Privacy Policy
Last Updated: August 30, 2026
1. Overview & Commitment
Nod First ("we", "our", "us") respects your privacy and is committed to protecting the personal data of seniors and family caregiving members. Nod First is designed with a privacy-first, self-hosted architecture.
2. Information We Collect
- Account & Auth Information: Email addresses and login credentials managed via Better Auth in our app.
- Household & Caregiving Data: Task descriptions, schedules, medication reminders, and family approval logs created within your household workspace.
- Technical & Session Data: IP address and essential session identifiers required for secure operation.
3. AI Processing
When local AI is configured, plain-language requests submitted to the Nod First task composer are parsed using a self-hosted local Large Language Model (Ollama). Your prompt inputs, task descriptions, and senior care details are not sold, shared, or sent to public AI training datasets.
When hosted AI is enabled and you allow it, your typed or spoken request and your household's place labels and place types are sent to Anthropic Claude through Router for task extraction. Anthropic and Router do not use these requests to train the model.
4. Third-Party Sharing
We do not sell, rent, or trade personal or senior care data to third-party advertisers or data brokers. Data is stored solely on your configured server/database instance.
5. Do Not Sell or Share Your Personal Information
We do not sell personal information, and we do not share personal information for cross-context behavioral advertising. Nod First runs no advertising or ad-tracking technology, so there is currently no "sale" or "sharing" of your information for us to opt you out of under laws like the CCPA/CPRA.
6. Data Security & Breach Notification
We take reasonable technical and organizational measures to protect your information, consistent with Nod First's self-hosted architecture. No system is completely secure. In the event of a data breach affecting your personal information, we will notify affected users and any applicable regulators as required by law.
7. Your Privacy Rights (GDPR & CCPA)
Depending on your jurisdiction, you have rights to inspect, export, modify, or permanently delete your account and household care logs. Account deletion is available immediately inside the app, as described in the next section. For any other request, contact hello@nodfirst.com. We aim to respond to verifiable requests within 45 days, consistent with CCPA timelines.
8. Account Deletion and Data Retention
You can delete your account at any time from inside the app, under Account settings → Delete account on the web or Household → Delete account on mobile. Instructions are also published at nodfirst.com/delete-account.
Deleting your account permanently removes your email address, your name, your sign-in credentials, and every push notification token registered to your devices. Deletion is immediate and permanent: there is no grace period, and deleted accounts cannot be restored.
Tasks, recurring reminders, and activity history belong to a household rather than to one person, so what happens to them depends on who remains:
- If other members remain in the household, those shared records are kept so the remaining members do not lose their history, and a single entry noting your departure is added to the activity log.
- If you are the last member, the household is deleted along with every task, recurring reminder, and activity entry belonging to it.
9. The agency demo and pilot pages
The agency demo. If a home care agency or care management practice asks for a demo, we create a demo workspace with made-up clients and made-up family members. Nothing in it is a real person. The demo is opened by a link that sets one cookie in your browser, marked HttpOnly, which only tells our server which demo is yours; it is not used for advertising or tracking across sites. A demo lasts 14 days by default (never more than 60) and is then closed. While it runs we record which screens were opened and when, so the person who made it for you can see whether it was useful; those counts are deleted with the demo. Please don't type a real client's name or details into a demo; if you do, write to hello@nodfirst.com and we'll delete the demo the same day.
“See it with your firm's name on it” (/agency/try). To make a demo yourself we ask for a work email address and your firm's name, and optionally your name. We keep them so we can send you the link and, if you later start a pilot, know which demo you came from. We refuse throwaway email domains. We may send one reminder before the demo closes; we don't add you to a newsletter, and we don't sell or share the address.
Starting a pilot (/agency/pilot/start). When you accept the pilot terms we record your name, your firm, your email, the number of seats, the date and time, the exact words you accepted, and the network address (IP) and browser your request came from. That record is how both of us can show later what was agreed and when. It is kept for as long as your firm has an account with us, or, if the pilot never starts, for 12 months.
Texts to a phone during a demo. In a live demo an agency owner can ask us to send one example text to their own phone, so they can see what a family member would see. We send it through Twilio, one text per demo per hour, to the number typed in, and keep the number only long enough to send it. The text carries made-up client details only.
Sections 9 to 11 added August 30, 2026.
10. Services we use to run the product
We use a small number of outside services to deliver the product. Each one receives only what it needs to do its job, and none of them receives a client's care record.
- Twilio sends text messages (the family request links, the demo text above) and, when the phone line is switched on, answers calls to our number. Twilio receives the phone number and the message text. Calls are not recorded unless the greeting says so, and in California we say so before anything is recorded.
- Resend sends our transactional email (email verification, password resets, demo links, pilot confirmations, the record you export). Resend receives the email address and the message.
- Sentry is our error reporting service. It is switched off until we configure it; when it is on, it receives the technical details of an error (the page, the browser, the stack trace) and never the contents of a care record. We'll update this section on the day it's switched on.
- Our servers are our own; the language model that reads a care note runs on infrastructure we control, as section 3 says.
11. Agencies and practices
An agency or practice on a pilot or a paid plan owns its records. At any time, and at the end of a pilot whichever way it decides, the practice can ask for a full export of every client, task, request, approval and note as a file it can open without us, and for deletion of everything it entered. We deliver the export within 7 days of the request and delete the records within 7 days after that, then confirm in writing. Encrypted backups age out on their normal schedule, no later than 30 days later, and are not restored except to recover from a failure. Demo workspaces are deleted when they close.
12. International Users
Nod First is currently intended for users located in the United States. If you access the Service from outside the United States, including the European Union or United Kingdom, please be aware that your information will be processed in the United States, and Nod First does not yet offer the full set of protections required under regimes like the GDPR.
13. Contact Information
For privacy inquiries or data protection concerns, contact us at: hello@nodfirst.com.