Skip to content
Octonode home · Legal & privacy center

Privacy notice

Notice version: 2026-09-19. Operator review pending.

Who is responsible

The website operator and controller of account and website information is Niv Doron, an individual based in Israel, reachable at service@octonodes.com. A public business/contact address is pending. For personal data uploaded on a customer’s instructions, the workspace customer may be the controller; a separate processing agreement may be required.

Data collected and its sources

Information can come from you, workspace administrators, connected identity or repository providers, and use of the service. Categories include account email and profile details; memberships and permissions; project source, workflow inputs/outputs, execution logs, files and secrets you supply; community profiles, posts, comments and media; support correspondence; and subscription identifiers, invoices, usage and billing status. Hosting and security systems can process IP addresses, request metadata and operational logs. Avoid placing sensitive personal information in public posts or test fixtures.

Why data is processed

Account and workspace data enable sign-in, access control and collaboration. Project data is used to store and execute requested workflows. Billing and usage data support subscriptions, invoices and limits. Operational data supports security, reliability and troubleshooting. Contact information is used to answer requests. Checkout acknowledgement records link the signed-in user, workspace, server timestamp, policy version and checkout operation for contract and dispute evidence. Optional AI features process prompts and the project context supplied to them. The operator must confirm each lawful basis before relying on this notice: contract for requested services, legal obligations for required records, documented legitimate interests for appropriate security operations, and consent where required for optional processing.

Sharing and public content

Service providers involved in the configured deployment are listed on the Providers page. Workspace members and administrators can access information according to permissions. Publishing a community post, workflow or public design-document link makes its selected content available to recipients or the public, who may copy or index it. Connected integrations receive data needed for the actions you request. Disclosure may also be required by law. The source audit found no advertising or visitor-analytics tracker; the operator must verify live hosting settings and any sale, sharing or marketing practices separately.

Storage, retention and deletion

Data is stored in the configured hosting, authentication, database, object-storage, backup and connected-provider systems. A verified retention schedule for accounts, content, security logs, billing records and backups has not yet been supplied. The previous repository note about a universal 30-day backup purge was not sufficient evidence of complete deletion across all systems. Ask the contact channel about your data and deletion; this draft does not promise an unverified purge deadline.

International processing

Providers may process information in countries different from yours. Hosting regions, vendor legal entities, transfer safeguards and any required EU/UK representatives must be confirmed by the operator. Do not assume that a provider’s name or an HTTPS connection establishes an adequate international-transfer safeguard.

Your rights and requests

Depending on applicable law, you may have rights to access, correct, delete, export or restrict processing of your data, object to processing, withdraw consent, or opt out of sale/sharing and certain profiling. You may also complain to your local data-protection authority. Use Contact & requests for a private request; identify the affected account or workspace without sending a password or API key. Identity and authority may need to be verified. Mandatory legal exceptions and response periods apply. Customers’ workspace-content requests may need to be handled through the workspace controller. Rights requests must not lead to unlawful discrimination.

California and browser signals

California coverage depends on the operator and statutory thresholds. Where applicable, disclosure must cover data categories, sources, purposes, recipient categories, retention, sensitive information, and sale/sharing during the required reporting period. The source code currently enables no optional advertising or visitor analytics. Global Privacy Control is detected by the storage notice and optional tracking stays off. A live-service assessment is still required before making a company-wide no-sale/no-sharing claim.

Children

The service’s stated minimum age is 18. Contact us if an account or content appears to involve a child below that age.

Security and automated processing

The project uses authentication and workspace permissions, production transport protections, and checks at API boundaries. No system can guarantee absolute security. AI output and workflow actions require appropriate human review, especially for decisions affecting people. Customer-built workflows may perform additional processing outside these notices; their operators must provide any required explanations and safeguards.

Email the project contact