Nomi
🔒 Privacy

Privacy Policy

How we collect, use, and protect your data when you use Nomi.

Last updated: September 6, 2026

Nomi: Product Team Assistant is a Chrome extension that replaces your New Tab page and unifies tasks (Kanban), email, calendar, team chat, OKR, roadmap, PRD documents, research (Investigate), page analysis, and usability testing in one workspace.

Our guiding principle is Local-First: until you enable sync or connect an account, nearly all of your data stays only on your own device (chrome.storage.local) and is never sent to our servers.

1. Account Data

You may sign up with email + password, or sign in with a Google account (OAuth2). Passwords are never stored or transmitted in plaintext (bcrypt). Issued JWT tokens are stored only on your device and expire after 30 days. We do not use refresh tokens; after a token expires you sign in again. Tokens are never persisted server-side and expire automatically after 30 days.

2. Local Data (Local-First)

All app data (lists, tasks, notes, flowcharts, settings, OKR, roadmap, PRD, and Focus/Meet/Investigate sessions) is stored in the taskManagerData key inside Chrome local storage. By default this data stays on your device.

3. Cloud Sync (only with your consent)

If a change happens on both your device and the server, Nomi shows you a clear choice — keep your device version, keep the server version, or merge the two. Your local-only fields (auth, live sessions, caches) are always preserved.

If you sign in, Nomi syncs your state with https://back.nomi.cam/api so it stays consistent across your devices. Sync is whole-document and authenticated with a JWT. Local-only fields — such as auth state, live sessions, and sensitive caches — are never synced.

4. Google Integrations (only when connected)

With your explicit consent, Nomi may connect to these Google services:

  • Gmail (gmail.readonly + gmail.labels + gmail.send): used only by the in-app email client. Exact operations: reading inbox/folder messages, applying/removing labels, and sending emails that the user themselves composed and clicked "send" on. We never perform permanent deletion; only read/archive flags are applied.
  • Calendar (calendar.readonly): read-only, to display events in the calendar view.
  • Tasks (tasks): two-way sync of task lists with Nomi columns.
  • Drive (drive.file): only files inside Nomi's dedicated Drive folder (not the entire Drive). This scope is non-sensitive.
  • Email address (userinfo.email): only to identify the account.

All of these are enabled only when you connect them in Settings and can be disconnected from your Google account at any time.

5. IMAP/SMTP Email (non-Google accounts)

For non-Google email accounts, the account password is encrypted at rest with AES-256-GCM on the server. The encryption key lives only on the server (environment variable) and is never sent to the client; the extension never receives the plaintext password and only references the account by its server id.

6. Investigate Collector

When an Investigate Mode session is active, a lightweight content script (collector) runs on web pages to capture research sources. Exact limits:

  • The script runs only while an Investigate session is active; otherwise it is completely inactive and no code executes.
  • No data is collected automatically or in the background. Every capture happens only in response to your direct interaction (e.g. selecting text or clicking "save").
  • It records the page URL, title, selected text, links, and your notes.
  • It never reads password fields or form values.

The https://*/* host permission is used solely for this optional, user-driven feature, in line with the principle of least privilege.

7. Usability Test Recording (participant role only)

If you join a usability test as a participant (via usability.nomi.cam or the companion extension), and only with your explicit opt-in consent:

  • Your interactions with the product page (clicks with normalized coordinates, scroll, focus changes, page errors, timer) are recorded. Typed form values and clipboard text are never stored.
  • With your optional consent: microphone audio and/or camera video, and gaze estimation from the camera — which is converted only to normalized 0–1 points (raw video never leaves the browser).

All of this data is sent only to the test facilitator (the person who created the link) and is buffered on your own device during the run. Retention is set by the facilitator, and you may request deletion of your data via privacy@nomi.cam.

8. Team Chat

Chat messages are exchanged between you and contacts you choose via a "Nomi Code". Optional end-to-end encryption (E2E) is supported for 1:1 conversations.

9. Anonymous Analytics

We use Google Analytics (anonymous, install/update events only, with a random client id) to improve the product. No task or email content is ever sent to analytics.

10. Sharing

You may share parts of your workspace with others by sharing your Nomi Code. Filtering is enforced server-side; sensitive data (passwords, tokens, email credentials) is never exposed to the viewer.

11. Permission Justifications

Full justifications for each permission are recorded in the Chrome Developer Dashboard. Summary:

  • storage: store app data on your device (Local-First).
  • alarms: periodic background sync, calendar-event reminders, and force-update checks.
  • identity: Google sign-in and retrieval of Google API tokens (only with your permission).
  • notifications: alert you about calendar events and reminders.
  • activeTab / scripting: run page-analysis and research-capture actions only on your direct interaction with the active tab; scripts are never run in the background without your consent.
  • tabs: identify the extension's own tabs and relay messages between internal parts of the extension.
  • sidePanel: open the "Today" view in the browser side panel.
  • host_permissions (https://*/*, http://*/*): used solely for two optional, user-driven features — (1) research-source capture (only while an Investigate session is active) and (2) usability-test recording (only in the participant role with explicit consent). In all other cases this permission is not exercised, and the extension follows least privilege.

12. Data Retention & Security

  • Communication with the server is over HTTPS with JWT authentication.
  • IMAP passwords are encrypted with AES-256-GCM; the key lives only on the server.
  • Large data (audio/images/screenshots) stays in IndexedDB on the device and is never part of sync.
  • Synced data is stored on a dedicated, access-controlled database.

13. Your Rights

  • You can sign out at any time; local data remains on your device.
  • Removing the extension deletes local data.
  • You have the right to request a copy or deletion of your synced data from the server, and to revoke Google access at any time.
  • Request any of the above via privacy@nomi.cam; we respond within 30 days.

14. Third Parties

  • Nomi server (back.nomi.cam) — sync and cloud features
  • Google (accounts.google.com, gmail/drive/calendar/tasks) — only with your permission
  • Google Analytics — anonymous stats

15. Google API Limited Use Compliance

Nomi's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements, and to the Chrome Web Store User Data Policy. Google user data is used only to provide the user-facing features described in the extension and is not used for advertising, profiling, data brokerage, or training generalized AI/ML models.

16. Contact

For any privacy question: privacy@nomi.cam
Website: nomi.cam