Effective beta policy. This Privacy Policy applies to current use of nodedough and explains how JBNX LLC handles personal information.
Privacy Policy
Effective date: August 12, 2026 · Version 1.0
nodedough is operated by JBNX LLC (“JBNX”, “we”, “us”). This policy explains what we collect, why, and the choices you have. The short version: you type your budget in, we store it to run the app for you, we don't sell it, and we don't connect to your bank.
1. What we collect
Information you provide
- Account data: email address, display name, password (stored as a hash by our authentication provider), optional two-factor enrollment.
- Budget data you enter: account names, balances, recurring incomes and expenses, plans, and notes. This is manually entered by you. We never ask for bank login credentials and do not connect to financial institutions.
- Workspace membership: who you invite to a household or company workspace and their roles.
Information collected automatically
- Service logs: standard technical logs such as IP address, user agent, request path, and timestamps for security, reliability, and operations.
- Product analytics: limited first-party product-use events may be collected when analytics is enabled. We do not use third-party ad trackers or collect the financial values you enter as analytics properties.
Payment information
Payments are processed by Stripe. Card details go directly to Stripe; we receive only subscription status, plan, and billing metadata (never full card numbers). See Stripe's privacy policy for how it handles your data.
2. What we use it for
- Operating the Service: storing and displaying your budget, syncing across your workspace, projections.
- Authentication, security, fraud and abuse prevention.
- Billing and subscription management.
- Service communications (e.g., password resets, billing notices, material changes to terms).
We do not sell your personal information, and we do not share it for cross-context behavioral advertising. There is no ad tracking in the app.
3. Legal bases (GDPR)
Where the GDPR applies, we process your data on these bases: contract (running the Service you signed up for), legitimate interests (security, abuse prevention, service improvement), and legal obligation (tax and accounting records).
4. Who processes data on our behalf
| Processor | Purpose | Data involved |
| Supabase | Database hosting and authentication | Account and budget data |
| Stripe | Payment processing and billing portal | Payment and subscription data |
| Railway | Application hosting | Service traffic and logs |
| Google | Optional “Continue with Google” sign-in | Email and basic profile, if you choose it |
These providers may use subprocessors described in their own privacy and security documentation. We may replace a provider or add a service provider when needed to operate the Service, and we will update this policy when that materially changes how personal information is handled.
5. Sharing within your workspace
nodedough is designed for shared budgeting. Data you put in a shared household or company workspace is visible to the members of that workspace according to its sharing and role rules. Check who is in a workspace before adding sensitive information.
6. Data retention
- Account and budget data: retained while your account is active.
- After a verified deletion request: account and budget data is deleted or de-identified within the period reasonably needed to complete the request, except records we must keep for legal, tax, fraud-prevention, or dispute-resolution purposes.
- Backups and service logs expire on operational schedules and may be retained longer when needed to investigate abuse, protect the Service, or comply with law.
7. Your rights and choices
- Access, correction, deletion: you can edit most data directly in the app. Request a full export, account deletion, or other privacy help through Support.
- Portability: you may request your data in a machine-readable format.
- Product analytics: you may ask us to stop associating future optional product-use events with your account by contacting Support.
- GDPR (EEA/UK): you also have rights to restrict or object to processing and to lodge a complaint with a supervisory authority.
- California: where applicable, you may have rights to know, delete, correct, and receive equal service when exercising privacy rights. We do not sell personal information or share it for cross-context behavioral advertising.
We will respond to verified requests within the timeframe required by applicable law.
8. Security
- All traffic is encrypted in transit (TLS). Data is encrypted at rest by our hosting providers.
- Database access is governed by row-level security so accounts can only read the workspaces they belong to.
- Passwords are hashed by our authentication provider; we never see them. Two-factor authentication is available.
- No system is perfectly secure; if a breach affecting your personal data occurs, we will notify you and regulators as required by law.
9. International transfers
The Service is operated from the United States, and our providers may process information in the United States and other countries where they operate. Where applicable law requires a transfer safeguard, we rely on the safeguards made available by our service providers, such as standard contractual clauses or an adequacy mechanism.
10. Children
Accounts are limited to adults age 18 and older, and the Service is not directed to children. An adult may enter information about dependents as part of a household budget. We do not knowingly allow a child to create an account or provide information directly; if you believe that happened, contact us and we will investigate and delete it as required.
11. Changes to this policy
We may update this policy. For material changes we will give notice by email or in-app at least 14 days before the change takes effect.
12. Contact
Submit privacy requests through Support. Select or mention “Privacy request,” describe the right you want to exercise, and include a reliable way for JBNX LLC to respond. We may verify your identity before completing a request.