Security at NoCodePro.AI
We say plainly what we do to protect your account, your data, and the apps you build — and we don’t claim badges we haven’t earned. Everything on this page is something you can hold us to.
Encrypted on the way to us
Everything travels over TLS — the same encryption your bank uses. Passwords are held by our sign-in provider and never reach our database.
Secrets get their own key
Your keys and project secrets each get their own lock, with AES-256-GCM, before they are stored — on top of the encryption our hosting provider already applies.
Your work is not training data
Paid prompts, code and project content are routed to billed provider keys, which are not used to train models. We do not sell your data, and we run no advertising trackers.
European privacy law applies
GDPR covers us and we follow it — including the right to get your data out and the right to have it erased.
It stays yours
Three promises with a mechanism behind each one — not a policy sentence hoping you never test it.
Export whenever you want
You can export your full project source from your account. Every download is checked first — a broken or empty one is refused rather than handed over.
Deletion that really deletes
Delete your account and you have 30 days to change your mind. After that we clear your data everywhere it is held, and wipe what the AI remembers about you. Financial and audit records are anonymised and kept, because tax and fraud law requires it.
You can see who we rely on
Every company we share data with is named in full in the DPA. If you cancel a paid plan, your projects become read-only. You can still export them for 60 days before generated files are cleared, and your blueprints and project details are kept either way.
Getting in is the hard part
Most breaches are a sign-in problem, so that is where the strictest controls sit — including on us.
Two-factor and passkeys
Sign-in and sessions run on Clerk. You can add an authenticator app or a passkey, review active devices, and end any session from your security settings.
Our own staff are challenged too
Sensitive operations in our internal admin tools require staff to re-authenticate at the moment of the action, not just at sign-in.
Abuse gets throttled
The parts of the platform that spend money or touch sensitive data are capped per person, so a stolen session or a runaway script cannot quietly drain an account.
Secure defaults you didn't have to ask for
You describe the product in plain English. Keeping it secure underneath is our job, not yours.
Sensitive routes require sign-in
When your app holds personal, payment or health data, every page that touches it is marked as needing sign-in — and one that misses it is repaired before the blueprint is accepted, not after you notice.
Keys stay on the server
Any keys and settings you add are stored encrypted, and unlocked on our own servers when your app goes live. They are never written into the files a visitor downloads.
You can take the code and go
Export the running source at any time. If we ever disappear, your app does not.
What we’re honest about
- A real disclosure channel, published at /.well-known/security.txt
- A public status page you can check without asking us
- A full sub-processor list in the DPA — no unnamed third parties
- No advertising or cross-site tracking anywhere on the platform
Found something? Tell us.
Email support@nocodepro.ai with steps to reproduce. We acknowledge reports, and we won’t pursue good-faith researchers who follow coordinated disclosure and avoid privacy violations or service disruption.