nod nod
How it works For businesses
Get Nod

Privacy policy

Last updated: 14 September 2026

This Privacy Policy explains how Nod (“we”, “our”, “us”) collects, uses, shares, and protects information when you use the Nod mobile app, related services, and the website gonod.app (together, the “Service”). By using the Service you agree to this Policy and our Terms of Service.

Privacy contact: privacy@gonod.app. Store listing URL: https://gonod.app/privacy/.


1. What Nod is (read this first)

Nod helps people nearby share what they are open to — a coffee, a chat, a workout, an idea — and talk when both sides say yes.

  • What others see: when you post a Nod, nearby people can see that Nod and profile details the product shows with it (for example display name and photo). They do not see your live location, GPS coordinates, street address, or a pin of where you are.
  • No user location map: Nod does not put you — or anyone else — on a map for other users. Location is used only to decide whether a Nod is nearby so we can show a list of Nods. In-app radar graphics are decorative and do not show positions.
  • Manual discoverability: you become discoverable by posting a Nod. There is no “always share my location on a map” mode and no automatic map check-in.
  • Permission first: we ask for location (and other permissions) through the operating system. You can decline.

2. Who this Policy applies to

This Policy applies to users of the Nod app and visitors to gonod.app. It does not apply to third-party websites or services that link to or from Nod. If you use Nod on behalf of an organization, you confirm you are authorized to accept this Policy for that organization.

3. Categories of information we collect

Depending on how you use Nod, we may collect the following categories of personal information (names follow common US “notice at collection” style):

  • Identifiers — account id, email address, display name, device / push tokens, approximate analytics identifiers.
  • Demographic / eligibility — date of birth (to enforce 17+).
  • User content — Nod text, profile fields (bio, interests, what you do, looking for), chat messages, reactions, photos you upload, report text / screenshots.
  • Precise location — device location used for Nearby matching and stored privately with an active Nod for matching. Not shown to other users on a map.
  • Proximity / Bluetooth data — anonymous BLE identifiers mapped to your account for proximity features when you act.
  • Internet / network activity — app feature events, website page views and clicks, IP address (as processed by hosting / analytics providers), referring URLs.
  • Device information — OS type/version, app version, device model class as provided by the OS or SDKs, language, crash/diagnostic signals if provided by platform tooling.
  • Inferences — limited product inferences from usage (for example that a feature was used) to improve Nod — not advertising profiles for sale.
  • Sensitive personal information (as defined in some US state laws) — precise location while used for Nearby / active Nods; account login credentials (processed by our auth provider). We do not use sensitive PI to infer characteristics for advertising.

4. Sources of information

  • You — account signup, profile, Nods, messages, settings, reports, support emails.
  • Your device — permissions you grant (location, Bluetooth, notifications, photos), and technical data needed to run the app.
  • Other users — content they send you (messages), or reports that mention you.
  • Service providers — auth, hosting, push, analytics, and email delivery systems that process data on our behalf.
  • We do not buy personal data from data brokers to build your profile.

5. Device permissions

Nod requests permissions through iOS / Android system dialogs. You can refuse or later revoke them in system Settings. Refusing may disable related features.

  • Location — to show nearby Nods and to store a Nod’s matching coordinates privately. Decline = Nearby matching that needs your location will not work. We do not use location to publish you on a map.
  • Bluetooth — when you create a Nod or connect. You can browse Nods with location alone.
  • Notifications — optional pushes (Nods, matches, messages). Manage categories under Profile → Notifications.
  • Photos / media library — only if you pick a profile photo or send a chat image.

Device biometrics (Face ID / fingerprint) may unlock your phone or the app via the OS; Nod does not collect or store biometric templates.

6. Information you provide in detail

  • Account — email, password (hashed / managed by our auth provider), date of birth, display name, optional profile photo.
  • Profile — optional bio, interests, what you do, looking-for preferences, and similar fields you choose to fill in.
  • Nods — text you post. While active, associated lat/lng for proximity matching only (not shown as a map pin to others). Deleted with the Nod or your account.
  • Connections & chat — connection requests, chats, images, emoji reactions after mutual connect.
  • Safety & support — reports, blocks, support messages, optional screenshots.
  • Preferences — email / push notification toggles and similar settings.

