Privacy Policy
Last updated: 7 October 2026
This Privacy Policy explains how Nodana collects, uses, shares, and protects personal data when you visit our website, create an account, contact us, or use our dashboard, APIs, command-line tools, hosted nodes, and related services (together, the Service).
1. Who we are
Nodana, trading as Nodana (Nodana, we, us, or our), is the controller of personal data described in this policy unless stated otherwise.
For privacy enquiries or requests, use our contact form and mention privacy in the subject.
When you use a hosted node to process information about your own customers or users, you are responsible for determining the purposes of that processing, providing appropriate privacy information, and having a lawful basis. Nodana may act as a processor for that information. Contact us to discuss the data-processing terms needed for your use of the Service.
2. Personal data we collect
The information we collect depends on how you use the Service.
Account and identity data
This includes your email address, user and account identifiers, display name, email verification status, authentication records, notification preferences, and, if you enable it, two-factor authentication information. If you sign in with GitHub, we receive your GitHub account identifier, username, display name, and verified email address. We use browser and device information, a device identifier, and sign-in timestamps to recognise devices and send new-device security notifications.
Service and node data
This includes node names and identifiers, configuration, status, endpoint URLs, uptime information, API-key records and permissions, webhook destinations and delivery records, notification preferences, request logs, usage and billing records, and the information needed to deploy and maintain your nodes. Webhook records may include payment-event payloads, response status, and delivery attempts. We also store saved payment recipients if you choose to save them.
Hosted nodes process payment hashes, invoice references, amounts, fees, and payment timestamps. The Analytics page summarises this node payment activity; it is not a third-party website visitor-tracking tool. Nodana stores the node password selected for dashboard/API access in encrypted form. Node provisioning also temporarily stores encrypted credentials needed to complete setup. Protect the passwords and recovery seed provided when your node is created.
Do not include secrets or personal data in node names, labels, support messages, or logs unless necessary.
Payment and credit data
This may include the credit amount selected, invoice identifier, Lightning invoice, sats amount, exchange-rate information, payment status, payment timestamps, account balance, bonuses, and billing history. We do not collect payment-card details when you pay using a Lightning wallet, but your wallet provider processes information under its own privacy policy.
Communications
We collect information you send when you contact support, report a problem, submit feedback, or otherwise communicate with us. This may include your contact details and the content of the communication.
Technical and usage data
Our servers and infrastructure providers process technical information needed to deliver and secure the Service, including IP addresses, browser and user-agent information, timestamps, request paths, response status, errors, and security events. Node request logs contain the request method, path, client IP address, user-agent string where available, and timestamp. Avoid putting personal data or secrets in URLs, because paths may appear in logs.
Our contact form uses Cloudflare Turnstile to help detect automated submissions. Cloudflare processes browser and network signals to perform this security check. The API verifies the resulting token before sending your message. The form collects your name, optional company name, email address, subject, and message, and delivers them to our contact inbox using Amazon SES, with your email address as the reply address. See Cloudflare's Turnstile Privacy Addendum for information about its processing.
Information from third parties
If you sign in through a third-party identity provider, we receive the account information you authorise that provider to share. We may also receive information from infrastructure, security, email, monitoring, and payment-service providers where needed to operate and protect the Service.
3. How we use personal data and our lawful bases
We use personal data for the following purposes and on the following lawful bases, where applicable under data-protection law.
| Purpose | Typical data | Lawful basis |
|---|---|---|
| Create and administer accounts; authenticate users | Account, identity, and session data | Performance of a contract |
| Deploy, operate, monitor, back up, and support nodes | Account, service, node, log, and usage data | Performance of a contract |
| Create Lightning invoices, apply credit, calculate usage, and keep billing records | Account, payment, credit, and usage data | Performance of a contract; legal obligation where financial records must be retained |
| Send verification, security, balance, service-status, and support messages | Identity, account, notification, and communications data | Performance of a contract; legitimate interests in operating and securing the Service |
| Prevent fraud, abuse, and security incidents; enforce our terms | Identity, technical, log, payment, and usage data | Legitimate interests in protecting Nodana, our users, and others; legal obligation where applicable |
| Diagnose faults, measure performance, and improve the Service | Technical, usage, analytics, and support data | Legitimate interests in maintaining and improving the Service |
| Comply with law and respond to lawful requests | Any relevant data | Legal obligation; legitimate interests in establishing and defending legal claims |
| Respond to enquiries about the Service | Contact details and message content | Steps taken at your request before entering a contract; legitimate interests in responding to enquiries |
Where we rely on legitimate interests, we consider whether our interests are necessary and balanced against your rights. You may object to this processing as described below.
