Privacy notice: Nodle IoT Dashboard
Last updated 2026-10-07
This notice explains what the Nodle IoT Dashboard (dashboard.nodle.com) and its AI connector do with your data. It adds to Nodle's Privacy Policy, which covers who is responsible for your data, the legal bases, international transfers, your rights and how to contact our Data Protection Officer.
What we collect
Account and organization
- Your email address, which you sign in with using a one-time code.
- A wallet address: a wallet is created for you the first time you sign in, and the dashboard uses it to register fleets.
- The organizations you belong to and your role in each.
- When you create an organization: your name, the organization’s name, your email and phone number, a description of your activity and your expected network usage.
Fleets, devices and detections
- Fleets: name, identifier and status.
- Beacon devices: name and identifier.
- Detections of your devices by the Nodle network: time, approximate location with its accuracy, and signal strength.
- Webhooks you configure (address, signing secret and selected fields) and their delivery history.
Fleet registration
When you register a fleet, from the dashboard or through the AI connector, the fleet's identifier, the owner and operator addresses and the locations you register are recorded in a public registry, on a public blockchain, that anyone can read and that cannot be erased. A fleet can be released later, but its history stays public.
API keys, billing and support
- API keys you create (name and creation date) and wallet addresses you link with a label.
- Your organization’s plan and subscription status. Payments go through Stripe; Nodle does not receive or store card details.
- The subject and message you send from Support, with your account email.
AI assistant in the dashboard
- Your questions and the conversation context, sent to Google Gemini, which plans how to answer and writes the answer from the organization data it needs.
- Coordinates in an answer may be sent to OpenStreetMap’s Nominatim service to find place names.
- Our server keeps the last 10 exchanges in memory for a short time (see below); your browser keeps the conversation for the session.
AI connector
The connector lets AI applications such as Claude, ChatGPT or Codex work with your organization (how to connect).
- What an AI application can read, only for the organization you connected: your email and roles, the organization’s name, fleets (name, identifier, status, device count), devices (name, fleet, last detection time, last location, signal strength), recent detections of a device (time and location) and webhooks (host, status, recent deliveries). It never receives webhook secrets or full webhook addresses.
- What it can change, only if you allowed it when you connected: fleet and device names, whether a webhook is on, and test events sent to a webhook (admins and editors); and fleet registrations on the Managed Service (admins of Managed Service organizations), for which the identifier, name and locations you ask to register go to Nodle’s registration service.
- What we store about a connection: your email, organization and roles, the permissions you granted, the AI application’s name and identifier, and when the connection was created, last used, expires or was revoked. Access tokens are stored only as hashes. A connection that can register fleets also keeps an encrypted credential for the registration service, cleared when the connection is revoked.
- What the AI application sends us: only the arguments of each request, for example a fleet identifier or a new name. We do not receive your conversation.
Technical data
- Request logs: our hosting provider records your IP address, browser user agent, the address requested and the time.
- AI connector logs: for each connection, permission grant and request, your email, the organization, the AI application, the action and its outcome. Never tokens, secrets, conversation content or IP addresses.
- Rate limiting: IP addresses are hashed before use and kept only as counters.
- Browser security reports about blocked content: the origin and path of the page and of the blocked resource, without query strings.
- Maps: your browser loads map tiles directly from Mapbox or OpenStreetMap, which receive your IP address; Mapbox may also receive usage events from the map.
- Sign-in is handled by Privy, which uses Cloudflare Turnstile to block bots and loads a font from Google Fonts.
How we use it
- To provide the dashboard: sign-in, your organizations, fleets, devices, detections and webhooks.
- To deliver detections to the webhooks you configure.
- To answer questions in the AI assistant.
- To let the AI applications you connect read and act within the permissions you granted.
- To register the fleets you ask us to register on the Managed Service.
- To manage subscriptions, answer support requests and follow up on new organizations.
- To keep the service secure: authentication, rate limiting, abuse prevention and troubleshooting.
Who receives it
- Our service providers: Privy (sign-in and wallets), Google Cloud (hosting, database and logs), Google Gemini (AI assistant), OpenStreetMap Nominatim (place names), Mapbox and OpenStreetMap (map tiles, from your browser), Stripe (payments), Mailgun (support email) and Slack (our team’s notifications about new organizations).
- The AI applications you connect, which process what they receive under their own provider’s terms.
- The webhook endpoints you configure, which receive the detection fields you selected.
- Anyone reading the public fleet registry, for the data described under Fleet registration.
Nodle does not sell this information.
How long we keep it
| Data | Kept |
|---|---|
| AI connector connections | A connection lasts at most 30 days; its record is deleted 30 days after it expires or is revoked |
| Rate-limit counters | About a day |
| Detections of your devices | 14 days; anonymous weekly activity statistics may be kept longer |
| Webhook delivery history | 14 days |
| AI assistant conversation on our server | 2 hours, in memory only |
| Request and application logs | 30 days |
| Session cookie | Until your sign-in expires, at most 7 days |
| Sign-in transfer cookies | 10 minutes at most |
| Fleet registrations in the public registry | Permanent: a fleet can be released, but its record stays public |
| Account, organization, fleet and device data | As described in Nodle's Privacy Policy |
Your choices
- Revoke AI connector connections at any time in Settings › Connected apps. Organization admins can revoke any member's connection, and removing a member or changing their role revokes their connections.
- Turn webhooks off or delete them, and delete API keys, at any time.
- To access, correct or delete your data, or object to its use, see Nodle's Privacy Policy.
Cookies
The dashboard sets only the cookies it needs to work; it sets no advertising or analytics cookies. Privy, Mapbox and Stripe may set their own when you use them.
| Cookie | Purpose | Lifetime |
|---|---|---|
authjs.session-token, __Secure-authjs.session-token | Keeps you signed in. Encrypted, and not readable by the page's scripts. | Until your sign-in expires, at most 7 days |
magiclink_token, wallet_address, whitelist_status | Carry your sign-in from the login step to choosing a team | 10 minutes at most |
post_login_redirect | Returns you to an AI connector authorization after you sign in | 10 minutes |
demo_mode | Remembers that you turned on demo data | 365 days, or until you turn demo data off |
Contact
For questions about this notice, use the privacy contact in Nodle's Privacy Policy.