Privacy & Security

Privacy & Security

Last updated: June 28, 2026

Our Commitment

NodeSkela is built around trust. We collect the minimum information needed to run the platform, and we never sell your data. This page explains what we collect, how we use it, and the security measures we take to protect you.

Information We Collect

  • • Email address — used as your account identifier and visible to other members of your group.
  • • Display name — chosen by you, visible to your group.
  • • Occupation — optional, shown on your profile.
  • • PIN (hashed) — a 4 or 6-digit PIN used for authentication. Stored as a salted hash (PBKDF2), never in plaintext after first login.
  • • One-time codes (hashed) — OTP codes for login and PIN changes. Hashed and expire within 10 minutes.
  • • Session tokens — issued per login to maintain your session. Each new login invalidates previous sessions.
  • • Auth tickets — short-lived tokens issued after identity verification, used once to complete session-issuing actions.
  • • Security metadata — failed attempt counts, lockout timestamps, and rate-limit timestamps to protect against brute-force attacks.
  • • Terms acceptance — the timestamp of when you accepted the Terms of Service.
  • • Admin flag — whether your account has platform admin privileges.
  • • Messages — content you send in group chat, including text, attachments (images, files, voice memos), reactions, replies, and edit/delete state.
  • • Thoughts of the week — optional weekly reflections shared within your group, plus an archive of past thoughts.
  • • Task list — items you add under "working on," including titles, due dates, and completion status.
  • • Streak data — week keys tracking your consecutive weekly activity for streak badges.
  • • Group activity — invite links you create, last-active timestamps, and membership status per group.
  • • Group data — group name, access key, banner image, member count, feature unlock level, and custom roles.
  • • Referral tree data — invite tokens, slot numbers, referral depth, and descendant counts used to map your invite tree.
  • • Co-creator assignments — if you are a group creator, records of members you've promoted to co-creator.
  • • Private notes — notes you write about other members (visible only to you and platform operators) and notes others write about you (not visible to you).
  • • Vote-to-kick records — if your group has unlocked this feature, records of who initiated a vote, who voted, and the outcome.
  • • Call signaling data — WebRTC offer/answer/ICE candidate records for video calls within your group. These accumulate during active calls.
  • • Bug reports — your email, name, and description when you submit a bug report.
  • • Content reports — when you report a message, the message content and context are sent to group creators.
  • • System notifications — automated announcements posted in group chat (e.g., when a member joins or completes a task).
  • • Built-in metadata — every record stores a unique ID, creation date, last-updated date, and the ID of the user who created it.

We do not collect: location data, device identifiers, IP addresses for tracking, browsing history, advertising identifiers, or third-party analytics data. No location, device, or behavioral tracking is implemented.

How We Use Your Information

  • • To authenticate you and keep your account secure.
  • • To display your profile and messages within your group.
  • • To send you login notifications and inactivity reminders.
  • • To track group growth and unlock features as your group grows.
  • • To respond to bug reports and support requests you submit.

NodeSkela may also use the data it collects for advertising, analytics, product improvement, and other business purposes. We may share aggregated or de-identified data with partners or service providers.

Security Measures

  • • PIN-based authentication — your 4-digit PIN is required on every login.
  • • Session tokens — each login generates a new session token, invalidating previous sessions.
  • • Login notifications — you receive an email when your account is accessed.
  • • Group access keys — chat access requires a shared key set by your group creator. Treat this key as a convenience, not a security boundary: anyone who has it can enter the group until the creator regenerates it.
  • • Invite link expiration — invite links expire after 15 minutes if unused.
  • • Admin-only access — sensitive operations require admin privileges.

Email Communications

  • • Login notifications — you receive an email when your account is accessed.
  • • Mention notifications — when another member @mentions you in chat, we email you. You can turn this off in your Profile (mention email opt-out).
  • • Re-engagement reminders — inactive members may receive automated nudge emails.
  • • Bug report replies — only if you request a response.

Who Can See Your Data

  • • Group members see your display name, email, profile, thoughts, and messages within your shared group.
  • • Group creators can manage membership, reset member PINs/display names, and write private notes about members.
  • • Platform operators (admins) have administrative access to groups, messages, profiles, and private notes, including the ability to enter any group for support and moderation.
  • • Private notes written about you are visible only to the creator who wrote them and to platform operators — not to you or other members.

Third-Party Services

We use a third-party email provider (Resend) to send transactional emails. Your email address and the content of those messages are shared with Resend solely for delivery. We do not sell or rent your personal data to any third party.

Data Retention

Your data is retained while your account is active. If you leave a group or are removed for inactivity, your messages, private notes written about you, invite history, and profile data may be retained for a grace period to preserve group context. You can request full deletion of your account and associated data by contacting us at privacy@nodeskela.com.

Your Rights

  • • Access the personal data we hold about you.
  • • Request correction of inaccurate information.
  • • Request deletion of your account and data.
  • • Opt out of non-essential email notifications.

Cookies

NodeSkela uses essential session storage to maintain your login state. We do not use tracking cookies or third-party advertising cookies.

Children's Privacy

NodeSkela is not intended for users under 13 years old. We do not knowingly collect information from children. If you believe a child has provided us with information, please contact us.

Contact

Questions about privacy? Email privacy@nodeskela.com.