Local application analysis
Visible page structure, routes, links, controls, trusted user actions, request and response details, timings, headers, textual or JSON bodies, screenshots, insights, and timeline state selected by the user.
Privacy Policy
This policy explains how NodeLume handles personal information across the NodeLume Chrome extension, nodelume.ai, support communications, and subscription services. It is designed to address the Brazilian LGPD, the EU and UK GDPR, and applicable United States state privacy laws.
NodeLume does not operate an analysis backend, advertising tracker, or cloud synchronization service for application captures. Site maps, recordings, network details, screenshots, insights, and timeline data are processed and stored locally in your browser unless you intentionally export or share them.
This policy applies to the NodeLume Chrome extension, the website at nodelume.ai, contact and support communications, and subscription-related information that NodeLume receives.
NodeLume is the controller of personal information it receives and determines how to use, including account and sign-in information, installation records and account associations, campaign attribution and conversion events, contact inquiries, and subscription fulfillment records. Paddle acts as Merchant of Record and authorized reseller for subscriptions and purchases made through Paddle checkout and processes payment-method and transaction information under its own privacy notice.
This policy does not govern the websites or applications you choose to analyze. Those services remain subject to their own privacy policies and controls.
NodeLume is designed to inspect and organize browser-visible application activity on your device. Application analysis data is not uploaded to NodeLume for analytics, advertising, profiling, artificial intelligence training, or synchronization.
Because captures remain in extension storage, NodeLume cannot view, retrieve, synchronize, sell, or use them. You control when a capture starts, how long it remains stored, and whether it is deleted or exported.
Visible page structure, routes, links, controls, trusted user actions, request and response details, timings, headers, textual or JSON bodies, screenshots, insights, and timeline state selected by the user.
When you sign in with Google, NodeLume stores the Google profile information made available for authentication, including your name, email address, profile photo, and the account identifier needed to connect that sign-in to your NodeLume account. NodeLume does not receive your Google password.
Records that identify a NodeLume extension installation, its status, and its association with a signed-in user and subscription. These durable backend records allow you to view and revoke connected installations and allow NodeLume to provide licensed access.
Name, work email, company or project, area of interest, message content, direct emails, and the information reasonably needed to respond to a request.
Plan, trial and subscription status, trial and billing dates, purchase, customer, subscription, and transaction identifiers, contact details, transaction records, and the complete raw payloads of Paddle webhook events received by the NodeLume backend. Raw webhook payloads may contain the Paddle customer, subscription, transaction, event, status, and billing information described below. NodeLume does not receive complete payment-card details.
Advertising and campaign identifiers included in a landing URL, including gclid, gbraid, wbraid, UTM parameters, and the landing page, together with transaction and conversion events used to determine whether a campaign led to an account, trial, checkout, purchase, or subscription event.
Basic request information that hosting and security providers may process automatically, such as IP address, browser type, requested path, date and time, and security events.
NodeLume does not place third-party advertising cookies, operate behavioral analytics, or use tracking pixels on this website. Infrastructure providers may use strictly necessary security technologies. If you arrive through a URL containing campaign parameters, NodeLume may retain the gclid, gbraid, wbraid, UTM parameters, and landing page and connect them with later conversion or transaction events. NodeLume uses this information to measure campaign performance, not to analyze the contents of your extension captures or build a profile of your activity on other websites. Contact-form information is processed only when you submit the form, and transaction information is processed when you use checkout, billing, or subscription services.
NodeLume does not use captured application data for targeted advertising, data brokerage, cross-context behavioral advertising, creditworthiness decisions, or training generalized artificial intelligence models.
activeTab and scriptingInteract with the browser tab the user explicitly chooses and connect visible page structure, clicks, routes, and screen states to a local map.
storageStore maps, recordings, history, preferences, and limited account state in the extension's local storage.
webRequestObserve request and response activity associated with the selected recording tab.
Requested only when full recording needs access across domains called by the selected tab and removed automatically when recording ends.
You can decline optional permissions, stop a recording, delete individual recordings or local history, revoke permissions in Chrome, or remove the extension. Removing the extension ordinarily deletes its local extension data, subject to Chrome's behavior and any exports you created.
If you choose Google sign-in, Google authenticates you and provides NodeLume with the profile information described above. Google processes the sign-in interaction under the Google Privacy Policy. NodeLume uses the information it receives to create or access your account and associate your installations and subscription with you.
NodeLume uses Paddle as Merchant of Record and authorized reseller for subscriptions and paid purchases. When you start a seven-day free trial, Paddle collects a valid payment method and may validate and securely store it for the first charge and later renewals. Paddle collects and processes information needed for checkout and order fulfillment, which may include your name, contact details, billing address or location, payment and purchase details, tax information, device or network information, and fraud-prevention signals. Paddle uses this information to validate payment methods, process payments after the trial unless canceled, calculate and remit applicable taxes, issue invoices and receipts, manage subscriptions, prevent fraud, handle refunds and chargebacks, and provide transaction support.
