Legal · draft
Privacy policy
An outline of the privacy policy, with the facts of how NoodleOps handles data today for whoever writes it. Nothing on this page is in force.
Controller
[The data controller and how to contact them — to be written once the legal entity and jurisdiction are settled]
Repository data
The desktop application reads repositories on the user's Mac. Repository data stays on that machine: the account service stores none.
What the account service keeps
- Email address and WorkOS user id. Your email address, written at your first sign-in and refreshed when WorkOS reports a change, the id WorkOS gives your account, its status, and when it was last confirmed with WorkOS, created and deleted.
- Teams, roles and seats. The teams you belong to, your role in each, who owns them, and the seats and invitations held for them.
- Team changes in progress. An invitation, removal or seat change while it completes, and who made it; an invitation keeps only a hash of the invitee's email, dropped once it is resolved.
- Installations and device labels. Each installation of the desktop app you activate: its device label, when it was last seen, a hash of its credential, and the leases issued to it; and any evaluation access granted to a team, with who granted it and why.
- Subscription and billing state. Your subscription's plan, seats and status, its billing periods and what each charged, checkouts in progress and the Paddle customer id — not card details, which stay with Paddle.
- Sign-in sessions. Each sign-in session: hashes of its secret and its CSRF token, the WorkOS session it belongs to, when you signed in, when it expires, and how it ended. A sign-in in progress, for ten minutes: hashes of its state, of its browser binding and of the desktop app's handoff code, its PKCE challenge, the local port the desktop app listens on when it started the sign-in, when a browser claimed it, and — once you confirm it — your user id, the session and the plan you chose, and the one-minute deadline of the code it hands back to the app.
- The audit trail. Who did what to a team or account, and whether it was allowed: the actor, the action, its target, its result and when — and, for an action by NoodleOps staff, the reason they gave, which a team's own audit view never shows: it names them only as NoodleOps support.
- Deletion requests. A request to delete your account, its progress at WorkOS, Paddle and PostHog, and when it completed — and a fingerprint of the private link you follow it with, never the link itself.
- Provider events. For each event WorkOS or Paddle sends: its id, type, subject and time — not its contents, only the ids a deletion names — and which ones were applied; the ids of deleted accounts, so they are never recreated; and, for each account, team or subscription that has had events, a record keyed by its WorkOS or Paddle id that keeps them processed in order.
- Team sharing. If your team shares project health: the team's sharing default and who last changed it, and a random value your team's apps hash project identities with; for each project a member chose to share, that hash — not the project's name, address or files — the name the member typed for it, its counts and last check result, who analysed it and when; and the check profiles your team's owner or admins published, who published each, and which members confirmed them. Unsharing a project deletes its summary.
- Analytics id. If you turn on usage analytics in the desktop app: a random id made for your account when its first event is sent, which PostHog receives in place of your email or any account id. Deleting your account deletes your events from PostHog through this id; it is kept until PostHog has deleted them, then removed.
Sign-in is provided by WorkOS and payments by Paddle; card details stay with Paddle.
[Retention periods and the legal basis for each — to be written once the legal entity and jurisdiction are settled]
Cookies
The account service sets four cookies on its own host, each
__Host- (secure, host-only):__Host-noodleops_login— binds a sign-in in progress to your browser, for ten minutes.__Host-noodleops_session— your session: at most 24 hours, and two hours without use.__Host-noodleops_csrf— a token the account page sends back with every change, so another site cannot make one for you.__Host-noodleops_desktop— binds a sign-in started from the desktop app to the browser that opened it, for ten minutes.
This site sets none, and runs no analytics.
Usage analytics
The desktop app sends usage analytics only if you turn them on in the app; they are off until you do, and you can turn them off at any time. They go to the account service, which forwards them to PostHog's EU cloud under the random id above — never your email or an account id.
The account service's request to PostHog carries your IP address: it runs on Cloudflare, which adds it, and the service cannot remove it. Each event names a placeholder address instead, and the PostHog project is set to discard IP addresses. A test event sent through the service and read back from PostHog showed no IP address stored.
Deleting your account deletes your usage analytics from PostHog: PostHog removes them in the background, which can take days or weeks, and the deletion completes only once they are gone.
What is sent: that an upgrade run started, reached review or did not (and at which stage), how long it took, how many checks ran and how many packages changed, the package manager, the app version, and which features you opened. Never a package, project or folder name, a path, a URL, code or command output.
The account page and this site send no analytics.
Processors
WorkOS (identity), Paddle (payments), Cloudflare (hosting), Neon (the account database), PostHog (usage analytics, EU; only if you turn them on).
When the account service calls WorkOS, Paddle or PostHog while handling your request, Cloudflare adds your IP address to that call, and the service cannot remove it.
[Their locations and the transfer safeguards — to be written once the legal entity and jurisdiction are settled]
Your rights
An account holder can request deletion from the account page.
[The rights that apply and how to exercise them — to be written once the legal entity and jurisdiction are settled]
Questions: support@noodleops.dev.