Nod reads your repository, finds where personal data lives, and opens the fixes your team can review and merge.
-- days until full compliance is required on 13 May 2027
export async function signup(req) {const { name, phone, email } = req.body;if (!req.body.consent) return badRequest("Consent required");const user = await db.users.insert({name, phone, email,consentAt: now(), noticeVersion: "v1",});await scheduleErasure(user.id, { after: "24 months" });await sendWelcome(email);return ok(user);}
Most apps collect phone numbers, emails and locations from the first day. Few record why they collected them, how long they keep them, or how a person can ask for them to be deleted. From 13 May 2027, India's DPDP law makes that a legal problem, with penalties up to ₹250 crore.
No questionnaires and no consultants. Nod works from your actual code.
Start with read-only access to one repo. Nothing changes until you approve it.
Nod lists every place your code collects, stores, shares or logs personal data, with the file and line.
Each fix arrives as a normal pull request with a plain explanation. Merge what you agree with.
Five areas of the law, each matched to a concrete change in your code.
Penalties reach up to ₹250 crore. Teams that start in 2026 have time to fix things properly.
Tick what is true for your app today. It takes thirty seconds and nothing leaves your browser.
We are onboarding a small group of Indian software teams before the deadline. Tell us what you build.
No. Nod handles the engineering side: finding data flows and writing the code changes. You should still have counsel review your policies and obligations.
Any organisation that processes digital personal data in India, or serves users in India, from startups to large enterprises.
No. Nod opens pull requests. Nothing reaches your main branch until someone on your team reviews and merges it.
The pilot starts with read-only access to the repositories you choose. It looks at code and configuration, not your production data.