nomad.

Privacy Policy

Last updated: 2026-07-18

nomad. ("the app", "we", "us") is a multi-tenant software service that helps its business customers run LinkedIn outreach and manage a lightweight contact CRM. Each customer's data is held in a separate, isolated database. This policy explains what information the app accesses, how it is used, and how it is protected. Access is limited to authorized users who have been invited by a customer organization; the app is not an open consumer service.

Information the app accesses

How information is used

Information is used solely to provide the app's features to the customer who entered it — storing and retrieving files, showing contacts, and sending messages that customer's users initiate. Information is not sold or rented, is not used for advertising, and is not used to train generalized artificial-intelligence models.

Google user data — Limited Use

nomad.'s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

Where information is stored

File contents are stored in the connected Google Drive account. Everything else (contact records, notes, settings) is stored in a private, per-customer database on servers the service operator controls. The app relies on the following service providers to deliver its features, each governed by its own privacy policy: Google (sign-in and Drive), LinkedIn (optional sign-in), Unipile (LinkedIn access), Cloudflare (its AI Gateway routes AI requests, and R2 holds encrypted off-site backups), and — where a customer enables them — Calendly (meeting scheduling), ActiveCampaign (email contacts) and Plug & Pay (payment processing). Only the data required for a given feature is shared with the provider that powers it.

AI features send the text needed for a specific request (for example a contact's profile summary, with precise locations reduced to country level) to the AI provider the customer has selected for its workspace — Google Gemini, Anthropic, or OpenAI. Requests are routed through Cloudflare's AI Gateway. No provider is permitted to use this data to train generalized AI models, and AI features can be left unused.

Product analytics

The operator measures how the app itself is used, to find broken and unused features. This is first-party and self-hosted — no third-party analytics or advertising service is embedded in the app, and no data is shared with one. It is deliberately minimal:

This concerns the customer's own users signing into the app — not the contacts held in a customer's CRM, who are never tracked this way.

Data retention and deletion

Your rights

Individuals whose personal data is held in a customer's CRM may, on request to that customer organization (which acts as the data controller), exercise their rights under applicable data-protection law (including the EU/UK GDPR):

To make any of these requests, contact [email protected].

Contact

Questions about this policy can be directed to [email protected].


See also our Terms of Service.