NOME
Legal

Privacy Policy

This policy describes what information NOME collects, how it is used, and the choices you have.

Effective September 1, 2026

01Information we collect

We collect information in three ways: information you provide directly, information generated by your use of the service, and information collected automatically by our systems.

Information you provide

  • Account information — name, email address, organization, and authentication credentials (stored as salted hashes, or delegated to your identity provider when using single sign-on).
  • Workspace content — environment specifications, registered contract artifacts, scenarios, and any metadata or labels you attach to them.
  • Billing information — where applicable, billing contact details and the last four digits of a payment method. Full payment details are handled by our payment processor and never stored by NOME.
  • Communications — messages you send to support, security, or other NOME contacts.

Information generated by use

  • Environment data — snapshots, run records, state diffs, traces, and events produced by executing operations in your environments.
  • Audit records — authentication events, API key operations, and administrative changes within your workspace.

Information collected automatically

  • Service logs — request metadata such as timestamps, endpoints, response codes, IP addresses, and user-agent strings.
  • Usage analytics — aggregated, de-identified measurements of how the Console and documentation are used.

02How we use information

We use the information we collect to:

  • Provide, operate, and maintain the service, including running your environments.
  • Authenticate users and secure workspaces against unauthorized access.
  • Respond to support requests and security reports.
  • Monitor reliability, diagnose incidents, and improve performance.
  • Enforce our Terms of Service and applicable limits.
  • Send transactional communications such as security notices and service changes.
  • With your consent, send product updates. You can opt out at any time.

We do not sell personal information. We do not use workspace content or environment data to train machine-learning models, and we do not share it with other customers.

03Data retention

We retain information for as long as necessary to provide the service and meet legal obligations.

CategoryRetention
Account informationDuration of the account, plus 30 days after deletion.
Active environment dataWhile the environment is active or until you delete it.
Archived snapshots90 days after archive, unless restored or deleted earlier.
Audit records12 months.
Service logs30 days in primary storage; 90 days in cold storage.
Support communications24 months.

When you delete a workspace, associated data is removed from primary systems within 30 days and expires from backups on a rolling basis thereafter.

04Service providers

We work with a small number of third-party providers who process information on our behalf to deliver the service. Each is bound by contractual obligations to protect the information and to use it only for the purposes we specify.

  • Cloud infrastructure — hosting, storage, and networking for the control plane and execution planes.
  • Payment processing — subscription billing and invoicing.
  • Transactional email — delivery of account and security notices.
  • Error monitoring and analytics — reliability and de-identified usage measurement.

A current list of subprocessors is available on request. We will notify workspace administrators before adding a subprocessor that will process workspace content.

05Security

We protect information using technical and organizational measures appropriate to its sensitivity, including encryption in transit and at rest, per-environment isolation, scoped access controls, and audit logging. Our approach is described in more detail on the Security page.

No method of transmission or storage is completely secure. If we become aware of a breach affecting your information, we will notify you without undue delay in accordance with applicable law.

06Your rights

Depending on where you live, you may have rights regarding your personal information, including the right to:

  • Access the personal information we hold about you.
  • Correct inaccurate or incomplete information.
  • Delete your personal information, subject to legal retention requirements.
  • Export your information in a portable format.
  • Object to or restrict certain processing.
  • Withdraw consent where processing is based on consent.

You can exercise most of these rights directly from the Console under Settings. For anything else, contact us using the details below. We will respond within the timeframe required by applicable law. You also have the right to lodge a complaint with your local data protection authority.

07Cookies

We use a minimal set of cookies and similar technologies:

TypePurpose
Strictly necessarySession authentication and security (e.g. CSRF protection). Cannot be disabled.
PreferencesRemembering settings such as the last selected workspace.
AnalyticsDe-identified usage measurement for the website and Console. Optional.

We do not use advertising cookies or cross-site tracking. You can control optional cookies through your browser settings or the preference controls in the Console.

08Changes to this policy

We may update this policy as the service evolves or as legal requirements change. When we make material changes, we will notify workspace administrators by email and update the effective date above at least 14 days before the changes take effect. Continued use of the service after that date constitutes acceptance of the updated policy.

09Contact

Questions about this policy or about how we handle information can be directed to privacy@nomefamily.lol. For security matters, see Responsible Disclosure.