1. Controller and contact
The data controller for account administration, security, abuse prevention, product operation, and direct communications is the individual publisher identified in the Legal Notice. Contact: [email protected].
When a user configures Noria to process another person's data solely on that user's instructions, the user is normally the controller and the publisher acts as processor; see the Data Processing Terms.
2. Data collected
- Account: email, display name, authentication state, avatar, preferences, and the accepted Terms version, date, and authentication method.
- Connections: provider identity, granted scopes, connection status, and encrypted OAuth or bot credentials.
- Workflows: nodes, edges, expressions, settings, versions, collaborators, public-template metadata, and data samples you deliberately pin.
- Executions: status, timestamps, node inputs and outputs needed for debugging, errors, and delivery identifiers.
- Security: IP address where required for rate limiting or incident investigation, user-agent and request metadata, authentication events, and administrative actions.
- Reports and communications: report reference, category, target, explanation, optional email, handling decision, support messages, and related evidence you submit.
- Analytics: aggregate page-use measurements and, only after consent, Microsoft Clarity data described in the Cookie Policy.
- Donations: voluntary donations are processed by Stripe. Payment details are entered on Stripe; Noria does not collect payment card details.
Do not place passwords, private keys, unnecessary personal data, or regulated sensitive data into workflow fields, logs, public templates, support messages, or abuse reports.
3. Purposes and legal bases
- Contract or steps requested by you: account access, workflow storage and execution, integrations, exports, support, and requested deletion.
- Legitimate interests: securing the beta, preventing fraud and abuse, diagnosing failures, measuring aggregate use, enforcing the Terms, and defending legal claims, balanced against user rights.
- Consent: optional analytics cookies, session replay, and optional marketing communications; consent can be withdrawn.
- Legal obligations: responding to valid authority requests, preserving legally required information, and notifying competent authorities where required.
- Vital interests: exceptionally, handling information necessary to address an imminent threat to life or safety.
4. Retention
- Account and workflows: while the account exists, then deleted through the account-deletion process unless a narrow exception below applies.
- Execution logs: up to 90 days during the beta.
- OAuth connection events: up to 90 days; active encrypted credentials remain until disconnection or account deletion.
- Administrative audit log: up to two years to document sensitive operator actions.
- Open abuse reports: while necessary to investigate and decide them.
- Closed abuse reports: normally one year after resolution, longer only for a documented legal hold, authority request, ongoing threat, or legal claim.
- Support communications: only as long as reasonably necessary to handle the request and related follow-up.
- Consent preference: stored locally until you clear it or change your choice.
Account deletion removes active account, workflow, execution, and connection records from normal product systems. It may not immediately erase minimal information that must be isolated and retained for legal compliance, security, fraud prevention, dispute resolution, or the establishment, exercise, or defence of claims. Encrypted backup copies disappear through their normal rotation and are not restored for ordinary use.
5. Recipients and service providers
Data is shared only as needed with:
- infrastructure providers operating the web application, API, queues, database, backups, and network;
- MongoDB for the primary database, configured for the deployment's selected region;
- the SMTP provider for sign-in and service emails;
- Sentry, if enabled, for errors and sampled performance data with default PII collection and Session Replay disabled;
- Plausible for aggregate analytics, if configured, and Microsoft Clarity only after consent;
- Discord, Twitch, Google, YouTube, or another provider when you connect it or direct a workflow action to it;
- Stripe to process voluntary donations when you choose to support Noria;
- competent authorities, courts, advisers, or affected providers when lawfully required or necessary to address serious abuse.
Personal data is not sold and is not shared for third-party advertising.
6. International transfers
Processing is kept in the EEA where the selected infrastructure permits it. Some providers or connected services may process data outside the EEA. Where GDPR transfer rules apply, an adequacy decision, Standard Contractual Clauses, or another lawful transfer mechanism is used together with appropriate supplementary safeguards.
7. Security
- TLS for network transport and secure, HTTP-only authentication cookies in production;
- AES-256-GCM encryption for stored OAuth and bot credentials;
- rate limiting, captcha controls, provider signature checks, and outbound-network protections;
- role-limited, two-factor-protected administrative access and an administrative audit trail;
- secret redaction, dependency monitoring, error monitoring, kill switches, and incident-response controls.
These measures reduce risk but cannot guarantee absolute security. If you discover a vulnerability or misuse, use the private reporting channel instead of placing secrets in a public discussion.
8. Your GDPR rights
Depending on the circumstances, you may request access, rectification, erasure, restriction, portability, or object to processing based on legitimate interests. You may withdraw consent at any time without affecting prior processing. Account export and deletion controls are available in settings.
Send requests to [email protected]. We may request proportionate identity verification and normally respond within one month. You may also complain to your local supervisory authority; in France, this is the CNIL.
9. Cookies and analytics choices
Strictly necessary authentication and preference storage operates without consent where permitted. Optional Microsoft Clarity analytics loads only after a positive choice. Details, lifetimes, and controls are in the Cookie Policy.
10. Children
Noria accounts are intended for adults aged 18 or over during the beta. The Service is not designed to collect children's data. If you believe a child's data has been submitted, contact us so it can be investigated and removed where appropriate.
11. Changes and contact
This policy will be updated when processing materially changes. Significant changes will be announced in the Service or by email where appropriate. Questions may be sent to [email protected].