Privacy Policy

Last updated: August 16, 2026

This Privacy Policy explains how Nodrya handles information when you use the service. Nodrya is currently a beta service, and its data practices may evolve as features are added or changed.

1. Information you provide

When you create and use an account, Nodrya stores information you provide, including your email address, display name, password hash, account settings, notes, categories, tags, note metadata, imported content, and attachments. If you enable TOTP multi-factor authentication, the service also stores the secret required to verify your authenticator codes.

You decide what you put in your notes and attachments. Please consider the sensitivity of information before storing it, particularly if you do not use note encryption.

2. Information generated when you use the service

Nodrya stores timestamps and records needed to operate features such as sessions, imports, password resets, and email delivery. Password-reset records may include the requesting IP address and browser user-agent string. Operational error logs may include information such as request URL, request method, user identifier, IP address, error context, and stack information when needed to diagnose failures.

3. Notes and browser-side encryption

Normal, unencrypted note data is stored by the service in readable form so Nodrya can provide its features. For a note you choose to encrypt, protected note content is encrypted and decrypted in your browser using AES-256-GCM with a key derived from your passphrase. The passphrase itself is not sent to the Nodrya server.

Information needed for organization and filtering may remain unencrypted, including categories, tags, priority, due dates, encryption status, timestamps, and other note metadata. Encryption therefore does not make every fact associated with a note invisible to the service.

If you choose to save an account-wide encryption key for convenience, that key is stored in your browser's local storage. Nodrya has no server-side passphrase escrow. If you lose an encryption passphrase, Nodrya cannot recover the protected content.

4. How information is used

Information is used to provide and secure the service, authenticate users, store and retrieve notes and attachments, process imports, deliver transactional messages such as password resets, enforce service limits, troubleshoot errors, prevent abuse, and maintain the application.

Nodrya does not currently include an advertising or behavioral-profiling system, and the application does not intentionally sell personal information.

5. Service providers and external resources

Nodrya may rely on infrastructure and service providers to operate. The current application supports AWS Simple Email Service (SES) for transactional email and may be deployed behind hosting, proxy, or content-delivery infrastructure such as Cloudflare. Browser libraries are also loaded from third-party content delivery networks. Those providers may receive technical information such as your IP address and browser request details when your browser or the service communicates with them, subject to their own policies.

6. Cookies and local browser storage

Nodrya uses a session cookie to keep you authenticated. Session lifetime may be longer when you choose the trusted-device option. The application also uses browser local storage for preferences such as theme and, only if you choose that convenience feature, an account-wide encryption key.

7. Attachments and imports

Imported archives and attachments are processed to provide the import and file features you request. Attachment records are associated with your account and files are intended to be served through authenticated download routes rather than as public files. Import jobs may temporarily retain archive files and processing status while an import is queued or running.

8. Data retention and account deletion

Account content is generally retained while your account remains active. You can request account deletion from Settings. The current deletion process removes your user record and database records linked to it through the application's relational data model.

Some information may remain outside those account-linked database records, including operational or email logs, backups, cached copies, and files awaiting storage cleanup. These may be retained for security, troubleshooting, continuity, or technical reasons and are removed or overwritten according to the operator's maintenance and retention practices.

9. Security

Nodrya uses measures intended to reduce security risk, including one-way password hashing, authenticated sessions, CSRF protection on state-changing requests, prepared database queries, optional TOTP multi-factor authentication, and browser-side encryption for notes when you enable it. No online service can guarantee absolute security.

10. Children

Nodrya is not directed to children under 13, and users under 13 should not create an account. If the operator learns that personal information from a child under 13 has been collected in circumstances requiring parental consent, appropriate steps should be taken to address it.

11. Your choices

You can update account settings, change your password, enable or disable MFA, manage notes and attachments, and delete your account through the application. Depending on where you live, applicable law may provide additional privacy rights.

12. Changes to this policy

This policy may be updated when the service or its data practices change. The date at the top of this page will be updated when revisions are published. Material changes may also be communicated within the service when appropriate.

13. Contact

Privacy questions or requests can be directed through the support contact provided at www.nodrya.com. Do not send account passwords, encryption passphrases, MFA secrets, or password-reset tokens.