Privacy policy
Last updated: September 28, 2026
This translation is provided for convenience. The Portuguese version is the legally binding one and prevails in case of any discrepancy.
How Nodo handles your data, under Brazil's General Data Protection Law (LGPD, Law No. 13,709/2018) and Internet Civil Framework (Law No. 12,965/2014). Questions or requests to exercise your rights: [email protected].
1. Data we collect
- Account: e-mail and password (stored only as a hash).
- Subscription: status, dates and billing records.
- Payment: processed by SyncPay. Name, e-mail and CPF (Brazilian taxpayer ID) are sent to the payment processor to register the subscription. The CPF is not stored in Nodo's database. For card payments, the data is transmitted to the processor to create a single-use token; Nodo does not store it in its database. We do not keep bank details.
- Minimal technical use: the link to authorized devices, the subscription status and the IP address, handled temporarily to limit abuse of the APIs.
- Extension: a refresh token bound to the device, a temporary credential, e-mail and subscription status to keep and show access. Preferences, allowed channels, stream state and ad records stay in the browser.
2. Connections and technical records
Nodo does not keep individual browsing history or the content of HTTPS connections relayed by the nodes. The nodes process the IP address needed for the connection and keep aggregate metrics of connections and volume. Technical failures may create error records containing the destination domain. The website server uses the IP temporarily in memory to limit abusive attempts to access the APIs.
The extension processes Twitch pages and requests to identify the stream, apply the chosen coverage and check the route. Depending on the selected mode, control requests and other Twitch requests may go through the exit node. Code on the page may use Twitch's own authentication cookie for a playback request to Twitch; that cookie is not sent to Nodo. We use only essential cookies on our website, with no advertising tracking.
The use of information obtained through Chrome APIs complies with the Chrome Web Store User Data Policy, including the Limited Use requirements: we process this data to provide, maintain and protect the extension's described features. We do not use it for personalized advertising, nor do we sell it. Human access occurs only when necessary for requested support, security or compliance with the law.
3. Legal bases
We process your data for the performance of a contract (LGPD art. 7, V), compliance with a legal obligation (II), legitimate interest in security and fraud prevention (IX) and, where applicable, consent (I).
4. How we use and share data
We use the data to maintain your account and subscription, bill, provide support and prevent abuse. We do not sell your data. We share the minimum with SyncPay, our payment processor, with infrastructure providers (hosting and database) and with authorities — only under a court order and limited to registration data.
Payments processed by SyncPay. Nodo is responsible for the service and for support.
We use Resend to send password recovery, welcome, security and payment confirmation e-mails. We share with this service the e-mail address and the content needed for the message. We record the send attempt and its acceptance to track failures and avoid duplicates. These account notices do not subscribe you to marketing campaigns.
5. International transfer
Part of the hosting and database may process data outside Brazil, with partners that meet LGPD standards.
6. Retention
- Account: during the contractual relationship and, afterwards, for as long as needed for legal obligations and the defense of rights. Deletion requests are assessed through the contact below.
- Payment and tax records: 5 years.
- Extension: local tokens are removed when you sign out or uninstall the extension. The server keeps the hash of the device-bound token and marks the record as revoked after sign-out or device removal; revocation does not automatically delete that record from the database. Local ad records older than 7 days are removed on the next extension startup.
- Connection:we do not create individual browsing history; abuse-control data expires in memory according to the window of each limit. Technical error records stay in the servers' journal and are removed by rotation according to capacity. There is currently no fixed maximum retention period configured for these records.
After that, we delete or anonymize the data, unless required by law.
7. Your rights
Under the LGPD (art. 18) you may access, correct, port, anonymize or delete your data, withdraw consent and learn with whom we share it. Write to [email protected] — we reply within 15 days.
8. Minors
The service is for people aged 18 or older. We do not knowingly collect data from minors.
9. Security
We protect your data with hashed passwords, HTTPS and access control. In a relevant incident, we notify those affected and Brazil's data protection authority (ANPD).
10. Changes
We may update this policy; we communicate relevant changes.