nodi logo
Privacy Policy

Last updated: March 12, 2026

Welcome to Nodi ("we," "us," or "our"). Nodi is a talent platform that connects companies and recruiters with top candidates. This Privacy Policy explains how we collect, use, store, share, and protect your personal information when you use our website and services (collectively, the "Service"), whether you are a candidate or a recruiter/employer.

By accessing or using the Service, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. If you do not agree, please do not use the Service.

1. Information We Collect

1.1 Information from Candidates

  • Account information: Full name, email address, and password.
  • Profile information: Data extracted from your uploaded CV/resume, including education history, work experience, skills, certifications, and contact links.
  • Optional details: Bio, social media links (LinkedIn, GitHub, portfolio), salary preferences, job interests, location, and other optional fields you choose to provide.
  • Authentication data: If you sign up or log in using Google, we receive your name, email address, and profile picture from your Google account.

1.2 Information from Recruiters and Employers

In addition to the account and authentication data described above, we collect the following from Recruiters:

  • Account information: Full name, email address, password, company name, and role/title.
  • Company details: Company description, logo, website, industry, and location.
  • Job offer data: Job descriptions, requirements, salary ranges, and other details you post on the platform.
  • Recruitment activity: Candidate folders, interview notes, pipeline stages, and communication records created within the platform.
  • Authentication data: If you sign up or log in using Google, we receive your name, email address, and profile picture from your Google account.
  • Google Calendar data: If you connect your Google Calendar, we access your calendar events to check availability and create interview events on your behalf. We request the Google Calendar API scope (https://www.googleapis.com/auth/calendar) to read your existing events (for availability checks) and create new events (for scheduling interviews with candidates). We do not modify or delete your existing calendar events.

1.3 Automatically Collected Information

  • Usage data: Pages visited, features used, time spent on the platform, and interaction patterns.
  • Device information: Browser type, operating system, device type, and screen resolution.
  • Cookies and similar technologies: Session cookies for authentication, preference cookies for locale settings, and analytics cookies (see Section 8).

2. How We Use Your Information

We use the information we collect for the following purposes:

2.1 For Candidates

  • Create and maintain your candidate profile.
  • Display your profile on Nodi so recruiters and companies can discover you.
  • Match you with relevant job opportunities based on your skills and preferences.
  • Send you notifications about job offers, profile views, and platform updates.

2.2 For Recruiters and Employers

  • Provide access to candidate profiles for recruitment purposes.
  • Enable you to create and manage job offers, folders, interview pipelines, and recruitment workflows.
  • Facilitate sharing and collaboration of job offers and candidate data with authorized team members.
  • Schedule interviews between you and candidates by accessing your Google Calendar to check your availability and create calendar events with meeting details.
  • Send you platform updates and notifications related to your recruitment activity.

2.3 General Purposes

  • Improve, maintain, and secure the platform's functionality and performance.
  • Analyze usage patterns to enhance user experience.
  • Comply with legal obligations and enforce our Terms.
  • Prevent fraud, abuse, and unauthorized access to the platform.

3. Google API Services — Limited Use Disclosure

Nodi's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically:

  • We only request access to the Google user data that is necessary for the Service to function. This includes: (a) authentication and basic profile information (name, email, and profile picture) for all users, and (b) Google Calendar data for Recruiters who opt in to the interview scheduling feature, used exclusively to check availability and create interview events.
  • We do not use Google user data for serving advertisements, including retargeting, personalized, or interest-based advertising.
  • We do not allow humans to read your Google user data unless: (a) we have your affirmative agreement, (b) it is necessary for security purposes (e.g., investigating abuse), (c) it is necessary to comply with applicable law, or (d) the data (including derivations) is aggregated and anonymized and used for internal operations.
  • We do not transfer Google user data to third parties unless: (a) it is necessary to provide or improve user-facing features that are prominent in the requesting application's user interface, (b) you provide affirmative consent, (c) it is necessary for security purposes, or (d) it is necessary to comply with applicable law.
  • We limit our use of Google user data to the practices explicitly disclosed in this Privacy Policy.

4. Profile Visibility and Data Sharing

4.1 Candidate Profile Visibility

  • Your candidate profile is publicly visible by default when you create an account.
  • Anyone visiting Nodi may view parts of your profile such as your first name, experience, skills, and general background.
  • Only registered recruiters or companies can access full profile details, including your last name, resume, contact links (LinkedIn, email, etc.), and salary expectations.
  • If you prefer to keep certain information private, do not upload or include it in your profile.

4.2 Making Your Profile Private

You can make your profile private at any time from your Settings page. When your profile is private:

  • It will no longer appear in public searches or be visible to non-recruiter visitors.
  • Only you will be able to view or edit your information.
  • Recruiters will not be able to access your full profile unless you choose to make it public again.

