Legal / Privacy

Privacy Policy

Last updated 4 September 2026

The short version

We do not sell personal data, and we never will. Our websites carry no advertising and we build no profile of you. Nothing on either site follows you around the web today, and section 4 says what would have to happen first if that ever changed.

We run two websites. www.nomadiumrobotics.com is where we describe what we build. Reading it is anonymous: no account, no cookies, no analytics, no third-party scripts. hangar.nomadiumrobotics.com is our digital store, and a store needs more. To buy something there you sign in, so we hold an account and a record of what you own. Payment is taken by Stripe, not by us, and no card number ever reaches our systems.

If you have bought from us we may email you about our products, and every one of those has an unsubscribe link that works. Section 3.8.

If you send us an ArduPilot flight log for Augury to analyse, that is entirely your choice, we tell you exactly what we do with it in section 3.6, and you can have it deleted at any time. We never publish the log. If you enter a leaderboard with it, what goes public is your chosen display name and the figure you are competing on, never your GPS track.

The rest of this page is the detail the GDPR requires.

1. Who is responsible

The controller of your personal data is:

Nomadium Robotics EDPK
UIC 208662142 · VAT BG208662142
5 Hristo Belchev Street, 1000 Sofia, Bulgaria
team@nomadiumrobotics.com

We have not appointed a Data Protection Officer. We are not required to: we do not monitor people on a large scale and we do not process special categories of data. Any privacy question sent to the address above reaches the people who can answer it.

One exception worth naming up front. When you buy something from us, Stripe is the merchant of record. That means Stripe is the legal seller of that transaction and is a controller of your payment data in its own right, not simply a supplier acting on our instructions. Section 6 explains what that changes for you.

2. What this policy covers

One policy, both websites, so the two can never drift apart. It covers:

  • www.nomadiumrobotics.com, our main site
  • hangar.nomadiumrobotics.com, our digital store, and the account behind it
  • Augury, our flight-log analysis tool, any log you choose to send us for it, and our leaderboards
  • email and messages you send us, and our Discord server

It does not cover other companies’ websites we link to, or the social platforms where we also post, including YouTube, LinkedIn and Instagram. Those services collect data under their own policies and we have no control over them.

3. What we collect, and when

Nothing here is collected in the background. Each item below is attached to something you actually do.

3.1 Reading either website

Reading is anonymous. We ask you for nothing and neither site tries to work out who you are.

Like every website, ours is delivered by a hosting provider that keeps short-term technical logs. These typically record the IP address of the request, the browser’s user-agent string, the page requested, the time and the response status. The same is true of the service that runs our store’s backend, which additionally logs an internal request id so a failure can be traced.

We use these to deliver pages, keep the sites available and defend them against attack and abuse. We do not use them to build a picture of any individual and we do not export them.

Legal basis: legitimate interests, Article 6(1)(f) GDPR. Our interest is running secure, working websites.

3.2 Creating an account

You need an account to buy from the hangar. There is no guest checkout, because we would rather tie what you own to an identity you control than email download links around.

You sign in one of two ways, and each gives us a different amount:

  • A sign-in link sent to your email address. We get your email address, and nothing else.
  • Signing in with Google. Google gives us your email address, your name, your profile picture and your Google account identifier.

Either way we hold an account identifier we generate, the sign-in method you used, and the times you created the account and last signed in. Identity is handled for us by Firebase Authentication, part of Google Cloud.

We never see or hold a password. There is no password to hold. Neither method uses one.

Legal basis: Article 6(1)(b) GDPR, performance of a contract and steps taken at your request before entering one.

3.3 Buying something

The purchase itself happens on Stripe’s own checkout page, on Stripe’s domain. Card numbers, billing addresses and payment details are collected by Stripe and never pass through our systems. We could not see them if we wanted to.

