Privacy Policy

Effective August 19, 2026

Who we are

modulate.pro is operated by Nupik Wenpach LLC (“we”, “us”). This policy explains what the service collects, why, how long it is kept, and who else touches it.

Privacy enquiries: noah@nupikwenpach.com, or (575) 909-1701.

What we collect

Three kinds of information, and nothing beyond what the product needs to work.

  • Account information. Your email address, optionally your first and last name, a hashed form of your password (never the password itself), and, if your employer has an organization account, which organization your email domain belongs to.
  • The content you create. Notes, checklists, tags, deadlines and reminder settings, images you attach, messages and reactions in chats, and the connections you form with other people. This is your material; we store it so the product can show it back to you.
  • Technical information needed to run the service. Session cookies, whether a request came from a phone or a desktop (used to show “added from your phone” on a note), and, if you turn on notifications, the push subscription your browser issues. Ordinary server logs record requests and errors.
  • Which pages get visited. We count page views so we know whether anyone is finding the site. Each view records the path, the site you arrived from (its domain only, never the full address), whether it was a phone or a desktop, your account if you were signed in, and a random identifier your browser generates for itself and stores locally. That identifier lets us count people rather than only clicks. It is not derived from your device, it identifies nothing outside this site, and clearing your browser data replaces it. We do not record IP addresses for this.
  • Which features get used. Separately from the page counting above, we record how the product is used: signing in, opening a board, creating or finishing a work order, filing or answering a request, entering a cost line, setting something up, changing a plan. This is ordinary product analytics, the same thing nearly every site you use does, and it is how we see what people actually reach for, what is slow, and what is broken in a way nobody would think to report. Each one carries the identifier of your account, the identifiers of the company and board it happened in, and numbers such as how many. None of them carries anything you wrote. Not the name of a work order, a site or a vendor; not a note, a photograph, a message or a cost line’s description. The events are a closed list written out in our source code, and the build refuses to ship one that has not been added to it deliberately
  • Which things get clicked, and what was written on them. A third counter, added on 7 September 2026, works differently from the two above. Rather than a list of events we wrote out by hand, it records clicks automatically, and each one carries the text of the thing that was clicked. On these public pages that text is ours. Signed in, it is yours: the title of a note, a work order or a site, as written on whatever was under your cursor. It also records movement between pages, and it stores its identifier in a cookie rather than in your browser’s local storage. It is provided by HeyCatch. This is the behaviour of their SDK and the settings that would narrow it are not exposed to us, so this paragraph describes what it does rather than what we would otherwise have chosen.
  • What you agreed to, and when. Creating an account records the moment you accepted these terms. If you ticked the box asking for occasional tips, that records the moment too, and which screen you were on. Leaving the box unticked records nothing, which is the same as never having been asked.

There is no advertising, no tracking pixels, no cross-site tracking, no fingerprinting, and no sale or sharing of personal information for advertising purposes. There is one cookie belonging to the click counting described above, and it is worth being exact about what kind, because the usual shorthand gets it wrong in both directions. It is written by a third party’s code and its contents are sent to that third party, but it is set on this site’s own domain rather than theirs. So it is a first-party cookie, it follows you nowhere else, and a browser setting that blocks third-party cookies will not remove it. What removes it is a content or tracker blocker that stops the script, or clearing this site’s data, which mints a new identifier rather than stopping one.

The three kinds of counting above are genuinely three things, and it is worth being plain about which goes where. The page-view counting is entirely our own and never leaves our servers. The feature-usage counting goes to PostHog on the terms in the section below: it is a list we wrote by hand, it carries identifiers, plans and counts and nothing you wrote, it does not record what you click on or what is on your screen, and it keeps its identifier in local storage rather than in a cookie. The click counting goes to HeyCatch, and it is the one that does record what you clicked, the text that was on it, and a cookie to recognise your browser between visits. No recording of your screen is made by any of the three.

Mobile numbers and text messages

If you give us a mobile number, it is used for exactly one thing: sending you a six-digit code to verify that the number is yours, and to sign you in. We store the number, the moment it was verified, and the moment you agreed to be texted at it. Codes themselves are stored only as a hash, never in a form anyone can read back.

If you cannot reach the number on your account, an administrator of your company, or of this service, can put a new one on it so a code can reach you. The record then says that they did, rather than that you agreed, and the code sent to it at your next sign-in is what proves it.

No mobile information is shared with third parties or affiliates for marketing or promotional purposes. The only company that receives your number is the messaging provider that carries the message to your handset, which may not use it for anything else. We do not sell, rent or trade mobile numbers, and we send no marketing texts at all.

Replying STOP to a message records the number as stopped, and nothing further is sent to it until you reply START.

Why we can use it

We process this information to provide the service you asked for, to keep accounts secure, to bill for paid plans, and to comply with the law. Where the GDPR applies, the legal bases are performance of a contract with you, our legitimate interest in operating and securing the service, and your consent where you have given it, notifications and the tips email being the clearest examples, both of which you can withdraw at any time.

