NoLabs
Data Protection

Privacy Notice

How nolabs, Inc collects, uses, shares, and protects personal data.

Version 2.3Last updated: 27 July 2026

About this notice

This notice explains how nolabs, Inc collects, uses, shares, and protects personal data.

It applies to:

  • Visitors to nolabs.ai and nono.sh and any subdomain or successor domain we operate
  • Users of the registry.nono.sh hosted service who create an account
  • People who contact us through forms, email, chat, or in-person meetings
  • Design partners, prospects, and customers with whom we discuss our products
  • Users of the nono open-source runtime who have telemetry enabled
  • Applicants for open roles at nolabs

It does not apply to:

  • Data that customers process inside their own environments using nono (that data does not reach us)
  • Employees and contractors of nolabs (covered by our internal Employee Privacy Notice)
  • Third-party websites or services we link to (their own privacy notices apply)

If any part of this notice is unclear, write to us at privacy@nolabs.ai and we will respond within a reasonable time.

Who we are

nolabs, Inc is a Delaware corporation. Registered office: 251 Little Falls Drive, Wilmington, DE 19808, United States. Correspondence address: 800 N. King Street, Suite 304-2335, Wilmington, DE 19801, United States. nolabs, Inc is the controller of personal data processed under this notice.

nolabs AI Ltd is a wholly-owned UK subsidiary of nolabs, Inc, incorporated in England and Wales (formerly Always Further Ltd). Company number 16866578. Registered office: 55 Station Road, Beaconsfield HP9 1QL, United Kingdom. nolabs AI Ltd provides development and operational services to nolabs, Inc as a processor. It is not a controller of the personal data covered by this notice; however, it provides a UK point of contact for data subjects and supervisory authorities in the United Kingdom and European Economic Area.

We have not appointed a Data Protection Officer because our processing does not require one under UK GDPR Article 37 or EU GDPR Article 37. All privacy inquiries can be sent to privacy@nolabs.ai.

What personal data we collect

Information you provide directly

  • Contact form and email: the name, email address, company, job title, and message content you provide when you get in touch. Our contact form is processed by Formspree on our behalf; submissions are forwarded to our internal Slack workspace and, where a business relationship follows, to our HubSpot customer relationship management (CRM) system.
  • Registry accounts: when you register an account at registry.nono.sh, we collect the identifying details you provide (typically name and email address) and any additional information required to operate the service.
  • Design partner and prospect communications: names, business contact details, employer, role, and the content of discussions we have about your evaluation or use of our products.
  • Careers applications: information you provide when you apply for a role. Handled under our separate recruitment process.
  • Meeting scheduling and calls: if you book time with us or dial in to a call, the information you supply for that purpose.

Information collected automatically

  • Server logs: our hosting provider, Vercel, records standard technical information including IP address, browser user agent, request path, referrer, and timestamp.
  • Website analytics: we use Fathom Analytics for cookieless, aggregated website analytics, and a small in-house analytics pipeline recording aggregate, non-identifying page and event counts.

Information from our product

  • nono update-check ping: the nono open-source runtime performs a background update check against update.nono.sh so that it can prompt users to upgrade when a new version is available. The check transmits:
    • a randomly-generated installation UUID stored locally at $XDG_STATE_HOME/nono/update-check.json (typically ~/.local/state/nono/update-check.json). The UUID is generated on first run, is not linked to any account or personal information, and exists solely to let the update service distinguish repeat pings from a given installation;
    • the current nono version, operating-system platform, and CPU architecture;
    • whether nono is running in a continuous-integration environment, and how nono was installed.

    The ping does not transmit file paths, agent inputs, credentials, or telemetry from the guarded process.

  • Registry request headers: requests that nono makes to our public package registry at registry.nono.sh carry the same installation UUID (as an X-Nono-UUID header) plus platform, architecture, CI-environment, and install-source headers. This allows us to aggregate registry usage by version, platform, and install channel.

    Telemetry is enabled by default. You can disable it with either method below:

    • Environment variable (per-shell or CI):
      export NONO_NO_UPDATE_CHECK=1

      Any value works — including an empty string — because the code only tests whether the variable is set.

