Privacy Notice
Effective July 20, 2026
NEXT_PUBLIC_LEGAL_NAME and NEXT_PUBLIC_LEGAL_ADDRESS before public launch and obtain legal review.Who operates Nala
This notice applies to the Nala website and Nala desktop application operated by the Nala project operator (“Nala,” “we,” or “us”). Contact us at support@nalaos.dev.
The important local-first distinction
The downloadable application is local-first. Nala does not currently provide a managed model backend. Your source code, terminal contents, prompts, model outputs, file paths, and project names are not sent to this website or its analytics system.
If you configure a third-party model, coding agent, terminal tool, or account, that provider may receive information under its own terms and privacy notice. Nala cannot control a provider you choose to run.
Information you choose to provide
- Contact forms: name, email, company, message, source page, and newsletter choice.
- Newsletter: email address, confirmation token, and confirmation status.
- Optional website account: email, name if provided, hashed session token, and account timestamps.
- Optional purchases if enabled: product, amount, currency, status, and processor transaction identifiers. Stripe handles payment-card details; Nala does not store complete card numbers.
Website analytics and delivery evidence
Optional browser analytics is off until you choose Allow analytics. If allowed, we use a random first-party session identifier for up to 30 days and store normalized page paths, allowlisted campaign parameters, normalized referrer origin/path, locale, and coarse device, operating-system, and browser families. We record CTA and download intent. We discard query values other than allowlisted UTM campaign values.
We do not persist raw IP addresses or full user-agent strings. An IP address is used transiently to create a secret-keyed rate-limit digest; that digest cannot be used by the dashboard to recover the IP. Hosting and network providers necessarily process network metadata to deliver requests and may keep their own security logs.
Artifact delivery, generated installer requests, bounded installer outcomes, first observed launch, and update stages may be counted without browser analytics so we can operate a reliable release channel. Installer records use a random, short-lived install ID. Application records contain only the event, app and target versions, release channel, platform, desktop-or-CLI source, and an allowlisted status code. They contain no persistent client identifier or machine fingerprint. Set NALA_TELEMETRY=0 before running a shell installer, or run nala telemetry off after installation, to suppress these lifecycle reports.
If Google Analytics is configured, its script is also blocked until you allow analytics. We honor Global Privacy Control and Do Not Track by disabling optional analytics, even if a prior preference said otherwise.
Analytics preference
Current state: not chosen
A Global Privacy Control or Do Not Track signal always wins over the saved preference.
Local storage and cookies
| Name | Purpose | Duration |
|---|---|---|
| nala_analytics_consent | Local-storage preference you explicitly choose | Until cleared |
| nala_sid | Optional first-party analytics session; set only after consent | 30 days |
| nala_session | Essential, revocable account login if you request an account session | 30 days |
| nala_admin_session | Essential restricted operator access; not used for public visitors | 8 hours |
Why we use information
- Provide requested downloads, accounts, emails, support, and optional purchases.
- Protect the site, prevent abuse, diagnose bounded release failures, and keep downloads trustworthy.
- Measure consented acquisition and installation stages and improve the website.
- Meet legal obligations and enforce applicable agreements.
We do not sell personal information or use it for targeted advertising.
Service providers and disclosure
We use infrastructure providers for website hosting, PostgreSQL, private object storage, and network delivery. If configured, we also use Resend for requested email, Stripe for payments, and Google Analytics for consented measurement. They process information on our behalf or under their own published terms. We may also disclose information when required by law, to protect people or systems, during a business transfer, or with your direction.
Retention
Analytics events are retained for the configured period (180 days by default) and keyed rate-limit counters for no more than roughly 48 hours after use. Expired installer tokens are not stored as reusable credentials. Account, lead, email, and transaction records are kept while needed to provide the requested service, meet legal obligations, resolve disputes, or until a valid deletion request applies. Backups may age out on a separate operational cycle.
Your choices and requests
You can decline or later disable analytics above, enable Global Privacy Control or Do Not Track, unsubscribe using an email footer, sign out to revoke a browser session, and request access, correction, deletion, or portability where applicable by emailing support@nalaos.dev. We may need to verify a request and may retain information where the law permits or requires it.
Security, transfers, and children
We use access controls, private storage, hashed or signed credentials, bounded inputs, and encrypted transport in production. No system can guarantee absolute security. Our providers may process information in the United States or other locations where they operate. Nala is not directed to children under 16, and we do not knowingly collect their personal information.
Changes and contact
We will post material changes here and update the effective date. Questions or privacy requests can be sent to support@nalaos.dev.