Legal

Privacy policy

Last updated: 9 October 2026

Nodz is in open beta. This document describes how the service works today; it may still be refined, and we will announce material changes here before they apply.

1. Who is responsible

The controller for personal data processed by Nodz is DevBiz, WALSTRAAT, 8020 OOSTKAMP, BELGIUM (registration number KBO 1022.925.574). For anything about privacy, email privacy@nodz.im.

2. The short version

3. What we process, why, and for how long

DataPurposeLegal basis (GDPR)Retention
Username, password verifier (Argon2id hash, never the password itself), public identity key, discoverability setting, creation date (day only), and which version of the terms of use you accepted and on which dayProviding your accountArt. 6(1)(b) contractUntil you delete your account; then everything is removed at once, except the username, which is kept on its own as a retired name so nobody can register it and impersonate you (Art. 6(1)(f)).
Public key log entry: a hash of your username, your public identity key, the dateLetting everyone check that the key they are given for you is the one published for your username, so a substituted key cannot go unnoticedArt. 6(1)(f) legitimate interest in the security of everyone's conversationsPermanent: the log can only grow, which is what makes it trustworthy. It contains no other data, and only someone who already knows your username and key can look it up.
Device identifiers, date added and date last active (day only), hashes of session tokensSigning you in and letting you manage your devicesArt. 6(1)(b)Sessions expire after 30 days. Devices remain until you remove them or delete your account.
Recovery verifier and your encrypted identity backupAccount recovery without emailArt. 6(1)(b)Until you create a new recovery code or delete your account. We cannot decrypt the backup.
Device public keys, device certificates, single-use MLS key packagesLetting others start encrypted conversations with youArt. 6(1)(b)Key packages are deleted when used; the rest until the device is removed.
Encrypted files you send (unreadable to us: encrypted on your device; we never learn the name, type or who it is for)Delivering files in conversationsArt. 6(1)(b)30 days, then deleted automatically.
Encrypted message envelopes (unreadable to us)Delivering messages, including to offline devicesArt. 6(1)(b)Deleted when delivered; undelivered envelopes after at most 30 days.
IP address and connection timesTransmitting data; protecting the service against abuseArt. 6(1)(f) legitimate interest in securityNot written to access logs. Abuse limits use pseudonymous counters that become unlinkable within 48 hours.
Technical error logs (no IP addresses, usernames or message data)Keeping the service workingArt. 6(1)(f)14 days
Emails you send usAnswering your question or reportArt. 6(1)(f), or (b) where it concerns your accountUp to 1 year after the matter is closed
Donations: amount, date, payment method and, depending on the method, payer name and account details as shown to us by MollieProcessing the donation; bookkeepingArt. 6(1)(b), and (c) for legal bookkeeping duties10 years (Belgian accounting and tax law). Donations are never linked to a Nodz account.

4. What we do not do

We do not profile you, make automated decisions about you that have legal or similarly significant effects (Art. 22 GDPR), show advertising, use analytics, or sell or rent data.

5. Cookies and storage on your device

This website sets no cookies. The Nodz app uses a single, strictly necessary session cookie to keep you signed in; it needs no consent. Your encryption keys and settings are stored in your browser's local storage (IndexedDB) on your own device; they are never sent to us in readable form. You can remove them at any time in Settings → This browser.

6. Who else receives data

We do not transfer personal data outside the European Economic Area. We only disclose data to authorities where the law requires it, and then only what we have: we cannot provide message content, contact lists or keys, because we do not hold them in readable form.

7. Security

Messages use the Messaging Layer Security standard (RFC 9420). Passwords are hashed with Argon2id. Connections use TLS. Databases are not reachable from the internet. Details are on our security page.

8. Your rights

You have the right to access, rectify and erase your data, to restrict or object to processing, and to data portability. In the app you can download your data (Settings → Your data) and delete your account at any time. Because we hold no email address or phone number, we verify requests through your signed-in account; if you cannot sign in, your recovery code proves that the account is yours. You can also write to privacy@nodz.im. We reply within one month.

You may lodge a complaint with a supervisory authority, for example the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit / Autorité de protection des données) (https://www.dataprotectionauthority.be).

9. Minimum age

Nodz is intended for people aged 16 or older.

10. Changes

If we change this policy, we will publish the new version here with a new date. Significant changes will be announced in the app before they take effect.

Back to Nodz