Paddle may share with NodeLume the buyer contact details, plan, customer and transaction identifiers, trial and subscription status, trial and billing dates, purchase history, and limited billing information needed to provide access, maintain the subscription, prevent abuse, and respond to product or billing support. NodeLume does not receive complete payment-card details, the full card number, or the card security code. Paddle processes transaction data in accordance with the Paddle Privacy Notice and handles the purchase as an independent Merchant of Record.
Paddle sends webhook events to the NodeLume backend so NodeLume can verify and apply subscription and transaction changes. NodeLume may store the complete raw webhook payload as well as transaction and conversion records derived from it for verification, idempotency, reconciliation, entitlement fulfillment, fraud prevention, troubleshooting, disputes, and audit purposes.
NodeLume uses a form-delivery service to send the information you submit to hello@nodelume.ai. Email providers process direct messages so NodeLume can respond.
NodeLume uses hosting and security providers that may process network information needed to deliver and protect the website. This infrastructure does not receive local extension captures.
We may preserve or disclose information we actually control when reasonably necessary to comply with law, prevent fraud, enforce agreements, protect rights and safety, or complete a merger, financing, acquisition, or sale of assets subject to appropriate safeguards and notice where required. This does not create access to local analysis data that NodeLume never receives.
NodeLume does not sell or rent personal information.
gclid, gbraid, wbraid, UTM parameters, and landing-page records are kept only as long as reasonably necessary to attribute campaigns, measure conversions, prevent duplicate reporting, and resolve measurement errors, after which they are deleted or anonymized.Retention periods may vary by record because subscription history, tax evidence, chargebacks, fraud investigations, and legal claims have different limitation and recordkeeping periods. NodeLume reviews retained backend data and applies the shortest period compatible with the purposes above and applicable law. You may request deletion by emailing the privacy contact below; NodeLume will delete eligible information and explain any information it must retain.
NodeLume operates from Brazil and uses providers that may process information in the United States, Europe, Brazil, or other countries. Where data protection law requires a transfer mechanism, NodeLume relies on an applicable adequacy decision, contractual safeguards such as Standard Contractual Clauses, or another lawful basis.
Rights depend on your location and the law that applies. They generally concern information NodeLume actually controls; because local extension captures are not available to NodeLume, you must manage those captures directly in the extension or Chrome.
Where the LGPD applies, you may request confirmation of processing, access, correction, anonymization, blocking or deletion of unnecessary or unlawfully processed data, portability where regulated, information about sharing, review of certain automated decisions, objection, and withdrawal of consent where consent is the basis.
Where applicable, you may request access, correction, erasure, restriction, portability, or objection; withdraw consent; and lodge a complaint with your local supervisory authority. You may also ask about applicable transfer safeguards. NodeLume does not make solely automated decisions that produce legal or similarly significant effects.
Residents of states with applicable consumer privacy laws may have rights to know or access, correct, delete, obtain a portable copy, and appeal a denied request, as well as opt out of sale, targeted advertising, or certain profiling. NodeLume does not sell personal information, share it for cross-context behavioral advertising, use it for targeted advertising, or use sensitive information to infer characteristics. We will recognize legally required browser opt-out preference signals; because NodeLume does not engage in sale or targeted-advertising sharing, no separate opt-out is currently necessary.
We will not unlawfully discriminate against you for exercising a privacy right.
Email hello@nodelume.ai with the subject “Privacy Request.” Describe your request and the email address, account, installation, or transaction identifier connected to the information. We may verify your identity and authority before acting. Authorized agents may submit requests where permitted by law.
NodeLume uses a local-first design, data minimization, transport encryption for website submissions, restricted service-provider access, and reasonable administrative and technical safeguards.
Application captures remain in the browser profile selected by the user. NodeLume has no server-side access to those captures and cannot use them for analytics, advertising, profiling, or artificial intelligence training.
NodeLume is a professional software product and is not directed to children under 16. We do not knowingly collect personal information from children through the website. If you believe a child submitted information, contact us so we can assess and delete it where required.
NodeLume's deterministic technical insights do not make decisions about people and are not used for credit, employment, insurance, housing, education, or other legally significant decisions.
We may update this policy when NodeLume's features, providers, or legal obligations change. Material changes will be presented before or when they take effect as required. The effective date above identifies the current version.
Contact hello@nodelume.ai with privacy questions or requests. Depending on your location, you may also complain to the Brazilian ANPD, an EU or UK supervisory authority, the California Privacy Protection Agency, or another competent regulator.
NodeLume privacy contact
hello@nodelume.ai
Operating from Brazil.