Privacy by Design

The Nova plugin collects zero telemetry. This website uses Plausible.

Local AI option • Direct provider connections • Local credential storage • Offline licence validation

The Short Version

The plugin and website are separate privacy surfaces

Zero Plugin Telemetry

Nova does not send its creator analytics, diagnostics, notes, prompts, AI responses, or feature-usage data.

Your AI Provider

Use a supported local provider, or connect directly to a supported cloud provider with your own credentials. Nova has no AI proxy.

Local Plugin Data

Settings, credentials, conversation history, licence status, and feature state are stored locally in your Obsidian environment.

Limited Website Services

novawriter.ai uses Plausible for analytics and separate providers for hosting, checkout, licence email, and existing records from the paused newsletter.

The Important Distinction

Nova's creator does not receive the writing you use in the plugin. If you choose a cloud AI provider, the content needed for your request goes directly to that provider under its terms. Use a supported local provider when you want AI requests to remain on your device.

Nova Plugin Privacy

What stays local and what leaves your device when you ask an AI provider for help

Telemetry and Content

The Nova plugin collects zero telemetry. There is no Nova analytics service, crash-reporting service, user account system, or AI proxy. Nova's creator does not receive your notes, document metadata, prompts, AI responses, provider usage, or feature activity.

Local Storage

Nova stores settings and feature data locally within your Obsidian environment. This can include provider configuration, protected credentials, recent conversation history, licence information, prompt preferences, ignored Prose Linter findings, and Writing Dashboard history.

Recent conversation history is automatically cleaned up after seven days. Other local data remains until you clear it, remove the relevant files, or remove the plugin data. Your vault, device, operating-system account, sync service, and backups remain your responsibility.

AI Provider Requests

When you use an AI-powered command, Nova sends the content needed for that request to the provider you configured. Depending on the workflow, that can include selected text, your instruction, linked-note context, or recent conversation context.

  • Supported local providers: requests can remain on your device or local network, depending on how you configured the provider.
  • Supported cloud providers: requests go directly to that provider over the network using your credentials.

Each provider controls its own processing, retention, and security practices. Review the provider's terms and privacy policy before sending sensitive material.

Credential Protection

Nova applies local AES-GCM protection before saving supported API keys and the Supernova licence key. Those values are used only for the provider connection or local licence validation you requested.

This protection reduces casual exposure in plugin settings data, but it is not a substitute for securing your device, Obsidian vault, operating-system account, sync service, and backups.

Licence Validation

Supernova licence validation happens locally in the plugin. Nova does not contact a licence server, track licence usage, or remotely revoke a licence. The key is delivered by email after purchase and then stored locally when you enter it in Nova.

Website and Commercial Services

What novawriter.ai uses outside the Nova plugin

Plausible Analytics

We use Plausible to understand aggregate website traffic and whether key site journeys work. Plausible does not use cookies or persistent user identifiers.

In addition to page views, the site records two named events: Checkout Started and Purchase Complete. These events may include a page-placement or offer label. They do not include your email address, licence key, note content, prompts, or AI responses.

Netlify Hosting

Netlify hosts novawriter.ai and runs its server-side checkout function. Like other web hosts, Netlify may process ordinary request information such as IP address, browser details, requested URL, timestamps, and security logs under its own privacy practices.

Stripe and Resend

Stripe processes Supernova checkout and payment information. Nova does not receive your full card details. Stripe provides the purchaser's email address and order information needed to fulfil the purchase.

After payment, a Netlify function generates the licence key and uses Resend to deliver it to the checkout email address. Transaction and delivery records may be retained as needed for fulfilment, support, fraud prevention, accounting, and legal obligations.

Paused Beehiiv Newsletter

Newsletter signup is paused, and novawriter.ai no longer accepts new subscriber addresses. A Supernova purchase does not subscribe you to email.

Beehiiv retains existing confirmed subscriber records while Nova considers whether to retire the newsletter. No launch email will be sent. Existing subscribers may request access, correction, or deletion by emailing hello@novawriter.ai.

Service Providers and Location

The website and AI providers described above may process information in Canada, the United States, or other countries where they operate. Their privacy policies govern that processing.

Retention and Your Choices

Retention

  • Plugin data: stays under your local control; recent conversation history is cleaned up after seven days.
  • AI requests: follow the retention policy of the provider you selected.
  • Website analytics: are retained by Plausible according to its service settings and data policy.
  • Newsletter data: existing records remain with Beehiiv while the newsletter is paused or until deletion is requested, subject to legal requirements.
  • Transaction data: may be retained by Stripe, Resend, Netlify, and Nova as needed for the purposes described above.

Your Choices

  • Choose a supported local provider when you do not want writing sent to a cloud AI provider.
  • Remove or replace provider credentials in Nova settings.
  • Clear local Nova data or remove the plugin.
  • Request access to, correction of, or deletion of website, purchase, or newsletter personal information associated with you, subject to legal retention requirements.

Security and Transparency

We use reasonable safeguards appropriate to a small, privacy-first software project, but no device, network, provider, or storage system can be guaranteed completely secure.

Nova is open source under AGPL-3.0, so its code can be inspected and built independently. Open source availability is not a claim that Nova has received a formal third-party security audit or certification.

Policy Changes

We may update this policy as Nova or its website services change. The current version and modification date will remain on this page. Nova's commitment to zero plugin telemetry will not be changed silently.

Contact

Shawn Duggan is responsible for Nova's privacy practices. For privacy questions, access or correction requests, deletion requests, or complaints, email hello@novawriter.ai. Do not send note content, API keys, licence keys, or other secrets.

Verify and Explore

Review the source, read the terms, or install Nova

View Source Code

Inspect Nova's public source code and network behavior.

View on GitHub (opens in new tab)

Read the Terms

Review the software and Supernova purchase terms.

View Terms

Install Nova

Set up Nova with a supported local or cloud provider.

Installation Guide