Legal · Privacy

Privacy, without the fog.

This notice explains the information the current browser service is designed to handle, where provider configuration matters, and which production policies are not finished yet.

StatusPre-production draft · legal review requiredEffectiveApplies toNaratake browser SaaS

01 · Scope and readiness

What this notice covers.

It covers the Naratake marketing pages and the browser-based Naratake Studio workspace: the editor, project and asset storage, preview, release history, publishing, support, and billing controls when those services are configured. Customers work in the browser; this notice does not describe the older Local Studio desktop product as an end-user delivery path.

Some integrations exist as guarded application boundaries but have not been connected to verified production accounts. Where this notice says when configured, the feature is conditional, and the provider may process information under its own terms.

02 · Information we handle

The data follows the work you ask Naratake to do.

Account and workspace identity

When Clerk is configured, Naratake receives provider user and organization identifiers and session context. Naratake then resolves the active workspace and its database membership role; the application role, not a client-supplied workspace value, controls access.

Project and editor content

Project documents, page copy, business details, theme choices, component settings, immutable revisions, save metadata, release records, and other content you enter in the editor.

Images and other supported assets

Uploaded raster images, file metadata, byte size, media type, server-computed content hash, project references, and cleanup state. Current cloud asset routes reject SVG and unsupported or spoofed image formats.

Publishing information

The reviewed revision, the eligibility result, build and verification state, provider-safe deployment identifiers, the live release pointer, and rollback history for every release you publish.

Billing records, when configured

Workspace plan and entitlement state plus the Stripe customer, Checkout, and subscription identifiers needed to reconcile access. Payment-card entry happens on Stripe-hosted pages; Naratake is not designed to receive raw card details through its own forms.

Support and operational context

Messages you send to support and the details you include. Hosting, identity, payment, and deployment providers may also generate request, device, network, timestamp, or error logs according to the production configuration and their own notices.

Content you intentionally publish becomes publicly accessible at the published site. Do not place secrets, private customer records, regulated health data, or payment-card data in public page content.

03 · How information is used

Only for operating and protecting the service.

  • Authenticate a user and resolve the correct workspace membership and permissions.
  • Save, recover, display, preview, validate, and version project work.
  • Store and serve workspace-scoped assets through the application boundary.
  • Evaluate publishing eligibility, build the reviewed revision, promote it, and support rollback.
  • Process subscription access and open hosted Checkout or billing portals when Stripe is configured.
  • Respond to support requests, investigate failures, prevent abuse, and protect service integrity.
  • Comply with valid legal obligations after the responsible entity and jurisdiction are finalized.

The current marketing application does not intentionally install advertising or behavioral-analytics trackers. Naratake does not currently sell personal information or use workspace content for targeted advertising.

04 · Providers and disclosures

Conditional providers, named by role.

Naratake only uses these roles when the relevant production service is configured. The final provider inventory must be published after deployment choices are approved.

Identity
Clerk may authenticate users and organizations when production keys are configured.
Payments
Stripe may host Checkout and the customer portal and process signed billing events when configured.
Application hosting
The selected hosting provider serves the marketing site and Studio and may process request logs.
Database and private object storage
Approved providers store tenant-scoped metadata, project bundles, and assets when configured.
Site deployment
An approved build and deployment provider may receive the frozen artifact and provider-safe identifiers.

Naratake may disclose information when required by valid law, to protect users and the service, or as part of a reviewed business transaction. A final production policy must add the applicable legal tests, notice process, subprocessor list, and any required data-processing terms.

05 · Workspace isolation

Tenant scope comes from the server session.

Project and asset routes derive workspace identity from the authenticated server session rather than accepting a workspace target from the browser. Database membership roles are authoritative for ordinary authorization, and the production data model is designed to apply tenant scope within database transactions. Private object references stay server-side; object-provider credentials and direct private object URLs are not returned to the browser by those routes.

These controls reduce cross-workspace risk, but they are not a certification, and they are not a promise that a future deployment cannot fail. See the Security & Trust page for the implemented boundaries and the production verification that is still outstanding.

06 · Retention and deletion

No instant-deletion promise.

Naratake retains project revisions and release records to provide autosave recovery, conflict handling, release traceability, and rollback. Logical asset deletion may enter a delayed cleanup workflow so active references are rechecked before physical removal. The production retention periods for accounts, projects, revisions, provider logs, billing ledgers, and support records have not yet been approved.

There is no promised one-click account or workspace deletion workflow in the current build. Send a request to hello@naratake.com. Naratake must verify the requester and the workspace authority, then confirm the available scope and timing. Do not assume immediate erasure, a particular backup behavior, or deletion from a provider’s legally required records; the final production policy must state the actual backup, restore, and retention design after it is implemented and tested.

07 · Your choices

Control what you enter and publish.

  • Review content and assets before you publish; published pages are intentionally public.
  • Keep workspace memberships current and use the least-privileged role appropriate for each person.
  • Use the identity provider’s account controls when Clerk is configured.
  • Use Stripe’s hosted portal for supported subscription actions when billing is configured.
  • Contact Naratake to ask about access, correction, export, restriction, objection, or deletion.

Rights vary by location. The responsible legal entity and the process for jurisdiction-specific requests must be finalized before production; this page does not shorten any rights that applicable law provides.

08 · Children

A business tool, not a children’s service.

Naratake is intended for people authorized to build or operate a business website. It is not directed to children, and users should not knowingly submit a child’s personal information through a workspace unless they have a valid, reviewed legal basis and the service has been approved for that use.

09 · Changes and contact

Make the policy follow the product.

This notice will need revision when the production entity, providers, regions, retention schedule, deletion and export workflows, or operational capabilities change. A new effective date should accompany material changes.

Privacy questions or requestshello@naratake.comInclude the workspace name and the type of request. Do not email passwords, payment-card details, or secrets.