What we receive back and store, keyed to your account, is deliberately narrow:

  • what you bought, and which price you paid
  • the amount, the currency, and Stripe’s identifiers for the payment
  • whether it was later refunded or charged back, and when
  • the version of the product on sale at the time, and the update term you were sold
  • the time of the purchase
  • the email address the order was placed with, and Stripe’s identifier for the invoice it issued you

That record carries no name and no postal address. It holds one contact detail, the email address, and it holds that because two things need it. If you buy before you have an account, that address is the one thing that lets us join the purchase to you afterwards. And when you ask us what happened to an email about your order, we can answer from the order itself rather than from a server log we have already discarded.

Until 2026-09-03 this paragraph said the record carried no email address at all, which was true when it was written. It is corrected here rather than quietly reworded. A policy that changes without saying so is worse than one that was out of date.

The reason for the rest of the record is unchanged: we are not trying to keep three copies of the same thing. Section 3.2 says what your account holds, and the paragraph below says what we can see in Stripe.

We can see the customer record Stripe holds, in Stripe’s own dashboard, because Stripe is the merchant of record for your purchase. That includes the email address you gave at checkout, the country used to work out your VAT, the amount and the tax, and the status of any refund or dispute. We use it to support you, to reconcile our revenue and to answer questions about an order.

Legal basis: Article 6(1)(b) GDPR for the purchase and for giving you what you paid for. Article 6(1)(c), a legal obligation, for records we are required to keep. Article 6(1)(f) for detecting fraud and abuse.

3.4 Downloading what you bought

When you download a file you have bought, our backend checks that you own it, prepares a copy for you, and hands your browser a signed link that expires after one hour. The file comes straight from storage and never travels through anything of ours in between.

Your copy is marked. Files we sell may carry a serial that identifies the purchase they came from. It is there so that a leaked file can be traced back to the account that bought it, which is what makes selling an open design workable at all. That serial is derived from your account identifier and is not readable as your name, your email address or anything else about you.

Per-customer copies are deleted automatically one day after they are made. Downloading again simply makes a new one.

Legal basis: Article 6(1)(b) GDPR for the download itself. Article 6(1)(f) for the serial, our interest being the protection of our intellectual property.

3.5 Referrals and affiliates

If you share a referral link, we store a referral code against your account and we record which account the referral came from and which purchase it led to. We need that link to apply your friend’s discount, to credit the referrer, and to see whether a scheme is working at all. So a purchase made through a link is connected, in our records, to the person whose link it was.

If you take part in a referral or affiliate programme, we report back to you on the referrals your link generated, so that you can check what you have earned. The programme’s own terms say exactly what that report contains before you join it. We do not hand a referrer somebody’s contact details as part of it.

Legal basis: Article 6(1)(b) GDPR where the scheme is part of what your account or your affiliate agreement gives you. Article 6(1)(f) for the abuse checks that stop somebody referring themselves, our interest being a scheme that is not being gamed.

3.6 Flight logs you send to Augury

This one deserves its own section, because a flight log says more than it looks like it does.

Sending us a log is voluntary and nothing in our products requires it. If you do send one, we receive the file as recorded by your autopilot. An ArduPilot log usually contains a full GPS track: where the aircraft took off, where it flew, where it landed, at what times, along with the aircraft’s configuration, its parameters and its telemetry. A take-off point is frequently somebody’s home, field or place of work, so this is location data about a person even when no name appears anywhere in the file.

We use logs you send us to:

  • analyse that flight and give you the result
  • find and fix faults in our aircraft, our parameters and our tooling
  • improve Augury itself, including the reference data it compares a flight against

We never publish the log file itself, we do not give it to other customers, and we do not sell it. Where a log feeds a benchmark or a reference figure, it does so in aggregate, with no position data and nothing identifying the flight or the operator. The one exception is a leaderboard you choose to enter, and it is described below.

Only send us logs you are entitled to share. A log may contain data about people other than you, including another pilot, a client, or the location of a third party’s property. If it is not yours to send, please do not send it.

Legal basis: consent, Article 6(1)(a) GDPR. You can withdraw it at any time by emailing us, and we will delete the logs you sent. Withdrawal does not undo analysis already delivered, and it does not reach an aggregate figure a log has already contributed to, because that figure no longer contains anything about you.

Retention: we keep a log until you ask us to delete it, or until it is of no further use to us, whichever comes first.