    • Config file (persistent, per-user) $XDG_CONFIG_HOME/nono/config.toml (typically ~/.config/nono/config.toml):
      [updates]
      check = false

    Either opt-out prevents the update.nono.sh update-check network call and prevents the X-Nono-UUID installation identifier being sent on requests to registry.nono.sh, whether or not an installation UUID was previously generated. To also remove the stored UUID from disk, delete the state file:

    rm -f ~/.local/state/nono/update-check.json

    Pack update hints respect the same opt-outs and have an additional opt-out via NONO_NO_PACK_UPDATE_HINTS=1.

    Note on residual identifiers. Even with the update-check opt-out enabled, registry requests to registry.nono.sh currently include coarse platform, architecture, CI-environment, and install-source headers, and /pull requests include a coarse pull-reason header. These carry no per-install identifier.

    Where enabled, the update-check ping and registry requests are processed by our product analytics processor, PostHog, hosted in the European Union.

  • Registry (registry.nono.sh) product events: when you are signed in to the registry hosted service, we collect product usage events associated with your account, such as pages visited, features used, and actions taken within the service. These events are identifiable because they are linked to your registered account. Product events are processed by PostHog hosted in the European Union.

Information from third parties

  • Business enrichment: for prospects, we may enrich publicly available business information to prepare for meetings.
  • Referrals: if someone introduces you to us, we may hold the introduction context and the referrer's name.

We do not knowingly collect any special categories of personal data (racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic or biometric data, health, sex life, or sexual orientation). Please do not send us such information.

How we use personal data

We process personal data for the purposes and on the legal bases set out below.

PurposeDataLegal basis
Operate and secure our websites and servicesServer logs, IP, technical metadataLegitimate interests
Understand how our websites are usedAggregated Fathom / in-house analyticsLegitimate interests
Respond to inquiriesContact details, message contentLegitimate interests
Operate the registry and administer user accountsAccount details, product usage eventsPerformance of a contract
Understand how the registry is used, and prioritise improvementsProduct usage events linked to accountsLegitimate interests; contract
Discuss products with prospects and design partnersBusiness contact details, communication historyLegitimate interests; contract
Enter into and perform commercial agreementsBusiness contact details, agreement recordsContract; legitimate interests
Recruit for open rolesApplication content, interview notesLegitimate interests; pre-contractual steps
Comply with legal, tax, accounting obligationsFinancial records, correspondenceLegal obligation
Prompt users to upgrade nono; aggregate registry usage by platformInstallation UUID, version, OS, architecture, CI-flag, install source (no PII)Legitimate interests; user may disable at any time

Where we rely on legitimate interests, we have carried out a balancing test. You have the right to object at any time — see Your rights below.

We do not:

  • Sell personal data
  • Share personal data with third-party advertisers
  • Serve targeted advertising on our sites
  • Use personal data to train, fine-tune, or improve AI or machine learning models

Who we share personal data with

We share personal data only with the following categories of recipient.

Service providers (processors) acting on our behalf:

ProviderRoleLocation
Vercel Inc.Website and application hostingUnited States
Fathom Analytics (Conva Ventures Inc.)Cookieless website analyticsCanada
PostHog Inc.Product analytics for nono opt-in telemetry and the registry hosted serviceEuropean Union
Formspree Inc.Contact form intakeUnited States
Slack (Salesforce, Inc.)Internal team communicationUnited States
HubSpot, Inc.Customer relationship managementUnited States
Google Cloud PlatformCloud storage and servicesUnited States and other regions
Amazon Web Services, Inc.Cloud hosting and servicesUnited States and other regions
nolabs AI LtdDevelopment and operational services to nolabs, IncUnited Kingdom

Each processor is bound by a data processing agreement (or equivalent) requiring them to process personal data only on our instructions and to apply appropriate security safeguards.

Professional advisers. Our accountants, lawyers, insurers, brokers, and auditors, on a need-to-know basis.

Corporate transactions. In a financing, acquisition, merger, or sale, we may share personal data with prospective counterparties and their advisers under confidentiality obligations.

Legal obligations. Government authorities, regulators, courts, and law enforcement where we are required by law to disclose. We will contest inappropriate requests where we can lawfully do so.

International data transfers

Some of our processors are located in the United States or Canada. Where we transfer personal data of UK or EEA residents outside those regions, we rely on adequacy decisions where available (for example, transfers to Canada under Fathom Analytics), Standard Contractual Clauses combined with the UK International Data Transfer Addendum, or other legally recognised mechanisms.