7. Information collected automatically

  • Location (permissioned) — GPS or network-assisted location for Nearby matching and sticky Nod coordinates while a Nod is active.
  • Bluetooth presence — anonymous BLE advertising identifiers mapped server-side for proximity. Over-the-air payload does not include your name, account id, or Nod text.
  • Push tokens — for Apple Push Notification service / Firebase Cloud Messaging when notifications are allowed.
  • App analytics — Firebase Analytics events (for example app opens, permission outcomes, Nod / match / message funnels) to understand product health.
  • Website analytics — Google Analytics 4 on gonod.app (pages, clicks, rough geo from IP as processed by Google).
  • Session replay — Microsoft Clarity in the app for anonymised taps / scrolls / screen flow. Text inputs (chat, Nod text) are masked before leaving the device.
  • Logs & diagnostics — server logs, security logs, and limited crash or performance signals needed to operate and secure the Service.
  • Cookies and similar technologies (website) — see section 12.

8. What we do not collect or do

  • We do not access your address book / contacts.
  • We do not collect payment card data (no paid features today).
  • We do not run third-party advertising networks in Nod today.
  • We do not sell your personal information for money.
  • We do not “share” personal information for cross-context behavioral advertising as defined under California law (we do not run that type of ad graph).
  • We do not use face recognition or build a face template database.
  • We do not display your precise location on a map to other users.
  • We do not require always-on automatic map check-ins.

9. How we use information

  • Provide the Service — accounts, Nearby Nod lists, connections, chat, profiles.
  • Proximity matching — location (± Bluetooth when you act) to decide which Nods are nearby — not to publish map positions.
  • Communicate — transactional email (security, account) and optional product notifications you enable.
  • Safety & integrity — spam/abuse detection, report review, enforcing Terms, securing accounts.
  • Improve Nod — analytics, debugging, UX research via masked session replay.
  • Legal compliance — respond to lawful requests; protect rights and safety.
  • Business operations — audits, aggregate metrics, and (if ever relevant) evaluating a financing or sale of the business (see section 11).

Legal bases (EEA/UK and similar): where those laws apply, we process data as needed to perform our contract with you (providing Nod), based on your consent (for example optional notifications or certain device permissions), for legitimate interests that are not overridden by your rights (security, product improvement, masked analytics), and to comply with law.

10. How we share information

10.1 Other users

  • Nearby (before mutual connection): active Nod text and profile fields the product surfaces on Nearby (e.g. name, photo, and other shown profile details). Not your coordinates, address, or map pin.
  • After mutual connection: chat content and profile information you share in that relationship.
  • Blocks: if you block someone, we stop discovery/contact between you as designed in product.

10.2 Service providers (processors)

Vendors who process data for us under instructions, including for example:

  • Supabase — authentication, database, storage, realtime
  • Firebase / Google — push delivery and in-app analytics
  • Apple — push delivery when you use iOS
  • Google Analytics — website measurement
  • Microsoft Clarity — masked session replay
  • Email delivery providers (e.g. Resend) — transactional / product email
  • Hosting / CDN for gonod.app (e.g. Cloudflare Pages)

10.3 Legal and safety

We may disclose information if we believe it is reasonably necessary to comply with law, court orders, or government requests; to protect Nod, our users, or the public; or in connection with security incidents or Terms enforcement.

10.4 Business transfers

If we are involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, information may be transferred as part of that transaction. We will require the recipient to honor this Policy or provide notice before personal information becomes subject to a different policy.

10.5 Aggregate / deidentified data

We may share or publish aggregate statistics that do not identify you (for example “Nods posted this week”). We commit to maintaining deidentified data in deidentified form and not attempting to reidentify it, except to test our deidentification.

11. Advertising

Nod does not currently show third-party ads in the app. We do not sell personal information to advertisers. If that ever changes, we will update this Policy and any required store disclosures before enabling it.

12. Cookies and similar technologies (website)

gonod.app may use cookies, local storage, pixels, or similar technologies to:

  • Operate the site (essential)
  • Measure traffic and campaigns (Google Analytics 4; optional UTM parameters on download links)
  • Remember basic preferences

You can control cookies through your browser settings. Blocking some cookies may affect site analytics. The Nod mobile app is not a browser cookie environment; it uses SDKs and device identifiers as described above instead.

Do Not Track: there is no consistent industry standard for DNT browser signals. We do not respond to DNT at this time; use cookie controls and your account / permission settings instead.

13. Your choices and safety controls

  • Decline or revoke OS permissions
  • Post, end, or delete Nods (controls discoverability)
  • Edit profile fields you share
  • Notification preferences (Profile → Notifications)
  • Block and report other users (Nearby, Chat, Profile)
  • Delete messages where the product allows
  • Delete your account (Profile → Security → Delete Account)
  • Email privacy@gonod.app for access / correction / deletion requests

We aim to review in-app abuse reports within 24 hours. Urgent safety: support@gonod.app with subject “Safety report”.

