Privacy Policy

This policy describes how Grainform at grainform.app handles information when you edit a scene, sign in, save a project or activate a license. Contact hello@grainform.app for privacy questions or deletion requests.

Account information

Email and password sign-in uses Google Firebase Authentication. Firebase receives your email and password to create and authenticate your account and sends password reset emails. Grainform does not store a copy of your password in its project database.

Google sign-in

If you choose Continue with Google, we request only your basic sign-in information: your Google account identifier, name, email address and profile picture. Google and Firebase Authentication use this information to authenticate you and maintain your Grainform account. Grainform uses it for account identification and access to your saved projects.

We do not request access to Gmail, Google Drive, contacts, calendars or other Google content. We do not sell Google user data, use it for advertising, or use it to train AI models. You can revoke Grainform's connection through your Google account settings; revoking access does not automatically delete your Grainform projects.

Images and projects

Images, SVGs and supported 3D models are processed in your browser. A public preview does not upload your original file. When you save a project, Grainform sends grain positions, source colors, editing history, material and animation settings, project names and collection names to Cloud Firestore under your Firebase account identifier. A reduced working image is saved for continued editing; large working images may be compressed. Original full-resolution image and model files are not uploaded.

Firestore rules restrict saved projects, working images and edit history to their account owner. We do not make your saved projects public or use them to train AI models.

Service providers

Google Firebase provides Hosting, Authentication and Firestore. These services process account information, saved project data and service requests to operate Grainform. Firebase processes service information according to its privacy and security documentation. Providers may process information in countries other than your own under their applicable data protection arrangements.

Grainform currently includes no advertising tracker or application analytics service. We do not sell your personal information. We may disclose information where legally required, to protect the service, or when you direct us to do so.

Browser storage

Firebase keeps your authentication session in browser storage. Grainform also stores a temporary guest project, its reduced working image and edits so you can continue editing or sign in. Opening plans also keeps the latest guest creation in local browser storage so a checkout return in another tab can reopen it. This recovery copy is available for seven days; expired copies are removed when recovery is next read. Saved-account projects return through their protected workspace route. An activated license key and activation identifier are kept in your browser. Signing out ends the active account session; guest drafts and license data can be removed by clearing Grainform's browser data.

Licenses and payments

Production checkout is currently unavailable. If you enter a license key, Grainform sends the key and activation identifier to Lemon Squeezy's License API to validate and activate it. When checkout becomes available, Lemon Squeezy will host it and process the order, billing information and payment details under its privacy policy. Grainform does not collect your payment card details.

Support

When you email us, we receive the information you choose to include, such as your email address, message and order identifier. Lark Mail hosts our hello@grainform.app inbox and support@grainform.app alias and processes those messages to deliver and store our support correspondence. We use this information to respond and resolve your request. Do not send passwords, card numbers or identity documents to the support inbox.

Retention and your choices

Saved projects remain until you delete them through your workspace or request account deletion. Deleting a project removes its project document, working image and saved edit history. Authentication information remains while your Firebase account exists. Guest drafts stay locally in your browser and can be removed by clearing the site's data.

You can ask to access, correct or delete your account information by emailing hello@grainform.app. We may need to verify account ownership before fulfilling a request. Service providers may retain security logs, backups and transaction records under their own retention policies or legal obligations. We will explain any applicable limitation when responding.

Security and children

Connections to the hosted site and Firebase use HTTPS. Saved project access requires authentication and owner authorization. No system can guarantee absolute security. Grainform is not intended for children under 13 and we do not knowingly collect their information. Contact us if you believe a child has provided personal information.

Updates and contact

We will publish changes here with the effective date. For privacy questions or deletion requests, contact Grainform at hello@grainform.app.