NavAI

Privacy Policy

Last updated: 7 September 2026

This policy explains what personal data NavAI collects, why, and what rights you have over it. It is written to be read by a customer, not a lawyer. See the note at the bottom about how it was produced.

1. Who controls your data

The data controller is Nvar Ali, trading as NavAI ( "NavAI", "we", "us").

Contact: nvara.005@gmail.com

2. What we collect, and why

Account data. Your email address and current credit balance, stored against your account. Collected when you sign up, used to let you log in, show your balance, and contact you about your account. Your password is never stored by us directly — it is handled entirely by our authentication provider, Supabase Auth, which stores it hashed.

Purchase records. When you buy credits, we store the Stripe checkout session id, which credit pack you bought, how many credits, the amount paid, and the date. We do not store your card details — Stripe collects and holds those directly.

Contact form submissions. If you use the Contact page, we store the name, email, and message you submit, so we can reply to you.

Prompts and generated images. When you generate an image, your prompt is sent to our image generation provider, Replicate, to produce the result. We do not keep a server-side record of your prompts or generated images. Your generation history is stored only in your own browser (localStorage) and is never sent to us — if you clear your browser data or switch devices, that history is gone and we cannot recover it for you.

Session cookie. A single cookie that keeps you logged in. See Section 7.

3. Our lawful basis for each use

  • Contract — creating your account, showing your credit balance, letting you generate images, and processing your credit pack purchases. We need this data to provide the service you're paying for.
  • Legitimate interests — keeping basic records to detect abuse, fraud, and misuse of the service (for example, screening prompts before they're sent to our generation provider). We consider this a proportionate use that doesn't override your own rights.
  • Legal obligation — retaining purchase records for UK financial record-keeping requirements (see Section 6).

4. Who else sees your data

We use the following processors to run NavAI. We don't sell your data, and we don't share it with anyone beyond what's needed to provide the service:

  • Supabase — our database and authentication provider. Holds your account record, purchase records, and contact form submissions, and manages your login credentials.
  • Stripe — processes your payment and holds your card details. We never see or store your full card number.
  • Replicate — receives your prompt to generate the image you asked for. Replicate is based outside the UK (in the United States).
  • Resend — sends account emails on our behalf (email verification, password reset, contact form notifications).

5. International transfers

Replicate processes your prompts outside the UK, in the United States. Where any of our processors store or process data outside the UK, we rely on the safeguards built into our contracts with them — such as the UK International Data Transfer Addendum or equivalent standard contractual clauses — to ensure your data continues to receive an appropriate level of protection.

6. How long we keep your data

  • Account data is kept for as long as your account is open.
  • Purchase records are kept for 6 years after the purchase, as required for UK financial record-keeping, even after you delete your account. When you delete your account, we remove the link between the purchase record and your identity — the record itself (amount, date, pack, Stripe session id) is kept, but it can no longer be tied back to you.
  • Contact form submissions are deleted if you delete your account (matched by the email address you submitted them with), and otherwise kept while relevant to responding to you.
  • Prompts and generated images are not stored by us at all, so there is nothing server-side to retain — see Section 2.

This matches exactly what happens when you use the account deletion tool described in Section 8 — if you ever see the two disagree, tell us, because one of them is wrong.

7. Cookies

NavAI uses exactly one cookie: a session cookie that keeps you logged in. It is strictly necessary for the service to work and cannot be switched off. We do not use analytics, advertising, or tracking cookies or scripts of any kind, so there is no cookie consent banner on this site.

8. Your rights

Under UK GDPR, you have the right to:

  • be informed about how your data is used (this policy),
  • access the data we hold about you,
  • have inaccurate data corrected,
  • have your data erased ("the right to be forgotten"),
  • restrict or object to certain processing,
  • receive your data in a portable, machine-readable format,
  • and not be subject to solely automated decision-making.

You can exercise the access and erasure rights yourself, right now, from your account page: it has a button to download everything we hold about you as JSON, and a button to delete your account. For any other request, or if something isn't working, email nvara.005@gmail.com.

You also have the right to complain to the UK's data protection regulator, the Information Commissioner's Office (ICO), at ico.org.uk/make-a-complaint or by phone on 0303 123 1113. We'd appreciate the chance to put things right first, but you don't need our permission to complain.

9. Changes to this policy

If we change this policy in a way that materially affects how we use your data, we'll update the date at the top and, where appropriate, tell you directly.