We do not use the contact form to enrol you in marketing communications. If we introduce processing that requires consent, we will provide the relevant information and obtain that consent before starting it. You may withdraw consent at any time without affecting earlier lawful processing.
4. When we share personal data
We do not sell personal data. We may share it with:
- infrastructure, hosting, database, storage, backup, and network providers;
- authentication and identity providers you choose to use;
- email, customer-support, monitoring, analytics, and security providers;
- professional advisers such as lawyers, accountants, auditors, and insurers;
- regulators, courts, law-enforcement bodies, or other parties where required by law or needed to protect legal rights; and
- a buyer, investor, or successor in connection with a proposed or completed merger, financing, reorganisation, or sale of all or part of our business.
Service providers may process personal data only for the services they provide to us and under appropriate contractual and security obligations.
Our service providers and integrations include:
| Provider | Purpose and information involved |
|---|---|
| Railway | Website and API hosting; requests, operational logs, and information processed by the hosted application |
| Fly.io | Hosted node infrastructure and storage; node configuration, credentials needed to run the node, and node/payment data |
| Neon | PostgreSQL storage for account, node, billing, device, and other application records |
| Upstash | Redis storage for sessions, short-lived authentication state, rate limits, and cached node information |
| Amazon Web Services / Amazon SES | Delivery of sign-in, verification, security, service, payment-notification, and contact emails; recipient addresses and email content |
| Cloudflare | Website/API traffic protection and delivery, and Turnstile contact-form verification; relevant request, browser, and security information |
| GitHub | Optional GitHub sign-in and distribution of software releases; GitHub sign-in involves the account information described above |
The API obtains public BTC/USD exchange rates from Coinbase. These rate lookups do not send your contact-form content or account identity to Coinbase. Lightning wallets, Lightning network participants, and node liquidity providers may process payment and channel information as part of the payment network. Payments you make or receive are not necessarily anonymous.
Where you configure a webhook, we send the selected event information to the destination you provide. You are responsible for choosing a suitable destination and explaining that processing to your own users where required.
5. International transfers
Some service providers may process personal data outside the United Kingdom or the country where you live. Where data-protection law requires it, we use an approved transfer mechanism, such as an adequacy regulation, the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or another lawful safeguard.
You may contact us for information about the providers, processing locations, and transfer safeguards relevant to your use of the Service.
6. Retention
We keep personal data only for as long as reasonably necessary for the purposes described in this policy, including providing the Service, meeting legal and accounting obligations, resolving disputes, preventing abuse, and enforcing agreements.
Retention depends on the type of data and may take account of:
- how long you have an account or an active node;
- whether the information is needed to provide or secure the Service;
- legal, tax, accounting, and limitation periods;
- the sensitivity and volume of the data; and
- whether the data can be deleted or anonymised safely.
The Service applies these specific expiry and cleanup periods:
| Information | Expiry or cleanup period |
|---|---|
| Sign-in session | 30 days from creation, or earlier when the session is invalidated, such as on sign-out |
| One-time email sign-in token | 15 minutes; consumed when used |
| GitHub sign-in state | 10 minutes; consumed during the sign-in callback |
| Two-factor sign-in challenge | 5 minutes |
| Cached node information | 10 minutes |
| Personal-plan node request logs | Records older than 7 days are removed by a daily cleanup job; removal may occur after the 7-day boundary |
| Webhook delivery records and event payloads | Records older than 3 days are removed by an hourly cleanup job |
Cookie and browser-storage lifetimes are described below. Those lifetimes do not necessarily determine how long the associated server-side records are kept. For example, device-recognition records may remain after the device cookie expires.
Account, billing, payment, device, other-plan node logs, infrastructure logs, and correspondence records do not all share a single expiry period. We assess their retention according to the criteria above. Deleting a node does not automatically erase its associated account, billing, or audit records. Contact us to request deletion or information about the records held for your account. Where applicable, copies may remain in provider backups until the relevant backup cycle ends.
7. Cookies and local storage
Cookies are small values stored by your browser and sent with matching requests. Local storage is browser storage that remains on your device and is not automatically sent with every request. We use these technologies for authentication, security, and interface preferences.
