Privacy Policy
Last updated: May 19, 2026 · This is our initial draft. We will publish a full Termly-generated version before our first paid product launches.
1. Introduction
NorthBright Labs LLC (“NorthBright,” “we,” “us,” or “our”) operates the website northbrightlabs.com and the AI tools listed at northbrightlabs.com (each, a “Service”). This Privacy Policy explains how we collect, use, share, and protect your information when you use our Services.
By using a Service, you agree to the practices described here. If you don't agree, please don't use the Service.
2. Information We Collect
Information you provide
- Account: email, password (hashed), display name
- Payment: handled by Stripe; we never see your full card number
- AI inputs: text, images, or files you submit to our AI tools
- Communications: support emails, feedback
Information collected automatically
- Device & browser: IP, browser type, OS, language
- Usage: pages visited, features used, timestamps, referring URLs
- Cookies: see “Cookies” section below
3. How We Use Your Information
- Provide and operate our Services
- Process payments and prevent fraud
- Respond to support requests
- Improve and develop new products
- Send service announcements and (with opt-in) newsletters
- Comply with legal obligations
We do not sell your personal information to third parties.
4. AI Inputs and Outputs
When you use an AI feature, your inputs (e.g., text or images) are sent to AI providers (OpenAI, Anthropic, Replicate, or similar) to generate outputs. These providers process your data under their own terms; we choose providers with strong privacy practices.
We do not use your inputs to train our own models. AI outputs are informational only — see the AI disclaimer on each product page.
5. How We Share Information
We share information only with these categories of recipients:
- Service providers who help us operate (Supabase for storage, Stripe for payments, Vercel for hosting, AI providers, email services like Resend)
- Legal authorities if required by law (subpoena, court order)
- Acquirers in a merger, acquisition, or asset sale (with notice to you)
6. Cookies
We use cookies for three purposes:
- Essential: session login, security (cannot be disabled)
- Analytics: anonymous usage data (Vercel Analytics)
- Marketing (if active): for EU/CA users, requires consent
7. Storage and Retention
Data is stored on Supabase servers in the United States. We retain personal information for as long as your account is active. When you delete your account, we delete your data within 30 days (except where retention is required by law, e.g. tax records for 7 years).
8. Your Rights
You have the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Delete your account and data
- Export your data (JSON download)
- Opt out of marketing communications
- EU residents: rights under GDPR (Articles 15-22)
- California residents: rights under CCPA/CPRA (right to know, right to delete, right to opt out of sale — we don't sell, but the right exists)
To exercise any right, email privacy@northbrightlabs.com. We respond within 30 days.
9. Security
We use industry-standard security practices: HTTPS in transit, encryption at rest, hashed passwords, principle of least privilege, and regular audits. However, no system is 100% secure. If you believe your account has been compromised, email security@northbrightlabs.com immediately.
10. Children
Our Services are not directed to children under 13 (or 16 in the EU). We do not knowingly collect data from children. If you believe we have, email privacy@northbrightlabs.com and we will delete it.
11. International Users
NorthBright Labs LLC is based in Wyoming, USA. By using our Services, you consent to your data being processed in the United States, which may have different data protection laws than your country.
12. Changes to This Policy
We may update this policy. Material changes will be announced via email or banner at least 30 days before they take effect. The “Last updated” date at the top reflects the latest version.
13. Contact Us
For any privacy question or request: