Legal
Privacy Policy
Effective 5 August 2026
This policy describes what Novofun collects, why, who else touches it, and what you can ask us to do about it. It describes how the platform actually works rather than what a generic policy would assume.
01Who we are
Novofun is the controller of the personal data described here. You can reach us about anything in this policy, including any request about your data, at support@novofun.com.
02What we collect
Account information.
- Your email address. Signing in uses a six-digit code sent to that address, so we do not store a password for you.
- An optional display name and avatar.
- Flags on your account, such as whether it is permitted to publish to the feed.
What you create.
- The characters you build, including their Identity reference sheets and the profile describing them.
- The prompts you write and the images and video generated from them.
- Reference images you upload — which, per our Terms of Use, must contain no people.
- Likes, favourites and anything you publish to the public feed.
Payments.
- Which credit pack you bought, the amount, and the payment reference from the payment provider.
- We never receive or store your card number or wallet credentials. Those go directly to the payment provider.
Technical and usage data.
- Your IP address, which is also used to rate-limit sign-in attempts and block brute force.
- Browser and device information, pages visited, and timestamps.
- Error reports when something breaks, which can include the page you were on and what the app was doing.
Marketing attribution.
- If you arrive through a campaign link we store the campaign parameters (utm_source, utm_medium, utm_campaign, utm_term, utm_content and gclid) in a cookie for 60 days, and attach them to your account if you sign up. This tells us which channels work.
03Why we use it, and on what legal basis
| Purpose | Legal basis (GDPR) |
|---|---|
| Running your account and generating what you ask for | Performance of our contract with you |
| Taking payment and keeping records of it | Contract, and legal obligation for accounting records |
| Screening prompts and uploads for prohibited content | Legal obligation, and our legitimate interest in a lawful platform |
| Preventing fraud, abuse and unauthorised access | Our legitimate interest in keeping the service secure |
| Fixing errors and improving the product | Our legitimate interest in a working service |
| Analytics and campaign measurement | Your consent, where required by local law |
| Answering your support messages | Contract, and our legitimate interest in supporting users |
04Automated screening you should know about
Novofun forbids images of real people, and enforces that automatically rather than by trust. We think you should know exactly what that involves.
- Reference images you upload are sent to Amazon Rekognition, which reports whether a face or person appears in the image and estimates the apparent age of anyone detected. An upload containing a person is rejected, as is one we could not check.
- Prompt text is sent to a language model via OpenRouter, which classifies it against our prohibited-content rules.
- Names appearing in prompts are checked against Wikidata, a public knowledge base, to determine whether the name belongs to a real person.
- A record of a blocked prompt — including the text — is stored for a limited period so the same attempt is not re-screened repeatedly.
- When screening blocks something, an alert containing the prompt text and your account email address is sent to an internal staff channel hosted on Telegram, so the decision can be reviewed.
These checks can block content automatically without a person reviewing it first. If you believe a decision was wrong, write to support@novofun.com and a person will look at it.
05Who processes your data for us
We use the providers below to run the service. They act on our instructions and are not permitted to use your data for their own purposes.
| Provider | What it handles |
|---|---|
| Vercel | Hosting the application and serving it to your browser |
| MongoDB Atlas | The database holding your account, characters, prompts and orders |
| Cloudflare R2 | Storage for your uploads and generated images and video |
| Grok (xAI) | Generating character portraits and improving prompt text |
| BytePlus | Image and video generation |
| RunPod | Infrastructure for part of the video pipeline |
| OpenRouter | Prompt screening and prompt improvement, using third-party language models |
| Amazon Rekognition | Detecting people and estimating apparent age in uploaded reference images |
| Wikidata | A public lookup used to detect the names of real people in prompts |
| Resend | Delivering sign-in codes and service emails |
| NOWPayments | Processing crypto payments |
| Google Analytics and Tag Manager | Usage analytics, in the production environment only |
| Sentry | Error and performance monitoring |
| Telegram | Internal staff alerts, including moderation alerts as described above |
Your credit balance is held on our own balance service rather than in the main database, and is keyed to your email address. Only your email address and your balance are held there — no characters, prompts, uploads or generations.
We also disclose data where the law requires it — for example to respond to a valid legal request, or to report content we are obliged to report. We do not sell your personal information.
06How long we keep it
- Account data: for as long as your account exists, and for a short period afterwards while backups age out.
- Characters, prompts and generations: until you delete them, or until your account is closed.
- Screening records for blocked prompts: kept briefly and then deleted automatically.
- Payment and order records: kept as long as accounting and tax law requires, typically several years.
- Analytics and error data: kept according to the retention settings of the providers listed above.
07Your rights
If you are in the UK or the European Economic Area, you have the right to access your data, correct it, delete it, restrict or object to how we use it, receive a portable copy, and withdraw consent where processing relies on it. You can also complain to your national data protection authority.
If you are in California, you have the right to know what we collect and why, to request deletion or correction, and to be free from discrimination for exercising those rights. We do not sell or share personal information as those terms are defined by the CCPA, and we do not offer financial incentives in exchange for data.
To exercise any of these rights, email support@novofun.com from the address on your account. Deletion is handled by our team on request rather than through a button in the app — we will confirm what has been deleted once it is done. We may need to keep certain records, such as payment history, where the law requires it.
08Where your data goes
The providers listed above operate internationally, so your data is processed outside the country where you live, including in the United States. Where the law requires a transfer safeguard, we rely on the European Commission's standard contractual clauses or an equivalent mechanism.
09Cookies
- Session cookies that keep you signed in. These are essential and cannot be turned off while you use an account.
- Attribution cookies holding campaign parameters for 60 days, as described above.
- Analytics cookies set through Google Tag Manager in the production environment.
If you are in the European Economic Area or the United Kingdom, the attribution and analytics cookies are only set after you accept them in the cookie banner. Until you do, analytics runs without cookies and campaign parameters are not stored. Refusing changes nothing else: signing in, generating and paying all work the same way.
You can change your mind at any time through the "Cookie settings" link in the footer, which brings the banner back. We ask again every six months in any case.
You can also clear or block cookies in your browser, though doing so will stop sign-in from working.
10Security
Data is encrypted in transit and at rest with our storage and database providers. Sign-in uses a one-time code with attempt and rate limits rather than a stored password. Access to production data is restricted to staff who need it. No system is perfectly secure, and we cannot guarantee absolute security.
11Children
Novofun is for adults only and is not directed at anyone under 18. We do not knowingly collect data from minors. If we learn that an account belongs to someone under 18, we close it and delete the data.
12Changes and contact
We will update this policy as the service changes, and will say so on the platform or by email when a change is significant. For any question about it, or to make a request about your data, write to support@novofun.com.