Legal

Privacy Policy

Last updated: August 1, 2026

How NovumOS handles your data.

1. Who we are

NovumOS is an agent-native kanban and work-management service ( "NovumOS," the "Service"), operated by Rho Forge LLC, 67 Millbrook Street, Suite 520, Worcester, MA 01606, USA ("we," "us," "our"). This Privacy Policy explains what personal data we collect, why, how we share it, how long we keep it, and the choices and rights you have.

This policy covers the NovumOS marketing website and the NovumOS product. It is incorporated into our Terms of Service.

2. Our role: controller and processor

Privacy law distinguishes the party that decides why and how data is processed (the "controller") from a party that processes data on another's instructions (the "processor").

  • We are the controller of the data we handle to run our business and provide the Service to you — for example, account details, billing metadata, product-usage events, website analytics, and support communications. This policy governs that data.
  • For personal data that you or your members place inside your content (boards, cards, comments, files — "Customer Content"), your organization is the controller and we act as a processor, handling that data on your instructions to provide the Service. If you are a business customer subject to GDPR or similar laws, a Data Processing Addendum may govern that processing.

3. Data we collect

Account data. When you sign up, we collect your email address and name, and either a password (stored only as a secure hash — we never store it in plain text) or a Google account identifier if you sign in with Google (we receive your Google-verified email, name, and profile picture). We also record organization membership and roles.

Customer Content. The boards, cards, comments, and files you and your members create, upload, or import. We process this to provide the Service (see §2). This may include imports you initiate from Notion; when you import using a Notion token, that token is treated as a transient secret — held only for the duration of the import job, never stored in plain text, and discarded when the job completes.

Payment metadata. When you subscribe to a paid plan, payments are processed by Stripe. Stripe collects and processes your card details directly; we do not receive or store your full card number. We store billing metadata such as your Stripe customer and subscription identifiers, plan, seat counts, billing status, and renewal dates.

Product-usage data. For signed-in users, we record first-party, server-side product events (such as actions taken on boards and by agents) to operate, secure, and improve the Service, to power audit and activity logs, and to enforce limits.

Website analytics and advertising. On our website we use Google Analytics 4 (GA4) and may use advertising tags or pixels, which use cookies and similar technologies (see §5). These help us understand how visitors find and use the site and how our advertising performs.

Server logs and security data. We automatically collect technical data needed to run and secure the Service — for example, IP address, browser/user-agent, request metadata, and timestamps — including data used for rate limiting, abuse prevention, and audit logging.

Support and other communications. When you email us (for example, support@, privacy@, or security@novumos.app) or contact us otherwise, we receive your message and contact details and keep a record of the correspondence.

We do not intentionally collect special categories of data (such as health or biometric data), and you should not place such data in Customer Content unless your own legal basis and safeguards permit it.

4. Why we use data, and our lawful bases

Where the GDPR or similar laws apply, we rely on the following lawful bases:

Processing purposes and their GDPR lawful bases
What we doWhyLawful basis (GDPR)
Create and secure your account; provide the ServiceTo deliver what you signed up forContract (Art. 6(1)(b))
Process Customer Content on your instructionsTo operate the Service for your organizationContract (as processor for our customer; Art. 6(1)(b))
Process payments and manage subscriptionsTo bill you and manage your planContract (Art. 6(1)(b)); legal obligation for tax/accounting records (Art. 6(1)(c))
Product-usage events, logging, rate limiting, abuse and fraud prevention, auditTo keep the Service reliable, secure, and improvingLegitimate interests (Art. 6(1)(f))
Send transactional/service email (verification, password reset, billing and past-due notices, security and important service notices)Necessary to provide the Service and to reach you about your accountContract (Art. 6(1)(b)); legitimate interests
Website analytics (GA4) and any advertising cookies/pixels we use (§5)To understand and improve our website and measure our advertisingConsent where required (Art. 6(1)(a))
Marketing / lifecycle email (planned)To tell you about features and offersConsent where required; otherwise legitimate interests with opt-out

Transactional vs. marketing email. Transactional and service messages are necessary to operate the Service and to keep you informed about your account, and you cannot opt out of them while you have an account (you can, however, control certain notification emails in your settings). Marketing and lifecycle email is planned; when we send it, we will do so consistent with applicable law, honor consent where required, and include a one-click unsubscribe in every marketing message. Unsubscribing from marketing does not stop transactional messages.

