Skip to content
Nova CreativeOpen the app

Legal

Privacy PolicyCookie PolicyTerms of ServiceRefund & withdrawal
← Back to Nova Creative

Privacy Policy

Effective and last updated: August 16, 2026

This Privacy Policy explains how Nova Creative, a service offered under the Novastorm name by Uladzimir Pranevich, a sole proprietor registered in Poland under the business name ULADZIMIR PRANEVICH, with registered address at ul. Kabacki Dukt 14 lok. 56, 02-798 Warszawa, Poland, NIP 8992922668, REGON 521728250 ("Nova Creative", "Novastorm", "we", "us"), collects, uses, discloses, and protects personal information when you use the Nova Creative website, application, APIs, GPU agent, support channels, and related services (the Service).

Uladzimir Pranevich is the controller of personal information used to operate the Service. For privacy questions or requests, contact privacy@novastorm.ai or use the postal address above. A third-party AI, payment, identity, or infrastructure provider may be a separate controller for information it receives under its own terms.

This Policy does not make third-party services part of Nova Creative. When you deliberately connect or select a third-party provider, its own privacy notice and terms also apply.

1. Summary

  • We use personal information to provide accounts, projects, AI and GPU workflows, storage, billing, security, and support.
  • We do not sell personal information, share it for cross-context behavioral advertising, or use it for targeted advertising.
  • We do not train our own AI models on your private prompts, projects, chats, or media. A third-party model provider may retain or use submitted content according to its terms and the type of account or API key used.
  • Content sent to a hosted AI provider or Cloud GPU leaves our application environment. Content run only on your own GPU is not sent to a hosted model provider, although it still passes through Nova Creative relay infrastructure when relay mode is used.
  • Uploaded and generated media may be stored on a public asset origin. Anyone who obtains its hard-to-guess URL may be able to access it. Do not upload secrets or content that requires access controls.
  • You can delete many items in the Service and can delete your account in Settings. Some records, provider copies, CDN caches, backups, and records required by law may remain for a limited period.

2. Information we collect

Account and identity information

We process your email address, display name, internal user ID, account role, sign-in method, account creation date, and authentication/security data. For password accounts, we store a salted password hash, not the password. For Google sign-in, we receive a Google account identifier, verified email address, and name; we do not receive your Google password.

Projects, prompts, chats, and media

We process information you submit or create, including:

  • project names, node graphs, prompts, variables, workflow versions, execution results, presets, and imported or exported workflows;
  • AI assistant messages, current-canvas context supplied to the assistant, mission plans, and saved chat history;
  • images, video, audio, voice recordings, 3D files, HTML/CSS creatives, reference files, model inputs, generated outputs, file names, and related metadata;
  • templates and workflows you create or share with other authorized users;
  • web image-search queries, search filters, result metadata, and copies of images you choose to bring into a workflow; and
  • external source, return, or callback identifiers used by an integrated Nova service.

Media, voice, faces, prompts, and other content may reveal personal information about you or another person. They may also reveal sensitive information such as health, racial or ethnic origin, religion, sexuality, or biometric characteristics. Nova Creative does not use submitted faces or voices to identify a person, but the content itself may still be sensitive. You must have a lawful basis and all necessary permissions before submitting another person's information. Do not submit regulated or sensitive data unless the selected processing route is appropriate for it and you are legally authorized to do so.

Provider credentials

We process API keys and related endpoint or region settings that you save for supported BYOK providers and GPU marketplaces. Saved BYOK keys are encrypted at rest, scoped to your account and provider, and are not returned to the browser after storage. They are decrypted only to perform an authorized provider request. Avoid putting credentials inside prompts, projects, URLs, feedback, or file names.

GPU and agent information

When you connect, share, or rent a GPU node, we process the node name and identifier, owner/share membership, GPU model, VRAM, health and load telemetry, installed or requested models, rental configuration and status, network/relay connection metadata, agent token hashes, timestamps, provisioning errors, and usage needed for billing and support. Nova Creative does not intentionally inspect unrelated files on a connected machine.

Billing and transaction information

We process wallet balance and ledger entries, credit purchases and usage, reservations and refunds, Cloud GPU rental history and rates, Stripe customer/subscription/session identifiers, subscription status, payment amount and currency, and timestamps. Stripe collects card, billing-address, and payment-method details directly. Nova Creative does not receive full card numbers or security codes.

