Privacy Policy
Effective date: 13 September 2026
Who we are
Nhoma (“Nhoma”, “we”, “us”) is operated by Waripixel, established in Arlington, Texas, United States. Waripixel runs nhoma.app, a service for writing simple agreements, sending them to another person, and signing them. For anything in this policy, contact us at hello@nhoma.app. Waripixel is the data controller for the personal data described below.
The short version. Your documents live in your device's own storage plus our database so the other party can open them. We set no advertising or tracking cookies, run no analytics, and never sell data. We share data only with the service providers needed to host the app, deliver email, process payments, and run the optional AI features.
Data we process
Documents and parties
- Agreement content you write or generate: terms, amounts, item lists, milestones, and every saved version of them.
- Party details: the sender's name and email, and the recipient's email address or phone number, entered so the document can be delivered and signed.
- Signatures: the drawn signature itself, the document version it binds to, the time of signing, the exact consent sentence the signer ticked, and a signing-context record containing the browser's user-agent string, the network (IP) address the signature was submitted from, and an approximate location (country, region, city) derived from it. This record exists to make a signature attributable and verifiable later, and is kept as part of the signed record.
- Document activity log: when a document is created, sent, opened, and signed, together with the time, the network (IP) address, the browser's user-agent string, and the country each of those actions came from. This is the audit trail behind a signed agreement.
- ID fingerprint (optional): if a signer chooses to link an ID document, only a SHA-256 fingerprint (hash) computed on the signer's device is stored — the ID image itself never leaves the device and is never uploaded.
- Identity check (when the sender requires it): the sender of a document can require the signer to pass an identity verification (a government ID plus a selfie face-match) before signing. The check itself runs on the verification provider's own pages (Didit — see the processor table below); Nhoma stores only the session reference, the outcome (approved or not), and the full name as read from the verified ID, which becomes part of the signature record. The ID images, the selfie, and the other data extracted from the document stay with the verification provider and never reach Nhoma's servers.
Uploads and AI inputs
- Photos and attachments you add to a document (milestone proof, receipts, item photos, files) are stored in our file storage.
- Voice recordings made in the builder are transcribed by AI and used to draft your document; photos submitted for extraction are analysed to suggest document content.
Payments
Payments are handled entirely by our payment providers (Stripe or Polar) on their own hosted checkout pages. We never see or store card numbers. We store the transaction reference, the product purchased, the resulting entitlement token, and the email address you used at checkout — the latter so a purchased pass can be recovered by mailing it back to the address that paid for it, and nowhere else.
Email log
When you send a document by email, we record the recipient address, the time, and the delivery reference. This log enforces sending quotas and prevents abuse of the email feature. Addresses that hard-bounce or mark our mail as spam are placed on a suppression list and are not written to again. If a signer chooses to verify their email before signing, we store a short-lived hash of the verification code and, in the signature record, whether verification succeeded.
Technical data
Like every website, our infrastructure processes IP addresses and request metadata to serve pages, prevent abuse, and keep operational logs. These logs are used for security and reliability only.
Bot protection (Cloudflare Turnstile)
Certain actions — saving or sending a document, and the AI features — are protected against bots by Cloudflare Turnstile. The check runs invisibly in the background: there is normally nothing to click and no puzzle to solve, so you will usually not see it at all. To tell people and bots apart, Turnstile evaluates technical signals from your browser, including your IP address, TLS fingerprint, user-agent and similar browser characteristics, and our site key and page origin. Cloudflare processes these signals on our behalf to protect the service, states that it cannot directly identify individuals from them, and may also use them as an independent controller to improve its bot-detection. Details are in the Cloudflare Turnstile Privacy Policy and Cloudflare's Privacy Policy.
