LEGAL · PRIVACY POLICY
Privacy Policy
Last updated 21 June 2026
Plain version
We do not know who you are. No email, no password, no name. Your recovery phrase never leaves your Mac. The only thing we send out is the text you highlight, never your identity, so we can build the report.
Contents
- 1. The short version
- 2. What we do not collect
- 3. What we store
- 4. What leaves your device
- 5. What stays on your device
- 6. Cookies and analytics
- 7. Payments
- 8. The Public Record and other people
- 9. How we share data
- 10. Retention and deletion
- 11. Your privacy rights (EEA/UK and California)
- 12. Security
- 13. Children
- 14. International users
- 15. Changes and contact
#1. The short version
Nolemy is built to hold as little about you as possible. There is no sign-up, no email, no password, and no profile. Your identity is a key on your own device. We could not tell a stranger who you are, because we do not know.
#2. What we do not collect
- No email address, phone number, or password;
- No real name or account profile;
- No raw IP address (we keep only a one-way hash, see Section 3);
- No payment card details (see Section 7);
- No location data, contacts, or advertising identifiers.
#3. What we store
To run the service and keep it free of abuse, we store:
- Your public key, the account identifier derived on your device;
- An auto-assigned handle (for example alpine-albatross-47), which is not personal and is changeable;
- A one-way, peppered hash of your IP address, used only for rate limits and abuse defence, and not reversible to your IP;
- A device fingerprint that is hashed on your Mac before it is sent. We receive only the hash, never your hardware ID;
- The public content of records you publish, and simple counters (checks used, records published).
#4. What leaves your device
When you check a claim, only the text of that claim is sent out, to find and analyse what people have already said about it. Your identity, your key, your IP, and your device are not attached to it. The claim text is sent to:
- Serper, to search the public web;
- DeepSeek, to compress community testimony into a structured report;
- Public community sources (Reddit, Hacker News, DuckDuckGo, YouTube, and Bluesky) to gather what people reported. Reports may also quote Trustpilot, X, and public forums.
#5. What stays on your device
- Reading text from a screen region (“Draw & Check”) runs entirely on your Mac with Apple’s on-device Vision framework. Screenshots never leave your computer;
- Your 12-word recovery phrase is stored only in the macOS Keychain and is never transmitted;
- Screen-recording permission, if you grant it, is used solely to read the region you draw. Nothing is recorded or sent.
#7. Payments
If you subscribe to Nolemy Pro, checkout is handled by Paddle, our Merchant of Record, by card or PayPal. Nolemy never sees or stores your card details. Paddle processes your payment information under its own privacy policy.
#8. The Public Record and other people
Records you publish are public by design and may be indexed by search engines. A record concerns real products, services, or organizations and may quote third parties or mention individuals.
If a record concerns you and you want it corrected or removed, email hello@nolemy.com with the link. We review every request and act where appropriate.
#10. Retention and deletion
We keep little, and short-lived security data (such as replay nonces) is pruned automatically. Because there is no email, there is no password reset and no self-service account deletion. Your key is the only credential, held only by you. Published records are durable until removed.
To remove a record, or to ask us to delete what we hold that relates to you, email hello@nolemy.com. Given how little we store, and that it is not tied to your identity, there may be limits on what can be located.
#11. Your privacy rights (EEA/UK and California)
If you are in the EEA, the UK, or California, data-protection law gives you rights to access, correct, or delete personal data we hold about you, and to object to or restrict certain processing. We honour these rights, and we will be candid about the limit that defines this product: we hold almost nothing tied to you. There is no name, email, or account behind your key, so there is usually no personal record for us to look up by identity.
What we can act on directly is a specific record (we can correct or remove it) and a specific public key (we can disable it). To exercise a right, email hello@nolemy.com with enough detail for us to locate what you mean. We do not charge for this and we do not retaliate for asking.
#12. Security
Personal data is minimised by design. Sensitive values such as IP addresses are one-way hashed with a server secret. Every request from the app is cryptographically signed. There is no central store of personal identity to leak.
#13. Children
Nolemy is not directed to children and is not intended for anyone under 16. We do not knowingly collect data from children.
#14. International users
Nolemy and the providers listed above may process the limited data we hold in countries other than your own. By using Nolemy you understand your information may be processed outside your country of residence. Where local law grants you data-protection rights, see Section 11.
#15. Changes and contact
We will reflect changes here and update the “Last updated” date. Questions, requests, or concerns: hello@nolemy.com.