Privacy Policy
Last updated: August 28, 2026
This Privacy Policy explains how Nodrya handles information when you use the service. Its data practices may evolve as features are added or changed.
Nodrya is owned and operated by Dispatch Dataworks LLC, a limited liability company registered in the United States. Dispatch Dataworks LLC is the controller responsible for the personal information described in this policy, and is the party to contact with any privacy question or request.
1. Information you provide
When you create and use an account, Nodrya stores information you provide, including your email address, display name, password hash, account settings, notes, categories, tags, note metadata, imported content, attachments, sharing settings, and Email to Note preferences. If you enable TOTP multi-factor authentication, the service also stores the secret required to verify your authenticator codes.
You decide what you put in notes, attachments, shared content, and email messages sent into Nodrya. Consider the sensitivity of information before storing or sharing it, particularly when note encryption is not enabled.
2. Information generated when you use the service
Nodrya stores timestamps and records needed to operate features such as sessions, imports, sharing, collaboration locks, password resets, email delivery, inbound Email to Note processing, and optional AI features. AI usage records may include the account and note identifiers, feature, provider, model, request status and identifier, processing duration, error code, and input, cached-input, cache-write, output, reasoning, and total token counts.
Nodrya also records product-usage events and daily account statistics for service analytics. These records may identify the account, action type, affected resource type and identifier, time, and limited structural details such as counts or whether a feature was enabled. Analytics events do not include note contents or search-query text.
Password-reset records may include the requesting IP address and browser user-agent string. Operational error logs may include request URL, request method, user identifier, IP address, error context, and stack information when needed to diagnose failures.
3. Notes and browser-side encryption
Normal, unencrypted note data is stored by the service in readable form so Nodrya can provide its features. For a note you choose to encrypt, protected note content is encrypted and decrypted in your browser using AES-256-GCM with a key derived from your passphrase. The passphrase itself is not sent to the Nodrya server.
Information needed for organization and filtering may remain unencrypted, including categories, tags, priority, due dates, encryption status, timestamps, and other note metadata. Encryption therefore does not make every fact associated with a note invisible to the service.
If you save an account-wide encryption key for convenience, that key is stored in your browser's local storage. Nodrya has no server-side passphrase escrow. If you lose an encryption passphrase, Nodrya cannot recover the protected content.
4. Sharing and collaboration
When you create a read-only link, Nodrya stores the information needed to operate and audit that share. Anyone who possesses the complete active link can access the shared content, subject to expiration, revocation, and any share passphrase you choose for encrypted shared content. Share pages are configured not to be indexed by search engines, but you remain responsible for deciding who receives a link.
When you share with another account, Nodrya stores the recipient email address, permission, status, and related activity. A pending invitation may be retained for an email address that does not yet have an account so it can be claimed if that address later registers or signs in. Nodrya does not provide a public account directory through this feature.
For encrypted link shares, the browser can create a separately encrypted point-in-time snapshot using a share passphrase. Collaborative encrypted notes use the note's encryption model; passphrases are not supplied to the server.
5. Email to Note
If you enable Email to Note, messages sent to your personal Nodrya note address are processed to create notes. Nodrya may process the sender address, subject, message body, message identifiers, and technical email information required for delivery, duplicate detection, abuse prevention, and troubleshooting. Email attachments are currently ignored by the note-ingestion feature.
You can restrict accepted senders, add allowed senders, or choose to accept mail from any sender. Processing activity is recorded so you can review accepted, rejected, and duplicate messages in Settings.
6. Offline and device-local data
Nodrya's Progressive Web App can store cached notes, categories, and pending offline changes in browser storage on your device. This device-local data is controlled by your browser and may be removed if you clear site data or uninstall the app. Unsynchronized offline changes have not yet been backed up to the Nodrya server.
Encrypted note keys are not intentionally placed in the service-worker cache. A convenience account key is stored in local storage only when you choose that feature.
