1. Who this policy covers
This policy applies to the hosted NoaCG Studio service at noacg-studio.vercel.app. NoaCG Studio is an independent open-source project. Questions and privacy requests can be sent to contact.noacg@gmail.com.
A separately self-hosted copy is operated by whoever deployed it. That operator decides which optional services are enabled and is responsible for its own privacy information.
2. What stays on your device
You do not need an account to create, preview, save locally, or export a graphic. Local projects, preferences, and drafts are stored by your browser on your device. They are not uploaded merely because you opened or used the studio.
You can remove local data using the studio's controls or your browser's site-data settings.
3. Information the hosted service may process
Account and cloud features
If you create an account, the service processes your email address, authentication details, account identifiers, and basic account status. If you choose cloud sync, community publishing, hosted productions, audience features, feedback, or cloud rendering, the content and settings needed to provide that feature are processed by the hosted service.
AI features
When you deliberately use an online AI action, NoaCG sends the material needed for that request. This can include your prompt, recent AI conversation, selected format and style settings, and images or templates you attach.
Managed NoaCG AI routes pass through Vercel AI Gateway to an eligible model provider. They request zero data retention and prohibit prompt training. The provider still receives the request transiently so it can generate the result, but eligible managed routes must not retain the prompt or use it for training. If no compliant route is available, the request fails instead of silently using a less private route.
Custom or bring-your-own-key providers are governed by the provider and account you choose. Their retention terms can differ from NoaCG's managed routes.
Do not submit sensitive, confidential, or special-category personal data to AI features. Only upload material you have the right to process.
Operational records
The service may record content-free operational details such as an account identifier, salted network identifier, feature used, model route, token counts, cost, timestamps, and success or error outcome. NoaCG's AI usage ledgers do not store prompts, uploaded images, or generated output.
On the hosted studio, optional first-party product analytics is off until you allow it. If allowed, it records a random browser identifier and five milestones: visit, return visit, signup, creation, and successful export. A creation or export carries only its fixed category, such as the creation path or export target. It does not collect project content, prompts, page URLs, campaign parameters, referring sites, user agents, or device fingerprints.
4. Why information is processed
- To provide an account or feature you requested, including cloud saves, rendering, publishing, and AI generation.
- To keep the service secure, enforce allowances, prevent abuse, diagnose failures, and control operating costs.
- To comply with legal obligations and respond to valid legal requests.
- With your separate consent, to understand whether people successfully create and export graphics and which creation paths need improvement.
Where data-protection law applies, these purposes generally rely on providing the service you requested, legitimate interests in operating it safely and reliably, legal obligation, or your consent. Optional product analytics relies on consent, is separate from account creation and the Terms, and can be refused or withdrawn without losing any feature.
5. Service providers and international processing
NoaCG does not sell personal information and does not use it for advertising. The hosted service uses processors only as needed to provide its features:
- Vercel for hosting, server functions, AI Gateway, and managed AI routing.
- Supabase for optional authentication, cloud storage, and hosted feature data.
- Authentication providers, such as Google, when you choose their sign-in method.
- AI model providers selected through the managed gateway, or selected by you for Custom/BYO use.
These providers may process data in countries other than your own. Where required, contractual and other legal transfer safeguards apply through the relevant provider agreements.
6. Retention
Local data remains until you remove it. Account and cloud content remains while needed to provide the feature or until it is deleted, subject to security, backup, dispute, and legal-retention requirements. Opted-in product analytics rows are automatically deleted after 90 days. Content sent through a managed ZDR AI route is deleted by the gateway and eligible provider after the request completes. Generated results are saved only when the product says they are being saved.
7. Your choices and rights
You can use the core studio without an account, avoid optional hosted features, choose what to upload, and remove local or cloud content through the available controls. Product analytics can be allowed or refused when first offered and changed later under Settings / Privacy. Withdrawing stops collection, removes the analytics identifier from this browser, and asks the hosted service to delete analytics rows associated with that browser and signed-in account. Browser Do Not Track and Global Privacy Control signals always disable analytics.
Send requests to contact.noacg@gmail.com. We may need to verify that the request concerns your account.
8. Changes
This policy may change when NoaCG's hosted features or providers change. The updated date above will change with it. Material changes will be presented through an appropriate service notice.