Security
Where your brand's data is held, who can read it, and how to take it out.
Who can read your brand
Your brand's rows are readable only by the people you put in that brand, and the rule sits in the database rather than in the app. Every table that holds brand content carries a policy of its own, so a query for somebody else's brand returns nothing, whatever asked for it.
That matters more than it sounds. A rule written in application code protects you as long as every route remembers to apply it. A rule written in the database protects you even when one does not.
Where it is held
In the EU. Nomi is built in Slovenia, and the database, the sign in and the stored files run on Supabase, hosted in the EU.
Not every company that touches your work sits in that one place, and the privacy notice names each of them beside the single job it does: the database, the model that answers you, the one that draws the picture, the one that collects the public ads, and the host. Each processes on our instructions and for no purpose of its own.
Which is the honest version of the question a European buyer is actually asking. Your brand's content is held in the EU, you can read and edit all of it from inside the app, and you can delete it without asking us.
What never reaches us
Your card details. Payments run through Stripe, and the card is handed to them rather than to us. We hold the fact that a charge happened, because we have to account for what was billed, and nothing about the card that made it.
Your password. It is held as a hash by our authentication provider, and we never see the password itself. Resetting it is something you do with them, not something we can do for you.
What we hold, and where you can read the list
Your account details, your brand and everything you gave it, your products and markets, your conversations, what Nomi made, and the notes it keeps between sessions. The full list is in the privacy notice, item by item.
Competitor research is the one part people ask about most, so it is worth saying plainly: it reads the ads the platforms already publish, in their own public ad libraries. It does not touch a competitor's account, and there is nothing private in it.
In transit
The app is served over HTTPS and nothing else. Browsers are told to refuse to put it in a frame, to stop guessing at file types, and to keep a referrer inside its own origin when it leaves for somewhere else.
Taking it out, and deleting it
Everything Nomi holds about a brand is filed under that brand, and the brand is the unit that deletes. Deleting one takes its chats, creatives, products, markets, personas and memory, and the stored files with them. You type the brand's name to confirm, there is no undo, and there is no export afterwards, so take a copy first.
Creatives download from the card menu, one at a time or as a zip, and briefs save as Markdown.
To delete your account, write to privacy@nomigrowth.com. We answer within 30 days. Every brand you were the last person in goes with it; a brand you share with a colleague survives, for them.
Telling us about a problem
Write to privacy@nomigrowth.com. If you have found something that puts customer data at risk, say so in the subject line and we will come back to you before we come back to anyone else.