Authentication and security cookies
| Cookie | Purpose | Lifetime |
|---|---|---|
nodana_session | Identifies your authenticated session so the API can authorise dashboard requests | Up to 30 days; removed on sign-out |
nodana_device | Recognises a browser used for sign-in and helps identify new-device logins for security notifications | Up to 365 days; replaced when a new device token is issued |
These are first-party API cookies, normally set by api.nodana.io. They contain identifiers rather than your email address or node password. In production they are marked Secure and HttpOnly, so they are sent over HTTPS and cannot be read by ordinary page JavaScript. The CLI and public API-key requests authenticate using a bearer token rather than these dashboard cookies.
Cloudflare may also use security cookies when its challenge or traffic-protection features require them. For example, cf_clearance can record a passed challenge when clearance is enabled. The particular Cloudflare cookies and lifetimes depend on the security features applied to your visit; a Turnstile token does not itself mean that a clearance cookie has been set. See Cloudflare's cookie information.
Browser preferences and navigation storage
| Storage key | Purpose | Lifetime |
|---|---|---|
nodana:theme in the dashboard; theme where used by the website/docs | Remembers or reads your light, dark, or system-theme preference | No fixed expiry; until changed or browser storage is cleared |
nodana:activeAccountId | Remembers the account selected in the dashboard | No fixed expiry; until updated, removed, or browser storage is cleared |
nodana:search-recents:<account identifier> | Stores up to five recently selected dashboard navigation items, such as a page or node; it does not store the text typed into the search box | No fixed expiry; entries are replaced as you navigate, or removed when browser storage is cleared |
nodana:node-update-notified:<update identifier> | Remembers that a node update notification has already been shown, to avoid repeating it | No fixed expiry; until browser storage is cleared |
The website/docs theme preference may also be managed by the documentation interface. Interface storage is used to remember settings or navigation on your device, rather than to build an advertising profile.
We do not currently integrate advertising cookies, advertising pixels, or third-party visitor-analytics trackers in the website or dashboard. Node payment analytics and operational security logs are separate from advertising or visitor tracking. If we introduce additional storage or tracking that requires consent, we will provide information and obtain consent before using it.
You can inspect, block, or delete cookies and local storage through your browser settings. Blocking authentication or security storage may prevent sign-in, device recognition, or contact-form verification; clearing preference storage resets the relevant settings. Deleting a browser value does not itself delete your Nodana account or the server-side records associated with it.
8. Security
We use technical and organisational measures designed to protect personal data, such as access controls, authentication, encryption where appropriate, monitoring, backups, and restricted staff or service-provider access.
No system is completely secure. You are responsible for protecting your account, API keys, node credentials, wallet, devices, and recovery information. Please contact us promptly if you believe your account or data has been compromised.
9. Your data-protection rights
Depending on where you live and the circumstances, you may have the right to:
- ask for access to your personal data;
- ask us to correct inaccurate or incomplete data;
- ask us to delete your data;
- ask us to restrict how we use your data;
- receive certain data in a portable format;
- object to processing based on legitimate interests or to direct marketing;
- withdraw consent where processing relies on consent; and
- complain to a data-protection regulator.
These rights are not absolute, and exemptions may apply. To exercise a right, use our contact form and mention privacy in the subject. We may need to verify your identity before acting on a request. You do not have to contact us before exercising your right to complain to a regulator.
Your right to object: You may object at any time to our use of your personal data for direct marketing. You may also object to processing based on legitimate interests, in which case we will stop unless we have compelling legitimate grounds to continue or need the data for legal claims.
If you are in the UK, you may complain to the Information Commissioner's Office. We would appreciate the opportunity to address your concern first, so please contact us before making a complaint.
10. Automated decisions
The Service uses automated security checks, request rate limits, and billing controls. For example, requests may be rejected after rate limits are reached, and nodes may be stopped or deleted when account credit is exhausted under the applicable service terms. If you believe an automated security or billing action has affected you incorrectly, contact us so we can review it.
11. Children's privacy
The Service is not intended for children under 18, and we do not knowingly collect their personal data. If you believe a child has provided personal data to us, contact us so we can investigate and take appropriate action.
12. Third-party links and services
The Service may link to or integrate with third-party websites, wallets, identity providers, APIs, and software. Their privacy practices are governed by their own policies, not this one. Review those policies before providing personal data to them.
13. Changes to this policy
We may update this policy as our Service, data practices, or legal obligations change. We will publish the updated version here and change the “Last updated” date. If a change materially affects your rights, we will provide additional notice where required.
14. Contact us
Questions, requests, or complaints about privacy can be sent to:
- Name: Nodana, trading as Nodana
- Privacy enquiries: Contact Nodana. Please mention privacy in the subject so we can identify your request.