Privacy Policy
Last updated 12 September 2026
About this policy
This policy explains how Noding handles information when you use noding.xyz and the Noding extensions for Figma Weave and ComfyUI. Noding operates this service. Contact us at fedeaitools@gmail.com with privacy questions or requests.
Early-access emails
If you join our early-access list, we store your email address, the platform you selected, and a dated record of your notification preferences in our private Firestore database in the United States. We use this to confirm your signup and notify you when that version is available. Occasional product updates are a separate, optional choice. Signing up does not create a Google account or upload your workflows. Our service records a keyed hash of the request IP address to limit abusive submissions; it does not store the raw address in the signup record.
We keep signup details until you opt out or they are no longer needed for these purposes. Email fedeaitools@gmail.com to unsubscribe, correct your details or request deletion. Our email integration uses Resend to deliver signup confirmations and notifications. Resend processes recipient addresses, message content and delivery information. Incoming messages to our Noding email address are processed by Resend and forwarded to our support inbox. Notification emails include an opt-out method.
Local use and optional accounts
You can use the editor and save a device library without signing in. Guest prompts and workflows stay in browser storage unless you export them, insert them into another platform, or explicitly import them into an account library and enable sync. Signing in alone does not upload your guest library or enable sync.
Information we handle
If you sign in with Google, we use your email address and Google account identifier to authenticate you and create a Noding account identifier. Our account service records your email, last activity time, sync settings and contribution preferences, including dated consent records. Authentication tokens are handled by Google, Firebase and the extension; the extension keeps its Firebase tokens in browser session storage. We do not receive your Google password.
If you enable sync, we store saved prompts, workflow expressions, descriptions, names, shortcuts, item identifiers and revision information. This content may contain personal information you choose to include. Please avoid storing passwords, API secrets or information you do not have permission to share.
Google Drive and database copies
Sync saves snapshots in Noding’s private application-data area of your Google Drive and a separate private copy in our Google Cloud Firestore database. Firestore coordinates changes across devices. The Weave and ComfyUI editions keep separate libraries under your account.
We request the drive.appdata permission to create, read and delete the app’s own configuration files. This does not give Noding access to your ordinary Drive documents or folders. These backup files are not presented as ordinary documents in your Drive file list. We also request identity and email permissions for sign-in. Drive access is requested when you choose a Drive feature.
How we use information
We use this information to authenticate you, provide library storage and restoration, resolve sync conflicts, maintain your preferences, respond to support requests, and protect the service. Cloud providers may process technical information such as IP addresses, request times, errors and device or browser details when serving requests. We do not sell personal information or use Google account or Drive data for advertising.
Noding follows the Google API Services User Data Policy, including applicable Limited Use requirements. Access to private content is limited to providing the service, support you request, security needs and legal obligations.
Model training and contribution preferences
Noding does not currently train models on your prompts or workflows. Storing a private database copy is not permission to use it for training. The optional contribution preference is separate from sign-in and sync, is off by default, and can be withdrawn in account settings. At present it records your preference only; no training dataset or model-training pipeline is implemented.
Any future contribution feature will explain what is contributed and how it is used before use begins, and require the permissions and consent applicable at that time. We will not use Google API data to train generalized AI models. An opt-in does not override Google’s data-use restrictions.
Service providers and international processing
Google provides authentication, Drive storage and our Firebase/Google Cloud backend. Our current Firestore database is in a United States multi-region and the account function runs in a United States region. Vercel hosts our website. Google and Vercel may process technical information in other countries where they operate. This means information may be processed outside your country, including outside Australia. Providers process information under their own terms and applicable arrangements. We may disclose information when required by law or necessary to address fraud, abuse or security incidents.
Retention and your controls
Device libraries remain until you delete them or clear the relevant browser or extension storage. Synced libraries remain while needed to provide your account’s sync service, until you use deletion controls or request removal. Older Drive snapshots may be removed after newer snapshots are saved; this is not a permanent version-history service.
Use Export to keep an independent copy. Delete cloud copies removes the selected edition’s database library and Drive snapshots and pauses sync, but retains local libraries. It does not delete your whole account or consent history. Close other open panels before deleting cloud copies; an upload already in progress may require repeating deletion. Signing out, disabling sync or revoking Google access does not by itself erase existing stored copies.
For account deletion, access, correction or deletion of remaining personal information, email us. We may need to verify your identity. Consent records and technical records may be retained where reasonably necessary for security or legal obligations; deletion from provider backups may follow their retention schedules. You can also revoke Noding’s access through Google Account connections.
Other platforms and browser storage
When you insert or run a workflow in Figma Weave, ComfyUI or a connected model provider, those services handle the content under their own policies and may charge for execution. Noding’s private library sync does not itself run those workflows. Browser storage supports device libraries and preferences. The current website source does not include advertising trackers; hosting services may keep operational request logs.
Security, questions and changes
We use authenticated account access, encrypted network connections and database access controls, but no storage system can be guaranteed secure. Contact us to report a concern, request a correction or make a privacy complaint. We will review your request and respond; you may also contact the privacy regulator available in your jurisdiction. For Australian privacy information, visit the OAIC.
We will update this policy when practices change and identify the revision date. Material new uses of personal information will be explained and consent requested where required.