โ† Back to projectnobi.ai

Privacy Policy

Last updated: March 25, 2026

The short version: Your data is encrypted at rest (AES-128, server-side), you own it, and you can delete it anytime. We don't sell your data. Ever.

โš ๏ธ Testnet Notice: Project Nobi is currently in testnet phase (Bittensor SN272). The service is under active development and testing. Data handling practices described in this policy are subject to change. During the testnet phase, data may be reset and service availability is not guaranteed. Use at your own risk.

This Privacy Policy explains how Project Nobi ("we", "us", "our") collects, uses, stores, and protects your personal data. This policy complies with GDPR Articles 13 & 14, UK GDPR, CCPA, and COPPA.

1. Data Controller

Project Nobi is the data controller for personal data processed through the Nori service.

2. What Data We Collect

2.1 Data You Provide Directly

CategoryExamplesPurpose
Account informationDisplay name, email addressAccount creation and communication
Conversation contentMessages, voice transcriptions, image descriptionsProviding the companion service
Memory dataFacts and preferences Nori learns from chatsPersonalisation and continuity
Feedback and supportBug reports, feature requests, ticketsService improvement
Account informationUsername, platform ID (Telegram/Discord)Service authentication

2.2 Data Collected Automatically

CategoryExamplesPurpose
Usage statisticsFeatures used, session length, message frequencyService improvement
Device informationDevice type, OS, app versionCompatibility and debugging
Technical dataIP address (hashed), error logsSecurity and performance
Cookies and local storageSession tokens, preferences, consent flagsAuthentication and UX

2.3 What We Do NOT Collect

3. Legal Basis for Processing (GDPR)

Processing ActivityLegal Basis
Providing the companion serviceContract (Art. 6(1)(b))
Memory storage and personalisationContract (Art. 6(1)(b))
Service operationContract (Art. 6(1)(b))
Safety filtering and abuse preventionLegitimate interests (Art. 6(1)(f))
Service analytics and improvementLegitimate interests (Art. 6(1)(f))
Marketing communicationsConsent (Art. 6(1)(a)) โ€” opt-in only
Legal complianceLegal obligation (Art. 6(1)(c))

4. How We Use Your Data

We do NOT: sell your data, use your conversations to train AI without opt-in consent, or share data with advertising networks.

5. Data Storage and Security

All conversation data and memory data is encrypted using AES-128 encryption before storage. Encryption keys are derived from your account credentials and never stored in plaintext. Data in transit is protected by TLS 1.3.

5.1 Decentralised Storage (Bittensor Network)

Nori operates on the Bittensor decentralised AI network. Messages may be processed by network participants ("miners") to generate AI responses. Data transmitted to miners is:

Honest disclosure: Miners decrypt conversation content during response generation โ€” they process message text in order to produce AI responses. Stored memories remain encrypted at rest (AES-128, server-side). End-to-end TEE encryption (which prevents miners from seeing plaintext) is code-complete and deploying to production โ€” it is not yet live for all users.

5.2 Data Architecture: Decentralised AI, Centralised Compliance

The AI inference layer (miners generating responses) is decentralised across the Bittensor network. However, all legal and compliance data is stored centrally on Project Nobi's own infrastructure โ€” never on miners.

This includes:

This architecture ensures that your data rights (access, erasure, portability) can always be fulfilled regardless of the state of the decentralised network. GDPR requires a data controller โ€” that is Project Nobi. We will always operate the application layer and at least one validator to ensure legal compliance.

6. Data Sharing

RecipientPurposeSafeguards
Bittensor minersAI response generationMiners process conversation content during response generation; stored data encrypted at rest (AES-128)
Cloud infrastructureHosting and storageData processing agreements; encrypted data
Legal authoritiesLegal complianceOnly when required by law or court order

We do NOT share data with advertising networks, data brokers, social media platforms, or any third party for marketing purposes.

7. Your Rights

7.1 GDPR Rights (EU/UK residents)

7.2 CCPA Rights (California residents)

7.3 How to Exercise Your Rights

8. Data Retention

Data CategoryRetention Period
Active account dataWhile your account is active
Inactive account dataAuto-deleted after 12 months of inactivity
Deleted account dataPermanently deleted within 30 days
Safety and abuse logs12 months
Anonymous analytics12 months then permanently deleted
Support tickets24 months then anonymised

9. Children's Privacy

10. Cookie Policy

TypePurposeDuration
Essential cookiesAuthentication, session managementSession or up to 30 days
Preference storage (localStorage)Theme, language, consent flagsPersistent until cleared
Analytics cookiesAnonymous usage analyticsUp to 12 months

We do not use advertising or tracking cookies. We respect the "Do Not Track" (DNT) browser signal.

11. International Data Transfers

Project Nobi is based in the United Kingdom. For EEA users, transfers to the UK are covered by the UK Adequacy Decision. Data transferred to Bittensor miners globally is encrypted in transit (TLS 1.3) and at rest (AES-128). Miners process conversation content during response generation โ€” end-to-end TEE encryption is code-complete and deploying to production.

12. Data Breach Procedures

In the event of a personal data breach:

To report a security vulnerability: security@projectnobi.ai

13. Data Protection Officer

We have appointed a Data Protection Officer to oversee GDPR compliance.

DPO Contact: dpo@projectnobi.ai

14. Professional Advice Disclaimer

โš ๏ธ Nori does NOT provide professional advice of any kind.

Nori is a personal AI companion for general conversation and information purposes only. Nothing Nori communicates constitutes financial, investment, tax, legal, medical, mental health, or any other professional advice.

All information and opinions shared by Nori are for general reference only. Always consult a qualified professional (financial advisor, lawyer, doctor, therapist, etc.) for matters specific to your situation.

By using Nori, you acknowledge that Nori's responses are not a substitute for professional advice.

15. Changes to This Policy

We may update this policy periodically. Material changes will be communicated with at least 14 days' notice via email or in-app notification. The latest version is always at projectnobi.ai/privacy.

16. Contact Us

GDPR Articles 13 & 14 compliant ยท UK GDPR ยท CCPA ยท COPPA โ€” Last updated March 30, 2026