5. Cookies and similar technologies

We use cookies and similar technologies for the following purposes:

  • Strictly necessary — to keep you signed in (a session cookie), protect against cross-site request forgery, and secure the Service. These are required for the product to work.
  • AnalyticsGoogle Analytics 4 on our website, which uses cookies to measure site usage.
  • Advertising — we may use advertising cookies or pixels (for example, from Google or Meta) to advertise NovumOS, including measuring our campaigns and reaching people who have visited our site with ads on other platforms. These may share information about your visit with the advertising platform.

Where required by law, we ask for your consent to analytics and advertising cookies through our cookie consent banner before they are set, and you can change or withdraw your choice at any time through the banner or your browser controls. Declining these cookies does not affect your ability to use the product.

6. Your communication choices

  • Transactional/service email: required while you have an account (see §4).
  • Notification email: you can turn specific product notification emails on or off in your account settings.
  • Marketing email (when offered): you can opt out at any time via the one-click unsubscribe link or your account settings.

7. How agents access data

If your organization connects an AI agent, that agent is a member of your organization and can access only the organization data its token's scope and role allow — for example, a specific board it has been granted access to. You control what agents you connect, what they can access, and when to pause or revoke them. Agents run on your own AI-provider keys; we do not send Customer Content to AI providers on your behalf, and we do not provide the AI models that power your agents.

8. How we share data — subprocessors, and no sale

We share personal data only as described here. We do not sell your personal data to data brokers, and we do not sell Customer Content.

Advertising and marketing tools. We may use advertising platforms (for example, Google or Meta) to promote NovumOS, including tags or pixels that measure how well our advertising works and help us reach interested audiences (see §5). Where these tools use cookies or similar technologies and the law requires consent, they are used only with your consent. We do not use Customer Content for advertising.

Service providers (subprocessors). We use vendors to run the Service; each processes data only to provide services to us, under contract. We may add or replace vendors as the Service evolves. Our current principal vendors:

Current principal subprocessors
SubprocessorPurposeLocation
Amazon Web Services (AWS)Cloud hosting and storageUnited States
StripePayment processingUnited States
GoogleSign-in (OAuth), website analytics (GA4), and advertising servicesUnited States
Amazon SESTransactional (and, when launched, marketing) email deliveryUnited States
Forward EmailInbound email routing (our @novumos.app addresses)United States

Endpoints and destinations you configure — such as your own webhook URLs or a Notion workspace you import from — are controlled by you, not by us, and are not our subprocessors; data sent to them goes at your direction.

People you authorize. Content is visible to the members, guests, agents, and share-link recipients you or your organization authorize (see the sharing controls in the product and the Terms).

Legal and safety. We may disclose data if required by law, subpoena, or valid legal process, or where we reasonably believe disclosure is necessary to comply with law, enforce our Terms, or protect the rights, safety, or security of our users, the public, or us.

Business transfers. If we are involved in a merger, acquisition, or sale of assets, data may be transferred as part of that transaction; we will require the successor to honor this policy or provide notice and choice as required by law.

International transfers. We host and process data in the United States. If you access NovumOS from outside the U.S. (for example, the EEA or UK), your data will be transferred to and processed in the U.S. Where required, we implement appropriate safeguards for such transfers (such as Standard Contractual Clauses or an equivalent mechanism).

9. Your rights

Depending on where you live, you may have some or all of the following rights regarding your personal data.

9.1 Everyone

You can access and export your organization's content at any time using the in-product one-click export (available on every tier). You can correct account details in your settings, and you can delete your account or organization. To make any other request, or to exercise the rights below, email privacy@novumos.app. We will verify your request and respond within the time required by law. You will not be discriminated against for exercising your rights.

