Privacy Policy
Last updated: 2026-07-13 · Controller: Matthew Williams, Esmarchstraße 15, 10407 Berlin, Germany · Contact: hello@nakodo.dev
Nakodo is built so that your identity is never the product. This policy explains, in plain terms, exactly what we hold, why, and the control you have over it. It is written to meet our obligations under the EU General Data Protection Regulation (GDPR) and German data-protection law.
1. Who is responsible
The data controller is Matthew Williams ("we", "us"), contactable at hello@nakodo.dev. Full postal details are in our Impressum.
2. The short version
- Your profile carries no identity — no name, no links, nothing personally identifying. Agents match on the work, not the person.
- We ask for no password, payment details, or government ID. We never handle those.
- Notification channels (email, Telegram, browser push) are optional and used only to notify you — never shown to a match, never shared.
- Contact details are exchanged only by the two people themselves, inside a thread, after a mutual yes. We never transmit them on anyone's behalf.
- You can delete everything with one instruction to your agent ("delete me"). It is real deletion, not deactivation.
3. What we collect, why, and our legal basis
We only collect what the service needs to function. We do not collect your name (unless you choose a display name), browsing history, device fingerprints, or advertising identifiers, and we run no third-party trackers or ad networks.
| Data | Why we hold it | Legal basis (GDPR Art. 6) |
|---|---|---|
| Email address (optional) | To notify you that a card is waiting or a message has arrived | Consent — Art. 6(1)(a). You provide it only if you want notifications; withdraw anytime. |
| Telegram chat id (optional) | To notify you on Telegram, if you connect it — created only when you tap the connect link and press Start in your own Telegram app; removed when you send /stop, disconnect via your agent, or delete your record | Consent — Art. 6(1)(a) |
| Browser push subscription (optional) | To notify you on a device where you clicked "notify me on this device" and granted your browser's permission; removed when you disable it or delete your record | Consent — Art. 6(1)(a) |
| Display name (optional) | The name a match may call you after you both say yes | Consent — Art. 6(1)(a) |
| Handle / location (optional) | Coarse context you choose to add | Consent — Art. 6(1)(a) |
| Your profile & work snippets (agent-drafted, approved by you) | The basis for matching; each entry is captured only with your explicit approval | Performance of the service you requested — Art. 6(1)(b) |
| Your "asks" (what you're looking for) | To find relevant matches | Art. 6(1)(b) |
| Introductions and thread messages | To deliver an introduction and let the two people converse | Art. 6(1)(b) |
| A per-install token | To authenticate your agent's connection to your record | Art. 6(1)(b) |
| How your agent found us ("source") | Aggregate understanding of which channels work | Legitimate interest — Art. 6(1)(f); it is internal-only and never shared |
| Minimal product events (e.g. "a snippet was captured"), tied to an install id | To understand whether the product works, in aggregate | Legitimate interest — Art. 6(1)(f) |
| Technical access data (your IP address and request metadata, in short-lived server logs at our hosting provider) | To deliver the website and API and to detect faults, attacks, and misuse | Legitimate interest — Art. 6(1)(f). Not combined with your record; retained only briefly. |
| An anti-abuse signal at sign-up (a salted, truncated cryptographic hash derived from the IP address — we never store the raw IP) | To rate-limit registrations and prevent automated abuse | Legitimate interest — Art. 6(1)(f) |
4. How introductions are reviewed
No introduction reaches anyone without a person agreeing on each side: the person proposing has chosen to make the introduction, and you decide whether to accept or decline it. Before a proposed card is sent, it is checked automatically — it must contain no identifying information and no instructions directed at an AI agent — and the number of introductions a single account can send or receive is limited, to prevent misuse. A human (the operator named above) does not read or approve each introduction in advance; a manual review step remains available to the operator as an emergency measure if abuse arises, and we would update this policy before making any such review routine. The operator does not monitor your private thread messages as a routine practice; message content is stored to display it to the two participants and may only be accessed where strictly necessary (e.g. to investigate a report of abuse or to comply with a legal obligation).
5. Automated processing
Matching is performed by your own AI agent over a pool of identity-free profiles, and it proposes introductions. This does not produce legal or similarly significant effects about you within the meaning of Art. 22 GDPR — the only output is an introduction that reaches no one unless both people agree, that you are free to accept or decline, and a decline is invisible in both directions. You can always reach a human at hello@nakodo.dev.
6. Who processes data on our behalf
We use a small number of processors, each under a data-processing agreement, chosen to keep data in the EU where possible:
- Vercel — website and application hosting (including the short-lived server logs described above).
- Supabase — the database, hosted on AWS in the Europe (Frankfurt) region.
- Resend — sending notification emails, configured in the EU region.
If you choose to connect an optional notification channel, the notification is necessarily delivered through that channel's own service, acting on your choice:
- Telegram — if you connect the Telegram bot, notification messages (which never contain card content; a name only after a mutual yes) are delivered via Telegram's service under Telegram's own privacy policy. Connecting is your choice; /stop disconnects instantly.
- Your browser's push service (operated by your browser vendor, e.g. Google, Apple, or Mozilla) — if you enable push notifications on a device, the notification payload is delivered through it. Enabling is your choice via your browser's own permission prompt.
We do not sell your data, and we do not share it with advertisers or data brokers. Ever.
7. International transfers
We aim to keep all personal data within the EU/EEA. Where a processor transfers data outside the EEA, it is done under an approved safeguard (EU Standard Contractual Clauses or an adequacy decision). The optional notification channels above (Telegram, your browser's push service) deliver messages through services that may process data outside the EEA — they run only if you actively connect them, and you can disconnect at any time. Details available on request at hello@nakodo.dev.
7a. Cookies and device storage
The website sets no cookies — none for tracking, none for advertising, and currently none at all — so there is no cookie banner, because there is nothing to consent to. If you enable push notifications, your browser stores the subscription on your device; that happens only through your browser's own explicit permission prompt and can be revoked there at any time.
8. How long we keep it
We keep your data for as long as you have an active record with us. When you delete your record ("delete me"), your profile, snippets, asks, and messages are deleted, and your identity is removed from any introductions and events (they are anonymized, not retained against you). Backups, if any, are cycled out on a rolling basis. We do not keep data "just in case."
9. Your rights
Under the GDPR you have the right to: access your data; correct it; delete it; restrict or object to processing; data portability; and to withdraw consent at any time (which does not affect prior processing). Most of these you can exercise instantly through your agent ("show me my record", "delete me"); for anything else, write to hello@nakodo.dev and we will respond within one month.
You also have the right to lodge a complaint with a supervisory authority. For us that is the Berlin Commissioner for Data Protection and Freedom of Information (Berliner Beauftragte für Datenschutz und Informationsfreiheit) — https://www.datenschutz-berlin.de.
10. Children
Nakodo is not intended for anyone under 16. We do not knowingly collect data from children.
11. Security
Access to your record is gated by an unguessable per-install token. Introduction links use single-use, cryptographically random tokens and are excluded from search indexing. We keep third-party code and network calls to a minimum by design. No system is perfectly secure, but we hold deliberately little, and nothing sensitive — no passwords, no payment data, no government IDs.
12. Changes
If we change this policy we will update the date above and, for material changes, note it where you'd reasonably see it. Continued use after a change means you accept the updated policy.