Legal
Privacy Policy
Version 1.1 · Last updated:
NomiPad is made and sold by FOP Artem Maliuha, trading as Invis Matters. Orders are processed by Paddle.com, our Merchant of Record.
1. Who is responsible
The controller of personal data described here is FOP Artem Maliuha, trading as Invis Matters, the maker and seller of NomiPad (“we”, “us”):
- Seller
- FOP Artem Maliuha, a sole proprietor (фізична особа-підприємець) registered in Ukraine
- Trading name
- Invis Matters
- Address
- Ukraine, 03113, Kyiv, vul. Druzhkivska 4, apt. 8
- Tax number (РНОКПП)
- 3128710556
- support@nomipad.com
For anything in this policy, including requests about your data, write to support@nomipad.com.
2. The short version
- Your files never leave your computer. We never see what you open or type.
- No telemetry, no analytics, no crash reporting in the app, and no analytics or tracking on this website.
- The free version needs no account and sends us nothing. If you buy NomiPad Pro, we keep your account (email and a hashed password), your purchase status, and the devices you signed in on.
- Payments are handled by Paddle, our Merchant of Record. We never see your card details.
- We don’t sell data, show ads or share data for advertising.
3. The NomiPad app
- Your files are read and written only on your computer. NomiPad never uploads them or any part of them.
- Settings and your session (open windows and tabs, fonts, shortcuts) are stored locally in NomiPad’s folder in your user profile. Untitled tabs that were never saved are not stored.
- Your license, after you sign in, is stored on your computer together with a sign-in token. The license is checked locally, so NomiPad works offline.
- NomiPad contains no telemetry, analytics or crash-reporting code. It does not report what you do or which files you open.
The app connects to the internet only in these cases:
-
License sign-in, refresh and sign-out, and only if you use NomiPad Pro. NomiPad talks to
nomipad.com/apiwhen you sign in (it sends your email, password, the device’s name, operating system and NomiPad version), to renew a Pro license (at start-up and then once a day while NomiPad is running, but only in the last 14 days before your license’s end date; it sends the sign-in token), and when you sign out. Like any server, ours sees your IP address when this happens. The free version never makes these requests. - Images in Markdown documents that point to a web address are loaded from that address, as a browser would. The site hosting the image sees your IP address. Local images and all other content are not affected.
- Links you click (for example “Buy” or a link in a document) open in your web browser.
4. This website
- No analytics, no advertising or tracking cookies, no tracking pixels and no third-party scripts on the public pages. Fonts are served from nomipad.com. The one exception is the checkout: see the last point below.
- Our web server keeps standard access logs (IP address, time, the page requested, the referring page, the browser’s user-agent string and the response) to run the site and protect it from abuse. They are deleted after 14 days.
-
Cookies. Only if you sign in to your NomiPad account on this site, we set two strictly necessary
cookies that keep you signed in, and nothing else:
-
np_at: a short-lived sign-in token (15 minutes, renewed automatically while you use the site); -
np_rt: keeps you signed in between visits; it changes every time it is used and expires 30 days after it was issued, or when you sign out.
nomipad.com/apiover HTTPS, can’t be read by scripts on the page (HttpOnly,Secure,SameSite=Lax), and are never shared with other sites or other nomipad.com subdomains. Because they are strictly necessary for a service you asked for, they need no consent banner. -
-
Local storage in your browser, never sent to us: your light/dark theme choice; a
“signed in” flag (
np-account) so the page header can show “Account” instead of “Sign in”; and, if you start buying NomiPad Pro before you have confirmed your email, a note of that (np-intent) so the checkout can open when you come back. That note is removed when the checkout opens, or after 3 days. -
Checkout. When you click “Buy NomiPad Pro”, and only then, the page loads Paddle’s checkout
script (
Paddle.js) fromcdn.paddle.comand opens Paddle’s checkout window frombuy.paddle.com. Paddle receives your account’s email address (so the purchase is linked to your account) and whatever you enter in the checkout, and may use its own cookies and similar technologies there, for example to prevent fraud; see Paddle’s privacy notice. “Manage subscription” takes you to Paddle’s customer portal in the same way.
5. Your account
You only need an account for NomiPad Pro. For an account we store:
- your email address, and whether and when you confirmed it;
- your password, as a one-way hash (bcrypt). We can’t read your password, and we will never ask you for it by email;
- when the account was created and last signed in to;
- website sign-in sessions: when each started and expires, the IP address and the browser’s user-agent string, so you and we can spot a sign-in that wasn’t you;
- one-time links we email you (to confirm the address or reset the password), stored hashed until used or expired;
- your plan and its status (Free or Pro; active, cancelled or ended; end date).
