Legal/Privacy Policy

Privacy Policy

Last updated: 7 October 2026

This Privacy Policy explains how Nodana collects, uses, shares, and protects personal data when you visit our website, create an account, contact us, or use our dashboard, APIs, command-line tools, hosted nodes, and related services (together, the Service).

1. Who we are

Nodana, trading as Nodana (Nodana, we, us, or our), is the controller of personal data described in this policy unless stated otherwise.

For privacy enquiries or requests, use our contact form and mention privacy in the subject.

When you use a hosted node to process information about your own customers or users, you are responsible for determining the purposes of that processing, providing appropriate privacy information, and having a lawful basis. Nodana may act as a processor for that information. Contact us to discuss the data-processing terms needed for your use of the Service.

2. Personal data we collect

The information we collect depends on how you use the Service.

Account and identity data

This includes your email address, user and account identifiers, display name, email verification status, authentication records, notification preferences, and, if you enable it, two-factor authentication information. If you sign in with GitHub, we receive your GitHub account identifier, username, display name, and verified email address. We use browser and device information, a device identifier, and sign-in timestamps to recognise devices and send new-device security notifications.

Service and node data

This includes node names and identifiers, configuration, status, endpoint URLs, uptime information, API-key records and permissions, webhook destinations and delivery records, notification preferences, request logs, usage and billing records, and the information needed to deploy and maintain your nodes. Webhook records may include payment-event payloads, response status, and delivery attempts. We also store saved payment recipients if you choose to save them.

Hosted nodes process payment hashes, invoice references, amounts, fees, and payment timestamps. The Analytics page summarises this node payment activity; it is not a third-party website visitor-tracking tool. Nodana stores the node password selected for dashboard/API access in encrypted form. Node provisioning also temporarily stores encrypted credentials needed to complete setup. Protect the passwords and recovery seed provided when your node is created.

Do not include secrets or personal data in node names, labels, support messages, or logs unless necessary.

Payment and credit data

This may include the credit amount selected, invoice identifier, Lightning invoice, sats amount, exchange-rate information, payment status, payment timestamps, account balance, bonuses, and billing history. We do not collect payment-card details when you pay using a Lightning wallet, but your wallet provider processes information under its own privacy policy.

Communications

We collect information you send when you contact support, report a problem, submit feedback, or otherwise communicate with us. This may include your contact details and the content of the communication.

Technical and usage data

Our servers and infrastructure providers process technical information needed to deliver and secure the Service, including IP addresses, browser and user-agent information, timestamps, request paths, response status, errors, and security events. Node request logs contain the request method, path, client IP address, user-agent string where available, and timestamp. Avoid putting personal data or secrets in URLs, because paths may appear in logs.

Our contact form uses Cloudflare Turnstile to help detect automated submissions. Cloudflare processes browser and network signals to perform this security check. The API verifies the resulting token before sending your message. The form collects your name, optional company name, email address, subject, and message, and delivers them to our contact inbox using Amazon SES, with your email address as the reply address. See Cloudflare's Turnstile Privacy Addendum for information about its processing.

Information from third parties

If you sign in through a third-party identity provider, we receive the account information you authorise that provider to share. We may also receive information from infrastructure, security, email, monitoring, and payment-service providers where needed to operate and protect the Service.

3. How we use personal data and our lawful bases

We use personal data for the following purposes and on the following lawful bases, where applicable under data-protection law.

PurposeTypical dataLawful basis
Create and administer accounts; authenticate usersAccount, identity, and session dataPerformance of a contract
Deploy, operate, monitor, back up, and support nodesAccount, service, node, log, and usage dataPerformance of a contract
Create Lightning invoices, apply credit, calculate usage, and keep billing recordsAccount, payment, credit, and usage dataPerformance of a contract; legal obligation where financial records must be retained
Send verification, security, balance, service-status, and support messagesIdentity, account, notification, and communications dataPerformance of a contract; legitimate interests in operating and securing the Service
Prevent fraud, abuse, and security incidents; enforce our termsIdentity, technical, log, payment, and usage dataLegitimate interests in protecting Nodana, our users, and others; legal obligation where applicable
Diagnose faults, measure performance, and improve the ServiceTechnical, usage, analytics, and support dataLegitimate interests in maintaining and improving the Service
Comply with law and respond to lawful requestsAny relevant dataLegal obligation; legitimate interests in establishing and defending legal claims
Respond to enquiries about the ServiceContact details and message contentSteps taken at your request before entering a contract; legitimate interests in responding to enquiries

Where we rely on legitimate interests, we consider whether our interests are necessary and balanced against your rights. You may object to this processing as described below.

