Privacy Policy

Last updated: 29 September 2026

For accounts created before 14 September 2026, the updated rules on AI model providers and quality tests (sections 3, 4, 5 and 8) apply from 28 September 2026. The same date applies to how sections 3 and 5 describe our product search providers, for accounts created before 20 September 2026.

1. Who is responsible

NovaVerto AI (novaverto.com) is operated by Rastislav Bertusek, sole proprietor, Brackenweg 14, 5200 Brugg, Switzerland. We are the controller of the personal data described here. Contact for anything privacy-related: info@novaverto.com.

We process data in line with the Swiss Federal Act on Data Protection (FADP) and, where it applies to you, the EU/UK GDPR.

2. What we collect

We do not knowingly collect data from children under 16 and the Service is not intended for them.

3. How photos are handled

Location and camera metadata (EXIF, including GPS) is stripped from every upload before anything else happens. Uploads are screened automatically and rejected if they appear to show people, personal documents or explicit content. Photos and generated images are stored privately on Google Cloud Storage and are only accessible through short-lived signed links tied to your account — nothing is public unless you explicitly share a design. To generate a design your photo is sent to an AI image model; today that is Google's Gemini models on Google Cloud. To find matching products, crops of the generated furniture (never your original photo) are sent to a product search provider that looks for matching items in online stores.

Which AI providers may receive your photos. We may use other AI model providers besides Google, for generating designs or for the quality tests described below. Whichever provider we use, your photos, your designs and anything derived from them are only ever sent to providers that do not use the data to train AI models and that keep it only as long as necessary — to answer the request and, where the provider requires it, for a limited period of security and abuse monitoring (typically no more than 30 days) — after which they delete it. Providers that train on the data they receive never get your photos or designs, and we do not use your photos or designs to train AI models either.

Improving the Service. To keep results good, we may use your photos, designs and the images generated from them to test and improve the Service — for example to compare how different AI models render the same room, or to tune the instructions we give them. These tests follow the rules above, are carried out only by us, and their results are stored privately on our own cloud storage. They are never published, never shown to anyone outside NovaVerto and never used for advertising, and they are deleted as described in section 8. You can object to this use at any time (section 10), and we will exclude your account from future tests.

Photos submitted through the API. Some businesses use our API to offer redesigns inside their own products. A photo that reaches us that way is processed exactly as described above — metadata stripped, screened, stored privately, and sent only to the AI providers named here under the same no-training, limited-retention rules — and is stored under the API customer's account, which can delete it at any time. That business is responsible for having the right to submit the photo and for telling its own users how their data is handled. If you have used such a product and want to know what it sent us, ask that business first; if you cannot get an answer, contact us and we will help where we can.

4. Why we process your data (legal bases)

We do not sell personal data and we do not show third-party advertising.

5. Who we share data with

We use a small number of processors, each bound by a data-processing agreement:

Apps you connect. If you connect an AI assistant or another app to your account (for example Claude, ChatGPT or Gemini), we send it what it asks for on your behalf: your email address, plan and credit balance, your projects and designs (including links to the images and videos), and the products matched to them. We do this only after you approve the app, and only until you disconnect it on your account page or it is disconnected automatically after 90 days without use. These apps are not our processors: you choose them, and their providers handle what they receive under their own terms and privacy policies — including any photo you give the assistant directly in a chat. Our rules on AI model providers (section 3) cover the providers we send your photos to, not an assistant you connect.

We may also disclose data if required by law or to protect our rights, and to a successor if the business is transferred (you would be notified).

6. International transfers

Because our providers operate in the United States, your data leaves Switzerland/the EEA. Google, Stripe, Meta and Sentry are certified under the Swiss–U.S. and EU–U.S. Data Privacy Frameworks; where a provider is not, we rely on the EU Standard Contractual Clauses (with the Swiss addendum). Runware is based in the United Kingdom, which Switzerland and the EU recognise as providing an adequate level of data protection. Copies are available on request.

7. Cookies and local storage

Strictly necessary storage runs without asking: sign-in state (kept in your browser's local storage by Firebase/Identity Platform), a session cookie on Stripe's checkout and billing pages, and the cookie that remembers your consent choice. Anything else — statistics or marketing cookies — is loaded only after you opt in through the cookie banner, and you can change or withdraw that choice at any time via "Cookie settings" in the footer. Consent is managed by Cookiebot (Usercentrics A/S, Denmark). The table below is generated from our latest scan and lists every cookie by purpose and lifetime.

8. How long we keep data

9. Security

Data is encrypted in transit (TLS) and at rest, stored in private buckets and databases that are not reachable from the internet, and accessed by services with least-privilege service accounts. Secrets are kept in a managed secret store. No system is perfectly secure; if we learn of a breach affecting you, we will notify you as the law requires.

10. Your rights

You can, at any time:

Send requests to info@novaverto.com from the address on your account; we answer within 30 days.

11. Changes to this policy

We will post any changes here and update the date at the top. If a change materially affects how we use your data we will notify you by email or in the app before it takes effect.

12. Contact

info@novaverto.com — see also our Terms of Service.