Privacy Policy
Effective date: July 2026
This Privacy Policy explains how Nocturne(“Nocturne”, operated by Nocturne Inc, “we”, “us”) collects, uses, and shares information when you use our website and application (the “Service”).
Information we collect
- Account data — name, email address, password (stored hashed by our auth provider), and profile details you provide.
- Organization data — workspaces you create or join, team membership, and content you create in the Service.
- Billing data — subscription and payment status. Card details are handled by Stripe and never stored on our servers.
- Usage & device data— product analytics events and basic device/log information, collected only where permitted (see Cookies & analytics).
How we use information
To provide and secure the Service, authenticate you, process subscriptions, send transactional email, provide support, comply with legal obligations, and — with your consent — understand product usage.
Cookies & analytics
We use strictly necessary cookies to keep you signed in and remember your active workspace. We do not load product analytics or store campaign attribution unless you explicitly allow analytics. If you allow it and arrive via a marketing link (with utm_* or ref parameters), we may store the campaign values already present in that URL in a browser cookie for up to 30 days so we can measure which channels lead to new accounts. Declining or withdrawing consent stops future analytics and attribution collection and removes that attribution cookie; it does not affect access to the Service. This browser preference does not retroactively remove records created while consent was active, such as attribution submitted with an account or waitlist signup. Account-linked records follow the controls below; a standalone waitlist signup requires a separate verified-email request through the contact method below.
Analytics preference
You have not chosen whether to allow product analytics.
How we share information
We share data with processors who act on our behalf under contract — for example our infrastructure and database provider (Supabase), payments (Stripe), email delivery (Resend), background jobs (Inngest), error monitoring (Sentry), and optional product analytics (PostHog and Vercel Analytics). We do not sell your personal information.
Data retention
We keep account and organization data while your account is active and as needed for the purposes above. Some records are retained on a schedule (for example, raw billing webhook payloads are scrubbed after 60 days and read notifications after 90 days). Completed private data-export artifacts are removed after seven days. Deleting an account is subject to legal retention requirements and can retain or anonymize content shared with an organization.
Your rights
Depending on your location (e.g. GDPR/UK GDPR, CCPA/CPRA) you may have rights to access, correct, export, or delete your personal data, and to object to or restrict certain processing. Signed-in users can request an export or account deletion from Settings → Security. Exports include personal data and content you authored in organizations you currently belong to; attachments are represented by metadata, not file contents. You can also contact us using the details below.
Security & international transfers
We use industry-standard measures including encryption in transit, row-level access controls, and least-privilege service credentials. Data may be processed in countries other than yours; where required we rely on appropriate safeguards for those transfers.
Children
The Service is not directed to children under 16, and we do not knowingly collect their data.
Changes
We may update this policy from time to time; material changes will be posted here with a new effective date.
Contact
Questions or requests? Email us at hello@stay-nocturne.com. Data controller: Nocturne Inc, Miami, FL, governed by the laws of Miami-Dade County, Florida.