6. Licenses and devices
- Each time you sign in inside the app, we record an activation: the device name, operating system and NomiPad version the app reports, when it was first and last seen, the last IP address it connected from, and a hash of its sign-in token.
- We keep a log of the licenses we issue (the plan, your email, when it was issued and when it expires), because each license is signed with your email in it.
We use this to deliver and renew your license, to let you sign devices out, and to prevent license sharing and abuse.
7. Purchases (Paddle)
NomiPad Pro is sold by Paddle.com, which is the Merchant of Record for all our orders. Paddle collects and processes what is needed for the payment (name, email, billing country and postcode, payment details, tax information) as an independent controller under Paddle’s privacy notice. We never receive your full card number or other payment details.
Paddle sends us notifications about your order, which we store: the Paddle customer, subscription and transaction identifiers, the product, price, currency, amounts and tax, the status and dates, and the email address and country on the order. We use them to match the purchase to your account, give you your license, answer your questions, and keep business and tax records.
8. Email and support
- We send transactional email only: confirming your address, resetting your password, and notices about your account, license or subscription (for example, a price change before a renewal, or a change to these documents). Receipts and invoices come from Paddle. We send no marketing or newsletters.
- If you write to us, we use your address and message to reply and to help you, and keep the conversation as described in section 12.
9. Who else processes data
We use a small number of providers, each only for the purpose listed:
- Hetzner Online GmbH (Germany): hosting. Our website, API and database run on a server in Hetzner’s data centre in Helsinki, Finland (EU).
- Paddle.com (Paddle.com Market Limited, UK, and its group): Merchant of Record for orders, payments, tax, invoices and refunds (see section 7).
- Resend (Resend, Inc., USA): delivers our transactional email. It receives your email address and the message.
- Namecheap (Namecheap, Inc., USA): our domain registrar. Mail sent to support@nomipad.com is forwarded through Namecheap’s email forwarding to the operator’s mailbox.
We may also disclose data where the law requires it, or to protect our rights in a dispute. We do not sell personal data or share it for advertising.
10. Where data is stored
Our database and logs are stored in the EU (Finland). We operate NomiPad from Ukraine and access the data from there. Resend and Namecheap are in the USA, and Paddle operates worldwide. Where data leaves the EU/EEA, we rely on the European Commission’s adequacy decisions (including the EU-US Data Privacy Framework where the provider participates) or the Standard Contractual Clauses offered by the provider.
11. Why we may use it (legal bases)
For people in the EU, EEA and UK, the legal bases under the GDPR are:
- Contract (Art. 6(1)(b)): your account, licenses, activations, purchase records and transactional email, which we need to provide what you signed up for or bought;
- Legal obligation (Art. 6(1)(c)): keeping purchase records for tax and accounting;
- Legitimate interests (Art. 6(1)(f)): server access logs, session and activation records used for security, preventing fraud and license sharing, and answering messages you send us. You can object to these (section 13).
We do not use your data for automated decisions that have legal or similarly significant effects on you.
12. How long we keep it
- Web server access logs: 14 days.
- Website sessions: until you sign out or the session expires; then deleted.
- Account, plan and activation records: as long as you have the account. An activation is deleted when you sign that device out.
- Purchase records and Paddle notifications: for as long as tax and accounting law requires (at least three years after the year of the purchase), including after the account is deleted.
- Support email: up to two years after the conversation ends, unless you ask us to delete it sooner.
When you delete your account, we delete or anonymise its data within 30 days, except the purchase records we must keep. Licenses already on your computer are not affected by account deletion, but Pro can no longer be renewed.
13. Your rights
You can ask us to give you a copy of your data (access and portability), correct it, delete it, restrict its use, or object to uses based on legitimate interests. Write to support@nomipad.com from the email address on your account; we answer within one month and may ask you to confirm it’s you. These rights are free of charge. If you are in the EU, EEA or UK, you can also complain to your local data-protection authority; in Ukraine, to the Ukrainian Parliament Commissioner for Human Rights. We would appreciate the chance to fix things first.
14. Security
All traffic to nomipad.com uses HTTPS. Passwords are hashed with bcrypt; sign-in tokens and one-time links are stored only as hashes. Licenses are signed so they can’t be forged. Access to the server and database is limited to us. If a breach affecting your data happens, we will tell you and the authorities as the law requires.
15. Children
NomiPad is not directed at children. You must be old enough to enter into a contract where you live to create an account or buy a plan. We don’t knowingly collect data from children under 16; if you believe we have, write to us and we will delete it.
16. Changes and contact
If we change this policy, we update this page and the version and date at the top, and email account holders about material changes before they take effect. Questions and requests: support@nomipad.com.