Skip to content
Nuvirs
CreateExplore scenesExplore 360°How it works
Open studio

NUVIRS / LEGAL

Privacy Policy

How we handle your account, creative work, and payment records when you use Nuvirs.

Draft prepared: September 20, 2026 · Version 1.1

Draft: the operator’s legal name and country are awaiting confirmation. This is not yet the final policy for publication.

Terms of ServicePrivacy PolicyAcceptable Use
ON THIS PAGE1. Who we are2. Information we collect3. How we use information4. Providers & sharing5. Cookies & local storage6. Retention & deletion7. International processing8. Security9. Your rights10. Children11. Policy changes12. Contact

1. Who we are

This Policy applies to Nuvirs at nuvirs.com and its image and 3D creation tools. Nuvirs is operated by an individual. The operator identified below is responsible for personal information processed to run this service.

Service
Nuvirs · nuvirs.com
Support & privacy
nuvirs@proton.me

Third-party websites, sign-in services, and hosted checkout pages also have their own privacy notices. This Policy explains our processing; it does not replace theirs.

2. Information we collect

  • Account information: your name, email address, profile photo, email-verification status, and identifiers provided through Google sign-in. Authentication records may include authorization tokens, session identifiers, IP addresses, and browser or device information.
  • Creative content: prompts, reference images, project titles, generation settings, generated images, panoramas, 3D assets, and links you choose to create. Uploaded content may contain personal information, including recognizable people.
  • Service activity: generation status, timestamps, provider references, error information, and credit reservations, charges, and returns needed to operate your account.
  • Purchase records: selected credit packs, order identifiers, amounts, currency, taxes where supplied, payment status, and signed payment-provider event records. These records can include billing details, payment references, and limited payment-method information such as a card’s last four digits. We do not collect or store full card numbers or card security codes.
  • Communications: information you send when contacting us, such as your email, order reference, and the details of a support request, content report, moderation appeal, or privacy request.

Account and content information comes from you, your sign-in provider, or your use of the service. Payment status and generated results come from the providers that fulfill your requests. Please avoid uploading unnecessary sensitive personal information.

3. How we use information

  • Provide the service: authenticate you, store projects, process generations, deliver results, manage credits, and fulfill purchases. Where a legal basis is required, this processing is necessary to perform our agreement with you or take steps you request before a purchase.
  • Maintain and protect the service: diagnose errors, prevent fraud and unauthorized access, screen text prompts for prohibited content, reconcile payments, and respond to support requests. Where applicable, we rely on legitimate interests in operating a secure, reliable service, balanced against your rights.
  • Meet legal obligations: keep required transaction records and respond to valid legal requests.
  • Honor your choices: share content when you create a share link and handle privacy requests. Where processing requires consent, we will seek that consent separately; this Policy itself is not a request for consent.

Nuvirs does not train its own AI models on your prompts, uploads, or generated content. Third-party processing is explained below. We do not use your data for targeted advertising or sell your personal information.

4. Providers and sharing

Nuvirs is configured to use GPT Image 2 (gpt-image-2) for image generation and editing through third-party API providers, and World Labs Marble 1.1 Plus (marble-1.1-plus) for 3D worlds and panoramas.

An additional image provider exposes the model identifier gpt-image-2.5. This is the provider’s identifier; Nuvirs does not represent it as an independently verified official OpenAI model release. Image requests may be routed between configured providers according to availability and selected settings. Using GPT Image through an intermediary does not imply that Nuvirs has a direct service agreement with OpenAI.

We disclose information needed to operate the service to these providers:

  • Cloudflare: website and API hosting, database and asset storage, and network delivery. This includes account records, projects, generation assets, and technical request information.
  • Google: account sign-in and authentication. Google handles information collected through its own services under its privacy policy.
  • Image-generation providers: the configured model endpoint receives your prompt, necessary reference images, and generation settings for the GPT Image model routes identified above. Requests pass through the configured third-party API provider. Contact us before uploading sensitive material if you need details about the provider handling your request and its data practices.
  • World Labs: descriptions, reference images, and settings needed to create 3D worlds and panoramas. World Labs handles its copies of requests and generated resources under its applicable terms and privacy practices.
  • Waffo Pancake content safety: before creating a new image or 3D world, we send the text prompt for a safety decision. Generation proceeds only when the decision allows it. According to Waffo’s content safety documentation, this check is stateless and does not retain the original prompt after returning a decision. Nuvirs does not create a separate prompt log for these checks. Prompts in accepted generation requests are still stored with your projects as described in this Policy.
  • Waffo Pancake and its payment partners: hosted checkout and payment processing. We send your account email, an internal account or workspace reference, order metadata, and the selected product. Waffo collects payment details on its checkout and sends us payment and refund status records.

