Explainer, Error Diagnosis, Security Hardening, Code Optimizer, Workflow Cleanup, Error Pattern Analysis, Performance Profiler, Workflow Builder, Deep Dive, and Debug Companion). When you tap one of these features, the App sends the relevant workflow content to an AI service so the model can analyse it and return a response.

5.2 What gets sent to the AI

When you invoke an AI feature, the App may send the following to the AI provider you have chosen (or the default, Nodey AI):

  • The workflow definition (nodes, connections, parameters, and any code inside Code nodes you wrote)
  • The names and metadata of the workflow
  • Execution data relevant to the request (for example, error messages, run timing, the failing node's input/output) — truncated to a model-appropriate length
  • Your follow-up prompt or question, if any (e.g., for Deep Dive or Debug Companion)
  • The user-controlled portions of any data inside your n8n workflow that the AI is asked to analyse — for example, if you ask the AI to diagnose an error in a node that processed customer data, the AI request will include that data

5.3 Who the AI provider is

You can choose between two modes:

(a) Nodey AI (default). Managed AI requests are routed through a relay operated for Nodey on Cloudflare Workers to Mistral AI. Firebase Authentication provides a pseudonymous installation identity, Firebase App Check verifies the app, and RevenueCat verifies subscription access. The relay processes your selected workflow definitions, execution details and prompts in transit; it does not persist prompt content or generated responses. It stores pseudonymous request and quota records for rate limiting, with automatic expiry. Your device may cache AI results locally for display and reuse.

(b) Bring Your Own Key (BYOK). If you supply your own API key for Anthropic (Claude), Google (Gemini), or Mistral, the request is sent directly from your device to that provider using your key. We do not see, log, or proxy the prompt or the response. The AI provider's privacy policy and terms govern that interaction.

5.4 What the AI provider does with the data

The content sent depends on the AI tool you select. Providers process that content under their applicable terms and account settings:

  • Mistral AI — see https://legal.mistral.ai/terms/privacy-policy/. Its terms and the applicable service configuration govern retention and any use of API content for model improvement.
  • Anthropic (Claude) — see https://www.anthropic.com/legal/privacy. Anthropic's API does not use API customer data to train models by default.
  • Google (Gemini) — see https://ai.google.dev/gemini-api/terms. Behaviour depends on the API tier, region, and the user's API key configuration. Certain unpaid Gemini API uses permit Google to use submitted content and responses to improve its services and models. Paid-service terms and regional rules differ; review the terms that apply to your account before sending sensitive content.

In compliance with App Store Review Guideline 5.1.2(i) (third-party AI disclosure), we will obtain your explicit consent the first time you use any AI feature, with a disclosure that names the AI provider for that feature and explains what data will be sent. You may revoke this consent at any time in Settings → AI Settings, after which a new AI request requires your permission again. Revoking consent does not recall data already sent. You can also delete your stored BYOK keys at any time from the same screen.

You can use Nodey without ever using an AI feature. The non-AI features of the App (monitoring, executions, triggers, backup) do not send data to any AI provider.

5.6 Sensitive data inside your workflows

If your n8n workflows process sensitive data (health records, biometric data, government identifiers, payment card data, or similar), be aware that invoking an AI feature on those workflows will transmit that data to the AI provider. You are responsible for ensuring that doing so is lawful in your jurisdiction and consistent with your obligations to your own users. Review workflow and execution content before requesting AI analysis. Automatic filtering cannot guarantee that all sensitive information has been removed.


6. How we share information

We share personal information in the following circumstances:

6.1 Sub-processors and service providers

We use the following third parties to operate the Service. Their roles depend on the service and applicable agreement. Some process data on Nodey's behalf; stores, map services, and providers you configure may also process data for their own purposes under their privacy policies and terms. They are not all acting solely on our instructions.

Vendor Role Data shared Provider base / service footprint
Apple (Apple Inc.) App distribution, in-app purchases, push notifications (APNs) Subscription transactions, push tokens, App Store account events United States
Google LLC (Google Play, Firebase) Android app distribution, in-app purchases, Firebase Cloud Messaging, Remote Config, anonymous Authentication and App Check Subscription transactions, push tokens, installation identifiers and app-attestation metadata United States, Multi-region
Mistral AI AI model inference for managed Nodey AI AI prompt content (workflow data you submit) France; processing locations depend on the service and configuration
Anthropic (Anthropic, PBC) Optional AI inference when you supply your own Anthropic key AI prompt content (workflow data you submit) United States
Hostinger International, Ltd. Cloud hosting (web infrastructure) Server logs, request metadata Lithuania (EU)
Cloudflare, Inc. DNS, CDN, website services and the authenticated managed-AI relay IP addresses, request headers, form data and selected AI prompt/response content in transit; pseudonymous quota and request records United States, Global edge network
Firebase Crashlytics (Google) Crash reporting and diagnostics Crash logs, device info, Firebase Installation ID United States, Multi-region
Google Analytics 4 (Google) Website analytics on getnodey.com Pageviews, network request metadata, device and browser metadata, referrer, session events United States, Multi-region
Amplitude, Inc. Product analytics (in-app) Usage events, device characteristics, installation and app-user identifiers. City, region, IP-address analytics and advertising identifiers are disabled in the app configuration. United States
RevenueCat, Inc. Subscription management Pseudonymous app user ID, transaction events, entitlement state United States

