Trust

Privacy, traced from the product inward.

Nodefall works without an account. When you choose sign-in, Pro billing, cloud saving, or feedback, this notice explains what changes and who receives the data.

The data controller for Nodefall is Scott Santinho, an independent operator based in France. Privacy requests can be sent through the contact form at scottsantinho.com.

You can open the editor and create diagrams without signing in. Working GraphDocs, preferences, onboarding state, theme choices, and up to 20 named local snapshots are stored in your browser’s local storage. Nodefall does not upload those diagram bodies merely because you edit them.

Local data remains on that browser profile until you delete the design, clear the relevant browser storage, or use browser controls that remove site data. Private-browsing and device policies may erase it sooner.

Current share links and iframe embeds place a compressed, self-contained GraphDoc in the URL fragment. Browsers do not send that fragment in the normal request to Nodefall’s web server, but anyone who receives the full link can decode and view the diagram. Embeds may be configured as a freely pannable canvas or a guided walkthrough.

Treat a share link like the document itself: do not put secrets, credentials, personal data, or confidential architecture into it unless every recipient is authorized. A recipient, browser extension, screenshot, or downstream site can copy it; Nodefall cannot revoke a self-contained link.

Signing in is optional and is presented as a way to save work. Firebase Authentication handles Google, GitHub, and passwordless email-link sign-in. Depending on the method you choose, Nodefall and the provider process an account identifier, email address, display name, avatar, authentication provider, session information, IP address, and browser or user-agent information.

Google and GitHub also apply their own privacy terms when you choose their sign-in buttons. Firebase documents that Authentication processing is currently US-based; see the Firebase privacy and security information.

If you choose Pro, Nodefall sends Stripe the signed-in account’s email address, Firebase user identifier, selected plan, and return URL needed to create and reconcile Checkout. Stripe and Link process customer, subscription, invoice, payment, tax, fraud-prevention, and transaction-support data. Nodefall never receives or stores your complete card number.

Link acts as merchant of record for Managed Payments purchases. Nodefall stores a server-owned entitlement containing Stripe customer, subscription, price, status, period, and event identifiers so product access can follow the authoritative subscription state. Processed webhook identifiers are retained to reject duplicate or out-of-order billing events. Stripe and Link also apply their own privacy terms to transaction data.

When a Pro user saves a design to the cloud, Firestore stores user-scoped metadata and Cloud Storage stores the GraphDoc body. Security rules require the authenticated user identifier for reads and writes; App Check adds an application-integrity signal. The configured database and graph bucket are in the Paris Google Cloud region (europe-west9).

Cloud saving is an explicit choice. Nodefall does not inspect live cloud accounts, import credentials, or discover infrastructure behind the scenes. Diagram content is whatever you type, paste, import, or draw.

The Request-a-feature form stores the email address you enter, your free-text request, optional signed-in user identifier, current product context, submission time, and browser user-agent. It is used to read, triage, and respond to the request. Do not include sensitive personal data in free-text feedback.

Nodefall uses Vercel Web Analytics and Speed Insights to understand page use and performance. Vercel describes these products as anonymous and cookie-free: measurements can include the route or URL, referrer, time, coarse country or region, browser, operating system, device type, network details, Core Web Vitals, and related performance selectors. Nodefall does not receive a profile of an identified visitor from these tools.

Vercel explains the visitor-hash and reporting behavior in its Web Analytics privacy notice and Speed Insights privacy notice. Nodefall does not use advertising trackers or sell personal data.

  • Provide the service and your requested account features: perform the contract or take steps you request, including authentication, cloud saving, exports, and deletion.
  • Provide and reconcile Pro: create Checkout, manage recurring access, prevent duplicate fulfillment, handle cancellation, and keep product entitlement aligned with Stripe.
  • Keep Nodefall secure and reliable: legitimate interests in abuse prevention, application integrity, debugging, aggregate performance, and service maintenance.
  • Handle feedback: respond to the request you voluntarily submit and improve the product based on legitimate interests.
  • Meet legal obligations: retain or disclose limited records when applicable law, a valid legal request, or the establishment or defense of legal claims requires it.

Data is available only to the operator and service providers needed for the selected feature: Vercel for hosting and anonymous measurements; Google Firebase and Google Cloud for authentication, App Check, Firestore, and Storage; Google or GitHub when you select their OAuth sign-in; and Stripe and Link when you purchase or manage Pro. A share-link recipient receives the diagram you send them.

Some provider processing occurs outside the European Economic Area, including Firebase Authentication in the United States. The providers’ linked privacy documentation describes their applicable transfer safeguards. Nodefall does not sell data or share it with data brokers or advertisers.

  • Local drafts and preferences: until you remove them or the browser clears site storage; local version history is capped at 20 snapshots per mode.
  • Current cloud designs: until you delete a design or delete the account. The account-deletion flow removes the cloud library before deleting the Firebase user.
  • Older cloud object versions: overwritten or deleted GraphDoc bodies are automatically removed 30 days after becoming noncurrent.
  • Authentication records: according to Firebase’s documented service-retention and backup periods after account deletion.
  • Billing and entitlement records: Stripe and Link retain transaction records under their policies and legal obligations. Nodefall keeps the minimum subscription and processed-event identifiers needed for access control, accounting, disputes, and webhook integrity; account deletion cancels renewal but does not erase records that must be retained.
  • Feedback records: no automatic expiry is currently configured; they are kept while needed for product triage, support, abuse prevention, and record integrity, subject to periodic deletion review or a valid erasure request.
  • Anonymous measurements: according to the active Vercel plan’s reporting window; Vercel says its Web Analytics visitor hash is discarded after 24 hours.

Nodefall uses HTTPS, provider encryption in transit and at rest, user-scoped Firebase rules, and App Check application-integrity signals. Authentication and owner/Pro security rules remain the access boundary while App Check enforcement is monitored before activation. No online service can promise absolute security. Exported files and self-contained links leave Nodefall’s controls once you save or send them.

Depending on your circumstances and applicable law, you may ask to access, correct, erase, restrict, or receive a portable copy of personal data, and object to processing based on legitimate interests. Where processing relies on consent, you may withdraw it without affecting earlier lawful processing. Nodefall does not make decisions about you solely through automated processing with legal or similarly significant effects.

Send a request through the operator’s contact form. You may also complain to the French supervisory authority, the CNIL. The CNIL explains these rights in its individual-rights guidance.

Material changes will be reflected by updating the date at the top of this page and, when appropriate, by adding a more prominent product notice. Nodefall is not directed at children; a parent or guardian should contact the operator if they believe a child supplied personal data.

Questions, requests, and deletion help can be sent through scottsantinho.com/#contact.