Where we act as a processor on behalf of your organization (Customer Content, §2), we will refer certain requests to the relevant organization (the controller) and assist it in responding.

9.2 GDPR (EEA/UK and similar)

If the GDPR or UK GDPR applies to you, you have the rights to: access your data (Art. 15); rectify inaccurate data (Art. 16); erase data (Art. 17); restrict or object to processing (Arts. 18, 21), including objecting to processing based on legitimate interests and to direct marketing; data portability (Art. 20); and to withdraw consent at any time where processing is based on consent (without affecting prior processing). You also have the right to lodge a complaint with your local supervisory authority. Our lawful bases are set out in §4.

9.3 California (CCPA/CPRA) and other U.S. state laws

The CCPA/CPRA applies to businesses that meet certain thresholds (annual revenue above an inflation-adjusted floor — approximately US$26.6M in 2026 — or handling the personal information of 100,000+ California consumers or households, or deriving 50%+ of revenue from selling or sharing personal information). Rho Forge LLC does not currently meet any of these thresholds, so the CCPA/CPRA does not currently apply to us.

Even so, we extend the core rights to everyone, including California residents: you can request access to, correct, or delete your personal data by emailing privacy@novumos.app (see §9.1), you may use an authorized agent, and we will not discriminate against you for exercising these rights. Residents of other U.S. states with privacy laws have similar rights where those laws apply to us. If we grow to meet a threshold, or our practices change in a way that creates additional obligations, we will update this policy and provide any mechanisms the law then requires (such as a "Do Not Sell or Share My Personal Information" link).

10. Data retention

We keep personal data only as long as needed for the purposes described here, then delete or de-identify it.

  • Account and Customer Content: kept while your account/organization is active. After you delete your account or organization, we make data available for export for a grace period of 30 days, then delete or de-identify Customer Content from active systems within a commercially reasonable time.
  • Backups: residual copies may remain in encrypted backups until they expire on our normal cycle (currently 30 days).
  • Audit log: retained for 1 year.
  • Agent activity ledger: retained for 90 days by default.
  • Billing records: retained as required for tax, accounting, and legal purposes.
  • Server logs / security data: retained for a limited period appropriate to security and operational needs.

11. How we protect data

We take security seriously and apply administrative, technical, and physical safeguards appropriate to the data. In line with how the Service is built:

  • Encryption in transit for data moving between you and the Service.
  • Tenant isolation — every data path is scoped to your organization so one organization cannot access another's data.
  • Scoped, hashed credentials — API and integration tokens are random values stored only as secure hashes and can be scoped and revoked; passwords are stored only as secure hashes.
  • Access controls — role-based access within organizations and per-board restrictions you control; our staff may access organization data only as needed to operate and support the Service, and access to restricted boards is grant-based with audited owner-reclaim.
  • Audit logging of sensitive actions, retained for 1 year.
  • Backups with point-in-time recovery.

No method of transmission or storage is completely secure, so we cannot guarantee absolute security.

12. Children

NovumOS is not directed to children and is not intended for anyone under 16. We do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact privacy@novumos.app and we will delete it.

13. Breach notification

If we become aware of a security breach affecting your personal data, we will notify affected users and, where required, regulators without unreasonable delay and consistent with applicable law (including, for Massachusetts residents, M.G.L. c. 93H, and, where applicable, the GDPR). Where we act as a processor, we will notify the affected organization (the controller) so it can meet its own obligations.

14. Changes to this policy

We may update this Privacy Policy from time to time. If we make material changes, we will provide reasonable notice (for example, by email or an in-product notice) and update the "Last updated" date. Your continued use of the Service after changes take effect means you accept the updated policy.

15. Contact us

Questions, requests, or complaints about privacy:

Rho Forge LLC, 67 Millbrook Street, Suite 520, Worcester, MA 01606, USA.