Purposes and legal bases
| Purpose | Data used | Legal basis (GDPR) |
|---|---|---|
| Creating, delivering, and signing agreements | Document content, party details, signatures | Performance of a contract, Art. 6(1)(b) |
| AI drafting, transcription, and photo extraction | Your text, voice recordings, photos | Performance of a contract, Art. 6(1)(b) |
| Payments and entitlements | Transaction references, email | Performance of a contract, Art. 6(1)(b) |
| Abuse prevention, security, quotas | IP address, user-agent, email log | Legitimate interests, Art. 6(1)(f) |
| Signature verifiability | Signing-context record | Legitimate interests, Art. 6(1)(f) |
| Identity verification required by the sender | Verification outcome, verified name | Performance of a contract, Art. 6(1)(b) |
| Optional analytics (currently none running) | — | Consent, Art. 6(1)(a) — off unless you opt in |
Service providers (processors)
| Provider | What it does | Data it touches |
|---|---|---|
| Cloudflare, Inc. | Hosting, database, file storage, AI models (transcription, drafting, search), Turnstile invisible bot-check | All service data; IP addresses and browser signals (TLS fingerprint, user-agent) for Turnstile |
| OpenAI, L.L.C. | AI drafting and photo-content extraction in the builder | Text you submit for drafting; photo-derived content. Not used to train OpenAI's models under its API terms |
| Amazon Web Services, Inc. (SES) | Delivers the emails you send from Nhoma | Recipient address, email content with document links, delivery outcomes (bounces, complaints) |
| Resend, Inc. | Backup email delivery when the primary channel is unavailable | Recipient address, email content with document links |
| Stripe, Inc. | Payment processing (hosted checkout) | Payment and billing details, handled under Stripe's own privacy policy |
| Polar Software Inc. | Alternative payment processing (hosted checkout) | Payment and billing details, handled under Polar's own privacy policy |
| Didit (Didit ID, Inc.) | Identity verification when the sender requires it, on Didit's own hosted pages | The signer's ID document, selfie, and extracted identity data, handled under Didit's own privacy policy; Nhoma receives only the outcome and the verified name |
Fonts and styling are served from our own domain — no font or CDN provider sees your visits.
Some providers are based in the United States. Where personal data leaves the EEA/UK, transfers rely on the EU–US Data Privacy Framework and/or Standard Contractual Clauses maintained by each provider.
Cookies and on-device storage
Nhoma sets no advertising, analytics, or tracking cookies. The only cookie we set ourselves is iw_cc, which stores your consent choice (kept for 6 months). Cloudflare Turnstile, our invisible bot-check, may set its own strictly necessary cookies while it verifies you are human (see Cloudflare's Cookie Policy). You can review or change your choices any time via Cookie settings in the footer, or by clearing your browser data.
The app keeps working data in your browser's localStorage (on your device, never sent to us as such):
- Document vault — the list of documents created on your device and the keys that open them. Clearing it makes those links unrecoverable, so keep a backup.
- Entitlements — your Premium Pass token or unlock code.
- Preferences — language, signature ink style, currency, country override, guide and tip states, saved wizard templates.
- Caches — exchange rates and per-document send/keep flags.
All of this is functional storage the service needs to work; none of it is used for tracking.
Retention and deletion
- Documents, versions, signatures, and attachments are kept for as long as the document exists, because a signed agreement must stay verifiable for both parties.
- Deleting a document yourself: the owner can delete a draft, declined, or withdrawn document directly from its page — this erases its content, history, photos, and activity log, and scrubs the addresses from its email log. A sealed (fully signed) agreement is both parties' record and cannot be deleted unilaterally; write to us and we will weigh both parties' interests.
- Recipient details entered by a sender: if someone entered your email address or phone number into a document and you want it removed, contact hello@nhoma.app — for an unsigned document we remove it; for a signed one we retain only what the integrity of the record requires.
- Email logs and purchase records are kept as long as needed for quota enforcement, accounting, and dispute handling.
- Security logs are short-lived and rotate automatically.
Your rights
Under the GDPR (and similar laws such as the UK GDPR and CCPA) you can ask us for access to your data, rectification, erasure, restriction of processing, portability, and you can object to processing based on legitimate interests. Where processing is based on consent, you can withdraw it at any time. Write to hello@nhoma.app and we will respond within one month. You also have the right to complain to your local data-protection authority.
Note that erasing a document that another person has signed affects their copy too; where both parties' interests conflict, we may retain the minimum needed to preserve the integrity of a concluded agreement.
Children
Nhoma is not directed at children and is not intended for use by anyone under 16. We do not knowingly collect data from children.
Changes to this policy
We will post any changes on this page and update the effective date above. Material changes will be highlighted in the app.