4.3 Recruiter Data Visibility

  • Company profiles and posted job offers are visible to all users of the platform.
  • Internal recruitment data (folders, interview notes, pipeline stages) is only accessible to the recruiter who created it and any authorized team members with whom it has been explicitly shared.

5. Data Sharing with Third Parties

We do not sell or rent your personal data to third parties. We may share your information only in the following circumstances:

  • Service providers: We share data with trusted third-party service providers who assist us in operating the platform, including cloud hosting (Google Cloud Platform), authentication (Firebase), and analytics (Vercel Analytics). These providers are contractually obligated to protect your data and use it only for the purposes we specify.
  • Platform users: Candidate profile data is shared with registered recruiters as part of the core platform functionality. Recruiter data (company info, job offers) is shared with candidates browsing the platform.
  • Legal requirements: We may disclose your information if required by law, regulation, legal process, or governmental request.
  • Business transfers: In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you via email and/or a prominent notice on the platform before your data is transferred and becomes subject to a different privacy policy.
  • With your consent: We may share your data with other third parties when you have given us explicit consent to do so.

6. Data Retention

We retain your personal information for as long as your account is active or as needed to provide you with the Service. Specifically:

  • Account data: Retained for the duration of your active account and deleted within 30 days of account deletion request.
  • Profile data: Retained while your account is active. Upon deletion, your profile is immediately removed from public view, and all associated data is permanently deleted within 30 days.
  • Recruitment data: Interview notes, folders, and pipeline data created by recruiters are retained while the recruiter's account is active.
  • Usage and analytics data: Retained in aggregated and anonymized form for up to 24 months for service improvement purposes.

7. Data Security

We implement industry-standard technical and organizational measures to protect your data, including:

  • Encryption in transit: All data transmitted between your browser and our servers is encrypted using TLS/SSL (HTTPS).
  • Encryption at rest: Personal data stored in our databases is encrypted at rest using industry-standard encryption algorithms.
  • Authentication security: Passwords are securely hashed. We support secure authentication through Firebase Authentication, including Google OAuth 2.0.
  • Access controls: Access to personal data is restricted to authorized personnel on a need-to-know basis. Role-based access controls ensure that only appropriate users can access specific data.
  • Infrastructure security: Our services are hosted on Google Cloud Platform and Vercel, which maintain SOC 2 Type II, ISO 27001, and other security certifications.
  • Regular monitoring: We monitor our systems for vulnerabilities, unauthorized access attempts, and other security threats.

While we strive to protect your personal information, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security but are committed to promptly addressing any security incidents.

8. Cookies and Tracking Technologies

We use the following cookies:

  • Essential cookies: Required for authentication (session cookies) and core platform functionality.
  • Preference cookies: Store your language/locale preferences.
  • Analytics cookies: Used by Vercel Analytics and Speed Insights to collect anonymized usage data and performance metrics.

We do not use cookies for advertising or retargeting purposes. You can manage cookie preferences through your browser settings. Disabling essential cookies may affect your ability to use certain features of the Service.

9. Your Rights and Choices

Depending on your jurisdiction, you may have the following rights regarding your personal data:

  • Access: Request a copy of the personal data we hold about you.
  • Correction: Request correction of inaccurate or incomplete data through your account settings.
  • Deletion: Request deletion of your account and all associated personal data.
  • Portability: Request a machine-readable copy of your data.
  • Restriction: Request that we restrict the processing of your data under certain circumstances.
  • Objection: Object to the processing of your data for specific purposes.
  • Withdraw consent: Where processing is based on consent, you may withdraw it at any time.

You can exercise most of these rights directly through your account settings. For requests that cannot be handled through the platform, please contact us at hello@nodi.global. We will respond to your request within 30 days.

Please note that deleting your account will remove your profile from public view immediately. However, copies or cached versions may remain temporarily in search engines or other third-party systems beyond our control.

10. Children's Privacy

The Service is not directed to individuals under the age of 16. We do not knowingly collect personal information from children under 16. If we become aware that we have collected personal data from a child under 16 without verification of parental consent, we will take steps to delete that information promptly.

11. International Data Transfers

Your information may be transferred to and processed in countries other than your country of residence. These countries may have data protection laws that differ from your jurisdiction. By using the Service, you consent to the transfer of your information to these countries. We ensure that appropriate safeguards are in place to protect your data in accordance with this Privacy Policy.

12. Changes to This Policy

We may update this Privacy Policy periodically. When we make material changes, we will: (a) revise the "Last updated" date at the top of this page, and (b) notify you via email or a prominent notice on the platform. We encourage you to review this page regularly to stay informed of any changes.

13. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at: