Nodo

Nodo

Privacy notice

In force from 2026‑08‑25. In short: the content of your questions is never written down, no name or email address is stored here, and instead of your key we keep only its cryptographic digest. What remains, and for how long, is below.

What is stored

Two tables in the database concern a user at all, and this is everything in them:

What is held against each key
Record Why it is needed
A digest of the key To recognise the key when it is presented. The key cannot be recovered from it.
The plan and its name To know the monthly allowance, and what to look at when you write in for help.
Created and revoked dates To know whether the key is still valid.
Stripe customer and subscription id To tie a payment to a key, so that cancelling or refunding revokes it.
Units used this month To count the allowance. It is one number per month, not a list of requests.

What is not stored

  • The content of your questions. Your words - how you phrased the question - are written down nowhere, and there is no column they could go in.
  • The key itself. Only a digest is kept, which is why it cannot be shown a second time - to you or to us.
  • Your name, email, address or VAT number. Stripe collects these at checkout and holds them; our server never receives them.
  • Card details. They never reach our system at all.

What is counted

Aggregate counters about what the service itself did: which tool was called, about which act, and whether it answered or refused and why. These are numbers, not records. A row looks like get_article, timeline_has_gap, VTI, 40 - and it cannot say who asked, when, or in what words.

The act recorded is only the one the answer resolved to: our own catalogue handle or the register's document id, both already public in the list of acts. What you typed cannot reach this table: the counter is built from the answer and never from the request, and a test holds it there.

What it is for: these numbers show us what the product is missing - which acts lack editions, which provisions we cannot address - so we can fix it without having to ask you.

Server logs

Like every public server, ours writes a technical log: the time, the request method and path, the response code, the client's name and its IP address. It exists so that a failure or an abuse can be seen at all.

What matters is what does not reach it: MCP calls are POST requests to /mcp, so the path is just /mcp and the question stays in the request body, which the log does not record. The log shows that somebody called, not what they asked.

Logs rotate within a fixed size, so old entries are overwritten by new ones. Nothing is archived and no log is passed to anybody.

Cookies and analytics

There are no cookies and there is no analytics - neither ours nor anybody else's. That is why this site has no consent banner: there is nothing to consent to.

The one thing the site keeps in your browser is whether you chose the light or the dark theme. It lives in the browser's own localStorage, is never sent to us, and disappears when you clear your browser data.

Who else sees anything

Nobody, except the two without whom the service would not run:

  • Stripe, for payments. Pressing a plan button takes you to Stripe's own page, where you give your details to them directly.
  • The hosting provider, on whose hardware the server runs.

Data is not sold, not rented and not used for advertising. There is no advertising here at all.

How long it is kept

The key record and the monthly counts are kept while the key is valid and for two years after it is revoked - as long as accounting and a possible billing dispute require. On request they are deleted sooner, where accounting rules allow.

Your rights

Under the General Data Protection Regulation you may ask what is held about you, get a copy of it, have it corrected or erased, have its processing restricted, and object to that processing. One email to [email protected] is enough; the answer comes within a month and usually within a day.

Because no name is tied to a key here, you may need to give the email address on your Stripe receipt - otherwise we simply will not know which record is yours.

If you believe the data is being handled improperly, you may complain to the State Data Protection Inspectorate of Lithuania.

Changes and contact

This notice changes if what we do changes. The date at the top always shows the current version, and paying users are told by email about substantial changes.

The controller is Nodo. Data questions: [email protected]. Anything about the service itself: [email protected].