Support, feedback, and communications

We process messages sent to support, your account contact details, the page or feature involved, browser user-agent, and any diagnostic context you choose to include. Support messages are delivered to our support mailbox so we can respond. We also process delivery information for welcome, security, password-reset, billing, and other service messages.

Device, network, and operational information

We and our hosting/security providers process IP address, request date and time, requested endpoint, response status, browser/user-agent, referrer where supplied, session and security identifiers, rate-limit events, errors, stack traces, node/project context related to an error, and infrastructure logs. We use this information for authentication, delivery, debugging, capacity, fraud and abuse prevention, and security.

Registration source attribution

We record the first and last campaign visits leading to a new account: supplied UTM parameters, campaign/group/ad IDs, targeting keyword, click IDs (GCLID/GBRAID/WBRAID), match type, device/network and location criterion IDs where supplied, visit timestamps and page/referrer paths. Registration context includes browser language, timezone and User-Agent. This first-party collection runs automatically unless you reject analytics or send GPC/DNT. Browser attribution expires after 90 days; the registration record is linked to your account and removed with account/product deletion. It does not include your Google search history or infer an exact search query from your profile.

Browser storage and cookies

The application uses a strictly necessary HttpOnly authentication cookie. The browser also stores preferences and local workspace state such as theme, saved presets, a recent chat-session identifier, and temporary project state. A legacy bearer token may be stored during an administrator-authorized impersonation session.

On the public Nova Creative website, Google Tag Manager and campaign analytics start after you accept or after 5 seconds on a visible page with no saved choice. Opening Cookie settings pauses automatic activation; a saved rejection or GPC/DNT keeps it off. When activated, we load Google Tag Manager container GTM-52PTZKWX, record first-touch landing/campaign information in local storage, place consented page and CTA events in an in-memory data layer, and may send the same event payload to a configured Nova first-party measurement endpoint. The container may load configured Google Analytics tags, which can receive IP address, user agent, referrer, page URL, event data, and analytics identifiers. We set Google advertising storage, advertising user data, and advertising personalization to denied. We do not load Google Tag Manager or send those Nova analytics events before consent.

The consent record is versioned and treated as expired after 180 days; first-touch attribution is treated as expired after 90 days. An expired record is removed or replaced on the next visit. We treat an active Global Privacy Control or Do Not Track signal as a rejection of analytics. You can reject, accept, or later withdraw through the persistent Cookie settings control. Withdrawing clears the first-touch record we control, attempts to delete known first-party Google Analytics cookies accessible to this site, and reloads the page if necessary to stop loaded tags. See the Cookie Policy for the current technology table and controls.

Google Identity Services is loaded on the sign-in screen when Google sign-in is configured, and Google may receive device/network information or use its own storage under its policies. Stripe may use cookies or similar technologies on its hosted Checkout and customer portal. Those third-party pages and components are governed by their providers' notices.

3. Sources of information

We receive information:

  • directly from you and your browser or GPU agent;
  • from Google when you choose Google sign-in;
  • from Stripe about payments and subscriptions;
  • from AI, GPU, image-search, storage, and other providers when they return results, usage, status, or errors for a request;
  • from another authorized Nova service that initiates a creative-edit or generation job; and
  • from other users when they invite an account to a GPU share or submit content involving that person.

4. Why we process information and our legal bases

Where the EU GDPR, UK GDPR, or a similar law applies, we rely on the following legal bases:

