Legal
Privacy Policy
Nomi holds your address book, your mail and your calendar. This page says exactly what it keeps, what it only reads in passing, who else ever sees it, and how to get all of it back or delete it.
Last updated
1Who we are
Nomi is a personal assistant and personal CRM. It is built and operated by Jaime Noain, an individual based in the United Kingdom. There is no company behind it.
For the purposes of UK data protection law — the UK GDPR and the Data Protection Act 2018 — Jaime Noain is the data controller for the personal data described in this policy.
For anything about privacy, your data, or this policy, write to info@nomi.you. That address reaches a person, and it is the right address for every request described in section 11.
2The short version
Nomi is single-user. An account holds one person's data, and no other Nomi account can see it. There is no sharing, no team, and no shared workspace.
- Nomi is not advertising-funded. Your data is never sold, rented, or used to target advertising, and there are no advertising or analytics cookies.
- Your data is never used to train AI models. Not ours, not anyone else's. This includes everything Nomi receives from Google.
- Connecting Google is optional and reversible. Nomi asks for each Google permission only when you first use the feature that needs it, and you can disconnect at any time.
- You can take everything with you, or delete all of it. Settings ▸ Export downloads a complete archive; Settings ▸ Account ▸ Delete account removes the account and its data and revokes Nomi's access to your Google account.
The rest of this document is the detail behind those four sentences.
3What Nomi collects
Your account. Your email address, an account identifier, and the timestamps of sign-up and sign-in. Authentication is handled by Supabase Auth: your password is stored by Supabase as a cryptographic hash and is never visible to Nomi's code or to us. Nomi also stores the preferences you set — time zone, digest send time, quiet hours, which features are switched on.
What you put into Nomi. Everything you type, upload or import: contacts and the details you record about them, companies, places, notes and timeline entries, tasks, reminders, documents and their expiry dates, the “matters” you have going on, your own custom tables and fields, saved views, files you attach to a timeline entry, and the spreadsheets or LinkedIn connection exports you import. Some of this is personal data about other people — see section 5.
Your conversations with Nomi. The messages you send in Ask Nomi are stored so a conversation survives a reload. You choose how long they are kept, and you can delete any conversation or all of them at once (section 9).
Data from Google, if you connect it. Only the categories covered by the permissions you have actually granted — set out clause by clause in section 4.
Email you forward to your Nomi address. If you use the “email your assistant” feature, Nomi records the sender, the subject, an excerpt of your own instruction (about the first 2,000 characters), the names of any attachments, and what Nomi did in response. Attachment contents are never stored — a forwarded calendar invitation is read once, turned into a suggested event, and the file itself is discarded.
Enrichment data, if you turn it on. Enrichment is off until you enable it and supply your own provider API key. When it is on, Nomi sends a contact's LinkedIn profile URL to that provider and stores what comes back — job title, employer, location, profile photo and similar public professional information — against the contact.
Technical data. Ordinary server and platform logs generated by hosting the service, including IP addresses and request metadata held by our hosting and database providers. If error monitoring is enabled on a deployment, error reports (including a stack trace and the page that failed) are sent to Sentry. Nomi does not run product analytics, session recording, or advertising trackers.
4Google account data, permission by permission
Nomi never asks for all of these at once. You are asked for identity and contacts when you first connect, and for each of the others only when you first use the feature that needs it. What each permission is used for:
| Permission | What Nomi does with it |
|---|---|
openid, email, profile | Reads the email address and account id of the Google account you are connecting, so Nomi can label the connection and tell two connected accounts apart. |
contacts (read and write) | Reads your Google Contacts so you can import them into Nomi and so Nomi can match them to people you already have. Writes your Nomi contacts back to Google Contacts, which is how they reach the address book on your phone. Deleting a contact in Nomi deletes the copy Nomi created in Google. |
gmail.readonly | Reads your mail so Nomi can tell you what needs a reply, keep a history of your correspondence with the people you have saved as contacts, and spot commitments and dates. What is kept, and what is only read in passing, is set out in section 6. |
gmail.compose | Creates draft replies in your Gmail account for you to review. Nomi never sends email as you — it does not hold the permission that would let it. |
gmail.modify | Archives a message, applies a label, or moves a message to Trash — only at the moment you tap the button, never automatically. Trash is reversible; Nomi never deletes mail permanently and never reports mail as spam. |
calendar.readonly | Reads events from the calendars you choose, so Nomi can suggest timeline entries for meetings you actually had. |
calendar.events | Creates a calendar event — only when you accept a specific suggestion by tapping “Add to calendar”. Nomi does not invite other attendees. |
Google Limited Use. Nomi's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements. In particular:
- Google user data is used only to provide and improve the user-facing features described in this policy, and for no other purpose.