We do not promise that third-party AI providers have zero retention or never use data for model improvement. Their handling depends on the provider and applicable service arrangements. Do not submit content unless you have the necessary permissions and are comfortable with that processing.

Projects are not publicly listed by default. A share link allows anyone holding it to view the selected content without signing in until the link expires or is revoked. Recipients can retain copies; revoking a link cannot recall copies already downloaded.

We may disclose information when reasonably necessary to comply with law, respond to a valid legal request, protect rights or security, or resolve a payment dispute. If the service is transferred to another operator, relevant records may transfer with it, subject to applicable law and notice requirements.

5. Cookies and local storage

We use authentication cookies and session storage mechanisms to keep you signed in and protect your account. Sign-in sessions have a seven-day validity period and may be refreshed while you continue using the service.

The studio uses browser local storage and IndexedDB to save drafts, selected settings, and reference files on your device. Draft restoration currently accepts drafts saved within the previous seven days; this restoration window does not mean every saved file is physically deleted after seven days.

The current service does not use advertising cookies or third-party marketing analytics. You can clear or block cookies and site storage through your browser. Doing so may sign you out or remove locally saved drafts. Clearing local storage does not delete server-side projects or purchase records.

6. Retention and deletion

  • Accounts: account information remains while your account is active. You can request account closure and deletion by email; we may retain information required for legal obligations, security, or unresolved disputes.
  • Projects and assets: retained until you delete the project or request deletion. Project deletion removes it from normal access and revokes its share links. Asset files are removed through background cleanup, so physical deletion is not immediate. Files still used by another live project may remain, and an active or unsettled generation can delay project deletion.
  • Share links: currently expire after seven days and can be revoked earlier. Expiry ends access through the link; it does not delete the underlying project.
  • Transactions and credit records: retained for reconciliation, dispute handling, and applicable accounting or legal obligations. They are not automatically erased when a project is deleted.
  • Support and technical records: retained as needed to resolve the relevant request, investigate failures or abuse, and meet applicable legal obligations.

We have not established a fixed automatic deletion period for every record category. For a deletion request, we will explain any information that must remain and why. Provider-held copies follow the provider’s retention practices; browser-held copies can be removed through your browser settings.

7. International processing

Cloud hosting, sign-in, AI, and payment providers may process information outside your country of residence, where privacy laws may differ. The processing location depends on the provider and service configuration. Where applicable law requires safeguards for international transfers, those requirements apply to our processing. Contact us for information about the arrangements relevant to your data.

8. Security

We use measures including encrypted HTTPS connections, account-scoped access controls, private asset storage, and encrypted upstream API credentials to protect information. Access is limited to what is needed to operate and support the service. No system is completely secure; protect your sign-in account and treat share links as access credentials.

If a security incident creates a notification obligation, we will notify affected people or authorities as required by applicable law.

9. Your rights and choices

Depending on where you live and the applicable law, you may have rights to access, correct, delete, or obtain a portable copy of personal information; restrict or object to processing; or withdraw consent for processing that relies on consent. Withdrawing consent does not affect processing already lawfully carried out.

You can download results, delete projects, and revoke share links in the service. For other requests, use the contact below. We may ask for information reasonably necessary to verify account ownership, and we will respond within applicable legal time limits. Please do not send identity documents unless we request them through an appropriate channel.

Some information may be exempt from deletion or other requests because of legal obligations or the rights of others. We will explain applicable limitations. You may complain to your local data protection authority and exercise privacy rights without unlawful discrimination.

10. Children

Nuvirs is intended for users aged 18 or older. We do not knowingly collect personal information from children using the service. If you believe a child has provided personal information, contact us so we can investigate and take appropriate action.

11. Policy changes

We will update the date and version when this Policy changes. For material changes, we will provide notice on the website or through an appropriate account channel. Where a change requires consent, we will seek it before the new processing begins.

12. Contact

Contact the operator for privacy requests, questions about providers, or concerns about how your information is handled. Include your account email and the nature of your request.

Service
Nuvirs · nuvirs.com
Support & privacy
nuvirs@proton.me
Nuvirs

A little imagination. A new perspective.

Support: nuvirs@proton.me

Explore scenesPlansTerms of ServicePrivacy PolicyAcceptable UseReport content
© 2026 Nuvirs