Core app configuration and cached content are stored on your device. Android location selection also uses Google Maps. Its SDK collects device/app metadata, diagnostics, an SDK identifier, IP address, and map interactions such as panning and zooming. See Google's Maps SDK data disclosure. Our hosted services and providers may process data across their infrastructure in multiple countries. We do not guarantee that all processing is confined to Phoenix or the Netherlands; refer to each provider's privacy documentation for details.

We require each sub-processor to maintain appropriate technical and organisational measures consistent with this Privacy Policy and with applicable law.

We may disclose personal information if we believe in good faith that disclosure is necessary to (a) comply with a subpoena, court order, or other lawful request from a competent authority; (b) protect the rights, property, or safety of the applicable operator, our users, or the public; (c) detect, prevent, or address fraud, security, or technical issues; or (d) enforce our Terms of Service. Where lawfully able to do so, we will notify the affected user before disclosure.

6.3 Business transfers

If the applicable operator is involved in a merger, acquisition, financing, reorganisation, bankruptcy, or sale of assets, your information may be transferred as part of that transaction. We will notify you (by email or in-app notice) of any such change and any choices you may have.

For any other purpose, we will share information only with your consent.

6.5 We do not sell or "share" personal information

We do not "sell" personal information, and we do not "share" personal information for cross-context behavioural advertising, as those terms are defined under California's CCPA/CPRA, Colorado's CPA, Connecticut's CTDPA, Virginia's VCDPA, or similar laws.


7. International data transfers

The Nodey operators are based in the United States. Your data may be transferred to, processed in, and stored in the United States and other countries listed in Section 6.1. These countries may have data-protection laws that differ from those in your country.

For transfers from the European Economic Area, the United Kingdom, or Switzerland to a country not subject to an EU adequacy decision (such as the United States), we rely on:

  • The EU-US Data Privacy Framework and the UK Extension to that Framework, where the receiving entity is certified; and/or
  • Standard Contractual Clauses issued by the European Commission, supplemented where appropriate by additional safeguards.

You may request a copy of the safeguards applicable to a specific transfer by emailing privacy@getnodey.com .


8. Data retention

We retain personal information only as long as necessary for the purposes for which we collected it.

Data Retention
Connection configuration and credentials (on-device) Until removed in the App. Android app storage is removed on uninstall; iOS Keychain items can survive uninstall. Remove saved instances and provider keys before uninstalling if you want to erase them
Subscription records As needed to verify and restore purchases, handle disputes and meet applicable accounting and legal obligations. Store and RevenueCat records have their own retention rules
Crash logs (Crashlytics) Subject to Firebase Crashlytics retention and any deletion requests; disabling reporting stops future app reports
Usage analytics (Amplitude) Subject to the configured Amplitude project retention and deletion requests; disabling analytics stops future app events. No automatic anonymisation period is promised
AI prompt content (in transit through Nodey infrastructure) Not persisted by the Nodey AI relay. Separate pseudonymous quota and request records expire after the current and previous UTC day
Support communications While needed to resolve the request and maintain necessary support or legal records
Marketing email lists Until you unsubscribe
Server logs Under the hosting or service provider’s retention settings; retained only as needed for operations and security

Push notification tokens are rotated and automatically expire when invalid.


9. Your privacy rights

9.1 Universal rights

Regardless of where you live, you can:

  • Access the personal information we hold about you.
  • Correct information that is inaccurate.
  • Delete your personal information (see also Section 9.5 below).
  • Export your information in a portable format.
  • Withdraw consent for any processing based on consent (including AI features).
  • Opt out of marketing emails by clicking "unsubscribe" in any marketing email or contacting us.

To exercise any right, email privacy@getnodey.com . We will respond within 30 days (or as required by your local law).

