Privacy Policy
For accounts created before 14 September 2026, the updated rules on AI model providers and quality tests (sections 3, 4, 5 and 8) apply from 28 September 2026. The same date applies to how sections 3 and 5 describe our product search providers, for accounts created before 20 September 2026.
1. Who is responsible
NovaVerto AI (novaverto.com) is operated by Rastislav Bertusek, sole proprietor, Brackenweg 14, 5200 Brugg, Switzerland. We are the controller of the personal data described here. Contact for anything privacy-related: info@novaverto.com.
We process data in line with the Swiss Federal Act on Data Protection (FADP) and, where it applies to you, the EU/UK GDPR.
2. What we collect
- Account data — your email address, the sign-in identifier Google Identity Platform assigns to your account (or the identifier from the Google, Apple or Microsoft account you sign in with), account creation date, and the language/timezone of your browser. We store no password; the one-time sign-in codes we email you are stored hashed and deleted within a day. If you sign in with Google, Apple or Microsoft, that provider tells us your email address and an account identifier and nothing else from the account; its own privacy policy covers what it records about the sign-in. When you create your account we also note how you found us on that visit: the campaign tags on the link you arrived through (utm_source, utm_campaign and similar), the website that sent you, the page you first opened, and whether the link came from a Google or Meta ad (not the ad's click identifier). This is read from the address bar, not from a cookie.
- Room photos and designs — the photos you upload, the settings you choose (style, budget), the images we generate, and the furniture crops and product matches derived from them.
- Billing data — your Stripe customer id, plan, subscription status and period, purchase and refund history, and a credit ledger. Card numbers are handled by Stripe only; we never receive them.
- API and integration data — if you use our API: the name, creation date and last use of each API key (we store a one-way hash of the key itself, never the key), the callback address you attach to a request and the secret we sign callbacks with, and a log of the requests made with each key. Photos and other data sent through the API are handled like uploads made in the app (section 3). If you connect an AI assistant or another app to your account: the app's name, when you connected it and when it was last used, and a log of the requests it made. We store only one-way hashes of the access tokens we issue to it.
- Technical and usage data — IP address, browser type, timestamps, the pages and API calls you make, and error reports. We use these for security, abuse prevention and to fix bugs. We also keep the date you last used the Service while signed in (
last_active_at, one date, not a history), so that inactive accounts can be deleted as described in section 8. - Support messages — whatever you send us by email.
We do not knowingly collect data from children under 16 and the Service is not intended for them.
3. How photos are handled
Location and camera metadata (EXIF, including GPS) is stripped from every upload before anything else happens. Uploads are screened automatically and rejected if they appear to show people, personal documents or explicit content. Photos and generated images are stored privately on Google Cloud Storage and are only accessible through short-lived signed links tied to your account — nothing is public unless you explicitly share a design. To generate a design your photo is sent to an AI image model; today that is Google's Gemini models on Google Cloud. To find matching products, crops of the generated furniture (never your original photo) are sent to a product search provider that looks for matching items in online stores.
Which AI providers may receive your photos. We may use other AI model providers besides Google, for generating designs or for the quality tests described below. Whichever provider we use, your photos, your designs and anything derived from them are only ever sent to providers that do not use the data to train AI models and that keep it only as long as necessary — to answer the request and, where the provider requires it, for a limited period of security and abuse monitoring (typically no more than 30 days) — after which they delete it. Providers that train on the data they receive never get your photos or designs, and we do not use your photos or designs to train AI models either.
Improving the Service. To keep results good, we may use your photos, designs and the images generated from them to test and improve the Service — for example to compare how different AI models render the same room, or to tune the instructions we give them. These tests follow the rules above, are carried out only by us, and their results are stored privately on our own cloud storage. They are never published, never shown to anyone outside NovaVerto and never used for advertising, and they are deleted as described in section 8. You can object to this use at any time (section 10), and we will exclude your account from future tests.
Photos submitted through the API. Some businesses use our API to offer redesigns inside their own products. A photo that reaches us that way is processed exactly as described above — metadata stripped, screened, stored privately, and sent only to the AI providers named here under the same no-training, limited-retention rules — and is stored under the API customer's account, which can delete it at any time. That business is responsible for having the right to submit the photo and for telling its own users how their data is handled. If you have used such a product and want to know what it sent us, ask that business first; if you cannot get an answer, contact us and we will help where we can.
