Nomatra Privacy Policy

Last updated: September 4, 2026

Nomatra is a privacy tool: it helps you stop future online tracking and clean up your existing digital footprint. This page explains exactly what data the Nomatra app and its backend handle, in plain terms.

The short version: almost everything Nomatra tracks about your accounts, brokers, and settings stays on your device and is never sent anywhere. Breach monitoring is registered using a one-way hash of your email address; when you check for new breaches, your plaintext email is sent to our server for that single request only — never stored — so we can query Have I Been Pwned on your behalf. The only other thing that leaves your device is an anonymized crash report if the app encounters a bug, so we can fix it — never your email or broker/app data.

Data that stays on your device

Your progress through the Prevent checklist, which data brokers you've opted out of, which apps you've configured, and any notes you've entered are stored only in a local database on your device. This data is never uploaded, synced, or backed up to any Nomatra server. Uninstalling the app or clearing its storage deletes it permanently.

Breach monitoring

If you turn on breach monitoring, Nomatra hashes your email address on your device using SHA-256 and registers that hash with our server as a lookup key — never your plaintext email address. When you check for new breaches (for example, opening the breach details screen), the app sends your plaintext email address to our server for that one request only, so it can query the Have I Been Pwned breach database on your behalf — HIBP's lookup only accepts a real email address, not a hash. Your plaintext email is used solely to make that request and is never written to our database or logs; only the hash and your resulting breach status are stored. We cannot reverse the stored hash back into an email address, and we do not attempt to.

Broker and app-preset reference data

Nomatra ships with (and periodically updates from our server) two reference databases: known data-broker opt-out procedures, and privacy-setting presets for common apps. These are read the same way for every user — fetching them does not transmit anything specific to you.

Community contributions and aggregate stats

If you submit a new app preset, report a broken opt-out link, or share whether you turned a setting on or off, we only ever receive the single value you're submitting — for example {"value": "on"} for a setting share. We do not attach a user ID, device ID, IP-derived identity, or any other identifier to these submissions. Setting shares are immediately collapsed into an anonymous aggregate counter (e.g. "87% of users turned this off"); the individual event itself is discarded once counted and cannot be traced back to you.

Beta tester signups

If you fill out the beta tester form on our website to volunteer for testing, we collect the email address, platform (iOS or Android), and your answers to a short set of yes/no screening questions that you submit. Unlike the rest of this policy, this is stored as-is, including your real email address — not a hash — because we use it to actually contact you about participating in testing. This information is kept separate from the local-first, hash-only data described above, is used only to invite and follow up with beta testers, and is never used for marketing or shared with third parties. You can ask us to delete it at any time using the contact below.

Crash and error reporting

Nomatra uses Sentry to catch app crashes and errors so we can fix bugs faster. This is diagnostics, not analytics or advertising: it does not track your activity, does not build a profile of you, and does not share data with advertisers. A crash report can include your device model, OS version, and the technical details of what went wrong (for example, which screen was open and what code failed) — it never includes your email address, which brokers or apps you've configured, or anything else described above as staying on your device. We do not attach a screenshot to crash reports, and IP address collection is turned off at the reporting-service level.

What Nomatra does not do

Data retention

On-device data persists until you delete it yourself (in-app, or by uninstalling). Breach-monitoring records are keyed only by the email hash described above, with no other personal identifier attached to them server-side.

Contact

Questions about this policy or how Nomatra handles data can be sent to nomatraapp@gmail.com.