Privacy Policy
Last updated: July 24, 2026
What Novus stores
Guest work is stored device-locally in your browser using IndexedDB — it never leaves your device unless you explicitly export a `.novusvis` file. Signed-in projects, revisions, profiles, preferences, notifications, moderation records, and security events are stored in Turso (a hosted libSQL database), and the application itself is hosted on Vercel. Accounts use a public username and display name. Novus does not ask for or send to an email address; an internal non-routable credential identifier used by the authentication adapter is never exposed in application responses or used for communication.
Audio and uploaded assets
Audio analysis and rendering run in your browser. For each project, you choose whether its uploaded audio is saved. If you decline, Novus stores a fingerprint and analysis metadata so another device can ask you to reattach the matching file. If you opt in, audio, images, video, fonts, and models are stored as private Vercel Blob objects with Turso ownership metadata. Sources are not made public by publishing.
Uploads receive random paths, checksum and type validation, decode/parse checks, and quarantine status. Public posts use separate preview derivatives. Private source audio and models are never served by a community page.
Authentication and recovery
Passwords are stored only as secure hashes. Passkeys store public credentials; device private keys remain with your authenticator. Recovery codes are shown once, hashed, single-use, and replaced as a complete set. Recovery creates a short-lived HttpOnly session. Without a passkey, unused recovery code, or authenticated trusted session, Novus cannot self-recover an emailless account. Signup and account recovery are protected by Cloudflare Turnstile to block automated abuse.
Community and moderation
Projects and assets are private until you explicitly publish. Publication freezes one revision and its preview. Public profile data, posts, comments, reactions, follows, remix attribution, and view counts may be visible to others according to your selected visibility. Reports, blocks, moderation decisions, and immutable admin audit records are retained to operate and secure the community.
Security, analytics, and retention
Novus processes request metadata, coarse device/browser information, rate-limit state, and security events to prevent abuse and diagnose failures. Operational logs exclude passwords, recovery codes, raw project documents, usernames where avoidable, and private object paths. Novus uses Google Analytics 4 for aggregate usage measurement, loaded with Google Consent Mode v2: analytics and advertising signals default to denied in the EEA, UK, and Switzerland until you consent through the cookie banner, and your saved choice is reapplied on later visits. First-party Vercel Analytics and Speed Insights measure page and performance metrics. Advertising on marketing pages is served by Adsterra and Infolinks; Google AdSense verification assets remain in place while a re-application is pending. Advertising scripts follow your cookie preference and never load on Studio, Classic, account, or admin routes.
Account export and deletion controls are provided in settings. After account deletion, data enters a deletion queue and a scheduled job permanently removes it; public safety and audit records may be retained where necessary to prevent abuse or meet legal obligations.
Your choices
You can edit profile visibility, notification preferences, sessions, passkeys, and recovery codes; export project files; choose cloud audio storage per project; unpublish or report community content; and request account export or deletion. See the account security guide for the recovery model.