14. Retention

  • Account & profile — until you delete your account (unless longer retention is required by law).
  • Active Nod + Nod coordinates — until you delete the Nod or your account.
  • Chat / reactions — until deleted in-product or account deletion.
  • BLE session mapping — as needed for proximity; cleared when you clear a Nod / relevant session or delete your account.
  • Push tokens — until sign-out, permission revoke, rotation, or account deletion.
  • Analytics events — retained according to our analytics providers’ defaults / our configuration, typically on the order of months, in aggregate form longer.
  • Server logs — typically short periods unless needed for security investigations.
  • Abuse reports — may be kept after account deletion for safety and legal purposes, without pointing at a live profile.

15. Security

We use administrative, technical, and physical safeguards appropriate to the risk, including TLS in transit, hashed credentials via our auth provider, access controls, and least-privilege practices. No method of transmission or storage is 100% secure. Protect your password and device.

If we become aware of a breach that requires notice under applicable law, we will notify you and/or regulators as required.

16. International transfers

Nod is operated with infrastructure and vendors that may process data in the United States and other countries. Those countries may have different data-protection laws than your home country. Where required (for example EEA/UK transfers), we rely on appropriate safeguards such as Standard Contractual Clauses or vendor programs that provide an adequate transfer mechanism.

17. Your privacy rights

17.1 General

Subject to local law, you may request access, correction, deletion, portability, or restriction / objection to certain processing. Email privacy@gonod.app. We will verify your request and respond within the time required by law (typically within 30 days, or sooner where required). You may also delete your account in-app.

17.2 California (CCPA/CPRA) and similar US state laws

If you are a resident of California or another US state with a comprehensive privacy law, you may have rights to know/access, delete, correct, and opt out of “sale” or “sharing” of personal information, and to limit use of sensitive personal information, subject to exceptions.

  • Categories collected / disclosed: see sections 3 and 10.
  • Business / commercial purposes: see section 9.
  • Sale / sharing: we do not sell personal information for money and do not share it for cross-context behavioral advertising.
  • Sensitive PI: we use precise location only to provide Nearby / Nod matching — not to infer characteristics for ads. You may deny location permission or delete Nods / your account to limit this processing.
  • Non-discrimination: we will not discriminate against you for exercising privacy rights.
  • Authorized agent: you may use an authorized agent as permitted by law; we will take steps to verify both you and the agent.

To exercise these rights: privacy@gonod.app. If we deny a request, you may appeal by replying to our decision email with the subject “Privacy appeal”.

17.3 EEA / UK / Switzerland

Where GDPR / UK GDPR applies, you may also lodge a complaint with your local supervisory authority. You can withdraw consent where processing is consent-based without affecting the lawfulness of processing before withdrawal.

18. Children and age eligibility

Nod is for users 17 and older. We do not knowingly collect personal information from anyone under 17. Date of birth is collected for eligibility. If we learn we have collected data from someone under 17, we will delete it. Contact privacy@gonod.app. See also our Terms.

Store age ratings (App Store / Play) are set in each store and may differ from the in-product 17+ rule where a platform requires a higher rating.

19. Automated decision-making

Nod uses automated systems for things like proximity matching, content filters (for example profanity), and ranking / showing Nearby results. We do not use solely automated decisions that produce legal or similarly significant effects about you without human involvement as contemplated by GDPR Article 22. Safety enforcement may involve human review of reports.

20. Third-party links and SDKs

The Service may link to third-party sites (for example app stores). Their privacy practices are their own. Platform SDKs (Apple, Google, etc.) may collect data under their terms when you use OS features; we configure them for the purposes described here.

21. App Store and Play disclosures

Apple App Privacy and Google Play Data safety labels summarize data collection in store-required formats. This Policy is the detailed source of truth. If a label and this Policy ever conflict, contact us and we will correct the listing.

22. Changes to this Policy

We may update this Policy from time to time. We will change the “Last updated” date on this page. For material changes, we will provide additional notice (for example in-app or email) where required. Continued use after the effective date means you accept the updated Policy. If you do not agree, stop using Nod and delete your account.

23. Contact

Nod
Web: gonod.app
Privacy: privacy@gonod.app
Safety: support@gonod.app (subject: Safety report)
Privacy Policy URL: https://gonod.app/privacy/


This policy was last updated on 14 September 2026. View Terms of Service →

Nod

Proximity social for iPhone and Android. Private by design.

hello@gonod.app

Product

  • How it works
  • Get Nod
  • Safety

Company

  • For businesses
  • Support
  • Contact

Legal

  • Privacy
  • Terms

© 2026 Nod. All rights reserved.

App Store & Google Play