This Privacy Policy describes how ฅ^•ﻌ•^ฅ (“we”, “us”, “the Service”) handles information when you use our multi-tenant blog platform. By using the Service you agree to this policy.
Template for product launch — have qualified counsel review before production use.
1. Who we are
The Service is operated by the Novon project operators. Contact for privacy requests: privacy@novon.im.
2. Information we collect
2.1 Account & authentication
- GitHub account identifiers (id, login, name, email if provided by GitHub)
- Avatar URL and public profile fields returned by GitHub OAuth
- OAuth access token (used only to call GitHub APIs on your behalf)
2.2 Site configuration
- Site name, slug, theme, domain settings, content path, and related metadata you configure
- Repository owner/name and branch you connect
2.3 Usage & analytics
- First-party page views for your public blogs (path, approximate time, coarse geo if available, referrer, user-agent)
- We do not use third-party advertising trackers by default
2.4 Billing (when enabled)
- Subscription plan and Airwallex customer/subscription identifiers
- Payment card data is processed by Airwallex; we do not store full card numbers
3. What we do not store as primary content
Blog post bodies are stored in your GitHub repository. We read and write them via the GitHub API when you use the CMS; we do not run a separate proprietary document database for post content.
4. How we use information
- Provide authentication, multi-tenant hosting, and the dashboard CMS
- Publish your sites, feeds, and SEO assets
- Operate privacy-oriented analytics for site owners
- Enforce plan limits and process subscriptions
- Secure the Service, prevent abuse, and debug outages
- Communicate about service changes or security issues
5. Legal bases (EEA/UK where applicable)
- Contract — to provide the Service you request
- Legitimate interests — security, product improvement, aggregated metrics
- Consent — where required for optional cookies or marketing
- Legal obligation — when we must retain or disclose data by law
6. Sharing
We share data only with processors needed to run the Service, for example:
- Cloudflare — edge hosting, D1, KV, DNS
- GitHub — OAuth and repository content APIs (under your authorization)
- Airwallex — payments (when billing is enabled)
We do not sell personal information.
7. International transfers
Infrastructure may process data in regions where Cloudflare and our processors operate. Where required, we rely on appropriate transfer mechanisms provided by those processors.
8. Retention
- Account data — while your account remains active, then deleted or anonymized within a reasonable period after deletion request
- Analytics — retained according to your plan’s retention window, then deleted or aggregated
- Billing records — retained as required for tax and accounting
9. Security
We use industry-standard controls available on our platform (TLS in transit, access-controlled databases, secret-managed credentials). No method of transmission or storage is 100% secure.
10. Your rights
Depending on your location, you may have rights to access, correct, delete, or export personal data, or to object to certain processing. Contact privacy@novon.im.
11. Children
The Service is not directed to children under 16. We do not knowingly collect data from children.
12. Changes
We may update this policy. Material changes will be indicated by updating the “Last updated” date on this page.
13. Contact
Privacy questions: privacy@novon.im