How we collect, use, and protect your data at Novilay.
Last updated: 14 February 2026
Novilay ("we", "our", or "us") is operated by Cristhian Almora. We are the data controller responsible for your personal data processed through our Service.
This Privacy Policy explains how we collect, use, disclose, and protect your personal data when you use novilay.com and our image rights verification services (the "Service").
This policy applies to:
By using the Service, you acknowledge that you have read and understood this Privacy Policy.
Data Controller: Novilay by Cristhian Almora
Email: hello@novilay.com
Website: novilay.com
Data you actively provide to us:
Data collected during website scans:
For registered users:
Automatically collected when you use the Service:
Collected automatically for security and functionality:
We process your personal data for the following purposes:
| Purpose | Legal Basis (GDPR) |
|---|---|
| Providing the scanning service and generating reports | Contract performance |
| Creating and managing your account | Contract performance |
| Processing payments and subscriptions | Contract performance |
| Sending account-related communications | Contract performance |
| Automated monitoring and scheduled scans | Contract performance |
| Improving our Service and developing new features | Legitimate interest |
| Analyzing usage patterns and optimizing performance | Legitimate interest |
| Ensuring security and preventing fraud | Legitimate interest |
| Responding to legal requests and protecting our rights | Legal obligation / Legitimate interest |
| Sending marketing communications (with consent) | Consent |
We retain your data only as long as necessary for the purposes outlined in this policy:
| Data Type | Retention Period |
|---|---|
| Free scan reports | 7 days after scan completion |
| Pro/Max scan data | Duration of active subscription + 30 days |
| Enterprise scan data | Custom retention per agreement |
| Account information | Until account deletion + 30 days |
| Payment records | 7 years (legal requirement) |
| Server logs | 90 days |
| Analytics data | 26 months (anonymized) |
After the retention period, data is either deleted or anonymized so it can no longer be associated with you.
Important: When you use Novilay to scan websites, you may be analyzing content owned by third parties. This section explains how we handle that data.
When scanning a website, Novilay accesses:
By initiating a scan, you represent that:
Novilay processes third-party data solely to provide the scanning service and does not use it for any other purpose.
We do NOT sell your personal data to third parties. We share data only in the following circumstances:
We use trusted third-party services to operate Novilay:
| Provider | Purpose | Data Shared |
|---|---|---|
| Supabase | Database, authentication, storage | Account data, scan results, project configurations |
| Lemon Squeezy | Payment processing (Merchant of Record) | Email, payment information, subscription status |
| EasyCron | Scheduled task execution | URLs for automated scanning (no personal data) |
| Google Analytics | Website analytics | Anonymized usage data, IP address (anonymized) |
| Hosting Provider | Website hosting | Server logs, technical data |
We may disclose your data if required by law, court order, or to:
In the event of a merger, acquisition, or sale of assets, your data may be transferred. We will notify you before your data becomes subject to a different privacy policy.
| Cookie Type | Purpose | Duration |
|---|---|---|
| Essential | Authentication, session management, security | Session / 7 days |
| Functional | Preferences (theme, language) | 1 year |
| Analytics | Google Analytics (usage statistics) | 2 years |
You can control cookies through your browser settings:
Most browsers allow you to manage cookie preferences. Consult your browser's help documentation for instructions.
We do not currently respond to "Do Not Track" browser signals, as there is no industry standard for this feature.
Depending on your location, you have the following rights regarding your personal data:
UK residents have equivalent rights under the UK General Data Protection Regulation.
California residents have the right to:
To exercise any of these rights, contact us at:
We will respond to your request within 30 days. We may ask for verification of your identity before processing your request.
If you believe we have not handled your data properly, you have the right to lodge a complaint with a supervisory authority:
We implement appropriate technical and organizational measures to protect your data:
In the event of a data breach that poses a risk to your rights and freedoms:
Novilay serves users globally, including in the EU, UK, and US. Your data may be processed in countries outside your jurisdiction.
When transferring data outside the EU/EEA, we rely on:
Novilay is not intended for use by children under the age of 16 (or the applicable age of digital consent in your jurisdiction).
We do not knowingly collect personal data from children. If we become aware that we have collected data from a child, we will take steps to delete that information promptly.
If you believe a child has provided us with personal data, please contact us at hello@novilay.com.
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors.
When we make changes:
We encourage you to review this policy periodically to stay informed about how we protect your data.
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Data Controller: Novilay by Cristhian Almora
Privacy inquiries: hello@novilay.com
Website: novilay.com
We aim to respond to all privacy-related inquiries within 30 days.