NOFX (referred to as “we” or “us”) values your privacy. This policy applies to the NOFX website, dashboard, and related services. It does not apply to third-party apps, model providers, or external services you access with an API key. By using the service, you acknowledge that you have read this policy.
1. Information we process
- Account information: Registration email, account identifiers, email-verification status, and the account identifier and basic profile returned when you choose GitHub sign-in. NOFX Portal uses passwordless sign-in and does not issue or store sign-in passwords.
- Service records: Sign-in sessions, magic-link issuance and verification records, task completion records, rewards, the remaining-point lifecycle, and request summaries used to show usage and troubleshoot issues.
- Device and security information: IP address, request time, necessary browser and device information, and sign-in and security event records. We use this information to prevent abuse, enforce rate limits, and protect accounts.
- Information you submit: Content you enter in help, task, or other product features. Do not submit sensitive personal information unrelated to your use of the service.
2. How we use information
- Create and maintain accounts, including registration, sign-in, and email-ownership verification through an email magic link or GitHub when you choose it.
- Issue task rewards, calculate point validity, display API key usage, and provide customer support.
- Detect suspicious sign-ins, key abuse, automated attacks, and violations of the Terms of Service.
- Send necessary service notices, including security alerts, point-expiry reminders, and operational updates.
- Investigate failures and improve the service, using aggregated or de-identified information where practical.
3. Third-party services and sharing
To provide the service, we share information as necessary with Cloudflare (hosting, network security, and database infrastructure), email delivery services (magic links and necessary notices), API service providers, and GitHub only when you choose GitHub sign-in. Providers may process information only for the agreed purpose and must apply appropriate security measures.
We do not sell personal information or use it for unrelated ad targeting unless required by law, necessary to protect users or the service, or expressly authorized by you. The upstream model service you select processes the contents of your API requests; review that provider’s policy as well.
4. Cookies and local storage
We use essential session cookies to keep you signed in and prevent cross-site abuse. Essential cookies cannot be disabled without affecting service functionality. Non-essential advertising cookies are not a condition of using the service.
5. Retention and security
We retain information only as long as needed for the purposes described in this policy. Sessions, magic-link verification records, and security logs are retained for security and operational needs. Task, reward, and point records are retained through the relevant service and dispute-resolution periods. We review retention periods based on legal requirements, operations, and security risks.
We use access controls, encrypted storage, least privilege, and rate limits to protect information. Internet transmission and storage cannot be made absolutely secure. Protect your email account and API keys. If a sign-in link or key is exposed, stop using the affected credential and contact support.
6. Your rights
Where applicable law allows, you may request access to, correction of, or deletion of personal information; withdraw unnecessary consent; or object to processing. Some information is required to provide account and security services, and deleting it may prevent continued use. Submit requests through NOFX’s published support or security contact. We will verify your identity and respond within a reasonable period.
7. Minors
The service is not directed to minors below the age required by applicable law. If you believe a minor submitted personal information, contact us through the support channel. We will investigate and take appropriate steps, including deletion where required.
8. Policy updates
We may update this policy as the service, law, or security requirements change. The updated version will be posted here with its effective date. Material changes will be announced in the product or sent to the registered email address. Continued use after an update means you accept the revised policy.