- Google user data is not used to develop, improve or train generalized artificial intelligence or machine learning models. Where message content is sent to an AI provider to produce a summary or a draft for you, that is a one-off request whose output is shown to you — it is contractually not permitted to be used as training data, and Nomi does not permit it (section 7).
- Google user data is not transferred to anyone else, except to the service providers listed in section 8 strictly to operate these features, where you direct it, or where the law requires it.
- Google user data is never sold, and never used for advertising, credit assessment, or lending.
- No human reads your Google user data, except where you have explicitly asked for help with a specific problem, where it is necessary for security purposes, or where the law requires it.
Disconnecting. Settings ▸ Integrations disconnects a Google account. Nomi revokes its refresh token with Google immediately, stops all syncing, and deletes the mailbox metadata and calendar state associated with that connection. Contacts and timeline entries already created in Nomi stay, because they are yours — delete them in the app, or delete your whole account (section 10). You can also revoke Nomi's access directly at myaccount.google.com/permissions.
5Data about other people
A personal CRM is, by its nature, mostly information about other people: their names, contact details, where they work, what you last talked about, when their birthday is. You decide who goes into Nomi and what is recorded about them.
Nomi processes that information on your instructions, to give you the features you asked for. You are responsible for having a proper basis for holding it — see the corresponding clause in the Terms & Conditions. If someone whose details you hold in Nomi contacts us directly, we will point them to you, since you are the person who decides what is kept.
If you are using Nomi purely for your own personal and household purposes, UK data protection law may not apply to your use of it at all. That exemption is narrow, and it is worth checking rather than assuming — particularly if you use Nomi for work.
6What Nomi keeps from your mailbox, precisely
This is the part people most want a straight answer on, so here it is without rounding.
- Mail exchanged with people you have saved as contacts is kept, including the message text. Nomi groups it by person and by day and stores the parsed message text, so your history with someone survives in Nomi and so it can write a summary of the relationship. This is the record that makes the contact timeline work.
- All other mail — newsletters, receipts, strangers, bulk mail — is kept as metadata only. Sender, subject, labels, date, Gmail's own preview snippet of roughly 200 characters, and a one- or two-line AI summary. The full body is fetched from Gmail at the moment the summary is written, held in memory, and discarded. It is never written to the database.
- Nomi never stores attachments from your mailbox.
- The mailbox view works over a rolling 30-day window. Metadata that has fallen out of that window is retained in the database until the connection is removed or the account is deleted.
7AI, and what is sent to model providers
Nomi uses AI to summarise, to draft, to extract dates and commitments, and to answer your questions about your own data. To do that, the relevant excerpt has to be sent to a model provider:
- Anthropic — the assistant, summaries, drafted replies, extraction of tasks, documents and events.
- OpenAI — transcribing a voice note you record in Ask Nomi, and nothing else.
Both providers are used through their business APIs, whose terms do not permit them to use data submitted through the API to train their models. Nomi does not opt into any arrangement that would allow it. Providers may hold a request briefly for their own abuse-monitoring purposes under their published terms; Nomi itself stores nothing with them, and no account is created for you with either provider.
AI output is a suggestion, not a fact. Nomi proposes; you decide. Nothing is sent, deleted or filed on your behalf without you tapping it.
8Who else processes your data
Nomi is operated by one person, on infrastructure provided by other companies. These are the services involved, and whether they handle personal data:
| Service | Role | Personal data? |
|---|---|---|
| Supabase | Database, authentication and file storage — everything in your account lives here | Yes — all of it |
| Vercel | Hosting and serving the application, and running its scheduled jobs | Yes — in transit, plus request logs |
| Contacts, Gmail and Calendar, if you connect them; and place lookups in the location picker | Yes — under section 4 | |
| Anthropic | AI summaries, drafts, extraction and the assistant | Yes — the excerpt sent with each request |
| OpenAI | Transcribing voice notes | Yes — the audio you record |
| Resend | Sending your digest and account emails, and receiving mail sent to your Nomi assistant address | Yes — your email address and message content |
| People Data Labs | Contact and company enrichment — only if you enable it and add your own key | Yes — a contact's LinkedIn profile URL |
| EnrichLayer | Profile photos for enrichment — only if you enable it and add your own key | Yes — a contact's LinkedIn profile URL |
| Sentry | Error monitoring, where enabled on a deployment | Limited — error reports and technical context, not your records |
| OpenStreetMap / Nominatim | Turning an address into map coordinates | Only the address text you asked to place on a map |
| logo.dev | Company logos, fetched by your browser from a company's web domain | No — a company domain, never a person |
Nobody on this list is permitted to use your data for their own purposes. Nomi does not sell data to anyone, and shares it outside this list only where the law requires it or where you tell us to.
