Privacy Policy | nopa

nopa

Privacy Policy

Effective September 10, 2026. The short version: what you put into nopa stays on your device, because we built it with nowhere else for it to go.

No POST. Nothing left this device.

The whole policy in three sentences

Everything you open, write or make in nopa — files, notes, boards, passwords, recordings, results — stays in your browser on your device. There is no nopa server that receives it, stores it or could be breached for it. We count how often a tool is opened and whether it worked; we never see what you put in.

Do not take our word for it — watch the network

Open your browser tools, switch to the Network tab, then open any tool on this site and use it. Not one POST leaves the page: what you drop in never travels. The rows that do appear are our own code arriving from this same address, and every one of them is a GET.

Network
GETmini-bootstrap.jsscriptGETmini-shared.jsscriptGETvendor-react.jsscript POST

No POST. Nothing left this device.

What the Network tab shows while you work on this page

Why we can promise this

Most “free” tools upload your file, process it on their machines and send a result back. That upload is where the risk lives: a copy of your document now sits somewhere you cannot see, under rules you did not write. nopa is built the other way round. The PDF is merged, the background removed, the audio transcribed by your own browser, on your own hardware. The file never leaves the tab. This is not a policy we chose — it is how the product works, and we could not change it quietly even if we wanted to.

What lives on your device

Notes, boards, calendar events, the Files library, desktop icons, saved results and settings are stored by your browser (IndexedDB, localStorage and similar). Opening, previewing and playing files — images, PDFs, Office documents, audio, video — happens locally; playback uses local blob URLs, and nothing is uploaded. Public pages remember your language. AI tools cache their model files in the browser after the first download so the second run is instant.

Because it is your browser’s storage, it follows your browser’s rules: clearing site data or uninstalling the app removes it, and it does not travel to another device unless you export it yourself.

What we never see

We do not operate any server that receives your files, notes, passwords, audio, images, transcripts, generated outputs, tool inputs or even filenames. We do not ask for an account, an email address or a card. We cannot sell your data, hand it over or lose it in a breach — for the plainest reason there is: we do not have it.

What we do count

We use lightweight analytics (Yandex Metrika and, when enabled, Google Analytics or PostHog) to learn which pages are visited, which tools are opened and whether they finish successfully. That is how we know what to fix and what to build next.

What these tools receive is the event — “merge PDF opened”, “download clicked” — never the content. Nothing you type, upload or generate is sent in an analytics event; typed text is masked out of interaction tracking; query parameters are stripped. If you prefer that we count nothing at all, a browser privacy setting or a blocker will stop analytics entirely and nopa keeps working exactly the same.

Crash reports: off until you say so

If something breaks, we would love to know — but only with your permission. Crash reporting (via Hawk) is off by default. Turn it on in Settings → Data and nopa sends a sanitized report: the error message, the shape of the stack trace and the app version. Never your files, notes, inputs, history or identity. Turn it off again whenever you like.

AI that runs on your machine

Background removal, transcription and similar tools use machine-learning models downloaded once from a public hub such as Hugging Face and cached in your browser. The model comes to your device; your photo or recording does not go to the model. Processing happens locally, which is the only way it could be private. Models and libraries carry their own licenses, listed on the Licenses page.

When your browser talks to someone else

A few features fetch resources directly from third parties — from your device to them, never through us:

• Google Fonts, for typography • Hugging Face and similar hubs, for AI model files • emoji artwork CDNs (jsDelivr, GitHub, openmoji.org) when you preview or download emoji images • icon services (Google gstatic, DuckDuckGo) for desktop bookmark tiles — they see your IP and the bookmarked site’s host • jsDelivr, when the Retro app loads a game core the first time • analytics providers as described above, and Hawk only if you turned crash reports on

nopa does not proxy your content through any server of ours, because there is no such server.

Your data, your call

Export or copy any result at any time. Clear site data in your browser and it is gone — for good, since we hold no copy. Uninstall the app or simply stop using the site. Block analytics if you wish. Crash reports stay off unless you switch them on, and switch off the moment you say.

Who we are

nopa is made by a small team of contributors, not a registered company. Questions about this policy can be sent through the contact options on the site. We answer.

Children

nopa is a general-purpose productivity site. We do not knowingly collect personal information from anyone, children included — there is no place in nopa where personal information is collected.

Changes

When this policy changes, the effective date at the top changes with it. Using nopa after an update means you accept the revised policy — and the promise at the top of this page is the one part we do not intend to change.

Related documents

See also: Terms of Service and Licenses on this site.