Privacy Policy
What Noema knows about you, why, and what you can switch off.
The short version
Noema is built around what you tell it about yourself, so the default is restraint. Your answers, your reflections and everything you write inside an Experience stay in your account. They are never sent to an analytics vendor, never used to train a model on your behalf, and never sold. If you add an optional note about yourself in onboarding or Profile, that note is also sent to the AI model that personalises your Today ideas.
Who is responsible
Noema is operated by Hlib Serediuk, sole trader (Ukraine), acting as the data controller. For any privacy question or request — or anything else — write to noema.create@gmail.com. It is the only address we use, and it reaches a person.
What is collected
- Account data — your email address and password (stored hashed by our authentication provider), created when you sign up. Legal basis: performance of the contract.
- Your personal context — onboarding answers, the calibration derived from them, your Experiences, sessions and reflections, the reasons you give when you rate an Experience, how you like to engage with ideas, topics you want to avoid, and your delivery settings. Optional notes you write are used only to choose what Noema suggests; keep names out of them. This is the product. Legal basis: performance of the contract.
- Generation cost records — the compute cost of each Experience you generate, linked to your account, to enforce limits and measure cost.
- Product analytics — a fixed list of interaction events (for example "an onboarding step was viewed", "an Experience was completed") with an internal account identifier, the page address without its query string, browser and device details and a timestamp. The list is enforced in code: an event that is not on it is not sent. Optional product analytics is collected only with your consent. Noema does not keep these events in its own database.
- Technical logs — errors and request diagnostics needed to keep the service working and secure.
What is never collected
Analytics events carry no free text. Nothing you typed — a prompt, an answer, a reflection, a takeaway — is included in an event, and neither is your email address. The identifier attached to an event is a random guest identifier or an internal account id, rather than your name or contact details.
Cookies and similar storage
Signing in stores a session in your browser; that is strictly necessary and cannot be switched off while you are using the product. Product analytics requires your explicit permission and stays off while your choice or account permission is unknown. Nothing from PostHog is loaded before you choose Allow. After Allow, your choice is stored in your browser and PostHog's library keeps an identifier in your browser storage until you turn analytics off, which clears it. Your choice continues when you create your account. Decline and Account Off remain effective; agreeing to legal documents does not override them. You can turn analytics off from your profile.
Who your data goes to, and what they get
Noema is not one system. Five kinds of company touch data on our behalf, and each one gets a different, deliberately small part of it:
- Supabase — the database, authentication and file storage, hosted in the EU. This is where your account and your personal context actually live. It holds everything you have written in Noema.
- Cloudflare — application hosting and the generation Engine. Each Experience is generated there in an isolated environment, and the finished Experience files are stored there.
- PostHog — product analytics, hosted in the United States. After you allow analytics, your browser sends interaction events to PostHog directly. For an account that allows analytics, our server also sends one event when a payment is confirmed, with the plan tier and billing period only. PostHog discards the IP address of your device. It receives only listed events: an event name, a random guest or internal account id, the page address without its query string, browser and device details and a timestamp. No free text, no prompts, no reflections, no email address.
- Paddle — payments, as merchant of record. If you buy Plus, Paddle collects your billing details, payment method and the tax data an invoice needs. We never store your card details. We receive subscription state and minimal payment confirmations: transaction, subscription and customer references, plan, currency, captured amount and timestamps, linked to your account when available. We use these to verify purchases and measure paid activity separately from optional product analytics. Payment amounts and provider references are not sent to PostHog.
- AI model providers, reached through our gateway — to generate an Experience they receive a de-identified set of closed choices and short descriptors of your recent Experiences, never your name, email, account identifiers or text you wrote. Noema does not link this to your identity, but requests from one account can resemble each other, so a provider that keeps logs could tell they came from the same account, though not whose it is. We do not train models on your content. The AI Usage Policy sets out the detail.
Noema uses AI to create Experiences, including their text and images. AI-generated content is marked as such and may contain errors. Images made with AI are original illustrations and may carry technical markers that identify them as AI-generated.
Everyone above except Paddle acts as a processor under a data-processing agreement and may not use your data for their own purposes. Paddle acts as an independent controller for the payment itself, because it is the seller of record for the transaction. Beyond these, your data is not shared: it is not sold, not rented, not passed to advertisers or data brokers, and not disclosed to anyone else except where the law requires it or you ask us to.
How long it is kept
Account and personal-context data are kept while your account exists. Deleting your account removes them. PostHog keeps analytics events for 1 year, the retention of the plan we use. When you delete your account we ask PostHog to delete you and your events; PostHog carries this out on its side. Paddle retains billing records as required for its billing and tax obligations.
Your rights
Under the GDPR you can request access, correction, deletion, restriction, portability, and you can object to processing based on legitimate interest. Write to noema.create@gmail.com and we will respond within one month. You also have the right to complain to your local supervisory authority.
Turning analytics off
Your profile has a single switch that stops product analytics for your account. Turning it off stops your browser sending events to PostHog, clears the identifier PostHog stored in your browser, and stops us sending payment events. This applies to future collection; events already sent stay with PostHog for the period above until you delete your account.
Changes
We may update this policy as Noema changes. The date at the top shows the current version. If a change is material, we tell you before it takes effect with a notice in the app, and you keep using Noema under the updated policy without accepting it again. Where we rely on your consent, such as optional analytics, we ask again if what we do with your data changes significantly.