9.2 European Economic Area, United Kingdom, Switzerland

Under the GDPR and UK GDPR, you also have the right to:

  • Object to processing based on legitimate interests.
  • Restrict processing in certain circumstances.
  • Lodge a complaint with your local data protection authority. A list of EU authorities is available at edpb.europa.eu/about-edpb/about-edpb/members_en. The UK authority is the ICO at ico.org.uk.

9.3 California (CCPA/CPRA)

In addition to the universal rights above, California residents have the right to:

  • Know the categories and specific pieces of personal information we have collected about them.
  • Know the categories of sources from which the information is collected, the business or commercial purpose for collecting or selling the information, and the categories of third parties with whom we share it.
  • Opt out of the "sale" or "sharing" of personal information. We do not sell or share personal information, but you may submit such a request anyway and we will confirm.
  • Limit the use of sensitive personal information. We do not use sensitive personal information for any purpose other than providing the Service.
  • Non-discrimination for exercising any of these rights.

To exercise these rights, email privacy@getnodey.com . You may use an authorised agent; we will require reasonable proof of authorisation.

9.4 Other US states

Residents of Colorado, Connecticut, Virginia, Utah, Texas, and other states with comprehensive privacy laws have rights similar to those above. The same email address handles all such requests.

9.5 Account / data deletion

To request deletion of your data:

Deletion will remove your subscription record (subject to legal retention obligations described in Section 8), analytics records, support history, and any data in our infrastructure. On-device data (your n8n configurations, API keys, trigger settings) must be removed using the App and device controls. Uninstalling Android removes its private app storage; iOS Keychain items may survive uninstall. Remove saved instances and provider keys before uninstalling. Uninstalling does not cancel a store subscription.

We will confirm deletion within 30 days.


10. Security

We use technical and organisational measures designed to protect personal information against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These include:

  • Encryption in transit: HTTPS for connections to Nodey’s managed AI infrastructure and AI providers. Android permits unencrypted HTTP connections to user-selected local/private network servers and webhooks. The iOS share extension also accepts user-configured HTTP webhook URLs. HTTP is unencrypted; use HTTPS destinations when sharing confidential content.
  • Encryption at rest: API keys are stored in the iOS Keychain (kSecAttrAccessibleAfterFirstUnlockThisDeviceOnly) or Android Keystore.
  • Access controls: Operator personnel access to user data is limited to those with a business need.
  • Logging and monitoring: anomalous access patterns are monitored.
  • Vendor controls: providers process data under their applicable service terms, security controls and privacy policies.

No security control is perfect. If we discover a security incident affecting your personal information, we will notify you and any required regulator without undue delay and as required by applicable law.


11. Children

The App is not directed to children under 13 (or the equivalent minimum age in your jurisdiction; 16 in some EU member states). The App's age rating on the App Store is 4+ because it contains no objectionable content; this rating does not imply that the App is designed for children. We do not knowingly collect personal information from children under 13.

If you are a parent or guardian and you believe your child has provided us with personal information, contact us at privacy@getnodey.com and we will delete it.


12. Cookies and similar technologies on getnodey.com

The website offers optional Google Analytics. Before you accept analytics, Nodey does not load the Google Analytics script or send analytics events. You may accept or reject using the privacy panel; the same content is available either way.

If you accept, Google processes pageviews, referrers, device/browser information, session identifiers and network request metadata. Nodey disables Google Signals and advertising-personalisation signals in its website configuration. Google’s privacy policy describes its processing.

Your choice is stored locally for up to 12 months. Use the Cookie preferences button to change it. Rejecting clears accessible Google Analytics cookies and reloads the page to stop the loaded analytics library; it does not delete information already sent. If browser storage is unavailable, analytics stays disabled.

The site also loads resources required for its presentation, such as fonts and scripts. Their hosting services receive normal network request metadata. The current site does not load Website Speedy or provide a separate performance-cookie option.

The App itself does not use web cookies. App-level analytics are handled separately via the SDKs listed in Section 6.1.


13. Changes to this Privacy Policy

We may update this Privacy Policy from time to time. When we do, we will:

  • Update the "Last updated" date at the top of this document.
  • Post the revised policy at getnodey.com/privacy-policy.
  • For material changes, notify you via in-app notice and/or email at least 30 days before the change takes effect.

If you do not agree to a revised policy, you may stop using the Service. Continued use after the effective date of a revised policy constitutes acceptance of the revised policy.


14. Contact us

Privacy team privacy@getnodey.com
iOS operator phone (888) 441-3005
iOS operator mailing address Skin Kins Co., 1521 Alton Road, Miami Beach, FL 33139, USA
iOS operator registered office 1201 Orange Street, Wilmington, DE 19801, USA

For data subject requests, please use the email address above with the subject line [Privacy Request] so we can route it to the appropriate team within our response timelines.