Privacy Policy
Last updated 28 July 2026
This explains what [registered company name] ("Nadi") does with personal data. It covers the platform itself. Each community is run by its own owner, and section 2 explains where the line between us falls.
1. In short
- We collect what we need to run accounts, communities, and payments — and not more.
- We do not sell personal data, and we run no advertising or third-party analytics trackers.
- Card details never reach our servers; Stripe handles them.
- You can export or delete your data from account settings, or by writing to [privacy email].
2. Who is responsible for what
For your account — your email, your profile, your billing relationship with us — we are the data controller.
For what happens inside a community, the community's owner is the controller and we act as their processor: they decide who is admitted, what is posted, and what they do with a member list. If you want your data removed from a particular community, ask its owner first; if they do not respond, write to us and we will act.
3. What we collect
- Account data — name, email, handle, password hash, profile photo, bio, and language preference.
- Content — posts, comments, courses and lessons you write, calendar events, direct messages, and anything you upload.
- Membership and activity — which communities you belong to, your role in each, points and level, lesson progress, and event responses.
- Payment data — what you were charged, when, by which community, and the last four digits and brand of the card. Full card numbers go straight to Stripe and are never stored by us.
- Technical data — IP address, browser and device type, and timestamps, recorded in server logs and used for security, abuse prevention, and debugging.
We do not ask for special-category data — health, religion, politics, sexuality. If you choose to write it in a post, you are making it visible to that community.
4. Why we use it, and on what basis
- To provide the service — creating your account, showing you your communities, taking payments. Basis: performance of our contract with you.
- To keep it safe — detecting fraud, spam, and abuse; enforcing our terms; keeping audit logs. Basis: our legitimate interest in a service that is not overrun.
- To support and improve it — answering your questions, fixing what is broken, understanding which features are used. Basis: legitimate interest.
- To meet legal obligations — tax and accounting records, and responding to lawful requests. Basis: legal obligation.
- Marketing email — only if you opt in, and every message has an unsubscribe link. Basis: consent.
5. Who we share it with
We share personal data only with providers who process it on our instructions, under contract, and only for these purposes:
- Supabase — database, file storage, and authentication.
- Stripe — payments, payouts, and fraud checks. Stripe is a controller in its own right for the payment data it collects.
- Our email provider — transactional email such as password resets and receipts.
- Our hosting and error-monitoring providers — running the site and telling us when it breaks.
Beyond that we share data with a community's owner and moderators for the community you joined; with law enforcement or a court where we are legally required to and, where we are allowed, after telling you; and with a buyer if the business is ever sold, under the same commitments made here.
We do not sell personal data, and never have.
6. Cookies and local storage
Every cookie Nadi sets is strictly necessary for the site to work, which is why you are told about them rather than asked to consent. There are no analytics, advertising, or third-party tracking cookies, and nothing here follows you to another site.
| Name | Type | Kept | Purpose |
|---|---|---|---|
nadi-locale | Essential | 1 year | Your chosen language, and with it the direction the page is laid out in. |
nadi-consent | Essential | 6 months | Records that you have seen this notice, and any choice you made, so you are not asked again on every page. |
nadi-theme | Essential · local storage | Until cleared | Whether you prefer the light or dark palette. Held in local storage, not sent to the server. |
Blocking the essential ones will stop you being able to sign in. Clearing them signs you out and resets your language and theme.
7. How long we keep it
- Account and content — while your account is open.
- After you delete your account — removed or anonymised within 30 days, except where we must keep something longer.
- Payment and tax records — kept as long as tax law requires, typically six to seven years.
- Server and security logs — 90 days.
- Backups — overwritten on a rolling 30-day cycle, so deleted data can persist there briefly.
Posts and comments you made in a community may remain visible to that community after you leave, detached from your profile, so that conversations other people took part in do not fall apart. Ask us if you want them removed as well.
8. Your rights
Depending on where you live you can ask us to give you a copy of your data, correct it, delete it, restrict or object to how we use it, or send it to another service. You can also withdraw consent at any time where consent is what we relied on.
Most of this is self-service in account settings. For anything else, write to [privacy email] — we answer within 30 days. We will never charge you for asking or treat you differently for having asked. If you are unhappy with our answer you can complain to your local data protection authority.
9. International transfers
Our providers operate in several countries, so your data may be processed outside the one you live in. Where it leaves the UK or the EEA we rely on the European Commission's Standard Contractual Clauses, or on an adequacy decision covering the destination.
10. Security
Traffic is encrypted in transit, passwords are hashed and never stored in a readable form, access to production data is limited to the people who need it, and rendered content is sanitised so one member cannot run code in another's browser. No system is perfect; if a breach affects you we will tell you and the relevant authority within the time the law sets.
11. Children
Nadi is not for people under 16. If we learn that we hold data on someone younger, we delete it. If you believe a child has an account here, write to [privacy email].
12. Changes
We will post any material change here and, where it affects you meaningfully, tell you by email before it takes effect. The date at the top always reflects the current version.
13. Contact
[registered company name]
[registered address]
[privacy email]
See also our Terms of Service.