We're in beta — products are not yet available for purchase. Leave your email and we'll notify you when we go live.
Last Updated: December 21, 2024
Nodus is built on a foundation of privacy and security. We believe your data belongs to you—not to us, not to advertisers, not to anyone else.
When you create an account, we collect:
Payment processing is handled by Stripe. We do NOT store your credit card information. Stripe collects:
Your passwords, secrets, and sensitive data are encrypted before leaving your device:
Zero-Knowledge Encryption: We use end-to-end encryption. Even if our servers were compromised, your vault data remains encrypted and unreadable.
We collect minimal technical data to operate the service:
We do NOT track which specific websites you save passwords for, what you search for, or any behavioral analytics.
When you use OSINT tools, searches are processed server-side to aggregate public data. We temporarily log search queries for:
Search logs are anonymized and deleted after 30 days.
We use collected information ONLY to:
What We DON'T Do:
We share data ONLY in these limited circumstances:
All service providers are bound by strict data processing agreements.
If you're part of a Team subscription, team owners and members can see shared passwords and data according to team permissions.
We may disclose information if required by law (court order, subpoena, etc.). We will notify you unless legally prohibited.
If Nodus is acquired or merged, your data may transfer to the new entity. You'll be notified of any changes.
Security is our top priority. We implement industry-leading protections:
Your Responsibility
No system is 100% secure. You must maintain independent backups and protect your master password. We are not liable for data loss (see Terms of Service).
Under GDPR and other privacy laws, you have these rights:
To exercise these rights, email privacy@nodus.com or use the account settings in the app.
We respect your privacy but must comply with valid legal requests.
Because of zero-knowledge encryption, we CANNOT decrypt your vault even if compelled by law. We can only provide: email, subscription status, last login time, and metadata.
We use minimal cookies—only what's essential:
You can block cookies in your browser, but some features may not work properly.
Nodus is not intended for users under 13. We do not knowingly collect data from children. If we discover a child's account, we'll delete it immediately. Parents who believe their child created an account should contact privacy@nodus.com.
Nodus is operated from Belgium. Your data may be transferred to and stored in:
All data transfers comply with GDPR requirements. Non-EU providers use Standard Contractual Clauses (SCCs).
We may update this Privacy Policy from time to time. Changes take effect immediately upon posting.
Material changes will be notified via email. Continued use after changes constitutes acceptance. If you disagree, you must stop using Nodus and delete your account.
Questions about privacy or data protection?
Your privacy is not a commodity. It's a fundamental right.