7. AI-assisted keyword expansion
If you choose Generate AI expansion, enable AI tag suggestions, or enable automatic Smart AI Tagging for an unencrypted note, Nodrya sends that note's plaintext content, title, category, and tags to OpenAI through the OpenAI API. OpenAI processes this information to produce a short summary, additional topic-related keywords, and—when enabled—tag suggestions. Nodrya stores the resulting summary, generated keywords, suggested tags, model identifier, and generation time in its database. Suggest mode requires approval before adding tags; automatic mode may add suggested tags but never removes existing tags. AI processing is optional and is not available for encrypted notes.
Nodrya sends these requests with API response storage disabled. According to OpenAI's current API data controls, data submitted through the API is not used to train or improve OpenAI models unless the API customer explicitly opts in. Under OpenAI's default controls, however, prompts, responses, and related information may be retained in abuse-monitoring logs for up to 30 days, or longer when legally required or reasonably necessary to protect services or third parties. Different retention may apply if the Nodrya operator obtains and enables OpenAI's Zero Data Retention or Modified Abuse Monitoring controls. See OpenAI's API data controls for current details.
8. How information is used
Information is used to provide and secure the service, authenticate users, store and retrieve notes and attachments, process imports and inbound email, operate sharing and collaboration, synchronize offline changes, deliver transactional messages, understand feature adoption and product usage, generate administrator analytics, enforce service limits, troubleshoot errors, prevent abuse, and maintain the application.
Nodrya does not currently include an advertising or behavioral-profiling system, and the application does not intentionally sell personal information.
9. Service providers and external resources
Nodrya may rely on infrastructure and service providers to operate. The current application supports OpenAI for optional AI-assisted note summaries and keyword expansion, AWS Simple Email Service (SES) for transactional email, and Cloudflare services for deployment-related infrastructure and Email to Note routing/processing. Stripe processes card payments for paid plans on behalf of Dispatch Dataworks LLC and receives the billing details you enter during checkout; Nodrya does not receive or store full card numbers. Providers may receive content or technical information when required to provide the feature you request, subject to their own terms, policies, and retention controls.
10. Cookies and local browser storage
Nodrya uses a session cookie to keep you authenticated. Session lifetime may be longer when you choose the trusted-device option. Browser storage is also used for application preferences, offline/PWA data, and—only if you choose that convenience feature—an account-wide encryption key.
11. Attachments and imports
Imported archives and attachments are processed to provide the import and file features you request. Attachment records are associated with your account and files are intended to be served through authenticated download routes rather than as public files. Import jobs may temporarily retain archive files and processing status while an import is queued or running.
12. Data retention and account deletion
Account content is generally retained while your account remains active. You can request account deletion from Settings. The deletion process removes your user record and database records linked to it through the application's relational data model.
Some information may remain outside those account-linked database records, including operational, email, and de-identified AI usage logs, backups, cached copies, and files awaiting storage cleanup. These may be retained for cost accounting, security, troubleshooting, continuity, or technical reasons and are removed or overwritten according to the operator's maintenance and retention practices. Device-local browser data may also remain until it is removed by you or your browser.
13. Security
Nodrya uses measures intended to reduce security risk, including one-way password hashing, authenticated sessions, CSRF protection on state-changing requests, prepared database queries, optional TOTP multi-factor authentication, access controls for private attachments and shared resources, and browser-side encryption for notes when you enable it. No online service can guarantee absolute security.
14. Children
Nodrya is not directed to children under 13, and users under 13 should not create an account. If the operator learns that personal information from a child under 13 has been collected in circumstances requiring parental consent, appropriate steps should be taken to address it.
15. Your choices
You can update account settings, change your password, enable or disable MFA, manage notes and attachments, control Email to Note senders, create/revoke shares, and delete your account through the application. Depending on where you live, applicable law may provide additional privacy rights.
16. Changes to this policy
This policy may be updated when the service or its data practices change. The date at the top of this page will be updated when revisions are published. Material changes may also be communicated within the service when appropriate.
17. Contact
Nodrya is operated by Dispatch Dataworks LLC. Privacy questions or requests can be sent to privacy@nodrya.com. General support is available at support@nodrya.com. Do not send account passwords, encryption passphrases, MFA secrets, or password-reset tokens.