4. Why we process your data (legal bases)
- To provide the Service you signed up for (contract) — accounts, designs, credits, payments and support.
- Our legitimate interests — keeping the Service secure, preventing abuse and fraud, fixing errors, understanding aggregate usage, and testing and improving the quality of the designs we generate (section 3). This includes the suppression record described in section 8, which stops the free tier from being claimed repeatedly by deleting and re-creating an account, and the date of your last use that lets us delete inactive accounts instead of keeping their photos indefinitely.
- Legal obligations — keeping accounting records and responding to lawful requests.
- Consent — only where we ask for it explicitly, e.g. a marketing email you can opt out of at any time.
We do not sell personal data and we do not show third-party advertising.
5. Who we share data with
We use a small number of processors, each bound by a data-processing agreement:
- Google Cloud (Google LLC / Google Ireland) — hosting, database, file storage, sign-in (Identity Platform) and the Gemini API. Our infrastructure runs in the United States (us-central1).
- Other AI model providers — for generating designs and for quality tests (section 3) we may also use other AI model providers, directly or through the routing services OpenRouter (OpenRouter Inc., United States) and Runware (Runware Ltd, United Kingdom). Your data only goes to providers that do not train on it and keep it no longer than necessary, as described in section 3. Renders routed through OpenRouter go only to image-model providers that do not train on your photo and keep it for at most 30 days. The providers currently in use, and how long each keeps data, are listed on request.
- Stripe (Stripe Payments Europe / Stripe Inc.) — payments, subscriptions, invoices and the billing portal. Stripe is an independent controller for the payment data it collects; see Stripe's privacy policy.
- Product search providers — to find the furniture in a design we send crops of the generated image to providers that search online stores for matching items. They are in the United States, and we may change which one answers a search. The provider in use is listed on request.
- Sentry (Functional Software Inc., United States) — error monitoring; reports may include your IP address, browser details and the URL where an error happened.
- Cloudflare — DNS and email routing for our domain, and the Turnstile bot check shown when you create an account. Turnstile processes your IP address and signals about your browser to tell people apart from automated sign-ups; it does not read what you type. See Cloudflare's Turnstile Privacy Addendum.
- PostHog (PostHog Inc., United States) — product analytics: which pages and features you use, tied to your account id. Loaded only after you accept statistics cookies.
- Resend (Plus Five Five Inc., United States) — delivery of transactional email (welcome, billing and credit notifications). Links in our emails carry campaign tags (utm_source, utm_campaign) naming the email, and the small photo beside the signature loads from our own site, which tells us the email was opened. Both are recorded in PostHog against your account id so we can see which emails are useful. If you unsubscribe from marketing emails, opens are no longer recorded; blocking images in your mail app stops it too.
- Meta (Meta Platforms Ireland Ltd) — advertising measurement. If you accept marketing cookies, the Meta pixel records which pages you visit and whether you sign up or start a checkout. When a purchase completes, our server also reports the purchase and its value to Meta, along with a one-way cryptographic hash of your email address (never the address itself) so Meta can tell whether you came from one of our ads. Nothing is sent if you decline marketing cookies.
- Google Analytics / Google Ads (Google Ireland) — the same advertising measurement on Google's side, also only after you accept marketing cookies. Google Consent Mode is used, so no advertising identifiers are set until you have agreed. When a purchase completes, our server reports the purchase and its value to Google Ads, identified only by the click identifier Google itself added to the ad link you arrived on. If you are signed in, a one-way cryptographic hash of your email address (never the address itself) is also sent when you sign up or start a checkout, so Google can recognise its own click even after your browser has discarded the cookie that identified it. Nothing is sent if you decline marketing cookies.
- PromoteKit (United States) — our creator affiliate programme. If you arrive through a creator's link and accept marketing cookies, a cookie (60 days) records which creator referred you; if you then sign up or buy, that referral, your email address and the payment amount are shared with PromoteKit so the creator can be paid their commission. Buying with a creator's promo code does the same through Stripe, without a cookie. Nothing is recorded if you decline marketing cookies and use no code.