Leaderboards

We run leaderboards where pilots compete on things like speed, endurance and distance, using a flight log as proof of the claim. Entering one is your choice and nothing enters a leaderboard by itself. Submitting a log for analysis does not put you on a board.

If you do enter, what becomes public is the display name you choose, the figure you are competing on, the aircraft, and the date. The log itself is never published. No GPS track, no take-off or landing point, no route, no waypoints and no raw telemetry. We read the log to verify that the claim is real, and what we publish is the result of that check, not its input.

Choose a display name you are content to have public. It does not have to be your real name.

Legal basis: consent, Article 6(1)(a) GDPR. You can withdraw at any time and we will take your entry down. Two honest limits: taking an entry down cannot reach a copy somebody else has already saved or a search engine has already cached, and where removing an entry would rewrite a past season’s published result we may keep the figure under a placeholder name instead of deleting the row. Tell us if you would rather it went entirely and we will discuss it.

3.7 Emailing us, or filling in a form

When you write to us we receive your email address, any name or company you give, and whatever you put in the message. If you send an attachment, we receive that too. The same applies to any enquiry or configurator form on our sites: we receive what you type into it, and the form tells you what it asks for before you send it.

We use it to answer you and to continue the conversation.

Legal basis: Article 6(1)(b) GDPR where your message is a step towards a contract, for example an enquiry about buying or testing a product. Otherwise legitimate interests, Article 6(1)(f), in responding to people who contact us.

Retention: for as long as the enquiry or the relationship is live. Where a message becomes a business record, Bulgarian accounting and commercial law sets longer minimum periods and we keep it for those.

3.8 Email about our products

We send two different kinds of email and you are in charge of the second one.

Email you cannot turn off, because it is the service itself and not marketing: your sign-in link, your receipt, a notice that something you own has been updated, a safety or airworthiness notice about a product you bought, and anything we have to tell you about your account. Turning these off would mean not doing the thing you paid for.

Email you can turn off. If you have bought something from us, we may write to you about updates to it, about new products, and about what we are building. Every one of those messages has an unsubscribe link, it works immediately, and refusing costs you nothing else. We ask when we take your address, and you can change your mind at any time by using the link or by emailing us.

If you have not bought anything from us, we will not email you about our products unless you have asked us to. No bought lists, no scraped addresses, no cold outreach to people who filled in a support form.

Legal basis: legitimate interests, Article 6(1)(f) GDPR, in telling our own customers about our own products, relying on the existing-customer rule in Article 13(2) of the ePrivacy Directive as implemented in Bulgaria. Consent, Article 6(1)(a), for anybody who is not already a customer. You have an absolute right to object under Article 21(2), we do not weigh it against anything, and the unsubscribe link is the fastest way to use it.

Retention: we keep your address on the list until you unsubscribe. After that we keep the minimum needed to remember not to email you again, which is the only way an opt-out can be made to stick.

3.9 Our Discord server

We run a community Discord and link to it from our sites. If you join, Discord is the controller of that platform and its own privacy policy applies to you there. We see your Discord handle, your messages in our server, and whatever your profile shows. We use that to run the community and to support people. Leaving the server ends it, apart from anything covered by 3.10.

Legal basis: legitimate interests, Article 6(1)(f) GDPR, in running a support and community channel for our users.

3.10 Verifying that you built one

Our Discord runs a verification bot, so that a Verified Builder badge means something. It holds nothing about you unless you apply to it. If you never press the button, this section does not describe you.

If you do apply, we keep your Discord account ID, the aircraft serial you entered, what you wrote about your build, the code we asked you to write out by hand, a note of each photo you sent, and the decision we reached with who made it. The note of a photo is its file name, size and type. We do not keep copies of the photos. They stay on Discord, in the review thread, and we delete that thread when we delete the record.

We delete a rejected application after 30 days, and the private evidence behind a private claim after 30. A community application’s record goes after 90. We keep the serial itself, and the fact that it is verified, for as long as the verification stands.