Product analytics processed by PostHog are hosted in the European Union and therefore do not require transfer safeguards for UK/EEA data subjects.

A copy of the safeguard applied to any specific transfer is available from privacy@nolabs.ai.

How long we keep personal data

Data categoryRetention
Server logs90 days
Aggregated analytics (Fathom, in-house)Aggregate only; no individual identifiers
Contact form submissions and one-off inquiries24 months, unless a relationship is established
Registry accounts and product eventsDuration of the account; 6 months after account deletion, then removed from active systems
CRM recordsDuration of relationship, plus 7 years for tax and legal records
Recruitment applications12 months if unsuccessful, unless you consent to a longer period
Signed contracts and correspondence7 years from expiry, or longer where required by law
nono update-check pings and registry request headersRetained by PostHog for the standard PostHog retention period. Installation UUIDs are tied to the installation, not to any identified individual, and persist for the life of the installation unless the user opts out and deletes the local state file.

Your rights

Depending on where you are resident, you have the following rights over your personal data. We honour these rights regardless of the jurisdiction in which you are located.

Under UK GDPR and EU GDPR:

  • Right of access — a copy of the data we hold about you
  • Right to rectification — to correct inaccurate data
  • Right to erasure — to have data deleted in specified circumstances
  • Right to restriction — to limit our processing in specified circumstances
  • Right to data portability — to receive data in a portable format
  • Right to object — to processing based on legitimate interests, at any time
  • Right to withdraw consent — where we rely on consent
  • Rights relating to automated decision-making — we do not make solely automated decisions with legal or similarly significant effects

US state privacy laws:

Under applicable US state privacy laws (CCPA/CPRA and comparable state laws as they come into force), you may have the right to know, correct, delete, and receive a copy of your personal data, and to opt out of sale and targeted advertising. We do not sell personal data or use it for targeted advertising.

To exercise any of these rights, contact privacy@nolabs.ai. We will respond within one month (UK/EU GDPR) or 45 days (US state laws). We may need to verify your identity before responding.

Cookies and similar technologies

  • Fathom Analytics is cookieless by design and does not set persistent identifiers.
  • Vercel may set functional cookies for load balancing and security. These are strictly necessary.
  • The registry.nono.sh hosted service may set a session cookie once you have signed in, in order to maintain your session.
  • We do not use advertising, retargeting, or third-party marketing cookies on our marketing sites.

Where cookies require consent under applicable law, we present a cookie choice on first visit and honour the choice for subsequent visits.

Children's data

Our services are not directed at children. We do not knowingly collect personal data from anyone under the age of 16 (or the applicable age in your jurisdiction — 13 in the United States under COPPA and 13 in the United Kingdom for information society services). If you believe a child has provided personal data to us, contact privacy@nolabs.ai and we will delete it.

Automated decision-making

We do not make decisions with legal or similarly significant effects based solely on automated processing.

Security

We apply appropriate technical and organisational measures to protect personal data, including encryption in transit, access controls, cloud infrastructure and application logs, and staff training under our internal Data Protection Policy, Data Security and Acceptable Use Policy, and AI Acceptable Use Policy. Our flagship product, nono, is undergoing a third-party source-code security audit by X41 D-Sec through the Open Source Technology Improvement Fund (OSTIF).

No system is perfectly secure. If you believe your data has been compromised, contact us at privacy@nolabs.ai.

Changes to this notice

Material changes will be highlighted at the top of the notice and, where appropriate, notified through the site or by email. The "Last updated" date at the top always reflects the most recent revision.

Contact and complaints

Email: privacy@nolabs.ai

Postal (US, controller): nolabs, Inc, 800 N. King Street, Suite 304-2335, Wilmington, DE 19801, United States

Postal (UK/EU point of contact): nolabs AI Ltd, 55 Station Road, Beaconsfield HP9 1QL, United Kingdom

If you are not satisfied with our response, you have the right to complain to a supervisory authority:

  • United Kingdom: the Information Commissioner's Office (ico.org.uk), tel. 0303 123 1113
  • European Economic Area: the data protection authority in your country of residence
  • United States: your state attorney general or the relevant state privacy regulator

We would prefer to hear from you first so we can address any concerns directly.


This privacy notice is issued by nolabs, Inc, a Delaware corporation.