9Where your data is processed
Nomi is operated from the United Kingdom, but the providers above are international and several of them — the AI providers in particular — process data in the United States. That means some of your personal data is processed outside the UK.
Where that happens, the transfer relies on the mechanisms UK data protection law provides for it: the UK Government's adequacy regulations where they apply, or the standard contractual clauses with the UK International Data Transfer Addendum, as set out in each provider's own data processing terms.
10How long it is kept
- Everything you enter is kept until you delete it or delete your account. Nomi does not expire your records behind your back.
- Ask Nomi conversations follow the retention you choose in Settings ▸ Assistant — 30, 90 or 365 days, or kept until you delete them, which is the default. Anything past your chosen window is deleted automatically.
- Mailbox metadata and calendar state are deleted when you disconnect that Google account, and otherwise when you delete your account.
- Backups and provider logs held by Supabase and Vercel roll off on those providers' own schedules shortly after deletion; we do not keep separate copies of your data.
11Your rights
Under the UK GDPR you have the right to be informed, and the rights of access, rectification, erasure, restriction of processing, data portability, and objection to processing. Where processing rests on your consent — connecting Google, enabling enrichment — you can withdraw that consent at any time, without affecting anything done before you withdrew it.
Most of these you can exercise yourself, immediately:
- Access and portability — Settings ▸ Export downloads a complete archive of your data.
- Rectification — edit any record in the app.
- Erasure — delete individual records, or your entire account (section 10).
- Withdrawing consent — Settings ▸ Integrations disconnects Google; enrichment has its own switch.
For anything else, email info@nomi.you. We will reply within one month, as the law requires, and we will not charge you for it.
Nomi does not make automated decisions that produce legal effects or similarly significant effects for you. Its AI features propose things for you to accept or reject.
12Deleting everything
Settings ▸ Account ▸ Delete account does all of the following, in one step and without a waiting period:
- revokes the refresh token for every Google account you have connected, so Nomi's access to Google ends at that moment;
- deletes your authentication record, which cascades to every table that holds your data — contacts, companies, timeline entries, tasks, documents, mailbox metadata, conversations, saved views, imports, API keys and encrypted integration secrets;
- signs you out.
It cannot be undone. Export first if you want a copy. Deleting your Nomi account does not delete the contacts Nomi wrote into your Google Contacts — those are in your Google account, and you can remove them there.
13How your data is protected
Traffic to Nomi is encrypted in transit with TLS. Every table in the database enforces row-level security keyed to the account that owns the row, so one account cannot read another's data even if the application had a bug. Passwords are hashed by Supabase Auth and never reach Nomi's own code.
Google OAuth tokens, and the API keys you add for enrichment, are encrypted with AES-256-GCM before they are stored, and they live in a separate database schema that no browser or API client can reach — only server-side workers can decrypt them. Plaintext tokens never appear in a response, a log line, or an export.
Being straight about the limits: Nomi is a personal project run by one person. It holds no security certification, no SOC 2 or ISO 27001 audit, and no cyber insurance, and it does not claim any. No service can promise perfect security.
15Children
Nomi is not intended for children. Please do not create an account or use the service if you are under 16.
16Changes to this policy
Nomi is early-stage software and this policy will change as it does. The current version is always at this address, and the “last updated” date at the top tells you when it last moved. If a change materially affects how your data is handled, you will be told in the app or by email before it takes effect.
17Complaints
If something about how your data is handled troubles you, please raise it at info@nomi.you first — it is the fastest way to get it fixed.
You also have the right to complain to the UK's data protection regulator, the Information Commissioner's Office, at ico.org.uk/make-a-complaint or on 0303 123 1113. You do not have to contact us first.
Questions about this page? Email info@nomi.you.
See also Nomi's Terms & Conditions.