← Draw your SaaS

Privacy Policy

Effective: September 13, 2026

What we collect

We collect the checkout email you enter; the submitted URL and its normalized form; public crawl evidence; quote, checkout, order, price, currency, consent version and time; generated prompts and artwork; operational error and usage records; pseudonymous HMAC-derived visitor identifiers and view counts; and information you provide in a privacy or removal request.

We do not use login accounts. We do not intentionally collect card details; Polar handles payment information.

Why we use it

We use this information to prepare and reconcile checkout, record your requested immediate performance and policy acceptance, generate and publish the drawing, prevent duplicate views and abuse, maintain security and costs, respond to support or rights requests, and meet transaction or legal-record obligations. Depending on where you live, these purposes rely on performing your requested contract, legitimate interests in operating and securing the service, consent where required, and legal obligations.

The checkout email is transactional only. It is used for Polar checkout prefill, payment and consent reconciliation, support, and records. We do not use it for marketing, and the service does not currently send delivery email. It is not sent to the AI or image providers, or to Cloudflare R2.

Who receives data

Service providers process data for us: Vercel hosts the app and functions; Supabase stores application and transaction data; Polar handles checkout and payment as Merchant of Record; Cloudflare R2 stores public images; and OpenAI, Anthropic, and Google may process public page evidence and generation prompts. Their processing and international transfers are governed by their own terms and safeguards.

What becomes public

A successfully generated drawing, its title/category, a representative public URL, publication time, and view count can be public. Your checkout email, payment identifiers, consent record, IP-derived HMAC, and support or removal details are not intentionally published.

Retention

Checkout email on an unpaid quote is cleared after 30 days. For a paid transaction, we retain the information needed for the transaction, support, fraud prevention, disputes, and applicable legal obligations only as long as needed for those purposes. Pseudonymous per-visitor view records are deleted after one day. Consent versions and times, payment identifiers, generated or public content, and non-identifying accounting records may be retained longer where needed for transaction integrity, disputes, security, or legal duties. Removal records are retained as reasonably necessary to process and defend the request. Backups and provider records may expire on their own schedules.

Your choices and rights

Depending on your location, you may ask to access, correct, delete, restrict, or receive your personal information, object to certain processing, withdraw consent where consent is the basis, or complain to a regulator. These rights may be limited by mandatory transaction, fraud-prevention, or legal-record requirements.

For privacy, support, or removal requests, contact @Novembernine_ on X. You may also use the removal request form.

Security and children

We use access controls, signed webhooks, server-only credentials, data minimization, and bounded retention. No internet service is risk-free. The service is not directed to children, and you must be legally able to enter a paid contract in your location.

Changes

We will date material changes here and apply them prospectively where required.