Last updated July 27, 2026.
Your account email (via sign-in), and whatever you enter directly — tasks, notes, and calendar items. If you connect Gmail or Outlook, Nona requests read-only access to fetch and summarize your inbox.
Email content is read live over the provider's API for each request and is not stored afterward — it's processed in memory to generate summaries and briefs, then discarded. Nona's access is read-only: it cannot send, delete, or modify anything in your inbox. OAuth tokens that grant this access are stored server-side, encrypted, never in the browser.
Solely to run the features you use — generating your daily brief, parsing tasks, and triaging email. Task and email text is sent to the Anthropic API (Claude) to do that parsing and summarizing; Anthropic processes it under their own API terms and does not use API inputs to train models.
If you sign up for product updates, your email is stored separately for that purpose only. You can unsubscribe at any time from the unsubscribe page.
Nona runs on Vercel (hosting) and Supabase (database, authentication). Sign-in and email triage integrate with Google and Microsoft. None of these providers receive more than what's required to operate the feature in question.
You can request deletion of your account data at any time via the contact page. Disconnecting Gmail or Outlook revokes Nona's access immediately.
Nona is an actively developed MVP built by a solo founder. This policy describes how the product works today and will be updated as it changes — check back periodically if that matters to you.