Once you have an account, the counting described above is not one of the things you consent to. It is a condition of using the service, and the terms say so in as many words. There is no switch inside the product that turns it off, and we would rather tell you that than offer one that does nothing.

On these public pages, before an account exists, the third counter is yours to refuse. The bar on a first visit turns it off for this browser, and turning it off means it is never started: no script runs, no identifier is set, and no click is sent. That is also why the page reloads when you press it, since the only way to stop something already running is to arrive again without it. Two honest wrinkles. Remembering that you declined is itself something kept in your browser, in local storage rather than a cookie, because there is no way to remember a preference while storing nothing. And the refusal does not follow you into an account, for the reason in the paragraph above. A content or tracker blocker that stops the script works too, on any page, and the product goes on working without it. The AI features are a different case again and stay off until you turn them on.

Email you did not ask for is email we do not send. The only messages that go out without being requested are the ones the service cannot work without: a sign-in link you asked for, a password reset you started, a receipt for something you bought, or notice of a change to these terms. Tips and product news are opt-in, the box is never ticked for you, every one of those messages carries an unsubscribe link, and unsubscribing has no effect on your account or the transactional messages above. We do not sell, rent or share your address with anyone for their own marketing.

Who else touches your data

We use a small number of service providers, each doing one job. They act on our instructions and may not use your data for their own purposes.

  • Railway. Hosting, application servers, and the database where your content is stored.
  • Resend. Delivery of email such as sign-in links, invitations, password resets, and the occasional tips message if you asked for one. Receives your email address and the message. Your notes are never in any of them.
  • Your browser’s push service. Apple, Google or Mozilla depending on your device, only if you enable notifications. Receives the notification, so avoid putting anything sensitive in a note title if that concerns you.
  • PostHog. Product analytics: the feature-usage counting described above. Receives your account identifier, your email address, which plan and seat you are on, and the short list of events. Receives nothing you wrote. Session recording, heatmaps and surveys are switched off, in our code as well as in the account, so no recording of your screen is ever made.
  • HeyCatch. Product analytics: the click counting described above. Receives the elements you click and the text on them, which inside the product is text you wrote, along with the pages you move between and an identifier kept in a cookie. Session recording and surveys are switched off by their SDK, so no recording of your screen is made. The click text is not something their SDK lets us switch off.
  • Stripe. Payment processing for paid plans. Card details go directly to Stripe and are never seen by or stored on our servers; we keep only a customer identifier and the subscription status.
  • Anthropic. The AI features, and only if you have turned them on. They are off by default; each person accepts or declines them for their own account. When you use one, the notes or messages needed to answer are sent to Anthropic’s API, processed to produce the answer, and are not used to train their models. With the features off, nothing you write is ever sent to any AI provider.

We may also disclose information if legally compelled to, or to protect the rights and safety of our users. If the business is ever sold or merged, your data may transfer as part of it, and this policy continues to apply until you are told otherwise.

Where your data lives

The service is hosted in the United States. If you use it from outside the US, your information is transferred there and processed under this policy.

How long we keep it

Your content is kept for as long as your account exists. Delete a note and it is removed; delete your account and your notes, tags, attachments and account record are removed with it.

Notes themselves are never deleted by us on any schedule, on any plan. On the free plan, uploaded images and files are held for 90 days: you get an email with download links 15 days before anything is removed, and afterwards the note says the file expired rather than losing it silently. Paid plans keep attachments for as long as the account exists.

In a chat you can take back anything you sent, at any time: the words and any files go, and the thread shows that the message was deleted rather than closing the gap. You can also leave a conversation, which takes it off your list and leaves it standing for whoever is still in it. When the last person leaves a thread, it and everything in it are deleted outright.

Two deliberate exceptions. Messages you sent in a shared chat are anonymised rather than deleted, so that other people’s conversations remain readable. And we retain billing records for as long as tax and accounting law requires, independent of account deletion.

Your rights

You can access and correct your details, export your content, and delete your account from inside the product, with no need to email anyone and wait. Depending on where you live you may also have the right to object to or restrict certain processing, and to complain to a data protection authority.

Anything you cannot do from your account settings, write to noah@nupikwenpach.com and we will handle it.

Security

Traffic is encrypted in transit. Passwords are stored only as salted hashes and cannot be recovered, only reset. Access to your notes is checked on every request against your own account rather than assumed from the interface. No system is perfectly secure, and we will not pretend otherwise. But if a breach affects you we will tell you.

Children

This service is not directed to children under 13, and we do not knowingly collect their information. If you believe a child has created an account, contact noah@nupikwenpach.com and we will remove it.

Changes

If this policy changes materially we will update the effective date above and, for changes that affect how your information is used, tell you in the product or by email before they take effect.

Contact

Nupik Wenpach LLC. Email noah@nupikwenpach.com, or call (575) 909-1701.