We do not use the contact form to enrol you in marketing communications. If we introduce processing that requires consent, we will provide the relevant information and obtain that consent before starting it. You may withdraw consent at any time without affecting earlier lawful processing.

4. When we share personal data

We do not sell personal data. We may share it with:

  • infrastructure, hosting, database, storage, backup, and network providers;
  • authentication and identity providers you choose to use;
  • email, customer-support, monitoring, analytics, and security providers;
  • professional advisers such as lawyers, accountants, auditors, and insurers;
  • regulators, courts, law-enforcement bodies, or other parties where required by law or needed to protect legal rights; and
  • a buyer, investor, or successor in connection with a proposed or completed merger, financing, reorganisation, or sale of all or part of our business.

Service providers may process personal data only for the services they provide to us and under appropriate contractual and security obligations.

Our service providers and integrations include:

ProviderPurpose and information involved
RailwayWebsite and API hosting; requests, operational logs, and information processed by the hosted application
Fly.ioHosted node infrastructure and storage; node configuration, credentials needed to run the node, and node/payment data
NeonPostgreSQL storage for account, node, billing, device, and other application records
UpstashRedis storage for sessions, short-lived authentication state, rate limits, and cached node information
Amazon Web Services / Amazon SESDelivery of sign-in, verification, security, service, payment-notification, and contact emails; recipient addresses and email content
CloudflareWebsite/API traffic protection and delivery, and Turnstile contact-form verification; relevant request, browser, and security information
GitHubOptional GitHub sign-in and distribution of software releases; GitHub sign-in involves the account information described above

The API obtains public BTC/USD exchange rates from Coinbase. These rate lookups do not send your contact-form content or account identity to Coinbase. Lightning wallets, Lightning network participants, and node liquidity providers may process payment and channel information as part of the payment network. Payments you make or receive are not necessarily anonymous.

Where you configure a webhook, we send the selected event information to the destination you provide. You are responsible for choosing a suitable destination and explaining that processing to your own users where required.

5. International transfers

Some service providers may process personal data outside the United Kingdom or the country where you live. Where data-protection law requires it, we use an approved transfer mechanism, such as an adequacy regulation, the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or another lawful safeguard.

You may contact us for information about the providers, processing locations, and transfer safeguards relevant to your use of the Service.

6. Retention

We keep personal data only for as long as reasonably necessary for the purposes described in this policy, including providing the Service, meeting legal and accounting obligations, resolving disputes, preventing abuse, and enforcing agreements.

Retention depends on the type of data and may take account of:

  • how long you have an account or an active node;
  • whether the information is needed to provide or secure the Service;
  • legal, tax, accounting, and limitation periods;
  • the sensitivity and volume of the data; and
  • whether the data can be deleted or anonymised safely.

The Service applies these specific expiry and cleanup periods:

InformationExpiry or cleanup period
Sign-in session30 days from creation, or earlier when the session is invalidated, such as on sign-out
One-time email sign-in token15 minutes; consumed when used
GitHub sign-in state10 minutes; consumed during the sign-in callback
Two-factor sign-in challenge5 minutes
Cached node information10 minutes
Personal-plan node request logsRecords older than 7 days are removed by a daily cleanup job; removal may occur after the 7-day boundary
Webhook delivery records and event payloadsRecords older than 3 days are removed by an hourly cleanup job

Cookie and browser-storage lifetimes are described below. Those lifetimes do not necessarily determine how long the associated server-side records are kept. For example, device-recognition records may remain after the device cookie expires.

Account, billing, payment, device, other-plan node logs, infrastructure logs, and correspondence records do not all share a single expiry period. We assess their retention according to the criteria above. Deleting a node does not automatically erase its associated account, billing, or audit records. Contact us to request deletion or information about the records held for your account. Where applicable, copies may remain in provider backups until the relevant backup cycle ends.

7. Cookies and local storage

Cookies are small values stored by your browser and sent with matching requests. Local storage is browser storage that remains on your device and is not automatically sent with every request. We use these technologies for authentication, security, and interface preferences.

