Privacy Policy
Last updated: April 11, 2026
1. Information We Collect
When you sign in with Google, we receive your name, email address, and profile picture. We do not collect passwords — authentication is handled entirely by Google OAuth.
When you generate icons, we store metadata about your usage (style, timestamps, credit transactions) to operate the service. Generated images are returned directly to your browser and are not stored on our servers after delivery.
2. Payment Data
All payments are processed by Stripe. We never see or store your full credit card number. We store your Stripe customer ID to link transactions to your account. For details on how Stripe handles your data, see Stripe's Privacy Policy.
3. Cookies & Session
We use a single session cookie (authjs.session-token) to keep you signed in. We do not use advertising pixels or cross-site tracking cookies.
On our public marketing pages (home, pricing, docs, help, and legal pages) we run Microsoft Clarity to see which sections visitors read and click, so we can improve the page. Clarity is configured in cookie-free mode: it sets no cookies, cannot recognise you across visits, and only ever records aggregated interactions such as clicks and scrolls. It is never loaded on signed-in pages, so your generations, account details, and API keys are never captured.
4. How We Use Your Data
- Authenticate your identity and manage your account
- Process payments and manage credit balances
- Provide customer support and respond to bug reports
- Improve the service based on aggregated, anonymized usage patterns
We do not sell, rent, or share your personal data with third parties for marketing purposes.
5. Third-Party Services
We use the following third-party services to operate Icovela:
- Google OAuth — authentication
- Stripe — payment processing
- OpenAI — icon image generation
- Turso — database hosting
- Microsoft Clarity — cookie-free usage analytics on public marketing pages only
Each service processes data according to its own privacy policy. We share only the minimum data necessary for each service to function.
6. Data Retention
We retain your account data for as long as your account is active. Transaction logs are kept for financial record-keeping purposes. If you delete your account, we will remove your personal data within 30 days, except where retention is required by law.
7. Your Rights (GDPR)
If you are in the European Economic Area, you have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your data
- Object to or restrict processing of your data
- Request a portable copy of your data
To exercise any of these rights, contact us at support@icovela.com.
8. Security
We use industry-standard measures to protect your data, including HTTPS encryption, hashed API keys (SHA-256), and server-side secret management. No method of transmission over the internet is 100% secure, but we take reasonable precautions to safeguard your information.
9. Changes to This Policy
We may update this policy from time to time. We will notify you of significant changes by posting the new policy on this page and updating the "Last updated" date above.
10. Contact
Questions about this policy? Email us at support@icovela.com.