We're in beta — products are not yet available for purchase. Leave your email and we'll notify you when we go live.
Last Updated: April 12, 2026
Nodus is built on a foundation of privacy and security. We believe your data belongs to you—not to us, not to advertisers, not to anyone else.
When you create an account, we collect:
Payment processing is handled by Stripe. We do NOT store your credit card information. Stripe collects:
Your passwords, secrets, and sensitive data are encrypted before leaving your device:
Zero-Knowledge Encryption: We use end-to-end encryption. Even if our servers were compromised, your vault data remains encrypted and unreadable.
We collect minimal technical data to operate the service:
We do NOT track which specific websites you save passwords for, what you search for, or any behavioral analytics.
When you use OSINT tools, searches are processed server-side to aggregate public data. We temporarily log search queries for:
Search logs are anonymized and deleted after 30 days.
The Nodus Vault browser extensions for Chrome and Firefox communicate exclusively with the Nodus Vault desktop application installed on your device. No data is sent to any external server by the extension.
All of the above is stored in browser local storage (chrome.storage.local), sandboxed to the extension, and never transmitted anywhere.
The extension makes zero network requests. It communicates only with the Nodus Vault desktop application on your computer via the browser's native messaging API — a local, OS-level channel that never touches the internet.
If you save a credential while the desktop app is closed or the vault is locked, the extension holds it temporarily in browser local storage in plaintext until it can be handed off to the local agent, which encrypts it and writes it to your vault. Queued credentials are cleared from browser storage immediately upon successful sync.
Summary: The extension never sends your credentials, browsing activity, or any personal data to Nodus or any third party. Everything stays between your browser and your local device.
We use collected information ONLY to:
What We DON'T Do:
We share data ONLY in these limited circumstances:
All service providers are bound by strict data processing agreements.
If you're part of a Team subscription, team owners and members can see shared passwords and data according to team permissions.
We may disclose information if required by law (court order, subpoena, etc.). We will notify you unless legally prohibited.
If Nodus is acquired or merged, your data may transfer to the new entity. You'll be notified of any changes.
Security is our top priority. We implement industry-leading protections:
Your Responsibility
No system is 100% secure. You must maintain independent backups and protect your master password. We are not liable for data loss (see Terms of Service).
Under GDPR and other privacy laws, you have these rights:
To exercise these rights, email hello@nodus.tools or use the account settings in the app.
We respect your privacy but must comply with valid legal requests.
Because of zero-knowledge encryption, we CANNOT decrypt your vault even if compelled by law. We can only provide: email, subscription status, last login time, and metadata.
We use minimal cookies—only what's essential:
You can block cookies in your browser, but some features may not work properly.
Nodus is not intended for users under 13. We do not knowingly collect data from children. If we discover a child's account, we'll delete it immediately. Parents who believe their child created an account should contact hello@nodus.tools.
Nodus is operated from Belgium. Your data may be transferred to and stored in:
All data transfers comply with GDPR requirements. Non-EU providers use Standard Contractual Clauses (SCCs).
We may update this Privacy Policy from time to time. Changes take effect immediately upon posting.
Material changes will be notified via email. Continued use after changes constitutes acceptance. If you disagree, you must stop using Nodus and delete your account.
Questions about privacy or data protection?
Your privacy is not a commodity. It's a fundamental right.