Legal

Privacy Policy

Last updated: 20 June 2026

This Privacy Policy explains what data BioNodulo collects when you use our website and cloud platform, why, and your rights over it. The open-source desktop application runs locally and does not send your research data to us.

Data we collect

  • Account data — name, email, and organization, handled by our authentication provider (Clerk).
  • Billing data — processed by Stripe; we never store full card numbers.
  • Workflow & run data — the workflows you save and the input/output files of cloud runs, stored encrypted in object storage.
  • Operational logs — request metadata and audit logs used for security and debugging.

How we use it

We use your data only to operate, secure, and bill the Service. We do not sell your data, and we do not use your research data or workflows to train machine-learning models.

Subprocessors

We rely on a small set of infrastructure providers, including AWS (compute and storage), Clerk (authentication), Stripe (payments), and Vercel (web hosting). Each processes data on our behalf under their own data-processing terms.

Security & retention

Data is encrypted in transit (TLS) and at rest. Cloud run outputs and checkpoints follow tier-based retention and lifecycle policies; you can delete your workflows and files at any time. For details see our security documentation.

Your rights

Depending on your jurisdiction (including under the GDPR and CCPA) you may request access to, correction of, or deletion of your personal data. To exercise these rights, email privacy@bionodulo.com.

Contact

Questions about privacy? Email privacy@bionodulo.com.