Legal · Nodus Nexo
Nodus Nexo Privacy Policy
Effective 1 October 2026. Updated the same day: AI credits and the nodus.redtailden.com site.
On this page
- In short
- 01 — Who is responsible
- 02 — What stays on your phone
- 03 — Your account
- 04 — The AI features: what leaves and where it goes
- 05 — The vault (iPhone)
- 06 — Other services involved
- 07 — Your API keys
- 08 — Logs and security
- 09 — How long each thing is kept
- 10 — What you can do
- 11 — International transfers
- 12 — Children
- 13 — Changes
- 14 — Contact
This policy explains what data Nodus Nexo —the app for iPhone and for Android— the Nodus server it talks to, api.nodus.redtailden.com (which also answers as api.bitacora.redtailden.com), and the nodus.redtailden.com website handle: what stays on your phone, what leaves it, where it goes, what for, and how long it is kept. It is written from what the app's and the server's code actually do.
This is the Nodus part of Red Tail Den LLC's privacy policy. What is common to all its products —who we are, how to request deletion, your rights— is in the general policy; here goes what is true only of Nodus, and where the two say different things about Nodus, this one applies.
In short
- Your journal is stored on your phone. Memories, photos, files, dictations and recordings live inside the app.
- The app works without an account. Saving, reading the text in photos, searching and backups live on your phone.
- Your account, if you create one, lives on our server: first name, last name, email and a hash of your password.
- Nodus is free without AI. The paid Nodus plan adds the AI features and the vault. Apple, Google or Stripe charge for it; we never see your card.
- The vault is optional and, for now, only exists on iPhone. If you turn it on, your phone encrypts a copy of your journal before sending it, with a key that never passes through our server. We store that copy without being able to read it. What we do see is how many objects there are, how big each one is and when it changes.
- The AI features send content to other companies. Interpreting what you save, Ask, dictation, and transcribing meetings and videos send what is needed, through our server, to Anthropic, Groq or Supadata, with your own key or, on the Nodus plan, with the server's keys, paid for with credits. That content is not encrypted by the vault: our server and the provider see it in order to process it. Our server does not keep it, except video transcripts (30 days).
- There is no advertising, no tracking across apps or websites, and we do not sell data.
01
Who is responsible
Nodus Nexo belongs to Red Tail Den LLC, doing business as Evo Creative Studio. It is made by Eduardo Carrasco. In this policy, "we" means them.
The Nodus server runs on a Hetzner machine in Ashburn, Virginia, United States, and we operate it.
For any question or request about your data: info@redtailden.com, with the subject "Privacy request". It is the same address for every Red Tail Den LLC product.
If you also use Nodus Eco, the desktop app for Mac, with the same account, whatever Eco uploads to your vault gets the same treatment on the server as described here.
02
What stays on your phone
- Your whole journal: titles, summaries, text, categories, people, organisations, amounts, dates and the links between memories; also your dictations, your contexts and your meetings.
- The photos and files you attach, and the audio of your meetings.
- The text read from your photos. Text recognition happens on the phone.
- Your searches in the Library, with one exception explained in section 4.
- Your API keys (Anthropic, Groq, Supadata): on iPhone, in the system keychain; on Android, encrypted with a key from the phone's keystore.
- Automatic local backups: one copy per day, covering the last 30 days. They include memories you have already deleted, until that copy expires.
On iPhone, the database is protected by iOS file encryption and kept out of the iCloud backup. If you turn on Settings → Backup → "Include in the iCloud backup", it becomes part of your iPhone's iCloud backup, which Apple manages and we have no access to. On Android, the app does not take part in system backups.
Exporting is your choice. On iPhone, Settings → Backup produces a file encrypted with a password you choose, and Settings → Your data produces an unencrypted JSON. What you do with that file is outside our reach.
03
Your account
The app works without an account: saving, reading the text in photos, searching, the Library and backups live on your phone. An account is needed for what goes through our server: the AI features, the vault and the Nodus plan.
- What we keep: your first name, your last name, your email and a bcrypt hash of your password. The password itself is not stored. We keep your first name on the server so that, when you sign in on another device, the app still greets you the same way.
- Your sessions: for each sign-in we keep a fingerprint of the token (not the token) and its dates. A session expires after 60 days or when you sign out.
- Who sees it: we do. The admin panel shows, for each account, the name, the email, the sign-up date, the open sessions and the month's spending on the server's keys. It shows none of your content.
Sign-up is open: anyone can create an account.
The Nodus plan and payments.
- What it is. Nodus is free without AI. The Nodus plan, a monthly or yearly subscription, adds the AI features and the vault.
- Who charges. If you subscribe from the iPhone, Apple charges (App Store); from Android, Google (Google Play); on our website, Stripe. We never see or store your card details.
- What we receive. From whoever charges, only what we need to know whether your plan is active: the product, the purchase, renewal and expiry dates, whether it will renew, whether there was a refund, whether it was a test purchase, and the purchase identifier. The purchase is linked to your account with an internal identifier that doesn't contain your email.
- Refunds. Handled by whoever charged: Apple or Google, on their own pages; if it was on our website, write to us.
- Credits. On the Nodus plan, AI that doesn't run on your own key is paid for with credits: one credit is one US cent of what it actually costs. We keep your credit ledger: every purchase (how many, through which store and the purchase identifier), every use (the date, the kind of action —photo, note, question, dictation, video— and what it cost, without the content) and every refund. It is used to show you your balance and history. If a purchase is refunded, its credits are deducted.
04
The AI features: what leaves and where it goes
Some features need an AI model or a transcription service. When you use them, your phone sends the content needed to our server over an encrypted connection (HTTPS); the server passes it to the provider and returns the result to you. This content is not encrypted by the vault: our server and the provider read it in order to process it.
Whose key. If you entered your own Anthropic, Groq or Supadata key, that key is used and you pay the provider directly. If not, and you have the Nodus plan, the server uses its own keys and deducts the actual cost of each call from your credits: before calling it reserves the estimate, and it never charges more than that. A few invited accounts, chosen by hand, use the server's keys without credits. With no key of your own and no plan or no credits, the server calls no provider and the app tells you so.
| Feature | What leaves your phone | Who receives it | When |
|---|---|---|---|
| Interpreting what you save | The images (photos and screenshots), the text recognised in them and the text of what you save (notes, web pages, files, imported WhatsApp chats). If you add photos to a memory, also its title, summary and facts | Anthropic | When you save, or later if there was no connection, and only if you said yes: the first time something would be interpreted, the app asks you, and until then nothing is sent. You can change your answer in Settings → AI and keys |
| Filling in the other language | The text, and your own images, of memories you already saved that have their summary in only one language | Anthropic | In the background, a few at a time, with vision AI on and "Complete them on their own, a few at a time" turned on in Settings (if you pay for AI with credits, it starts off). Or when you ask for it with the button |
| Interpreting dictations, meetings and video transcripts | The transcribed text | Anthropic | When you save them, even with vision AI off |
| Ask | Your question; short cards for the candidate memories (title, category, a short summary, tags —including people— and date); then up to three full memories (title, summary, text, facts and your note) | Anthropic | Every time you ask |
| Searching the Library (iPhone) | The term you type, from three letters on | Anthropic | Only if some memory has its summary in only one language: the term is translated once so that memory can be found |
| Dictation (iPhone) | The audio of the dictation | Groq, which transcribes it | When you stop dictating |
| Meetings (iPhone) | The meeting audio, in pieces. With the copilot: the meeting notes, the latest sentences, your first name and the contexts you pick (your text and your documents' text) | Groq (audio) and Anthropic (notes and questions) | While you record, if you have a Groq key; otherwise, when the meeting ends |
| Transcribing a video | The video link | YouTube (our server asks it for published captions) and Supadata | When you save a video link, if you have a Supadata key |
What our server keeps from all this:
- Not the content. No images, audio, text or questions. Audio is processed in memory and never written to disk.
- The result, for three minutes. A copy of the result of interpreting or answering stays in the server's memory for three minutes, so that a retry from your phone is not charged twice.
- Video transcripts, for 30 days. The transcribed text is kept for up to 30 days after it finishes, so your phone can collect it even if it switches off midway and so the same video is not paid for twice. The video link, the job status and, if it failed, the failure detail are kept for as long as you have an account.
- The spending record, without content. For each call we record the date, the tokens in and out, the cost, the model, whether it used your key and which app it came from (iPhone or Android). It is used for the spending caps on the server's keys, to charge credits and to know what each feature costs.
- The application's technical log records, without your name or email, the cost of each call, whether it used your key and, when interpreting, the kind of document the model thought it saw (for example, "receipt") and the names of the fields it discarded.
What happens on the provider's side is governed by its own terms and retention policy, not by this code: Anthropic, Groq and Supadata. Interpreting a photo means asking a model to look at it, so the photo leaves your phone; there is no way around that while the feature is on.
05
The vault (iPhone)
The vault is for having your journal on more than one device. It ships turned off: you turn it on in Settings → Vault. The Android app does not have it yet.
What goes up. Your memories (title, summary, text, tags, people, organisations, amounts, facts, link, note and attachment file names), your dictations (the text) and your contexts (their text and their documents' text). The photos and files attached to your memories also go up, encrypted the same way and with the same key; the other device does not download them all at once, but each one when you open the memory it belongs to. When you delete a memory, its attachments are also deleted from the server on that device's next sync. Sync runs on its own when you open the app (at most every five minutes) and when you tap "Sync now".
How it is encrypted. Your phone creates a random 32-byte key and encrypts every object with it (AES-256-GCM) before sending it. That key never passes through our server — not when it is created, not when you sign in on another device, not to recover it.
The twelve words. When you turn the vault on, the app shows you a twelve-word phrase. It is not stored anywhere: not on the phone, not on the server. With it, the app seals your key in an encrypted "envelope", and that envelope is stored on our server, attached to your account, so your other device can download it. The envelope is opened on the device, with the twelve words; without them it is useless.
iCloud Keychain. When you turn the vault on you can choose to also keep the key (not the phrase) in iCloud Keychain; the option comes ticked. If you leave it, Apple carries the key to your other devices with iCloud Keychain's end-to-end encryption, and our server still never sees it. That adds a second path to the key, which is Apple's and is protected by your devices' passcodes. If you want the phrase to be the only path, untick it.
No phrase, no recovery. If you lose the twelve words and every device that holds the key, whatever is on the server stays encrypted forever. We cannot open it or help you open it.
What our server does see of the vault: which account each object belongs to, how many there are, how big each one is, when each was uploaded or changed, and the random identifier your device gave it. Because attachments are downloaded one by one when needed, it can also tell which objects are attachments and when each one is requested. What it does not see: what any object says or shows, whether an object is a memory, a dictation or a context, or which device uploaded it.
Deleting with the vault on. If you delete a memory, your phone replaces its copy on the server with an encrypted deletion marker that has no content. "Delete the whole journal" empties only the phone: the vault is untouched, and syncing fills the phone again.
Turning the vault off deletes the key from this device, and from the others if it travelled through iCloud Keychain. It does not delete what is already on the server: it stays there, encrypted, and can be opened again with the twelve words. To delete it, delete your account or write to us.
Each account has a 512 MB cap for memories, dictations and contexts, and a separate 2 GB cap for attached photos and files.
06
Other services involved
| Who | What they receive | Why |
|---|---|---|
| Anthropic | The images, texts and questions in section 4 | It is the model that interprets and answers |
| Groq | The audio of your dictations and meetings | It transcribes it |
| Supadata | The video link | It transcribes it when there are no published captions |
| YouTube | One request for the video, from our server | To find its published captions |
| The websites of the links you save (iPhone) | A visit from your phone, which shows them your IP address like any visit | The app reads the page's title, text and cover image. For YouTube and TikTok links it queries their public preview service |
| Apple | The vault key, if you choose iCloud Keychain; your journal, if you turn on the iCloud backup; distribution through the App Store and TestFlight; and charging for the Nodus plan, if you subscribe from the iPhone | Under Apple's policy |
| On Android, technical data from ML Kit (see below); if you install the app from Google Play, what Google collects as a store; and charging for the Nodus plan, if you subscribe from Android | Under Google's policy | |
| Hetzner | Hosts the server | Infrastructure |
On iPhone there is no third-party SDK: no analytics, no advertising, no measurement. Text recognition uses Apple's tools, on the phone itself.
On Android, text recognition uses Google's ML Kit. It runs on the phone and does not send your photos or the recognised text, but Google collects technical data for diagnostics and usage statistics: device model and system, app version, performance metrics and a per-installation identifier.
We do not sell your data or hand it to anyone for advertising. You are not tracked across apps or websites.
07
Your API keys
- Anthropic. Stored on your phone and sent with each request; the server uses it for that call and discards it. It is not written to the database or to the logs.
- Groq (iPhone). Stored on your phone and sent with each piece of audio. It is not written to the database or to the logs.
- Supadata. Stored on your phone. Because transcribing takes minutes and the server does it on its own, your key is stored alongside that job while it runs and deleted when it finishes or fails.
08
Logs and security
- Proxy log. For each request it records your IP address, the date, the path requested, the response code and the request headers (for example, which app made it and the language). It redacts the session token and your API keys. It never records content. At most ten 20 MB files are kept; with little traffic, that can mean several months.
- Application log. Records technical data without content (costs, errors, how many items a request had). When you delete your account, it records that a deletion happened, without your email. It rotates daily and the last seven files are kept, so nothing stays in it more than about eight days.
- nodus.redtailden.com log. For each visit it records the IP address, the date, the page requested, the response code and the browser. The site uses no cookies and no tracking. At most ten 20 MB files are kept.
- Abuse limits. Failed sign-in attempts keep the email and IP address for one hour. Created accounts keep the originating IP address for 24 hours, so nobody can open accounts in a loop.
- Security. Everything travels over HTTPS. Passwords are stored with bcrypt and session tokens only as fingerprints. Vault content arrives already encrypted from your phone.