PurposeInformation involvedLegal basis
Create and secure an account; authenticate sessions; provide projects, chats, storage, generations, GPU relay, rentals, exports, and requested integrationsAccount, content, credentials, GPU, device, and operational informationPerformance of our contract with you; steps requested before entering a contract
Route prompts and media to the provider, GPU, or callback destination you selectContent, account/routing identifiers, provider credentialsPerformance of our contract; your deliberate instruction to use the selected recipient
Process purchases, subscriptions, credit usage, refunds, and disputesAccount, billing, transaction, and usage informationPerformance of our contract; compliance with tax, accounting, consumer, and financial obligations
Protect users and infrastructure; prevent fraud, abuse, unauthorized access, and prohibited content; enforce our TermsAccount, content where necessary, GPU, transaction, device, and log informationOur legitimate interests in operating a safe, reliable service and protecting legal rights; legal obligations where applicable
Diagnose failures, provide support, measure reliability, and improve the ServiceSupport, error, usage, device, and limited content context needed to reproduce a problemPerformance of our contract; our legitimate interests in support and product reliability
Send service and security communicationsAccount and delivery informationPerformance of our contract; legal obligations; our legitimate interests in account administration
Measure consented landing-page use and campaign effectivenessDevice/network information, page and CTA events, random browser/event identifiers, landing/message variants, and campaign parametersConsent; you may withdraw it at any time through Cookie settings
Establish, exercise, or defend legal claims and respond to lawful requestsRelevant account, content, transaction, support, and log informationLegal obligation; legitimate interests in protecting rights and resolving disputes

We do not currently send marketing email or perform advertising profiling. If we introduce an optional use that legally requires consent, we will request it separately; you may withdraw that consent without affecting earlier lawful processing.

You generally must provide account and authentication information to create an account, and billing information to buy a paid feature. If required information is not provided, the relevant feature cannot be delivered. You are not required to provide optional profile information or connect a third-party key.

5. AI and workflow processing

Nova Creative is a workflow tool. The destination of content depends on the route you choose:

  • Your GPU: prompts and inputs are delivered to your connected node. In relay mode they transit our authenticated relay, but are not intentionally sent to a hosted model provider.
  • Cloud GPU: prompts, inputs, model downloads, and outputs are processed on a third-party data-center instance provisioned for the rental. Provider-level infrastructure logs may exist. Destruction of the instance does not remove copies already returned to the Service or retained in backups/logs.
  • Managed AI: prompts, media, parameters, account/routing identifiers, and generated outputs are sent to the managed upstream provider needed for the model you selected.
  • BYOK: the same request content is sent to the provider associated with your key. Your direct agreement with that provider controls its use of the content and key.
  • Web image search and remote media: a query is sent to the search provider. When you import a result or remote URL, our server contacts the remote host, which receives ordinary network request data.
  • Callbacks and connected Nova services: job status, results, URLs, and identifiers may be returned to the authorized service or callback destination that initiated the job.

AI providers can return inaccurate, offensive, or unexpected material. Do not rely on the Service for decisions that produce legal or similarly significant effects about a person. We do not use your content to make such decisions about you, and the Service does not perform solely automated eligibility, employment, credit, insurance, housing, education, healthcare, or legal decisions on our behalf.

6. Recipients and service providers

We disclose information only as needed for the purposes above. Recipients may include:

  • Hosting and operations: Hetzner and other infrastructure used to host the application, database, logs, and GPU control plane.
  • Asset storage and delivery: Bunny.net and any configured asset origin or CDN used for uploaded and generated files.
  • Payments: Stripe for Checkout, subscription management, fraud prevention, receipts, and payment processing.
  • Identity: Google when you use Google sign-in.
  • Consented website analytics: Google Tag Manager and any Google Analytics tags configured in that container; and a Nova first-party measurement endpoint if configured.
  • Email: Microsoft Azure Communication Services and email infrastructure used for transactional messages and support delivery.
  • Managed AI routing: Atlas Cloud and the model/upstream selected through it; and, where directly configured, Google/Gemini, OpenAI, Anthropic, DeepSeek, OpenRouter, Runway, Kling, Azure Speech, Midjourney-related infrastructure, or another model provider shown in the Service.
  • BYOK providers: the provider you select, including supported LLM, image, video, audio, avatar, speech, or GPU services.
  • GPU infrastructure and model hosts: vast.ai and other GPU marketplaces/data centers, Hugging Face or another model host contacted by the node, and the operator of a GPU node you choose to use or share.
  • Search and remote sources: Serper for image search and websites/CDNs from which you request remote media.
  • Connected services and callback recipients: a Nova service or destination authorized to initiate a job and receive its results.
  • Professional and legal recipients: auditors, insurers, accountants, advisers, authorities, courts, and counterparties where reasonably necessary for compliance, security, a corporate transaction, or legal claims.

Provider availability changes over time. The provider shown at the point of selection is the best indication of where a request will be sent. Contact us for current information about a particular managed route before submitting sensitive content.

