Norn is operated by Vlad Gorokhov, Praça de Bocage 67, 2900-276 Setúbal, Portugal. For privacy questions or requests, email privacy@norn.so or write to that address. This policy covers our website, documentation, Norn Cloud, and communications with us.
We do not sell customer data, use it for advertising, or use it to train AI models. AI features use customer-provided credentials, and coding runners run on customer-provided machines. Connecting an external service can send data to that service, as described below.
1. Our role and your workspace's role
We act as a data controller for information we use to operate our relationship with you, manage accounts, answer enquiries, secure the service, and understand use of our public website. This means we determine the purposes and means of that processing.
For personal data in a workspace that we host on a customer's behalf, that customer normally acts as controller and we act as processor. If the customer is itself a processor, we act as its subprocessor. The Data Processing Agreement governs that processing. The workspace owner or administrator determines who can access the workspace, which integrations are connected, and how its content is used. Their own privacy information may also apply.
A self-hosted Norn installation is operated by its host. We do not receive its workspace content simply because it runs Norn. Contact that host about its data practices. If you visit our website or send us support information, this policy applies to that interaction.
2. Information we process
- Account and profile information: email address, display name, avatar, timezone, account status, authentication information, and workspace memberships. Passwords are stored as hashes, not plaintext. Identity providers can supply identifiers and profile attributes when you use single sign-on.
- Workspace content: projects, issues, descriptions, comments, documents, attachments, member details, activity history, imports, and other information you or other authorised users submit. This can include personal data about colleagues, customers, and people who do not have a Norn account.
- Agent and integration information: instructions, conversation content, provider configuration and credentials, tool inputs and outputs, repository connections, runner identifiers, execution events, transcripts, logs, artifacts, reviews, and preview access information, depending on the features and retention settings you use.
- Security and technical information: IP addresses, user-agent and device information, session times, sign-in attempts, API activity, audit events, request details, errors, and performance measurements. Approximate session location may be derived from an IP address when a geolocation database is configured.
- Communications: messages you send us, the contact details needed to reply, and service emails such as invitations, verification messages, security notices, and notifications. Notifications may contain workspace names, issue titles, summaries, and links.
- Website analytics: pages and referring sites, outbound-link clicks, browser and operating-system categories, device categories, and approximate location, collected through our self-hosted Plausible installation.
Information comes from you, workspace members and administrators, the services you connect, and your interaction with our systems. You choose what to place in free-text fields and files. Avoid submitting sensitive personal information that is unnecessary for your work. Norn Cloud is free and has no payment checkout; we do not collect payment-card details for using it.
3. Purposes and legal bases
For processing where we are controller, we use the following legal bases under the GDPR:
- Providing the service you request: creating and administering your account, authenticating you, and responding to service requests, where necessary to perform our contract with you or take steps you request before entering it.
- Running an organisation's account: communicating with its users and administrators and managing the service relationship based on our legitimate interests and those of the organisation, where the contract is with the organisation rather than you.
- Security, reliability, and support: detecting abuse, investigating errors, operating infrastructure, and resolving support requests based on our legitimate interests in protecting users and providing a working service.
- Understanding our public website: limited, cookieless audience measurement based on our legitimate interest in understanding which pages are useful. We do not use this information for advertising or cross-site profiling. Where applicable law requires consent for a particular use, that use requires consent.
- Legal obligations and claims: complying with applicable law and valid legal requests, and retaining information necessary to establish, exercise, or defend legal claims. The basis is the applicable legal obligation or our legitimate interest in protecting legal rights, as appropriate.
Workspace content processed on a customer's behalf is handled under that customer's instructions and DPA; the customer is responsible for the legal basis for its use of that content. Providing account and authentication information is necessary to use the relevant features. Optional profile fields, integrations, and support submissions are your choice.
4. Cookies, browser storage, and diagnostics
The app uses session cookies to keep you signed in and cookies to remember interface preferences, including your last workspace, expanded navigation, panel sizes, and issue-list display settings. Browser storage also remembers local interface choices. Session cookies expire with the session; preference cookies can persist for up to a year, and local storage remains until it is cleared or replaced. You can clear or block storage in your browser, although doing so can sign you out or prevent features from working.
Our public website loads Plausible from plausible.hexmere.com, which we operate ourselves. Plausible does not use analytics cookies. It processes request information, including an IP address and user agent, to derive limited statistics and a daily visitor identifier rather than a persistent cross-site identity. The analytics script also measures outbound-link clicks and page fragments. This is separate from infrastructure access and security logs, which can contain IP addresses. See Plausible's explanation of its measurement method.
The Cloud app sends error and performance reports to our self-hosted Sentry installation at events.hexmere.com. Reports can contain diagnostic details such as request paths, browser information, stack traces, and timing. The application disables collection of user-profile information, cookies, HTTP bodies, and stack-frame variables, and filters authentication query parameters. These controls reduce collection; they are not a guarantee that no personal data can appear in an error. Session replay is not enabled in our Cloud deployment configuration.
5. Who receives information
- Your workspace and chosen recipients. Members and administrators see information according to their access. People receiving your notifications or a preview share link can receive the content you make available to them.
- Infrastructure providers. Hetzner supplies infrastructure and object storage for our hosted systems in Germany. Cloudflare serves our public website and documentation and provides DNS services; it processes visitor network and request data on its global infrastructure. The Cloud app's DNS records are not configured to proxy workspace traffic through Cloudflare.
- Services we operate. Epostix handles service email and enabled email intake. Plausible and Sentry run on our self-hosted Hexmere infrastructure. These are operated by the same Norn operator, rather than separate analytics or email SaaS vendors. Delivery to your email address also involves your recipient email provider.
- Connected third parties. Your AI provider, source-control host, identity provider, MCP servers, webhooks, import sources, Telegram if connected, and other services you authorise receive data needed for the selected integration. Their data practices and locations depend on your provider and configuration.
- Password security checks. The password breach check sends only the first five characters of a password's SHA-1 digest to the Pwned Passwords range API from our server. It does not send your password, full digest, email address, or browser IP address to that service.
- Necessary legal disclosures. We may disclose information when required by applicable law or a valid legal process, or as necessary and lawful to protect people, the service, and legal rights. We limit disclosures to what is necessary.
Access by the operator or an authorised person is limited to what is needed to operate, secure, support, or meet legal obligations concerning the service. The DPA's subprocessor schedule distinguishes our infrastructure providers from the external services you choose.
6. AI and customer-operated runners
Hosted AI conversations use the API key and compatible endpoint configured by your workspace. Conversation history, workspace and project instructions, and results of authorised tool calls can be included in requests. Our Responses API requests set response storage to false. That setting does not establish the provider's complete retention policy, prevent all security logging, or override your agreement with the provider.
Coding agents run on your runners under your provider accounts. Depending on your settings, Norn receives execution status, logs, transcripts, code changes, artifacts, and review information from those machines. Shared previews relay access to services on the runner. You control which machines, repositories, credentials, and external tools you connect. Your choices can cause data to leave the EU. We do not use these inputs or outputs to train models; your provider's processing is governed by your arrangement with it.
7. Locations and international transfers
Our core Cloud hosting and storage use infrastructure in Germany, and the operator is in Portugal. This is not a promise that every interaction stays in the EU: Cloudflare's public website delivery is global, recipients can be abroad, and your chosen integrations and runners may process data elsewhere.
Where a transfer we are responsible for requires safeguards under data protection law, we must use a valid mechanism, such as an applicable adequacy decision or the European Commission's Standard Contractual Clauses with any necessary supplementary measures. Cloudflare describes its transfer terms in its Data Processing Addendum. Contact privacy@norn.so for information or a copy of the safeguards applicable to your data. The DPA sets out our obligations for customer data.
8. Retention and deletion
We keep information for the purpose for which it was collected, taking account of the active service relationship, your instructions, security needs, and legal obligations. Different categories have different lifecycles:
- Accounts. Profile information is kept while the account is active. Account deletion clears the email address, display name, timezone, password hash, and avatar reference, revokes sessions, and removes memberships. A residual account record can remain to preserve references in shared content. Contributions to a workspace are not all deleted by deleting the contributor's account.
- Workspaces. Content is kept while the workspace remains in use, subject to its deletion and retention controls. Deleting a workspace starts a recoverable period before a background purge removes its stored content and files. The default recovery period is 30 days; the service shows the scheduled purge time. Contact us if your request requires different handling under data protection law.
- Execution material. Transcripts, artifacts, and runner workspaces are also subject to the applicable runner and workspace retention settings. A run's summary or history can remain after its detailed output or files are removed.
- Operational records. Sessions expire; temporary authentication records, import staging, and integration delivery records have separate cleanup schedules. Security and audit records can remain independently of account deletion for access accountability, abuse investigation, and legal claims. A configured cleanup interval is not a guarantee that every copy is erased at that instant.
- Backups. Deletion from live systems does not immediately rewrite existing backups. Our shared database backups use a 30-day recovery window. A backup needed to recover the start of that window can be older than 30 days, so this is not a promise of physical erasure exactly 30 days after deletion. Backup copies age out through backup rotation and are used for recovery, not ordinary access to deleted content.
- Support, diagnostics, and analytics. We keep support correspondence as needed to resolve and follow up on the request or a related claim. Diagnostic records are kept as needed to investigate failures and security problems, subject to system cleanup. Aggregate website statistics may be kept longer to compare usage over time.
We may retain information required by law or necessary for an existing dispute, with use limited to that purpose. For a deletion request covering information outside the in-app controls, contact us. We will assess what must be deleted, what can be anonymised, and what must be retained, and explain any applicable exception. Workspace owners should arrange return of needed data before a permanent purge.
9. Security
Norn uses access controls, password hashing, session revocation, encryption of stored integration secrets, and redaction of recognised sensitive log fields. Public Cloud access uses HTTPS. These measures do not make workspace content end-to-end encrypted: our systems must process it to provide the service. No system can guarantee absolute security. The DPA's security schedule describes the relevant controls and commitments without asserting a security certification.
10. Your rights and choices
Subject to applicable law, you can request access, correction, deletion, restriction, or portability of your personal data. You can object to processing based on legitimate interests and withdraw consent where processing relies on it; withdrawal does not affect the lawfulness of earlier processing. You can change notification settings, disconnect integrations, revoke credentials, and use the account and workspace controls available to your role.
Send requests to privacy@norn.so. We may need proportionate information to verify your identity or authority. Under the GDPR, we normally respond within one month; if a permitted extension is needed, we will tell you within that month and explain why. Requests are normally free, subject to the limited exceptions in law.
For data controlled by your workspace owner, contact that owner first. If you contact us, we will help route the request and assist the customer under the DPA. You can complain to Portugal's Comissão Nacional de Proteção de Dados (CNPD), or another competent supervisory authority, including one in your place of habitual residence or work. You do not have to contact us before complaining.
11. Children and automated decisions
Norn is intended for project collaboration and is not directed at children. Contact us if you believe a child has provided information that should not be held. We do not use personal data to make solely automated decisions about people that have legal or similarly significant effects. Customers remain responsible for how they configure and use their own agents and workflows.
12. Changes to this policy
We will update this page when our practices change and show the revision date. We will give additional notice of material changes where appropriate or required by law, and obtain consent where required before a new use. Questions can always be sent to privacy@norn.so.