Privacy Policy

Your privacy matters. Here's how we collect, use, and protect your data.

Last Updated: December 8, 2025

Effective Date: December 8, 2025

1. INTRODUCTION

Welcome to AfriNova ("we," "our," or "us"). We are committed to protecting your personal information and your right to privacy. This Privacy Policy explains what information we collect, how we use it, and what rights you have in relation to it.

AfriNova is an AI-powered full-stack development platform operated by AfriNova Technologies Ltd., a company registered in Uganda, that generates production-ready code. By using our service at https://afrinova.dev (the "Platform"), you agree to the collection and use of information in accordance with this Privacy Policy.

If you have any questions or concerns about this policy, please contact us at privacy@afrinova.dev.

2. INFORMATION WE COLLECT

2.1 Information You Provide

We collect information that you voluntarily provide when using AfriNova:

  • Account Information: Full name, email address, password (encrypted with bcrypt)
  • Profile Information: Avatar/profile picture, display name, bio, timezone (all optional)
  • Project Data: Project names, descriptions, prompts, tech stack selections, uploaded files (design files, documents, code), generated code
  • Payment Information: Billing name, billing address, payment method details. Note: We do NOT store credit card numbers or CVV codes. All payment data is processed securely by Stripe.
  • Communications: Messages you send to our support team, feedback submissions, survey responses, feature requests

2.2 Automatically Collected Information

When you use AfriNova, we automatically collect certain information:

  • Usage Data: Pages visited, features used, time spent on platform, generation requests, API calls
  • Device Information: Browser type and version, operating system, device type (mobile/desktop), screen resolution
  • Log Data: IP address (anonymized), timestamps, error logs, performance metrics
  • Cookies and Similar Technologies: Session cookies, preference cookies, analytics cookies (see Section 7)

2.3 Information from Third Parties

If you sign up using OAuth (Google, GitHub), we receive:

  • Name and email address from your OAuth provider
  • Profile picture (if available and you grant permission)
  • Public profile information as allowed by the provider

3. HOW WE USE YOUR INFORMATION

We use the information we collect for the following purposes:

πŸ› οΈ To Provide and Maintain Our Service

  • Create and manage your account
  • Process your project generation requests
  • Store and retrieve your projects and generated code
  • Provide customer support and respond to inquiries

πŸ’³ To Process Payments

  • Process subscription payments and renewals
  • Send billing receipts and invoices
  • Manage subscription upgrades and downgrades
  • Detect and prevent payment fraud

πŸ“§ To Communicate With You

  • Send service-related notifications (generation complete, errors, updates)
  • Send subscription and billing notifications
  • Respond to your support requests
  • Send marketing emails (only if you opt in - you can unsubscribe anytime)

πŸ“Š To Improve Our Service

  • Analyze usage patterns to improve features
  • Monitor platform performance and fix bugs
  • Train and improve our AI models (using anonymized data only)
  • Conduct research and development

πŸ”’ For Security and Fraud Prevention

  • Detect and prevent fraudulent activity
  • Enforce our Terms of Service
  • Protect against abuse and unauthorized access
  • Ensure platform security and integrity

βš–οΈ For Legal Compliance

  • Comply with legal obligations and regulations
  • Respond to lawful requests from authorities
  • Establish, exercise, or defend legal claims

4. INFORMATION SHARING AND DISCLOSURE

We do NOT sell your personal information to third parties. We only share your information in the following limited circumstances:

4.1 Service Providers

We share information with trusted third-party service providers who help us operate our platform:

  • Supabase: Database hosting, authentication, file storage
  • Stripe: Payment processing (they have their own privacy policy)
  • OpenRouter: AI model access for code generation
  • Vercel: Platform hosting and deployment
  • Resend: Transactional email delivery

These providers are contractually obligated to protect your data and only use it to provide services to us.

4.2 Legal Requirements

We may disclose your information if required by law or in response to:

  • Valid legal requests (subpoenas, court orders)
  • Legal processes or government requests
  • Protection of our rights, property, or safety
  • Enforcement of our Terms of Service

4.3 Business Transfers

If AfriNova is acquired, merged, or sold, your information may be transferred as part of that transaction. We will notify you via email and/or a prominent notice on our Platform before your information is transferred and becomes subject to a different privacy policy.

4.4 With Your Consent

We may share your information for any other purpose with your explicit consent.

5. THIRD-PARTY SERVICES

AfriNova integrates with several third-party services. Each has its own privacy policy:

Supabase (Database & Auth): https://supabase.com/privacy
Stripe (Payments): https://stripe.com/privacy
OpenRouter (AI Models): https://openrouter.ai/privacy
⚠️ Important: We are not responsible for the privacy practices of these third-party services. We encourage you to read their privacy policies.