We do not disclose personal information to data brokers and do not sell or share it for targeted or cross-context behavioral advertising.

7. International transfers

Our core application infrastructure is located in the European Union. Some providers, analytics services, GPU hosts, support systems, or model endpoints may process information in the United States or other countries whose laws differ from yours. A request may also be processed in the region attached to a GPU offer, provider account, or endpoint you select.

We will make a processor transfer that is subject to EU, EEA, UK, or Swiss transfer restrictions only where an applicable lawful mechanism has been put in place for that transfer. Depending on the provider and destination, that mechanism may be an adequacy decision, executed EU Standard Contractual Clauses, an executed UK International Data Transfer Addendum or Agreement, or another legally recognized safeguard. A transfer made at your specific request to a separately controlled provider may also be necessary to perform the contract or implement your request. Contact us to request the current mechanism for a particular provider; do not infer that every listed mechanism applies to every provider.

No transfer mechanism eliminates all risk that a foreign authority or third party may lawfully demand access under local law. Do not select a region or provider that is unsuitable for your legal or contractual requirements.

8. Public media URLs

Production media is generally stored on a separate public asset origin using long, hard-to-guess identifiers. The Service does not promise that those URLs are private, access-controlled, or revocable. A person with the URL may view or redistribute the file, and third-party sites may cache it. Search results and externally hosted provider outputs are controlled by their own hosts.

Do not upload passwords, API keys, trade secrets, protected health information, payment-card data, government identifiers, confidential client files, or intimate/sensitive media that requires private access controls. Deleting a Library entry or account removes its application record but may not immediately remove a CDN object, cached copy, provider copy, or a copy previously shared or downloaded. Contact support@novastorm.ai with the asset URL to request removal from storage we control.

9. Retention and deletion

Retention depends on the record and whether it is needed for an active account, transaction, security incident, or legal claim:

  • Account/profile data, active projects, saved chats, starred Library items, saved provider settings, and GPU-node records are generally kept while the account or item remains active.
  • Project history keeps a rolling number of versions. Deleting a project or version removes its database record but not necessarily media referenced elsewhere.
  • Ordinary unstarred generation-history records are normally removed after 90 days. Completed/failed/cancelled generation-job records are normally removed after 30 days. Public asset objects can outlive those records as described above.
  • Application error logs are normally kept for 30 days. Infrastructure and security logs may have different short retention periods needed for operations and incident investigation.
  • The website consent record is treated as expired after 180 days and removed on the next visit. Consented first-touch landing attribution is treated as expired after 90 days and replaced on the next consented visit. Google-controlled analytics identifiers may last up to two years, subject to the deployed container and Google settings.
  • Expired provider billing reservations are reconciled after approximately one hour. Temporary render files are normally collected after one day.
  • Password-reset tokens are stored only in hashed form and expire after one hour. Authentication and anti-abuse records are kept for their security lifetime.
  • Wallet, payment, subscription, tax, invoice, fraud, chargeback, and dispute information is kept for the period required by applicable accounting, tax, payment, limitation, and anti-fraud rules. Stripe independently retains records under its policy.
  • Support correspondence is kept as long as reasonably needed to answer the request, document the resolution, protect legal rights, and satisfy legal obligations.
  • Backups and CDN/provider caches may remain until they are overwritten or expire under their normal cycles. After a valid deletion request, we do not intentionally return a deleted account's data to ordinary active use merely because it remains in a backup.

You can delete projects, project versions, chats, Library records, provider keys, and GPU nodes in the Service. You can delete the account in Settings after stopping active rentals; active subscriptions are cancelled as part of that process. Account deletion removes or anonymizes the main application identity and deletes user-scoped application records. It does not cancel charges on an unrelated third-party account, recover files already shared, or guarantee immediate deletion by a separate provider.

We may retain a minimal record where necessary to comply with law, complete a transaction/refund, detect fraud or repeated abuse, enforce rights, or establish or defend a legal claim. Where possible, retained records are restricted or de-identified.

10. Security

We use measures designed to protect information, including encrypted transport, salted password hashing, encrypted BYOK credentials, hashed short-lived reset and agent tokens, authenticated GPU relay connections, access controls, rate limits, input validation, and secret redaction in error logging. Access is limited to personnel and service providers who need it for their role.