A public Builder Card is your choice and it is separate. Only the photos you marked public go on it, next to your Discord username and the aircraft serial in full, not masked. Ask us and we will take it down.

Applying is voluntary and nothing you bought depends on it. Leaving the server does not delete an application you already sent, so email us if you want it gone.

This all runs on our own hardware rather than a third party’s, which is why section 6 names no new provider for it.

Legal basis: legitimate interests, Article 6(1)(f) GDPR, in checking that a serial belongs to the person claiming it. Consent, Article 6(1)(a), for a public Builder Card, and you can withdraw it at any time.

4. Cookies and browser storage

We set no advertising cookies, no tracking cookies and no cross-site identifiers today. Nothing we currently run follows you to another website.

We may add advertising or conversion tracking later, because we may want to know whether an ad campaign works. If we do, it will not happen quietly. Everything below applies before a single such cookie is set:

  • it goes behind a consent banner, and nothing loads or is set until you accept
  • refusing is as easy as accepting, it is the default, and refusing costs you nothing else on either site
  • you can change your mind at any time, and there will be a visible way to do it
  • the provider is named in section 6 first, which is the standing rule this whole policy runs on

We will still never sell personal data, and we will not build a profile of you to sell or share with an ad network beyond what a campaign measurement needs. That part is not conditional.

What is actually written to your browser today:

  • www.nomadiumrobotics.com writes nothing at all. No cookies, no local storage, no session storage. This is a site you read.
  • hangar.nomadiumrobotics.com stores your sign-in session, once you sign in. Firebase Authentication keeps it in IndexedDB where the browser allows it, and falls back to local storage or session storage where it does not. It is what stops you having to sign in again on every page. While a sign-in link is in flight, the address you typed is held in local storage on your own device so the link can be completed in the same browser.
  • Stripe’s checkout page sets its own cookies, on Stripe’s domain, under Stripe’s policy. It is a different website and we have no say in what it does.

The sign-in storage is strictly necessary to provide a service you asked for, so it needs no consent, and that is the only reason there is no cookie banner on either site today. The day we add advertising, conversion tracking or a non-cookieless analytics product, a banner arrives with it. There is no version of this where one of those ships and the banner does not.

5. Analytics

We run no analytics on either site today. No page-view counter, no heatmap, no session recorder, no A/B testing tool.

We may add a way of counting page views, and we are committing here to how:

  • If we use a cookieless product, such as Cloudflare Web Analytics, it sets nothing in your browser, does not fingerprint you and cannot follow you to another site. It gives us aggregate counts and no picture of any individual. There is nothing to consent to, so there is no banner. Legal basis, so far as any processing occurs: legitimate interests, Article 6(1)(f) GDPR, in understanding whether our websites work.
  • If we use Google Analytics, which is not cookieless, we will ask you first. It will not load and it will set nothing until you accept, refusing will be as easy as accepting, and you will be able to change your mind. Legal basis: consent, Article 6(1)(a) GDPR, and Article 5(3) of the ePrivacy Directive as implemented in Bulgaria.

Either way, the provider gets added to section 6 and this section gets rewritten before it goes live.

6. Who else handles your data

This list is complete, and it is the register we maintain. If a company is not named here, it is not handling your data. We add a provider to this page before we switch it on, never afterwards. That is a standing rule written into how we build both sites, and it is the reason this section reads like an inventory rather than a paragraph.

Everyone below acts as our processor, on our instructions only, under a data processing agreement, unless it says otherwise.

Infrastructure and hosting

  • Cloudflare, Inc. (United States) and Cloudflare’s EU entities. Serves both websites, their DNS and their protection against attack. Handles the technical logs in section 3.1.

Accounts, store and files, all provided by Google Ireland Limited and Google LLC (United States) under Google Cloud and Firebase:

  • Firebase Authentication. Your account and how you sign in, per section 3.2.
  • Firebase Realtime Database. What you own, per section 3.3. Hosted in the EU, europe-west1.
  • Google Cloud Run. The service that creates a checkout, records a purchase and authorises a download. Hosted in the EU, europe-west1.
  • Google Cloud Storage. The files we sell, the per-customer copies in section 3.4, and any flight log you send us under section 3.6. Hosted in the EU, europe-west1.
  • Google Cloud Tasks. The queue that holds an email until it has been sent, so that a message survives a failure instead of being lost. A queued task carries the address the message is going to. Hosted in the EU, europe-west1.
  • Google Cloud Logging. The operational logs those services write.