6. DATA SECURITY

We take data security seriously and implement industry-standard measures to protect your information:

  • Encryption: All data in transit is encrypted using TLS 1.3. Sensitive data at rest is encrypted.
  • Password Security: Passwords are hashed using bcrypt with salt before storage.
  • Access Controls: Strict access controls limit who can access your data internally.
  • Regular Audits: We conduct regular security audits and penetration testing.
  • Secure Infrastructure: Our platform is hosted on secure, SOC 2 compliant infrastructure.
  • Database Security: Row-level security (RLS) ensures users can only access their own data.
⚠️ No Method is 100% Secure: While we strive to protect your data, no method of transmission over the internet or electronic storage is completely secure. We cannot guarantee absolute security.

7. COOKIES AND TRACKING TECHNOLOGIES

We use cookies and similar tracking technologies to enhance your experience:

7.1 Essential Cookies (Required)

These cookies are necessary for the platform to function:

  • Authentication: Keep you logged in
  • Security: Prevent CSRF attacks
  • Session Management: Maintain your session state

7.2 Preference Cookies (Optional)

These cookies remember your preferences:

  • Theme: Remember light/dark mode preference
  • Language: Remember your language selection
  • Settings: Remember your dashboard preferences

7.3 Analytics Cookies (Optional)

These help us understand how you use our platform:

  • Usage Analytics: Track feature usage and performance
  • Error Tracking: Help us identify and fix bugs

You can control cookies through your browser settings. However, disabling essential cookies may affect platform functionality.

8. YOUR PRIVACY RIGHTS

Depending on your location, you may have the following rights regarding your personal information:

πŸ” Right to Access

You can request a copy of all personal information we hold about you. Go to Settings β†’ Profile β†’ "Download My Data" or email privacy@afrinova.dev.

✏️ Right to Correction

You can update your account information anytime in Settings β†’ Profile. For other corrections, contact us at privacy@afrinova.dev.

πŸ—‘οΈ Right to Deletion

You can delete your account and all associated data in Settings β†’ Profile β†’ "Delete Account". This action is permanent and cannot be undone.

πŸ“¦ Right to Data Portability

You can export your projects and generated code at any time. Go to Settings β†’ Profile β†’ "Export All Projects".

🚫 Right to Object

You can object to certain data processing (e.g., marketing emails). Unsubscribe links are in all marketing emails, or go to Settings β†’ Preferences.

⏸️ Right to Restriction

You can request that we restrict processing of your data in certain circumstances. Contact privacy@afrinova.dev.

πŸ‡ͺπŸ‡Ί GDPR Rights (EU/EEA): If you're in the EU/EEA, you have additional rights under GDPR, including the right to lodge a complaint with your local data protection authority.
πŸ‡ΊπŸ‡Έ CCPA Rights (California): California residents have additional rights under CCPA. We do NOT sell your personal information. You can opt out of analytics by contacting us.

9. DATA RETENTION

We retain your information for as long as necessary to provide our services:

  • Active Accounts: We retain your data while your account is active
  • Deleted Accounts: After account deletion, most data is deleted within 30 days. Some data may be retained for up to 90 days for backup and recovery purposes.
  • Legal Requirements: We may retain certain data longer if required by law (e.g., tax records, transaction history)
  • Anonymized Data: We may retain anonymized, aggregated data indefinitely for analytics and research

10. CHILDREN'S PRIVACY

AfriNova is not intended for users under the age of 13 (or 16 in the EU/EEA). We do not knowingly collect personal information from children.

If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately at privacy@afrinova.dev. We will delete the information promptly.

11. INTERNATIONAL DATA TRANSFERS

AfriNova operates globally. Your information may be transferred to, stored, and processed in countries other than your own, including:

  • Uganda (our headquarters)
  • United States (where some of our service providers are located)
  • European Union (where some servers are located)

We ensure appropriate safeguards are in place for international transfers, including:

  • Standard Contractual Clauses approved by the European Commission
  • Adequacy decisions where applicable
  • Certifications and compliance frameworks (e.g., SOC 2)

12. CHANGES TO THIS PRIVACY POLICY

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.

When we make changes:

  • We will update the "Last Updated" date at the top of this policy
  • For material changes, we will notify you by email and/or a prominent notice on our Platform
  • Your continued use of AfriNova after changes constitutes acceptance of the updated policy

13. CONTACT US

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

AfriNova Technologies Ltd.

Email: privacy@afrinova.dev

Support: support@afrinova.dev

Location: Kampala, Uganda

Website: https://afrinova.dev

We aim to respond to all privacy-related inquiries within 30 days.