No online service or public URL is completely secure. You are responsible for securing your account, API keys, GPU machines, exported files, and any link you share. Notify abuse@novastorm.ai promptly if you believe an account, key, node, or file has been compromised.

11. Your privacy rights

Depending on your location and subject to legal exceptions, you may have the right to:

  • know whether we process your information and obtain access to it;
  • correct inaccurate information;
  • delete information;
  • restrict or object to certain processing;
  • receive information you provided in a portable format;
  • withdraw consent where processing relies on consent;
  • opt out of a sale, sharing for cross-context behavioral advertising, or targeted advertising;
  • limit certain uses of sensitive personal information;
  • appeal our refusal of a request; and
  • complain to a privacy or data-protection regulator.

We do not sell personal information or use it for targeted/cross-context behavioral advertising, so there is no such processing to opt out of. We do not discriminate against a person for exercising an applicable privacy right.

To exercise a right, email privacy@novastorm.ai from the account address and describe the request. We may ask for information reasonably necessary to verify identity, authority, and the affected account or asset. An authorized agent may submit a request where local law permits, but we may require proof of authority and direct verification. We will respond within the period required by applicable law and explain any denial and available appeal. Requests are normally free; legally permitted fees may apply to manifestly unfounded, excessive, or repetitive requests.

If you are in the EEA, you may complain to the supervisory authority where you live, work, or believe an infringement occurred. In Poland, the authority is the President of the Personal Data Protection Office (UODO). UK users may contact the Information Commissioner's Office (ICO). You may contact us first so we can try to resolve the issue.

California and other U.S. state disclosures

In the preceding 12 months, we have collected the categories described in section 2: identifiers; customer and transaction records; internet/network activity; approximate location inferred from IP; audio, visual and similar content; professional information you place in content; account credentials and other sensitive information; and inferences inherent in AI outputs or fraud/security review. We collect them from the sources in section 3, use them for the purposes in sections 4 and 5, and disclose them to the categories in section 6 for business purposes.

We have not sold those categories or shared them for cross-context behavioral advertising. We do not knowingly sell or share personal information of consumers under 18. Sensitive information is used only to provide and secure the Service, process a transaction, or as otherwise permitted by law; it is not used to infer characteristics for advertising.

12. Children

The Service is intended only for adults who can form a binding contract. You must be at least 18 years old (or the age of legal majority where you live) to create an account. We do not knowingly collect personal information from children. If you believe a child has provided information, contact us so we can investigate and delete it where required.

13. Changes to this Policy

We may update this Policy to reflect changes in the Service, providers, or law. We will update the date above and provide reasonable notice of a material change, such as an in-app notice or email where appropriate. We will request consent if a new use legally requires it. An earlier version continues to govern processing that cannot lawfully be changed without further notice or consent.

14. Contact

Privacy questions, requests, complaints, or security reports:

ULADZIMIR PRANEVICH

Sole proprietor / jednoosobowa działalność gospodarcza

ul. Kabacki Dukt 14 lok. 56

02-798 Warszawa, Poland

NIP: 8992922668 · REGON: 521728250

  • Privacy questions and rights: privacy@novastorm.ai
  • General or asset-removal support: support@novastorm.ai
  • Security and abuse reports: abuse@novastorm.ai

Please do not send passwords, API keys, payment-card details, or sensitive media by ordinary email. Ask for a secure submission method if the request requires supporting documents.

REUSABLE AI IMAGE & VIDEO WORKFLOWS.

Product

  • Models
  • Showcase
  • Avatar ads
  • Pricing

Resources

  • Build a workflow
  • Workflow guides
  • ChatGPT & Codex (MCP)
  • Support

Legal

  • Privacy Policy
  • Cookie Policy
  • Terms of Service
  • Refund & withdrawal

Contact

  • support@novastorm.ai
  • billing@novastorm.ai
© 2026 Nova Creative

By continuing to browse, you agree to analytics cookies. Cookie Policy

Privacy controls

Cookie settings

Necessary storage keeps the site working and remembers your consent. Analytics is optional. Opening these settings pauses automatic activation so you can choose what to enable.

NecessaryConsent record and security/delivery functions.
Always on

See our Cookie Policy and Privacy Policy.