Nolt uses third-party vendors and hosting partners, for hardware, software, networking, storage, and related technology we need to run Nolt.
Cloud and data centers. The application is stored and executed in a collection of systems operated by Heroku and Amazon Web Services (AWS). We use Heroku for app hosting, PostgreSQL, domain management, and add-ons. We use AWS for SES email sending and S3 backups/exports. Redis is used for queues, pubsub, cache, rate-limits, and related infrastructure. Privacy policies: Heroku, AWS, Redis
Content delivery and traffic optimization. We use Cloudflare, Cloudinary, and bunny.net to deliver the website content. Cloudflare ensures that your Nolt boards can be quickly accessed from all over the world, and is also used for custom hostnames, managed SSL, CDN/cache purge, and Cloudflare Access for Ghost. Uploads are hosted and delivered by bunny.net/BunnyCDN. Cloudinary is still present for legacy/deprecated file hosting paths. Privacy policies: Cloudflare, Cloudinary, bunny.net
Payment processing. Credit card billing information is handled and stored by our credit card payment processor Paddle. We never store or transmit your credit card information on our servers. Paddle is also used for billing, invoices, subscriptions, and payment hooks. Privacy policies: Paddle
Registration and authentication. Users can signup and login with our email-based passwordless authentication system (email OTPs) or with authentication providers such as Google, Twitter, Discord, GitHub, and Microsoft. Customer-enabled SSO providers may also be used via SAML, OIDC, or SCIM. That means no passwords are ever stored by Nolt, removing the risk of a password breach or leak. Privacy policies: Google, Twitter/X, Discord, GitHub, Microsoft
Profile information. When you authenticate via a social network, we store the email address and profile image. If no photo is available, an anonymized string created from your email address (also called a hash) is provided to the Gravatar service to see if a profile picture of you is available for display. Privacy policies: Gravatar, Google, Twitter/X, Discord, GitHub, Microsoft
Email and productivity applications. Nolt uses email and productivity applications from Google Workspace and Zoho Workplace. Email is used to communicate both internally and externally, while productivity tools are primarily used internally. Privacy policies: Google, Zoho
Usage statistics, tracking & marketing. On our own website (nolt.io) and landing pages, we use Google Tag Manager and Google Analytics with IP anonymization enabled to analyse traffic, evaluate marketing effectiveness, and discover which parts of our website and software need improvement. Google may also be used for fonts and scripts. However, such analytics and tracking services are entirely turned off by default on all boards unless board owners specifically install an analytics integration on their own Nolt board(s). Privacy policies: Google
Transactional emails. In order to send system emails, we use transactional email API and infrastructure services provided by AWS SES. Privacy policies: AWS
AI and moderation features. Nolt uses OpenAI for moderation checks. OpenRouter is used for changelog AI generation; by default it uses an Anthropic Claude model, so Anthropic is a downstream processor when that model is used. Cohere is used for changelog preview summarization. Privacy policies: OpenAI, OpenRouter, Anthropic, Cohere
Error reporting and monitoring. Nolt uses Sentry for error reporting, Datadog for tracing/APM, and PostHog for logs/telemetry export. Privacy policies: Sentry, Datadog, PostHog
Support and content applications. Nolt uses Ghost for the blog, help center, case studies, and member subscription APIs. We use Chatra for the support chat widget and Missive for support/sidebar integrations. Privacy policies: Ghost, Chatra, Missive
Board integrations. Nolt allows board administrators to integrate their Nolt board with other applications and services, such as Asana, Atlassian/Jira, Trello, GitHub, Slack, Discord, Intercom, Linear, monday.com, ClickUp, Azure DevOps, Microsoft Teams, Microsoft Planner, Google Analytics/GA4, Google Sheets, Microsoft Excel, Zoho Sheet, Fathom Analytics, Plausible Analytics, Matomo Analytics, Make, Zapier, Pabbly Connect, generic webhooks, and generic SSO providers via SAML/OIDC/SCIM. For these integrations to work, we share posts, comments, usernames, and related metadata with the relevant integration only if you install and enable it. Privacy policies: Asana, Atlassian/Jira/Trello, GitHub, Slack, Discord, Intercom, Linear, monday.com, ClickUp, Microsoft, Google, Zoho, Fathom, Plausible, Matomo, Make, Zapier, Pabbly
Contact
If you have any questions about this topic, please write to us at hello@nolt.io.
This data subprocessor list was last updated on July 1, 2026.