# Privacy Policy | NorthernGo

> Learn how NorthernGo handles your data: Firebase, Gemini, Stripe, Analytics after consent, and your GDPR rights.

Source: https://northerngo.com/privacy/
Language: en
Updated: 2026-08-28

---
Last updated: 22 August 2026

## 1. What data we collect

When you register on NorthernGo, we save the email address you provide (via Google Login or email/password) and your public profile picture to offer our service. We also save your order and subscription history to manage your account. If you use the support chat, the question is sent to Google Gemini to produce a reply; we do not store the chat log, only a monthly quota. If you post in the community we store your username and comment. If you connect GitHub we store your GitHub username and an encrypted OAuth token so export can work.


## 2. Prompts and generated code

We save the text prompts you enter and the code the AI generates, so you can access your projects. This applies to cloud mode. If you use local mode (WebGPU or Ollama), text prompts and generated code do not leave your device — see section 04. Image generation and document uploads still go via the cloud even in local mode.


## 3. Log Data & Operational Telemetry

When you use our Services, we automatically collect technical operational telemetries ("Log Data") to secure, maintain, and optimize the platform. This data includes internet protocol (IP) addresses, browser type and version, operating system, technical debug codes, error logs, and timestamps of your interactions. Log Data is processed based on our legitimate interest to prevent fraud, fix system bugs, and ensure infrastructure stability, and is retained only as long as necessary for these purposes.


## 4. Local AI Processing (WebGPU & Ollama)

When you use local models (WebGPU or Ollama), text generation and source-code creation happen on your own device. Text prompts and generated code in that mode are not sent to our servers.

Exception: image generation, document uploads and cloud mode still go via Google Gemini even if you chose local mode for text. Uploaded sketches in cloud mode leave your device.


## 5. Cookies and Local Storage

We use localStorage for functions required to run the platform: sign-in session, language, app drafts, local AI settings and your cookie choice. That is strictly necessary to deliver the service (Article 6(1)(b)), and does not require analytics consent.

The app draft is only the text in the prompt box. It stays in your browser so the idea survives while you create an account. It is not sent to our servers until you generate while signed in. It is deleted when you empty the box, when the build starts, or when you clear site data.

Visit statistics via Google Analytics are blocked until you actively consent. We do not use advertising cookies. You can change or withdraw analytics consent at any time via Cookie settings in the footer or your profile menu.


## 6. Why we collect the data & Payment Consent

Your cloud-stored information is used solely to operate the platform, identify you upon login, secure your saved cloud projects, and manage payments via our payment provider (Stripe). We never sell your data to third parties.

When upgrading to a paid plan, Stripe will process your payment details and automatically collect your explicit consent to our terms. This includes logging technical metadata (such as timestamp and IP address) as proof that you have waived your 14-day right of withdrawal in exchange for immediate access to the service.


## 7. Data Infrastructure & Sub-processors

We use the following sub-processors. Several are established in the US. Transfers rely on the EU Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework. Google Firebase (sign-in, Firestore, Hosting, Storage); Google Gemini (cloud-mode AI, image generation, document analysis, support chat and in-app AI in published apps); Google Analytics 4 (visit statistics, only after consent); Supabase (default database for your apps, PostgreSQL in the EU); Stripe (payments); Resend (transactional email and email your apps send); Render (API server); GitHub (optional source export, encrypted OAuth token). We do not sell your data. You can request an Art. 28 schedule with SCC references from support@northerngo.com.


## 8. Information Security & Encryption

All traffic between your browser and our services uses TLS. Cloud providers encrypt data at rest (AES-256 according to their documentation). We have not enabled multi-factor authentication on platform accounts. We do not review your project data unless needed for support or abuse handling.


## 9. How long we keep the data

Account data, projects and app databases are kept while you have an active account. When you (or an end-user in an app) use "Delete account" the data is held dormant for 14 days: it is not shown or processed, but can be restored by signing in. After that it is permanently deleted. Backups at sub-processors are typically cleared within 30–90 days. Render server logs are cleared within 30 days. Google Analytics events are cleared after 14 months. Stripe invoices are kept under bookkeeping law, in Sweden typically 7 years, even after the customer object is deleted. The support chat is not stored as message text.


## 10. Your rights

Under GDPR you have the right of access, rectification, erasure, restriction, objection and data portability (Art. 20). You can download your account data and projects via "Download my data" in the profile menu, and delete the account there. You can also contact support@northerngo.com or your supervisory authority.

---

NorthernGo is an AI-powered platform for building production-ready web apps with zero coding. Local AI generation via WebGPU is unlimited and free, and you own all generated source code. https://northerngo.com/