09
How long each thing is kept
| What | Where | How long |
|---|---|---|
| Your journal, attachments and recordings | Your phone | Until you delete them or remove the app |
| Automatic local backups | Your phone | 30 days |
| First name, last name, email and password hash | Server | Until you delete your account |
| Fingerprint and dates of your sessions | Server | Until you delete your account; each session expires after 60 days |
| Vault envelope and encrypted objects | Server | Until you delete your account |
| Content sent to the AI features | Server: no copy. Provider: under its terms | — |
| The result of an interpretation or an answer | Server memory | 3 minutes |
| The text of a video transcript | Server | 30 days after it finishes |
| Video link, job status and failure detail | Server | Until you delete your account |
| Your Supadata key alongside a job | Server | Until the job finishes or fails (see section 7) |
| Spending record (figures, no content) | Server | Indefinitely; if you delete your account, no longer linked to you |
| Proxy log | Server | Until the file rotates (ten 20 MB files at most) |
| Application log | Server | About eight days (rotated daily; seven files kept) |
| Failed sign-in attempts | Server | 1 hour |
| IP address of a created account | Server | 24 hours |
| Your API keys | Your phone | Until you delete them |
| Your plan's status (product, dates, purchase identifier) | Server | Until you delete your account |
| Your credit ledger (purchases, uses and refunds, without content) | Server | Until you delete your account |
| nodus.redtailden.com log | Server | Until the file rotates (at most ten 20 MB files) |
| Server backups (everything in this table that is on the server) | Hetzner | 7 days: one per day, and the last seven are kept |
10
What you can do
- Keep images and what you save from leaving. The app asks before sending anything to be interpreted for the first time: just say no. If you already said yes, Settings → AI and keys → turn off "Use cloud vision AI". That does not turn off Ask, term translation when searching, dictation, meetings or video transcription: those features only send something when you use them.
- Keep anything from reaching a provider. Do not enter API keys. Without a key, the server calls nobody (except for invited accounts).
- Take your data with you (iPhone). Settings → Backup for a complete encrypted file, or Settings → Your data for a JSON with the text.
- Delete your journal from the phone. Settings → Your data → "Delete the whole journal". With the vault on, read section 5 first.
- Delete your account (iPhone). Settings → Account → "Delete my account", with your password. The following are deleted from the server, permanently: your name, your email, your password, your sessions, your transcription jobs (links, texts and any Supadata key attached to them) and your whole vault: the envelope and every encrypted object. What remains is the spending record, no longer linked to you, and whatever was already written to the logs until those are deleted (section 8). Server backups are kept for 7 days; what you delete disappears from them as they expire.
- Delete your account (Android). Settings → Account → "Delete my account", with your password, with the same scope.
- Deleting your account doesn't cancel the subscription. If you have the Nodus plan, cancel it where you bought it: in your Apple account settings, in Google Play → Payments & subscriptions, or by writing to us if it was on the website.
- Ask by email, from any device. Write to info@redtailden.com with the subject "Privacy request" and say it is about Nodus; if you can, from your account's email address. We answer within 30 days, as for any Red Tail Den product.
- What deleting your account does not touch: what is on your phone. Your memories, your local backups, your API keys and the vault key stay there. "Delete the whole journal" empties the memories; local backups expire on their own after 30 days or disappear when you remove the app; your keys are deleted in Settings → AI and keys; the vault key, by turning the vault off. On iPhone, the system keychain may keep the keys even if you remove the app. Removing the app destroys the local database: if you want to keep it, export first.
- Empty only the vault on the server, without deleting the account. The app has no button for that today: write to us.
- Correct your name on the server. Write to us. The name you edit in Settings only changes the greeting on that phone.
Your rights. Depending on where you live —for example, in the European Union, the United Kingdom, Mexico, Brazil or California— you may have the right to access your data, correct it, delete it, take it with you, object to a use of it and complain to a data protection authority. Write to us and we will answer. You can do almost all of it yourself from the app.
Why we process your data. To provide the service you ask for: the account, the vault and the AI features you use. And out of a legitimate interest in keeping the server secure and running: the logs, the abuse limits and the spending record.
11
International transfers
Our server is in the United States. Anthropic, Groq and Supadata process data in the countries stated in their own terms. If you live outside the United States, using the server means your data travels there.
12
Children
Nodus Nexo is meant for adults and is not directed at anyone under 18, like every other Red Tail Den LLC product. We do not knowingly collect data from anyone under 18. If you believe a child has created an account, write to us and we will delete it.
13
Changes
If this policy changes, we will publish the new version at nodus.redtailden.com/en/privacy —and at redtailden.com/privacy-policy/nodus, which leads to the same page— with its effective date. If the change widens what leaves your phone, we will also say so in the app's release notes.
14
Contact
info@redtailden.com · Red Tail Den LLC, doing business as Evo Creative Studio · redtailden.com
The same policy is published at redtailden.com/privacy-policy/nodus.