Payments

  • Stripe. Its European entity is Stripe Payments Europe, Limited, in Ireland, working with Stripe, Inc. in the United States. Stripe takes the payment, checks it for fraud, calculates and remits the VAT, issues your receipt and handles refunds and disputes.

    Stripe is not only our processor. We use Stripe Managed Payments, under which Stripe is the merchant of record: the legal seller of the transaction. For your payment data Stripe is a controller in its own right and decides how it handles it, under Stripe’s own privacy policy. Two consequences worth knowing. Your bank or card statement will show Stripe, or Link, rather than our name. And a request to delete your data that reaches Stripe removes Stripe’s payment records, including the copies visible to us, which we cannot restore.

Email

  • Resend, Inc. (United States). Sends our email: sign-in links, receipts and notices about your account, and the product announcements in section 3.8 that you can unsubscribe from. It receives the address it is sending to and the content of the message.
  • Google Workspace, provided by Google Ireland Limited. Our own mailboxes. Anything you send to us at team@nomadiumrobotics.com is held here.

Community

  • Discord. Our community server, per sections 3.9 and 3.10. Discord is the controller of its own platform, not our processor. The verification bot in 3.10 is ours and runs on our own hardware, so there is no other company involved in it.

And what we do not use today. No advertising or ad-measurement networks. No data brokers. No visitor identification or lead enrichment services. No chat widget. No embedded video players, maps or social widgets. No font CDN: both sites serve their fonts from our own server.

That list is a statement of fact about today rather than a promise about forever, and section 4 sets out what has to happen before an advertising or measurement provider joins the list above. One thing on it is a promise about forever: we do not sell or rent personal data, and we never will.

We may disclose data where the law requires it, or to establish or defend a legal claim.

7. Transfers outside the EEA

We keep data in the EU wherever the choice is ours. Our databases, our storage and our backend all run in Google’s europe-west1 region, in Belgium.

Some of the providers above are established in the United States, or use group companies there. Where a provider is certified under the EU-US Data Privacy Framework we rely on that adequacy decision. Google and Cloudflare are both certified. Otherwise we rely on the European Commission’s Standard Contractual Clauses, together with the technical measures the provider applies. Resend’s transfers are covered by the Standard Contractual Clauses in its data processing addendum.

You can ask us which mechanism applies to a given provider and we will tell you.

8. How long we keep things

  • Technical and hosting logs: a short period set by the provider, typically about 30 days, after which they are deleted or aggregated.
  • Your account: until you delete it, or ask us to.
  • What you own: for as long as you have an account, so that you keep access to what you bought. See section 10 for what survives a deletion, and why.
  • The email address on a purchase record: for as long as we keep the purchase record itself. It is part of that record rather than a separate list, so it lives and goes with it.
  • Per-customer copies of files: deleted automatically one day after they are made.
  • Download links: they stop working one hour after they are issued.
  • Flight logs sent to Augury: until you ask us to delete them, or until they are of no further use to us.
  • A leaderboard entry: until you withdraw it, subject to the two limits in section 3.6.
  • A Builder verification application: 30 days after we reject it, or after a private claim is decided. 90 days for a community application. The review thread and its photos on Discord go at the same time. A verified serial and its status are kept while the verification stands.
  • Database backups of the verification records: the newest 14 daily copies, held where the bot itself cannot reach them, then overwritten.
  • Referral records: for as long as the scheme they belong to is running, plus whatever we need to settle what is owed under it.
  • Your address on our product-announcement list: until you unsubscribe. After that we keep the minimum needed to remember not to email you again.
  • Email and enquiries: for as long as the conversation or the relationship is live.
  • Records we are legally required to keep, including accounting and tax records: for the period the law sets, and no longer.

