Privacy Policy
Last updated 25 August 2026
We are a small team and this is written to be read, not to be survived. In short: we hold your data to run the product for you, we do not sell it, we do not track you across the web, and we use no advertising or analytics cookies at all.
Who we are
Nucle.OS is operated by No-Code District. In this document “we” means us, and “you” means the person or organisation using the product.
For general enquiries, and for any request described in this policy, contact hello@nucleos.app.
Two different relationships
This distinction matters, because your rights differ between them.
When you use Nucle.OS yourself — your name, email, sign-in activity — we are the controller. This policy governs that data.
When you put your own clients’ details into Nucle.OS — their names, emails, phone numbers, the work you do for them — you are the controller and we are your processor. We only act on your instructions. Those terms are in our Data Processing Agreement.
What we collect
Account data. Your name, email address, and — if you sign in with Google or LinkedIn — the basic profile they return. Optionally a profile photo, timezone and display preferences.
Workspace content. Everything you create: clients, contacts, deals, projects, tasks, time entries, invoices, documents, notes, messages and files. This is your data. We do not mine it, and we do not use it to train anything.
Connected accounts. If you connect Google for email or calendar, we store an encrypted access token and sync the messages and events you have authorised. You can disconnect at any time, which deletes the token.
Security and operational records. Sign-in events, failed sign-in attempts and lockouts (to protect your account), and an audit log of significant actions within a workspace. Our hosting providers keep short-lived server logs that may include IP addresses.
We do not collect special category data, we do not run advertising, and we do not build profiles of you.
Why we use it, and our lawful basis
To provide the product — performance of our contract with you. This covers your account, your workspace content, and the features you switch on.
To keep accounts secure — legitimate interests. Rate limiting, lockouts and audit logging exist to stop other people getting into your workspace.
To contact you about the service — legitimate interests for operational messages (a security notice, a change to these terms). Consent for anything promotional, which you can withdraw at any time.
To meet legal obligations — for example retaining financial records where the law requires it.
Cookies
We use a small number of cookies, and every one of them is strictly necessary for the product to function:
- Session cookies — keep you signed in. Without these you would be logged out on every click.
- Share-link cookies — remember that you entered the password for a specific shared document. Scoped to that one link and expire after an hour.
- Redirect cookie — returns you to the page you were heading for after you sign in.
There are no analytics, advertising or tracking cookies. We do not use Google Analytics or any equivalent. Our fonts are served from our own domain, so loading a page does not tell a font provider your IP address.
Because all of our cookies are strictly necessary, we are not required to ask for consent, and we would rather not show you a banner that serves no purpose.
Who else touches your data
We use a small number of providers to run the service. Each receives only what it needs, and none of them may use your data for their own purposes.
- Supabase — database, authentication and file storage. Hosted in the EU.
- Vercel — application hosting. Requests are currently served from the United States.
- Resend — sends email on your behalf and on ours.
- Daily.co — video meetings and recordings, if you use them.
- Google — only if you connect a Google account for email or calendar.
- Apollo.io — only if you use the prospecting feature, which looks up business contact details.
- Giphy — only if you use the GIF picker in chat.
- AI providers — only if your workspace configures its own API key. In that case your prompts go to the provider you chose, under your account with them.
We will never sell your data, and we do not share it with advertisers. If we are ever legally compelled to disclose something, we will tell you unless we are prohibited from doing so.
Where your data goes
Your database and files are held in the European Union. However, the application itself is currently served from the United States, and some of the providers above operate there too. Where personal data leaves the UK or EEA, those transfers rely on the UK International Data Transfer Addendum and the EU Standard Contractual Clauses.
If EU-only or UK-only processing is a requirement for you, tell us before you sign up — we would rather have that conversation early than discover it later.
How long we keep it
Your workspace content is kept for as long as your workspace exists. Items you delete go to Trash and are permanently removed after 15 days.
If you delete your workspace, the content is removed immediately and irreversibly, including the associated files. There is no hidden copy — but there is also no undo, so export anything you want first.
Backups taken by our database provider may persist for a short period after deletion before rotating out.
Your rights
Under UK and EU data protection law you can ask us to give you a copy of your data, correct it, delete it, restrict what we do with it, object to processing based on legitimate interests, or provide it in a portable format.
You can export the main record types yourself from Settings → Export. If you want something the export does not yet cover, email us and we will get it for you — we are not going to make leaving difficult.
If you are unhappy with how we have handled your data you can complain to the Information Commissioner’s Office at ico.org.uk. We would appreciate the chance to put it right first.
Security
Every table in our database enforces row-level security, so one workspace cannot read another’s records even if the application layer were bypassed. Credentials for connected accounts are encrypted before storage. Access to production is limited to people who need it.
We are not currently SOC 2 or ISO 27001 certified, and we are not going to imply otherwise. If you need a formal audit before you can adopt a tool, ask us and we will tell you plainly where we are.
Children
Nucle.OS is a business tool and is not intended for anyone under 16. We do not knowingly collect data from children.
Changes
If we make a material change we will email account holders and update the date at the top of this page. We will not change it quietly.