Privacy policy
Effective August 30, 2026
Northlit (northlit.ai) is an AI design studio operated by 3 Elements Design. This policy describes what we collect, how we use it, and the choices you have — whether you use Northlit in the browser, through the API, or by connecting an AI agent over MCP.
What we collect
Account information.When you sign in we receive your email address and display name from your sign-in provider (Google or Apple, via Firebase Authentication). We don't receive or store your passwords.
Content you create.Briefs, prompts, uploaded reference images, moodboards, generated images and videos, prototypes, brand assets, and the edits you make to them. This content is the product — it's stored so you can come back to it.
Usage and billing records. Which generations you run and their approximate compute cost (model, token and image counts), plan and credit state, and payment status. We use these to meter plans, show you your own usage, and operate the service. Card details go directly to Stripe — we never see or store card numbers.
Product analytics. Basic interaction events (pages viewed, features used) to understand what to improve.
How we use it
To provide the service: generating designs from your prompts, storing your work, enforcing plan limits, and billing. To operate and improve Northlit: debugging, abuse prevention, and understanding which features matter. We don't sell your data, and we don't use your designs to train our own models.
Service providers
Your data is processed by the infrastructure the product runs on: Google Firebase (sign-in), Vercel (hosting and file storage), Neon (database), Stripe (payments), Resend (transactional email), and Mixpanel (product analytics).
When you generate, your prompts and reference images are sent to the AI model provider that serves the request — such as Anthropic, OpenAI, Google, or fal.ai — to produce the output, under our agreements with them. If you configure your own provider keys (BYOK), those requests run against your account with that provider instead.
Sharing and publishing
Your work is private to you (and to project collaborators you invite) by default. Some actions publish deliberately: deploying a prototype creates a public URL, minting a build handoff link creates a tokenized document readable by anyone holding the link, and sharing a board grants access to the people you share it with.
Agents and API access
API keys and OAuth connections (for example, connecting Claude or another agent over MCP) act as your account: anything an agent creates, reads, or spends happens under your identity and billing. You can see and revoke every key and connection in Settings → API, which cuts off that access immediately.
Retention and deletion
Your content stays until you delete it. Deleting a canvas card, run, or asset removes the stored content and its files; usage and billing ledgers are retained as long as needed for accounting, plan enforcement, and legal obligations. To delete your account and its data, contact us and we'll complete it within 30 days.
Security
Traffic is encrypted in transit (TLS) and data is encrypted at rest by our storage providers. API keys are stored only as hashes — the plaintext is shown once at creation and is unrecoverable by us.
Changes and contact
We'll update this page when our practices change and revise the effective date above. Questions, requests, or deletion: support@northlit.ai.