Privacy

Nomi is operated by OPENFLOW d.o.o., Kranjska cesta 4, 4240 Radovljica, Slovenia. Registration number 9570675000, VAT SI77412770. That company is the controller of the personal data described here. Nomi is an AI marketing strategist for Meta advertising. This notice explains what we store, why, who else processes it, and how to get it back or get rid of it.

Last updated 30 August 2026

What we store

Your account. Your email address and your name. Passwords are handled by our authentication provider and stored only as a hash, and we never see or keep the password itself.

Your sign-ins. A record of when you signed in, changed your password or were invited, kept by our authentication provider so an account can be looked into when something goes wrong. It carries no IP address.

Your brand. Everything you or Nomi puts into a brand: its name, positioning, tone of voice, audiences and personas, colours and typefaces, competitors, the logo you upload, and any documents you add as knowledge sources. Where Nomi proposed a value rather than you typing it, we also store where it read that value from, so you can see why it thinks what it thinks.

Your products and markets. Product details, the markets you sell into, and the per-market facts that differ: price, offer, claims, landing page.

Your conversations. The messages you send Nomi, its replies, and any images or documents you attach. Attachments are stored as files.

What Nomi makes. Generated images, the prompt behind each one, and a set of labels describing the strategy it chose. We also record what each generation cost, so we can meter usage.

Memory. Nomi keeps a per-brand memory of things worth remembering between conversations. You can read, edit, pin and delete every item of it yourself.

Support. If you report a bug we store the report and any screenshot attached.

What we do not store

We do not store payment card details. We do not buy personal data about you from anyone, and we do not build advertising profiles of you.

Nomi's competitor research reads advertisements that platforms already publish publicly. It is not connected to your personal social accounts and does not read anything private.

Why we are allowed to

Almost all of it is stored because it is what running the service you signed up for takes, and the lawful basis for that is our contract with you: your account, your brand, your products and markets, your conversations, what Nomi makes, its memory and the support you ask for.

Three things sit on our legitimate interest instead, because they are not what you asked for and they are what keeps the service standing up: keeping it secure and finding out why it broke, keeping the competitor research current, and recording what a generation cost so that usage can be metered. You can object to any of the three, and the section on your rights says how.

Where the law requires a record to be kept, an invoice being the obvious one, that requirement is the basis for that record rather than either of the above.

We do not rely on your consent for anything described here, we make no decision about you by automated means that has a legal effect on you, and we do not process any of the special categories of data the law singles out.

Who else processes it

Running Nomi means passing some of this to companies that do one job each:

  • Supabase: database, authentication and file storage. Hosted in the EU.
  • Vercel: hosting, and the gateway every model call is routed through.
  • Anthropic: the model behind Nomi, and the per-brand memory store. Your conversations and brand context are sent so it can answer.
  • OpenAI: the standby model. It answers when Anthropic cannot, and it runs the web searches Nomi makes, so the same conversation can reach it.
  • Ideogram: image generation. Receives the prompt and any reference image you attached for that render.
  • ScrapeCreators: collects the public advertisements used for competitor research.
  • Apify: takes the screenshot of your website when Nomi first reads your brand.
  • Stripe: payments. Receives your email address and what you bought. Card details go to Stripe directly and never reach us.
  • Resend: sends the account emails, and receives the address to send them to.
  • Google: only if you choose to sign in with a Google account, in which case Google tells us your email address and your name.
  • Upstash: the short-lived store that lets a reply finish arriving after you reload the page. It holds that reply for minutes and nothing else.

Each processes on our instructions and for no purpose of its own.

Where it goes

Supabase holds the database, the files and the accounts in the EU, and that is where your data lives.

The others are in the United States or may process there, so using Nomi means some of your data is transferred outside the EU. Those transfers run on the European Commission's standard contractual clauses, or on the EU-US Data Privacy Framework where the company is certified under it. Ask us and we will tell you which one covers a given company.

Cookies and what your browser keeps

Nomi sets no advertising cookies, runs no analytics and carries no third-party tracker, on nomigrowth.com or in the app. There is nothing here to consent to, which is why nothing asks you to.

What there is:

  • A sign-in cookie in the app, written when you sign in and cleared when you sign out. Without it the app cannot tell that it is you.
  • A cookie holding whether the sidebar is collapsed, so the app opens the way you left it.
  • A few settings kept in your browser's own storage: the theme, your recent searches, which notices you have dismissed and which sessions you have already opened. They stay in that browser and are never sent to us.

nomigrowth.com stores nothing at all. It asks the app once whether you are signed in, so that the button in the corner can say Sign in or Open Nomi, and the answer to that question is a yes or a no.

How long we keep it

For as long as your account exists. Delete a brand and everything under it goes with it: its conversations, its images, its documents and its files, including the stored images themselves and not merely the rows pointing at them. Delete your account and the same happens to every brand only you were in; a brand you shared with someone else survives for them.

One exception, deliberately: a record that a charge happened outlives the brand it was for, because we have to be able to account for what was billed. It keeps no brand content.

The companies in the list above keep their own working copies on their own retention windows, which are short and which we do not control: a message a model was sent, a reply still on its way back to you, a record of a payment. Deleting your account here does not reach into them, so if you need one of those cleared as well, write to us and we will ask on your behalf.

Your rights

You can ask us for a copy of what we hold, ask us to correct it, ask us to delete it, ask for it in a portable file, ask us to restrict what we do with it, or object to the processing that runs on our legitimate interest. Asking costs nothing, and we answer within 30 days.

Most of it you can already do yourself from inside the app: the brand hub edits it, the memory tab edits and deletes it, and both a brand and an account can be deleted from the app without asking us.

For anything else, write to privacy@nomigrowth.com.

If you think we have handled your data wrongly, you can complain to the Slovenian supervisory authority, the Information Commissioner (Informacijski pooblaščenec, Dunajska cesta 22, 1000 Ljubljana, gp.ip@ip-rs.si), or to the authority where you live. We would rather you came to us first.

Changes

If this notice changes materially we will say so in the app rather than quietly edit the page.

Questions about any of this: privacy@nomigrowth.com