9. Your rights

Under the GDPR you have the right to:

  • access the personal data we hold about you (Article 15)
  • correct it if it is wrong (Article 16)
  • erase it in the circumstances the law allows (Article 17)
  • restrict how we use it (Article 18)
  • receive it in a portable form (Article 20)
  • object to processing based on legitimate interests (Article 21). Your objection to marketing email is absolute and we do not weigh it against anything (Article 21(2))
  • withdraw consent at any time, where we rely on consent, such as a flight log you sent us or a leaderboard you entered (Article 7(3))

To exercise any of these, email team@nomadiumrobotics.com. We will respond within one month. Exercising them costs you nothing.

Complaints. If you think we have handled your data badly, please tell us first so we can put it right. You also have the right to complain to a supervisory authority. Ours is the Commission for Personal Data Protection, 2 Prof. Tsvetan Lazarov Blvd, 1592 Sofia, Bulgaria, cpdp.bg. You may instead complain to the authority in the EU country where you live or work.

10. Deleting your account

Email us and we will delete it. Specifically, we remove your sign-in identity, the record of what you own, your referral code and any credit balance, any flight log you have sent us, and your address from our announcement list. Per-customer copies of files expire on their own within a day. Leaderboard entries come down too, subject to the two limits in section 3.6.

You do not have to delete your account to stop the email. The unsubscribe link does that on its own and changes nothing else.

Three things you should know before you ask.

You lose access to what you bought. The record of your purchase is the only thing that proves it. Deleting it means we can no longer give you the files or any future update to them, and we cannot reverse that.

A minimum record may survive, and only where the law requires it. Where we are obliged to keep an accounting record, or need to retain something to defend a legal claim, we keep the narrowest version of it and use it for nothing else.

Stripe holds its own record. Stripe is the merchant of record for your purchase and keeps the transaction under its own obligations. Deleting your Nomadium account does not delete Stripe’s copy. Stripe’s privacy policy explains how to make that request to Stripe.

11. Automated decisions and profiling

We make no automated decisions about you that produce legal effects or similarly significant effects, and we do no profiling.

One thing to disclose honestly: Stripe screens payments for fraud automatically, as merchant of record, and that screening can decline a payment. That is Stripe’s decision on Stripe’s systems, not ours. If a payment of yours is declined and you think it was wrong, tell us and we will help you take it up with Stripe.

12. Children

Our products are aimed at professional, industrial and institutional users, and our store is aimed at adult builders and makers. Neither site is directed at children, we do not knowingly collect data from them, and accounts are not intended for anyone under 16.

13. Security

Both sites are served over HTTPS only, with a content security policy that refuses scripts we have not authorised. Your sign-in session is proved to our backend on every request that matters, and owning something is checked separately from being signed in, every single time.

Files you have bought are held in closed storage that nobody can read directly. Access is a signed link that expires within the hour. Payment secrets are held in a managed secret store and never in our code. The service that takes payments can read the files we sell and cannot alter them, which is a boundary we built on purpose.

Our email and internal systems use multi-factor authentication and access is limited to the people who need it. No system is perfectly secure, but we hold very little about you in the first place, which is the most reliable protection there is.

14. Changes to this policy

We will update this page when what we do changes, and we will move the date at the top. If a change is material, we will say so on the page rather than leave you to spot it.

We update it first, not afterwards. A new provider, a new tool, a new form or a new way of counting visitors gets written into section 6 and into whichever section describes it before it reaches you. That is a rule we hold ourselves to, and this page is where you can hold us to it.

15. Contact

Questions about this policy, or about privacy generally: team@nomadiumrobotics.com.

Nomadium Robotics EDPK · UIC 208662142 · VAT BG208662142
5 Hristo Belchev Street, 1000 Sofia, Bulgaria

Still from the Pathfinder George YouTube channel showing the TerraHawk in the field

Join 25'000+ Followers

Follow our journey on our Founder's YouTube & IG channels:

PathfinderGeorge
[Learn more @ www.nomadiumrobotics.com]1.2.1[Aerial Robotics for a Resilient Future]