Apps you connect. If you connect an AI assistant or another app to your account (for example Claude, ChatGPT or Gemini), we send it what it asks for on your behalf: your email address, plan and credit balance, your projects and designs (including links to the images and videos), and the products matched to them. We do this only after you approve the app, and only until you disconnect it on your account page or it is disconnected automatically after 90 days without use. These apps are not our processors: you choose them, and their providers handle what they receive under their own terms and privacy policies — including any photo you give the assistant directly in a chat. Our rules on AI model providers (section 3) cover the providers we send your photos to, not an assistant you connect.
We may also disclose data if required by law or to protect our rights, and to a successor if the business is transferred (you would be notified).
6. International transfers
Because our providers operate in the United States, your data leaves Switzerland/the EEA. Google, Stripe, Meta and Sentry are certified under the Swiss–U.S. and EU–U.S. Data Privacy Frameworks; where a provider is not, we rely on the EU Standard Contractual Clauses (with the Swiss addendum). Runware is based in the United Kingdom, which Switzerland and the EU recognise as providing an adequate level of data protection. Copies are available on request.
7. Cookies and local storage
Strictly necessary storage runs without asking: sign-in state (kept in your browser's local storage by Firebase/Identity Platform), a session cookie on Stripe's checkout and billing pages, and the cookie that remembers your consent choice. Anything else — statistics or marketing cookies — is loaded only after you opt in through the cookie banner, and you can change or withdraw that choice at any time via "Cookie settings" in the footer. Consent is managed by Cookiebot (Usercentrics A/S, Denmark). The table below is generated from our latest scan and lists every cookie by purpose and lifetime.
8. How long we keep data
- Photos, designs and product matches — until you delete them, or until the account is deleted for inactivity as described in the Terms (section 11). Deleting a design removes its files immediately.
- Quality-test images (section 3) — deleted when the design or account they came from is deleted, and in any case within 90 days of the test.
- Account data — until you delete your account, or until the account is deleted for inactivity as described in the Terms (section 11), after which it is removed from our systems immediately and from backups within 30 days. An account with no active subscription and no unexpired credits is deleted 90 days after the latest of your last use of the Service while signed in, the end of your last subscription and the expiry of your last credits, after a warning email at least 14 days before. To apply this rule we keep
last_active_at, the date you last used the Service, for as long as the account exists. - Billing and accounting records — 10 years, as required by Swiss accounting law (Code of Obligations art. 958f). These are kept without your photos.
- Suppression record after you delete your account — 12 months, then deleted automatically. When you delete your account we erase your data, but keep one record that contains no readable details: an irreversible hash of your email address (and, if you ever paid, of your card's fingerprint as your payment provider reported it), computed with a secret key held outside our database. We use it for one purpose only — to see that the free starter credits have already been claimed for that address, so the free tier cannot be collected over and over by deleting and re-registering. It cannot be turned back into your address, it is never used to contact, profile or track you, and it is not shared with anyone.
- Server logs, API request logs, connected-app request logs and error reports — up to 90 days.
- Connected apps — disconnecting an app ends its access at once, and a connection that is not used for 90 days stops working by itself. The record that the connection existed (the app's name and the dates) stays with your account until you delete the account.
- Support emails — up to 24 months after the conversation ends.
9. Security
Data is encrypted in transit (TLS) and at rest, stored in private buckets and databases that are not reachable from the internet, and accessed by services with least-privilege service accounts. Secrets are kept in a managed secret store. No system is perfectly secure; if we learn of a breach affecting you, we will notify you as the law requires.
10. Your rights
You can, at any time:
- Access, correct or export your data — your designs are visible and downloadable in the app; for a full export email us.
- Delete — delete individual designs in the app, or delete your whole account under "My designs → Delete account". This cancels any subscription, removes your Stripe customer record and permanently erases your designs, photos and personal data (except the accounting records mentioned above).
- Object or restrict processing based on legitimate interests, and withdraw consent where processing is based on it.
- Complain to a supervisory authority — in Switzerland the Federal Data Protection and Information Commissioner (FDPIC); in the EU/UK your local data protection authority.
Send requests to info@novaverto.com from the address on your account; we answer within 30 days.
11. Changes to this policy
We will post any changes here and update the date at the top. If a change materially affects how we use your data we will notify you by email or in the app before it takes effect.
12. Contact
info@novaverto.com — see also our Terms of Service.