Nook
  • Features
  • Self-hosted
  • Download
  • Docs
Sign in
Menu
Features Self-hosted Download Docs Sign in
Create account
Home/Legal & privacy

Counsel-reviewable engineering draft

Nook Privacy Policy Draft

Draft privacy disclosures for the website, Cloud, customer Portal, support, and optional connected telemetry.

Not effective or legally approved

Qualified legal approval and a recorded effective version are required before commercial launch.

Document code
privacy_policy
Version
2026-08-02-draft.1
Locale
en-US
Status
engineering_draft_counsel_review_required
Product scope
Nook Cloud, Self-host Nook, Customer Portal, Marketing website
Canonical SHA-256
8fb245146553ae55c86018255d83a82b9ac9efaa42330437126e03abae704829

Status and roles

This is an engineering data map, not an approved privacy notice. The contracting entity, contact point, legal bases, jurisdictions, transfer mechanisms, controller/processor allocations, and statutory retention duties require qualified review.

The Portal is expected to act as controller for customer-account, commercial, licensing, security, and support-contact records. Nook Cloud role allocation depends on the final service and DPA. A self-host customer controls content and local member data inside its own deployment.

Self-hosted boundary

  • Messages, files, local member directories, local sessions, and local credentials do not flow to the Portal for licensing.
  • The Portal stores account, organization, billing, agreement, entitlement, deployment-binding, download, support-consent, notification, and sanitized audit metadata needed for those purposes.
  • Connected telemetry is not required for licensing. Any future telemetry must be opt-in, documented, data-minimized, and revocable.
  • Air-gapped deployments require no outbound telemetry or online Portal connection at runtime.
  • Support receives metadata only unless the customer creates an explicit scoped, expiring, revocable support grant; that grant does not create impersonation or local membership.

Rights and retention gate

Access, correction, deletion, portability, objection, restriction, complaint, and authorized-agent handling require a verified request workflow and jurisdiction-specific review. The engineering inventory identifies candidate records and actual technical TTLs; it does not promise deletion where no production erasure worker exists.

Security audit records currently carry a 90-day deletion timestamp. Short-lived sessions, challenges, enrollment capabilities, activation codes, and notification jobs have bounded expiries. Commercial records, agreements, entitlement history, and legal holds need an approved schedule before launch.

Owner-published no-payment production documents

These immutable excerpts are effective only for the product and locale shown. Their authority is the disclosed-risk global Platform Owner workflow; independent legal, finance, tax, source-rights, and security approval is not claimed.

saas · en

Nook records customer account, organization, billing, agreement, entitlement, subscription, and security-audit data for the production service. This owner-published disclosure is not represented as an independently approved legal privacy notice. The Portal binds acceptance to this exact content digest, customer account, organization, product, locale, and version.

Version
2026-08-17-owner-production.1
Content SHA-256
293b349ca79fd982ee7e7dbc31bf01fb7f43fdec84ee9365ce21f4741b6024f5

saas · cs

Nook pro produkční službu eviduje údaje o zákaznickém účtu, organizaci, fakturačním profilu, souhlasech, oprávnění, předplatném a bezpečnostním auditu. Toto zveřejnění vlastníka není vydáváno za nezávisle schválené právní oznámení o ochraně osobních údajů. Portál váže přijetí na přesný digest tohoto obsahu, zákaznický účet, organizaci, produkt, jazyk a verzi.

Version
2026-08-17-owner-production.1
Content SHA-256
2e767dd4cc878ae4292d3d7b7829aa44d8167e3544f4422142ae85651891f89c

self_hosted · en

Nook records customer account, organization, billing, agreement, entitlement, deployment-binding, download, support-consent, and security-audit data for the self-hosted production service. Messages, files, local members, and local credentials do not flow to the Portal for licensing. This owner-published disclosure is not represented as an independently approved legal privacy notice.

Version
2026-08-17-owner-production.1
Content SHA-256
84c653b108c2f6022caad3b17d7eb35d9e67e98732533590b1bd9e02a7b6db7c

self_hosted · cs

Nook pro self-hosted produkční službu eviduje údaje o zákaznickém účtu, organizaci, fakturačním profilu, souhlasech, oprávnění, vazbě nasazení, stahování, podpoře a bezpečnostním auditu. Zprávy, soubory, místní členové ani místní přihlašovací údaje kvůli licencování do Portálu neproudí. Toto zveřejnění vlastníka není vydáváno za nezávisle schválené právní oznámení o ochraně osobních údajů.

Version
2026-08-17-owner-production.1
Content SHA-256
091cb34e00e27cb50b90501f0400883244c06b4f7f550c98f4772dfc76a60b14

This exact draft can be referenced by document code, version, locale, product scope, and digest. A future approved version must use a new immutable version and record whether existing customers must reaccept it.

Review every legal and policy draft
Nook

Calm collaboration for teams and communities.

Product

Features Download Self-hosted

Resources

Documentation Self-hosting guide Operations & updates Build a bot Bot API

Legal

All legal drafts Cloud Terms Self-host License Privacy DPA Subprocessors Acceptable Use Support Security OSS Notices
© 2026 Nook Team. Product terms depend on the selected Nook service. Built with ♥ for calm teams.