Privacy Policy

Effective from March 25, 2026

This English text is a translation provided for convenience. The Russian version is the legally binding document; in case of any discrepancy, the Russian version prevails. Russian version

1. General Provisions

This Privacy Policy (hereinafter the "Policy") sets out the procedure for processing and protecting the personal data of Users of the Noders service (hereinafter the "Service").

The personal data operator is Individual Entrepreneur Gelvikh Leonid Vladimirovich, OGRNIP 317774600202454, INN 771004647806 (hereinafter the "Operator").

Personal data is processed in accordance with Federal Law No. 152-FZ "On Personal Data" dated 27.07.2006 and other regulatory legal acts of the Russian Federation.

By registering with the Service, the User consents to the processing of their personal data on the terms of this Policy.

2. What Data We Collect

2.1. Data provided by the User

  • Email address — upon registration.
  • Name and profile photo — when signing in via Google OAuth.

2.2. Data collected automatically

  • IP address.
  • User Agent (browser type and version, operating system).
  • Data on activity within the Service (creating canvases, launching generations).

2.3. Generation data

  • Text prompts entered by the User.
  • Generation parameters (model, settings).
  • Generation results (links to the generated files).

2.4. Payment data

Payments are processed through the YooKassa payment system (JSC "YooMoney"). The Operator does not collect and does not store Users' bank card data (card numbers, CVV, expiry dates or any other card details). All payment data is processed on the YooKassa side in accordance with the requirements of the PCI DSS security standard.

The Operator stores only: the payment identifier in the YooKassa system, the payment amount, the transaction status (success/failure) and the date of the transaction.

2.5. Third-party API keys

The Service allows the User to store their own API keys of third-party AI providers (BYOK mode — Bring Your Own Key) in order to run generations.

  • Data category: API keys (access tokens) of third-party services, provided by the User voluntarily.
  • Purpose of processing: running generations (sending requests to AI providers) solely at the User's direct request.
  • Storage: API keys are stored in encrypted form (AES-256) in the Supabase database (AWS servers, Europe region). Keys are decrypted only in the server's operating memory at the moment a request is executed.
  • Access: automated only — the Operator's server sends the request to the provider's API. Employees have no manual access to the keys.
  • Retention period: until the keys are deleted by the User through the account settings or until the User's account is deleted.
  • Transfer to third parties: API keys are not transferred to third parties. The keys are used only to send requests to the providers to which they belong, on behalf of the User.

3. Purposes of Data Processing

  • Provision of the Service — identifying the User, providing access to the functionality, saving canvases and generation results.
  • Billing — accounting for the token balance, processing payments, compiling transaction history.
  • Analytics — analysing the use of the Service in order to improve its quality and stability.
  • Quality improvement — optimising performance, identifying and fixing errors.
  • Notifications — informing the User about changes to the Service, the status of generations, and changes to the terms of use.

4. Cookies and Analytics

  • Authentication cookies — used to maintain the User's session (Supabase Auth). They are strictly necessary for the Service to operate.
  • Sentry — an error monitoring service. It collects technical information about errors so that they can be fixed promptly.
  • PostHog — a product analytics service (planned for implementation). It will be used to analyse the use of the Service's features.

5. Transfer of Data to Third Parties

The Operator may transfer the User's data to the following categories of third parties solely for the purpose of providing the Service:

5.1. AI model API providers

In order to run generations, text prompts and parameters are transferred to providers of AI models:

  • WaveSpeed AI — image and video generation.
  • Kie.ai — orchestration of AI tasks.
  • ElevenLabs — speech synthesis (text-to-speech).
  • fal.ai — video processing (lipsync).
  • OpenRouter — access to large language models (LLM).

Each provider processes data in accordance with its own privacy policy.

5.2. Payment system

YooKassa (JSC "YooMoney") — payment processing. The following is transferred: the payment amount, the email address for the receipt, and the User's identifier in the Service.

5.3. Infrastructure providers

  • Supabase (AWS, EU region) — database hosting and authentication.
  • Beget (RU) — CDN storage for generated files.
  • Sentry — error monitoring.

The Operator does not sell, transfer or provide Users' personal data to third parties for advertising or marketing purposes.

6. Data Storage

  • Database — Supabase (AWS, Europe region). Data is protected by Row Level Security (RLS).
  • File storage — Beget Cloud Storage (Russia). Generated files are stored on a CDN.
  • Encryption — all data is transmitted over the secure TLS 1.2+ protocol. Users' API keys (BYOK) are stored in encrypted form (AES-256).

7. User Rights

In accordance with Federal Law No. 152-FZ, the User has the right to:

  • Access to data — request information about which personal data is processed by the Operator.
  • Rectification — demand the correction of inaccurate or incomplete personal data.
  • Account deletion — delete their account through the Service settings. When an account is deleted, all related data (canvases, generations, payment history) is deleted in a cascade.
  • Data export — request an export of their personal data in a machine-readable format.
  • Withdrawal of consent — withdraw consent to the processing of personal data, which makes further use of the Service impossible.

To exercise these rights, the User may contact the Operator at the email address: privacy@noders.ru

8. Data Protection

The Operator takes the following measures to protect personal data:

  • Data is transmitted over the HTTPS protocol (TLS 1.2+).
  • The database uses the Row Level Security (RLS) mechanism, which ensures data isolation between Users.
  • Passwords are hashed by means of Supabase Auth (bcrypt).
  • Users' API keys (BYOK) are stored in encrypted form using the AES-256 algorithm (server-side encryption). Decryption takes place only in operating memory while a request is being processed.
  • Access to the infrastructure is restricted and controlled.

9. Data Retention Periods

  • Account data — stored for the entire period the account is active and for 30 (thirty) calendar days after it is deleted.
  • Logs and technical data — stored for 90 (ninety) calendar days.
  • Payment data — stored in accordance with the requirements of the accounting and tax legislation of the Russian Federation.
  • API keys (BYOK) — stored until deleted by the User or until the account is deleted. Upon deletion they are destroyed irrevocably.

10. Changes to the Policy

The Operator has the right to amend this Policy. In the event of material changes, the Operator notifies Users by email.

The current, legally binding version of the Policy is always available at /privacy; this page is its English translation.

11. Contacts

Data Protection Officer (DPO): privacy@noders.ru

For general questions about the Service: support@noders.ru