NovaFable

Privacy Policy

NovaFable turns a photo you choose into an illustrated story world. This page explains, without hedging, what leaves your device when you do that — and what happens to it afterwards.

Effective July 26, 2026 Applies to NovaFable for iOS Publisher Lumivelle

One photo, one job

A photo is uploaded only after you pick it and confirm, and only to render the story you asked for.

No face recognition

We never build a faceprint, template, or biometric identifier from your image.

Short-lived uploads

Source images clear our active systems within 24 hours of the render finishing or failing.

Never sold

We do not sell personal information, and we do not train models on your photos.

01Scope of this policy

"NovaFable," "we," and "us" refer to Lumivelle, the publisher of the NovaFable iOS application. This policy governs the app, the generation and account services it talks to, and the support channels reachable from inside it — referred to together as the App.

It does not govern anything you do outside the App: the App Store itself, a social platform where you later post a finished story, or any site you open through a link. Those are covered by their own policies.

02Photos you send for generation

Every story world in NovaFable starts from an image you hand over deliberately, through Apple's system photo picker. The App has no standing access to your photo library and does not scan, index, or browse it. Only the specific item you tap is read.

Before that item is uploaded, the App shows you a disclosure naming what will be sent, which providers will host and process it, why, and how long it is kept. Nothing is transmitted unless you accept. The image is resized and re-encoded on-device first, so what actually travels is a working copy sized for rendering rather than your full-resolution original.

Upload only images you have the right to use. If a photo shows another identifiable person, you need their permission before you submit it.

If the photo contains a face

Most story worlds work best with a portrait, so we are explicit about this. When your photo contains a face, our generation models read the visual characteristics present in the picture — shape, pose, colour, lighting — purely to draw the stylized character you requested.

NovaFable does not use that photo to identify or verify who you are, match you against any gallery or database, link separate uploads to the same person, or derive a faceprint, facial embedding, feature template, or any other biometric identifier. No such data is created, so none is stored, shared, or sold.

Where the processing happens

Uploads travel over encrypted connections into our cloud processing environment. Generation runs on models we operate ourselves; cloud vendors — currently Google Cloud Platform and Amazon Web Services — supply the storage and compute underneath. They act strictly on our instructions, may use the content only to deliver those services to us, and are contractually barred from using it for their own purposes or for training their models.

Your photos are never used for advertising, profiling, identity checks, facial recognition, or model training of any kind.

03Everything else we collect

Account and sign-in

NovaFable creates a device-scoped guest account on first launch so you can start immediately; it is keyed to a randomly generated identifier held on your device and in the iOS keychain, not to your Apple ID. If you later choose Sign in with Apple, Apple returns a stable user identifier and, at your discretion, a name and an email address — which may be a private relay address that hides your real one. We store that identifier so your credits and stories follow you across devices and reinstalls. We never receive your Apple password.

Story activity

Things you write to us

Feedback you submit in the App is stored with your message text and the account reference needed to reply and to show it back to you in your feedback history.

Purchases

Credit purchases are processed by Apple. We receive the product, transaction identifier, price, currency, and completion status so credits can be granted. We never see or hold your card number or payment credentials.

Measurement and attribution

We use Adjust to understand which campaign an install came from and whether a purchase followed. Depending on your device settings and local law this may include device and network attributes, an advertising identifier, campaign parameters, and event details. On iOS, access to the advertising identifier is requested through App Tracking Transparency, and declining is a normal, fully supported choice — the App works the same either way.

Integrity and diagnostics

To catch fraud, credit abuse, and automated misuse, and to fix crashes, we collect app version, OS version, device model and locale, network reachability, coarse device-integrity signals such as whether the device appears jailbroken or the app appears repackaged, and error logs. This is about protecting the service, not about profiling you.

04What we do with it

We do not use generated output or uploaded photos to train or fine-tune models, and we do not run advertising inside the App.

05Legal grounds (EEA and UK)

If data-protection law in your region requires a legal basis, ours are:

06Who receives information

We disclose only what a recipient needs, and only to these categories:

We do not sell personal information, and we do not share it for cross-context behavioural advertising as those terms are defined under California law.

07How long things are kept

Data
Retention
Uploaded source photo (including any face in it)
Deleted from active systems within 24 hours of the task completing or failing
Temporary processing files
Deleted with the source photo; incidental backup copies purge within 7 days
Generated images and videos
Kept for your history window, then removed; copies you save stay on your device until you delete them
Account, credits, purchase records
Until you delete your account, plus any period tax or accounting law requires
Feedback and ratings
Kept while useful for support and product quality, then deleted or de-identified
Security, fraud, and diagnostic logs
A short rolling window sized to the investigation and debugging need
Biometric identifiers
None — we do not create or collect any
Note. Deleting the App does not delete server-side account data. Use Profile → Delete Account for that, or write to us.

08Your controls

Built into the App:

Depending on where you live, you may also have rights to access, correct, port, restrict, or object to processing, and to withdraw consent. Email us and we will act within the time your law allows. We may need to confirm you control the account first — usually by asking you to send the request from the address linked to it, or to supply the User ID shown in Profile. Exercising a right never results in worse service or higher prices, and you may use an authorised agent where the law provides for one.

09Region-specific notes

California

In the past twelve months we have collected the categories described in sections 02 and 03: identifiers, commercial information, internet and device activity, visual information you submit, and inferences drawn to secure the service. Sources, purposes, and recipients are set out above. We do not sell or share personal information, and we do not knowingly collect it from anyone under 16.

EEA, UK, and Switzerland

Lumivelle is the controller for the processing described here. You may lodge a complaint with your local supervisory authority, though we would prefer the chance to resolve it first.

Illinois, Texas, and similar biometric statutes

NovaFable does not collect, capture, store, or profit from biometric identifiers or biometric information. Facial imagery is processed transiently to render your requested artwork and is deleted on the schedule in section 07.

10International transfers

Our providers operate globally, so information may be processed in countries other than the one you live in, including the United States. Where the law requires it we rely on approved transfer mechanisms such as the European Commission's standard contractual clauses and the UK addendum, together with technical measures like encryption in transit and at rest.

11Security

We use encrypted transport, encrypted request payloads, keychain-backed credential storage on device, scoped access controls, and short retention windows to reduce exposure. Screen-capture protection can be enabled on sensitive screens. None of this makes any system perfect: no transmission or storage method is completely secure, and we cannot guarantee absolute security.

12Children

NovaFable is built for users aged 13 and over, or the higher minimum age set where you live. We do not knowingly collect personal information from anyone younger. If you believe a child has given us information, contact us and we will investigate and delete it where appropriate.

13Changes to this policy

As the App evolves this policy will too. We will post the revised version here with a new effective date, and for material changes we will give additional notice — in-app or by email — where the law requires it. Continuing to use the App after a change takes effect means the updated policy applies to you.

14Contact

Privacy questions, data requests, or anything that looks wrong to you: [email protected]. Please tell us which country you are writing from so we can apply the right rules.