Privacy Policy

Last updated October 6, 2026

Notils ("Notils", "we", "us") builds software for small businesses, based in Janakpur, Nepal. This policy covers the Notils website (notils.com), the Notils dashboard (app.notils.com), and Notils Notify, our API for sending email from your own product. It explains what data we collect, why, who we share it with, and what you can ask us to do with it.

1. What we collect

  • Account information: your name, email address, and password (stored only as a one-way hash, never in readable form). If you sign in with Google, we receive your name, email address, and profile picture from Google instead. See §2.
  • Workspace information: the name of your workspace, the people you invite to it and their roles, and the brand details you add, such as a logo, a sender name, and a reply-to address.
  • Content you create: email templates, reusable blocks, and the projects you set up in the dashboard.
  • Messages you send through Notils Notify: the recipient's email address, the content and variables of each message, and its delivery status. You send these on behalf of your own users, so you decide what goes into them.
  • API keys: we store keys so we can check each request against them. You see the full key only once, when you create it.
  • Technical data: IP address, browser or device type, and request logs, used to keep the service secure, stop abuse, and fix errors.

2. Signing in with Google

If you choose "Continue with Google", Google shares your name, email address, and profile picture with us (the openid, email, and profile scopes). We ask for nothing else: no access to your Gmail, contacts, Drive, calendar, or any other Google data.

  • How we use it. Only to create your Notils account or sign you into it, and to show your name and picture in the dashboard.
  • How we share it. We do not sell Google user data, use it for advertising, or share it with anyone, except the hosting providers in §4, which store it on our behalf.
  • How we protect it. We send the sign-in token Google gives your browser to our own servers over HTTPS. There we check it against Google's public keys, then discard it. We don't keep Google access tokens.
  • Removing it. You can revoke Notils' access at any time at myaccount.google.com/connections, and ask us to delete your account as described in §7.

Our use of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.

3. How we use your data

  • To provide the service: sign you in, run your workspace, and deliver the messages you send.
  • To keep accounts secure, for example by verifying your email address and detecting abuse.
  • To contact you about your account, such as verification codes, password resets, invitations, and important changes to the service.
  • To diagnose problems and improve Notils.

We do not sell your data, use it for advertising, or use the content of your messages for any purpose other than delivering them.

4. Who we share data with

We use a small number of service providers that process data for us, only to run Notils:

  • Cloudflare: hosts the website and dashboard, and stores the logos you upload.
  • Render: hosts our backend services.
  • Neon: hosts our databases.
  • Resend: delivers emails, both the ones Notils sends you and the ones you send through Notils Notify.
  • Google: confirms your identity when you sign in with Google.

We may also disclose data if the law requires it. If we change these providers, we'll update this list first.

5. Your end users' data

When you send messages to your own users through Notils Notify, you decide what to send and to whom, and we process that data only to deliver it on your behalf. You're responsible for having a lawful basis to contact those recipients.

6. Cookies

The dashboard sets only the cookies needed to keep you signed in. They are httpOnly, so scripts in the page cannot read them. We don't use advertising or third-party tracking cookies.

7. Retention and your rights

We keep your account and workspace data while your account is active. You can view and edit your profile in the dashboard at any time. To get a copy of your data, correct it, or delete your account and its data, email privacy@notils.com from the address on your account. We act on deletion requests within 30 days. We may keep a small amount of data longer where the law requires it, such as security logs.

8. Security

All traffic is encrypted with HTTPS. Passwords are hashed, access tokens are short-lived, and workspaces are kept separate so one cannot see another's data. No system is perfectly secure, but we take reasonable steps to protect what you share with us.

9. Children

Notils is a business tool and is not intended for anyone under 16. We do not knowingly collect data from children.

10. Changes to this policy

If we change this policy, we'll update the date at the top. If a change is significant, we'll also tell you by email or in the dashboard.

11. Contact

Questions about this policy or your data: privacy@notils.com.