Last updated · July 20, 2026

Privacy Policy

How selfnode collects, uses, and protects your personal data. Sections 1–10 apply across the platform; each twin then has its own section setting out exactly what it holds — Twin-Seeker, Twin-Gig, Twin-Sales and Twin-Marketing.


01

Who We Are

selfnode, Inc. ("selfnode", "we", "us", or "our") operates selfnode.me and the selfnode suite of AI products — Twin-Seeker, Twin-Gig, Twin-Sales, and Twin-Marketing. All products run on a single shared backend and identity layer. Privacy enquiries: musama@selfnode.me.

02

Information We Collect

We collect information from three sources:

  • Information you provide directly — email on signup, name, password or OAuth profile fields, LinkedIn or profile URLs, and any contacts you import.
  • Information generated through product use — emails sent/received via connected Gmail or Outlook, ICP scores, pipeline activity, and sequence performance.
  • Technical information — IP address, browser, device type, referral URL, and session data via cookies.
03

How We Use Your Data

Your data is used only to operate selfnode and improve your results:

  • Provide and improve the selfnode services.
  • Generate AI-powered outreach, scoring, and insights on your behalf.
  • Send transactional emails — password reset, billing receipts.
  • Analyse product usage to fix bugs and build new features.
  • Comply with legal obligations.
We do not sell your data to third parties — ever.
04

Gmail & Outlook Integration

When you connect your Gmail or Outlook account, we store an encrypted OAuth refresh token. We use this token solely to send emails on your behalf and to sync inbox replies back into the relevant twin product. We do not read emails unrelated to your connected product's activity.

You can revoke access at any time from your Google or Microsoft account security settings — no action on selfnode's side is required.
05

Data Storage & Security

Your data is stored on servers in the United States (AWS us-east-1). We encrypt all data at rest (AES-256) and in transit (TLS 1.3). OAuth tokens are encrypted using Fernet symmetric encryption before storage. We conduct annual security reviews and follow OWASP security guidelines.

06

Data Retention

We retain your data for as long as your account is active. You may request deletion of your account and all associated data by emailing musama@selfnode.me. We will process deletion requests within 30 days. Some data may be retained longer if required by law or for fraud prevention.

07

Cookies

We use strictly necessary cookies for authentication sessions and CSRF protection. We do not use tracking or advertising cookies. We may use analytics cookies (privacy-first, anonymised) to understand aggregate product usage.

Disabling cookies in your browser settings will prevent you from signing in to any selfnode product.
08

Third-Party Sub-processors

We work with a small set of trusted sub-processors. Each is subject to a Data Processing Agreement with selfnode:

AWSAnthropicStripeResendPostHog
09

Your Rights — GDPR & CCPA

If you are based in the EU/EEA or California, you have the right to:

  • Access your personal data.
  • Correct inaccurate data.
  • Request erasure — the 'right to be forgotten'.
  • Restrict or object to processing.
  • Data portability — export your data in a machine-readable format.
Email musama@selfnode.me to exercise any of these rights. We will respond within 30 days.
10

Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes via email or an in-product notice at least 7 days before they take effect. Continued use of selfnode after that date constitutes acceptance of the updated policy.

11

Twin-Seeker — What We Hold

To run your job search, Twin-Seeker stores:

  • Résumé files you upload, plus the text extracted from them. Uploaded file bytes are encrypted at rest at the column level, in addition to disk encryption.
  • Your job pipeline — saved roles, stages, notes, follow-up dates and application history.
  • Interview-practice sessions: the questions asked, your typed or spoken answers and the resulting scores. Where you use voice, audio is sent to a speech-to-text provider for transcription and is not retained by selfnode after the transcript is produced.
  • Your professional identity profile — target roles, skills and writing samples used to tailor applications.
The job listings index is built from public job boards and employer ATS feeds. It is shared platform infrastructure, contains no personal data of yours, and is not deleted when you close your account.
12

Twin-Gig — What We Hold

To run your freelance back-office, Twin-Gig stores:

  • Sent and received mail from the mailbox you connect, used to build your writing voice and to detect client replies. You choose the mailbox and can disconnect it at any time.
  • Client records, proposals, contracts, invoices, scope baselines and time entries.
  • E-signature evidence for signed documents: the signer's typed name, email address, IP address, user agent, timestamp and the consent wording shown to them. This is retained as the audit record of the signature.
  • Payment configuration. If you connect your own Stripe account, the credential is encrypted before storage and is used only to create charges on your account.
selfnode never receives your clients' card details or funds. Payment card data is handled by Stripe and never reaches selfnode's servers.
13

Twin-Sales — Data About Other People

Twin-Sales is different from the other three twins: most of the personal data it processes is not yours. It is about prospects — people who are not selfnode users and have no relationship with us. For that data you are the data controller and selfnode is your processor, acting on your instructions.

  • Prospect records you import, or that are returned by the enrichment and account-discovery providers you enable — name, job title, employer, and business contact details.
  • Engagement records for messages you send: delivery, opens, clicks, replies and unsubscribes.
  • Your own sending configuration, including any domain you authenticate for sending.
You are responsible for having a lawful basis to process each prospect's data and for answering their access or erasure requests. We will assist you with any such request — email musama@selfnode.me. Unsubscribes and hard bounces are suppressed across the whole platform and are deliberately never deleted, because a suppression that can be erased is not a suppression.
14

Twin-Marketing — Connected Accounts

To run your brands, Twin-Marketing stores:

  • Brand profiles — positioning, voice, visual identity, guidelines and generated content.
  • Encrypted access tokens for the social, advertising, analytics and CRM accounts you connect. Tokens are used only to perform actions you have configured on those accounts.
  • Analytics and campaign results pulled back from those platforms, and revenue events sent to your brand's webhook, used to attribute results to campaigns.
  • Contacts synced from a connected CRM, and anyone who submits one of your published forms.
Where you invite a client to connect their own accounts through a share link, those credentials are stored against the brand and are used only for that brand. Revoking selfnode's access from the platform's own settings takes effect immediately and needs no action here.
15

Browser Extension — What Runs On Other Sites

The Twin-Seeker browser extension reads job listings on the boards you visit and fills your own details into application forms. It is the only part of selfnode that executes on websites we do not operate, so what it can and cannot see is worth stating exactly:

  • It runs only on the job boards and applicant tracking systems named in its permissions — LinkedIn, Indeed, Glassdoor, Greenhouse, Lever, Ashby and Workday. It is not present on any other site, and it does not read your browsing history, your open tabs or any page you have not navigated to on those domains.
  • On a listing page it reads the job title, company name and job description — and sends them to your selfnode account only when you click “Add to Seeker”. Nothing is transmitted from a page you merely visit.
  • On an application form it reads the form's own field labels, so it knows which box is a phone number and which is a LinkedIn URL. It fills empty fields only, never overwrites what you have typed, and never submits a form for you.
  • It stores two things in your browser's local extension storage: the selfnode API key you paste in, and a short-lived cache of your own autofill details. Neither is synced across devices, and page scripts on the sites above cannot read either.
  • It contains no analytics, no advertising identifiers and no third-party trackers. The only server it contacts is the selfnode API, authenticated as you.
Uninstalling the extension removes everything it stored in your browser. Revoking its API key in Settings → Login & Security stops it reaching your account immediately, without uninstalling.

Registered entity

selfnode, Inc.

South Governors Avenue #568031111BDover, DE 19904 US
+1 302-310-7836

Privacy enquiries

musama@selfnode.me

For account deletion, data access, correction, or any GDPR / CCPA request — we respond within 30 days.