Skip to content
Nomisma

[ Privacy ]

What we collect,
and what we do not.

Plain English. No dark patterns. Last updated July 18, 2026.

Summary

Nomisma LLC (“Nomisma,” “we”) operates nomisma.ai. We use first-party analytics, we do not set tracking cookies, we do not ship third-party scripts, and we honor Do-Not-Track and Global Privacy Control. The only personal data we ever store is what you give us through the contact form — and our admin tooling for the small team that reads it.

This policy is built around the CCPA/CPRA, the other U.S. state privacy laws, and the EU and UK GDPR — and we extend the same core rights to everyone who uses the site, wherever you live.

What we collect

From the contact form

  • Name, email address, organization (optional), and message content — only when you submit the form.
  • Submission metadata: IP address, browser user-agent string, and the referring URL (if any). Used to fight spam and to support the message if a follow-up is needed.

From first-party analytics

  • Pageview data: page path, referrer, UTM tags, time on page.
  • Coarse geo (country, region, city) derived from CloudFront request headers. We do not perform IP-to-location lookups.
  • Device class (desktop / tablet / mobile), operating system, and browser family, derived from the user-agent.
  • A pseudonymous, daily-rotating visitor identifier (server-computed SHA-256 hash of IP + user-agent + an internal secret, scoped to the current UTC day). It changes every 24 hours. It is not a persistent fingerprint.
  • Click events on elements we explicitly tag for tracking (e.g., “Apply to AI Startech,” “Request a briefing”). No keystrokes, no mouse trails, no session replay.

From admin sign-ins (Nomisma team only)

  • Email, Argon2id password hash, TOTP 2FA secret, last login timestamp + IP, append-only audit log of every action.

What we do not collect

  • No tracking cookies. The analytics tracker stores a transient session ID in sessionStorage only, which clears when you close the tab.
  • No third-party scripts. No Google Analytics, Meta Pixel, advertising pixels, or fingerprinters.
  • No persistent cross-day identifier. The visitor hash rotates every UTC day.
  • No sale or sharing of data.We never sell or share your personal information, and we never use it for targeted advertising or profiling — not for money, not for anything.
  • No sensitive personal information.We do not ask for or store the categories the law singles out — government IDs, precise geolocation, health, biometric, or financial-account data, or data revealing race, religion, and the like.
  • We honor DNT and GPC. If your browser signals Do-Not-Track or Global Privacy Control, the analytics tracker disables itself.

Why we collect what we do

  • Contact form data: to read your message and reply. To prevent abuse of the form.
  • Analytics:to understand which content is read, which CTAs are used, and where visitors come from — in aggregate.
  • Admin data: to authenticate the small Nomisma team and maintain an audit trail of who did what.

Where data is stored

All application data is stored in AWS RDS PostgreSQL in the United States, encrypted at rest with AWS KMS and in transit with TLS. Email delivery uses AWS SES (US). The website itself is served by AWS Amplify behind CloudFront. AWS acts as our data processor and operates under their published security and compliance posture.

We do not store data outside the United States.

If you reach us from outside the U.S. (including the EEA or UK), your information is transferred to and processed in the United States. Because we keep it with a single U.S. processor, never sell or share it, and store nothing abroad, that transfer is deliberately narrow.

Who sees the data

  • The Nomisma team. The studio is small — access is limited to operators with a legitimate need, behind 2FA.
  • AWS, as our infrastructure provider (the subprocessor operating our database, email, and hosting).
  • Nobody else. We do not transfer data to advertising networks, data brokers, or affiliate partners.

How long we keep data

  • Contact messages: retained while the conversation is active, plus up to 24 months for follow-up, then archived or deleted.
  • Analytics pageviews: retained for up to 24 months in detail, then aggregated.
  • Admin audit log: append-only, retained indefinitely (compliance evidence).
  • Admin sessions: automatically expire after 8 hours.

Your privacy rights

We extend the same core rights to everyone who uses this site, wherever you live. If you submitted the contact form, or believe we may hold information about you, you can ask us to:

  • Know and access the personal data we hold about you.
  • Correct anything inaccurate.
  • Delete it.
  • Receive a portable copy (CSV or JSON).
  • Object to or restrict how we use it, and withdraw any consent you have given.
  • Opt out of analytics at any time in your browser — we honor Do-Not-Track and Global Privacy Control.

We do not charge for any of this, and we will never treat you differently for exercising these rights.

California (CCPA / CPRA)

The categories under “What we collect” are the personal information we collect. We do not sell or share it, we do not use it for targeted advertising or profiling, and we do not process sensitive personal information — so there is nothing to opt out of on those fronts. You may act yourself or through an authorized agent, and you have the right not to be discriminated against for exercising your rights.

Other U.S. states

If you live in Virginia, Colorado, Connecticut, Utah, Texas, Oregon, or any other state with a consumer privacy law, you have these same rights — we apply them to every U.S. resident rather than gating them by state. Where your state grants a right to appeal a decision on a request, you may appeal by replying to our response or emailing info@nomisma.ai.

Europe & the United Kingdom (GDPR)

If you are in the EEA, UK, or Switzerland, our lawful bases are our legitimate interests (running and securing the site and understanding usage in aggregate) and, for the contact form, taking steps at your request. You also have the right to lodge a complaint with your local data protection authority.

To exercise any of this, email info@nomisma.ai. We respond within 30 days (up to 45 for U.S. state requests where the law allows), and we may ask a question or two to verify your identity before we act.

Cookies, in detail

We only set the cookies we absolutely need to operate the site — no advertising or analytics cookies.

  • nomisma_session— an httpOnly, Secure, SameSite=Lax cookie set only when an administrator signs into the admin app at /admin. Expires after 8 hours. Holds a random 256-bit token (the server stores only its SHA-256 hash).
  • sessionStorage (not a cookie)— the first-party analytics tracker stores a transient session ID in your browser’s sessionStorage, which clears automatically when the tab closes. It never leaves the site and is never read by third parties.

Under GDPR and ePrivacy these are considered strictly necessary and do not require a consent banner.

Children

The website is not directed at children under 13 and we do not knowingly collect data about them. If you believe a child has submitted personal data through our site, please email info@nomisma.ai and we will delete it.

Changes to this policy

When this policy changes materially, we update the “Last updated” date at the top and, if appropriate, note the changes in a prior version archive. Current version: July 18, 2026.

Contact

Nomisma LLC
Fremont, California, United States
info@nomisma.ai