Privacy Policy
Last updated June 12, 2026 · Private beta
What Nopal is
Nopal is a knowledge system for reasoning: your team records decisions, claims, knowledge, and discussions, and connects them. We process data to provide exactly that service; nothing is sold, and nothing is used to advertise to you.
What we collect
- Account data: your name, email, and authentication identity (managed by Clerk).
- Workspace content: the artifacts, comments, topics, relations, and files your team creates.
- Billing data: handled by Stripe; we never see or store full card numbers.
- Operational data: request logs, error reports (with personal data scrubbed), and a small set of manually chosen product events (e.g. “artifact created”). No advertising trackers, no session recording, no autocapture.
- Behavioral product signals: to improve Nopal, we record content-free interaction events, meaning an event kind (for example “a citation was clicked” or “an answer was rated”), timing, and internal record identifiers. These records are incapable of holding your text: never your questions, answers, titles, or documents. We read them only as aggregate counts and timings, never as any individual person’s activity.
- Aggregate counts: we compute totals across all workspaces (for example the number of artifacts on the public landing page). These are plain counts and can never be traced back to any workspace, person, or content.
AI features are opt-in
The /ask feature sends relevant workspace content to Anthropic (Claude) to answer your question, and search embeddings are computed by Voyage AI. These features are off by default; an organization admin must enable them, and each user sees a disclosure before first use. Your content is not used to train these vendors’ models under our agreements.
Who processes data for us
We use a small set of processors, each under a data-processing agreement: Supabase (database, files, realtime), Clerk (authentication), Vercel (hosting), Stripe (billing), Typesense Cloud (search index), Upstash (rate limiting), Anthropic and Voyage AI (opt-in AI features), Sentry (error monitoring, scrubbed) and PostHog (product analytics). Data is hosted in the United States. The beta is offered to non-EU organizations.
Your rights and controls
- Export: a machine-readable export of your data is available at any time, in every account state, from your account.
- Erasure: on request, we irreversibly erase your personal identifiers and redact your name from historical records, while your organization’s work product is preserved for its remaining members.
- Retention: content is never deleted because of billing state; if your subscription lapses, your account becomes read-only and export remains available.
- Notifications: browser push is strictly opt-in and per-browser; in-app updates can be marked read at any time.
Security
Every database table is protected by row-level security so organizations are isolated from one another; access to gated features is enforced server-side; webhooks are signature-verified; and the audit log of changes is immutable. Transport is encrypted (HTTPS with HSTS). Our own operators can technically reach the databases and file storage that hold your content, the way any infrastructure operator can; we do so only for operations, incident response, and support you ask for, our providers log that access, and our in-product staff tools are built to show aggregates rather than any member’s activity.
Contact
Questions or requests (including export and erasure): privacy@nopal.info.
This policy describes the private beta and will be updated before public availability.