Authentication and security cookies

CookiePurposeLifetime
nodana_sessionIdentifies your authenticated session so the API can authorise dashboard requestsUp to 30 days; removed on sign-out
nodana_deviceRecognises a browser used for sign-in and helps identify new-device logins for security notificationsUp to 365 days; replaced when a new device token is issued

These are first-party API cookies, normally set by api.nodana.io. They contain identifiers rather than your email address or node password. In production they are marked Secure and HttpOnly, so they are sent over HTTPS and cannot be read by ordinary page JavaScript. The CLI and public API-key requests authenticate using a bearer token rather than these dashboard cookies.

Cloudflare may also use security cookies when its challenge or traffic-protection features require them. For example, cf_clearance can record a passed challenge when clearance is enabled. The particular Cloudflare cookies and lifetimes depend on the security features applied to your visit; a Turnstile token does not itself mean that a clearance cookie has been set. See Cloudflare's cookie information.

Browser preferences and navigation storage

Storage keyPurposeLifetime
nodana:theme in the dashboard; theme where used by the website/docsRemembers or reads your light, dark, or system-theme preferenceNo fixed expiry; until changed or browser storage is cleared
nodana:activeAccountIdRemembers the account selected in the dashboardNo fixed expiry; until updated, removed, or browser storage is cleared
nodana:search-recents:<account identifier>Stores up to five recently selected dashboard navigation items, such as a page or node; it does not store the text typed into the search boxNo fixed expiry; entries are replaced as you navigate, or removed when browser storage is cleared
nodana:node-update-notified:<update identifier>Remembers that a node update notification has already been shown, to avoid repeating itNo fixed expiry; until browser storage is cleared

The website/docs theme preference may also be managed by the documentation interface. Interface storage is used to remember settings or navigation on your device, rather than to build an advertising profile.

We do not currently integrate advertising cookies, advertising pixels, or third-party visitor-analytics trackers in the website or dashboard. Node payment analytics and operational security logs are separate from advertising or visitor tracking. If we introduce additional storage or tracking that requires consent, we will provide information and obtain consent before using it.

You can inspect, block, or delete cookies and local storage through your browser settings. Blocking authentication or security storage may prevent sign-in, device recognition, or contact-form verification; clearing preference storage resets the relevant settings. Deleting a browser value does not itself delete your Nodana account or the server-side records associated with it.

8. Security

We use technical and organisational measures designed to protect personal data, such as access controls, authentication, encryption where appropriate, monitoring, backups, and restricted staff or service-provider access.

No system is completely secure. You are responsible for protecting your account, API keys, node credentials, wallet, devices, and recovery information. Please contact us promptly if you believe your account or data has been compromised.

9. Your data-protection rights

Depending on where you live and the circumstances, you may have the right to:

  • ask for access to your personal data;
  • ask us to correct inaccurate or incomplete data;
  • ask us to delete your data;
  • ask us to restrict how we use your data;
  • receive certain data in a portable format;
  • object to processing based on legitimate interests or to direct marketing;
  • withdraw consent where processing relies on consent; and
  • complain to a data-protection regulator.

These rights are not absolute, and exemptions may apply. To exercise a right, use our contact form and mention privacy in the subject. We may need to verify your identity before acting on a request. You do not have to contact us before exercising your right to complain to a regulator.

Your right to object: You may object at any time to our use of your personal data for direct marketing. You may also object to processing based on legitimate interests, in which case we will stop unless we have compelling legitimate grounds to continue or need the data for legal claims.

If you are in the UK, you may complain to the Information Commissioner's Office. We would appreciate the opportunity to address your concern first, so please contact us before making a complaint.

10. Automated decisions

The Service uses automated security checks, request rate limits, and billing controls. For example, requests may be rejected after rate limits are reached, and nodes may be stopped or deleted when account credit is exhausted under the applicable service terms. If you believe an automated security or billing action has affected you incorrectly, contact us so we can review it.

11. Children's privacy

The Service is not intended for children under 18, and we do not knowingly collect their personal data. If you believe a child has provided personal data to us, contact us so we can investigate and take appropriate action.

The Service may link to or integrate with third-party websites, wallets, identity providers, APIs, and software. Their privacy practices are governed by their own policies, not this one. Review those policies before providing personal data to them.

13. Changes to this policy

We may update this policy as our Service, data practices, or legal obligations change. We will publish the updated version here and change the “Last updated” date. If a change materially affects your rights, we will provide additional notice where required.

14. Contact us

Questions, requests, or complaints about privacy can be sent to:

  • Name: Nodana, trading as Nodana
  • Privacy enquiries: Contact Nodana. Please mention privacy in the subject so we can identify your request.

On this page