NovalinkIn dev

Privacy Policy

Last updated September 17, 2026

This policy covers the hosted Novalink service. If you run Novalink on your own infrastructure, your data never reaches us and you are responsible for it. We keep what we collect to what the product needs to work.

01What we collect

  • Account details: your email address and name. If you sign in with Google, we receive the name and email on your Google account.
  • Workflows: the graphs you build, their names, published versions, and node configuration.
  • Run history: each run's trigger payload, the inputs and outputs of every node, errors, timings, and token counts, so you can replay and debug runs.
  • Credentials: API keys and headers you save. They are encrypted at rest, never returned to the browser after saving, and redacted from stored run inputs.
  • Workflow generation prompts: the descriptions you type into the AI assistant.

We do not use analytics, advertising trackers, or tracking pixels.

02How we use it

  • To sign you in and keep your session active.
  • To store, run, and show the history of your workflows.
  • To draft workflows from your descriptions when you use the AI assistant.
  • To prevent abuse, such as rate limiting AI generation and blocking requests to private networks.
  • To answer you when you contact support.

03Who processes your data

We do not sell your data. We share it only with the providers that run the service:

  • Supabase handles authentication and stores your account email, name, and password hash.
  • Google verifies your identity if you choose to sign in with Google.
  • Vercel hosts the application.
  • Our database provider stores workflows, runs, and encrypted credentials.
  • Anthropic receives your prompt when you generate a workflow with AI, and receives the node inputs of agent nodes that use an Anthropic credential.

Workflows can also send data anywhere you configure them to, for example an HTTP Request node calling an external API. Those services receive what your workflow sends under their own terms.

04Cookies and local storage

  • Session cookies from Supabase keep you signed in.
  • A sidebar cookie remembers whether you collapsed the navigation.
  • Local storage remembers your light or dark theme.

05Retention and deletion

We keep your data while your account exists. Deleting a workflow deletes its versions and run history. To delete your account and everything in it, email support@novalink.live from the address on the account and we will remove it within 30 days.

06Security

Traffic is encrypted in transit and credentials are encrypted at rest. Novalink is still under development, so no system is guaranteed to be free of flaws: avoid storing data you cannot afford to lose, and report any vulnerability to support@novalink.live.

07Your rights

You can ask us for a copy of your data, to correct it, or to delete it by emailing support@novalink.live. Depending on where you live, you may also have the right to object to processing or to complain to your data protection authority.

08Children

Novalink is not intended for anyone under 16, and we do not knowingly collect their data.

09Changes to this policy

We will update the date above when this policy changes, and email account holders about material changes before they take effect.

10Contact

Questions about privacy: support@novalink.live.