Legal · Privacy
Privacy, without the fog.
How Naratake handles your information, works with service providers, and responds to privacy requests.
01 · Scope and readiness
What this notice covers.
This notice covers Naratake’s marketing pages and browser workspace: editing, project and asset storage, previews, release history, publishing, support, and billing where enabled. LocalSite Studio is a separately licensed desktop product; its handling of data is outside the scope of this notice.
A few integrations exist in the code but are not connected to a production account. Where this notice says when configured, the feature is conditional, and the provider may process information under its own terms.
02 · Information we handle
The data follows the work you ask Naratake to do.
Account and workspace identity
When Clerk is configured, Naratake receives provider user and organization identifiers and session context. Naratake then resolves the active workspace and its database membership role; the application role, not a client-supplied workspace value, controls access.
Project and editor content
Project documents, page copy, business details, theme choices, component settings, immutable revisions, save metadata, release records, and other content you enter in the editor.
Images and other supported assets
Uploaded raster images, file metadata, byte size, media type, server-computed content hash, project references, and cleanup state. Current cloud asset routes reject SVG and unsupported or spoofed image formats.
Publishing information
The reviewed revision, the eligibility result, build and verification state, provider-safe deployment identifiers, the live release pointer, and rollback history for every release you publish.
Billing records, when configured
Workspace plan and entitlement state plus the Stripe customer, Checkout, and subscription identifiers needed to reconcile access. Payment-card entry happens on Stripe-hosted pages; Naratake is not designed to receive raw card details through its own forms.
Support and operational context
Messages you send to support and the details you include. Hosting, identity, payment, and deployment providers may also generate request, device, network, timestamp, or error logs according to the production configuration and their own notices.
Content you intentionally publish becomes publicly accessible at the published site. Do not place secrets, private customer records, regulated health data, or payment-card data in public page content.
03 · How information is used
Only for operating and protecting the service.
- Authenticate a user and resolve the correct workspace membership and permissions.
- Save, recover, display, preview, validate, and version project work.
- Store and serve workspace-scoped assets through the application boundary.
- Evaluate publishing eligibility, build the reviewed revision, promote it, and support rollback.
- Process subscription access and open hosted Checkout or billing portals when Stripe is configured.
- Respond to support requests, investigate failures, prevent abuse, and protect service integrity.
- Respond to applicable legal requirements.
Marketing visit counts use cookieless Cloudflare Web Analytics. Links can carry five campaign parameters, a public Naratake entry-page path and a broad source category; we do not retain the full referrer URL or extract its search query. At cloud sign-up, you can choose to save this context with your Clerk account so we can compare registrations and recorded payments by entry page. The choice is off by default and is not required to register. Desktop checkout continues to store campaign parameters in Stripe. We do not use advertising pixels, session recordings or cross-site identity profiles, sell personal information, or use workspace content for targeted advertising. Contact support to remove optional source data saved with your account.
04 · Providers and disclosures
Conditional providers, named by role.
These are the companies that actually handle data on Naratake’s behalf today, named. Each processes information under its own terms. A subprocessor list with data locations and a change-notice process still has to be published — that is a real gap, not a formality.
- Identity
- Clerk authenticates users and organizations.
- Payments
- Stripe hosts Checkout and the customer portal and processes signed billing events. Card details are entered on Stripe’s pages and never reach Naratake.
- Application hosting
- Railway runs the marketing site, Studio and the background services, and processes request logs. Cloudflare provides DNS and the cookieless visit counting described above.
- Database and private object storage
- Neon stores tenant-scoped metadata in Postgres; Vercel Blob stores project bundles and uploaded assets. Both are private and scoped to one workspace.
- Site deployment
- Vercel builds and serves published customer sites, and Neon provisions a separate database for each site published with its back office. A site you publish is public by design.
Naratake may disclose information when required by valid law, to protect users and the service, or as part of a reviewed business transaction. A final production policy must add the applicable legal tests, notice process, subprocessor list, and any required data-processing terms.
05 · Workspace isolation
Tenant scope comes from the server session.
Project and asset routes derive workspace identity from the authenticated server session rather than accepting a workspace target from the browser. Database membership roles are authoritative for ordinary authorization, and the production data model is designed to apply tenant scope within database transactions. Private object references stay server-side; object-provider credentials and direct private object URLs are not returned to the browser by those routes.
These controls reduce cross-workspace risk, but they are not a certification, and they are not a promise that a future deployment cannot fail. See the Security & Trust page for the implemented boundaries and the production verification that is still outstanding.
06 · Retention and deletion
No instant-deletion promise.
Naratake retains project revisions and release records to provide autosave recovery, conflict handling, release traceability, and rollback. Logical asset deletion may enter a delayed cleanup workflow so active references are rechecked before physical removal. The production retention periods for accounts, projects, revisions, provider logs, billing ledgers, and support records have not yet been approved.
There is no promised one-click account or workspace deletion workflow in the current build. Send a request to support@naratake.com. Naratake must verify the requester and the workspace authority, then confirm the available scope and timing. Do not assume immediate erasure, a particular backup behavior, or deletion from a provider’s legally required records; the final production policy must state the actual backup, restore, and retention design after it is implemented and tested.
07 · Your choices
Control what you enter and publish.
- Review content and assets before you publish; published pages are intentionally public.
- Keep workspace memberships current and use the least-privileged role appropriate for each person.
- Use the identity provider’s account controls when Clerk is configured.
- Use Stripe’s hosted portal for supported subscription actions when billing is configured.
- Contact Naratake to ask about access, correction, export, restriction, objection, or deletion.
Rights vary by location. The data controller is identified in “Changes and contact” below; procedures for requests that depend on location still need to be documented. This notice does not limit rights provided by applicable law.
08 · Children
A business tool, not a children’s service.
Naratake is intended for people authorized to build or operate a business website. It is not directed to children, and users should not knowingly submit a child’s personal information through a workspace unless they have a valid, reviewed legal basis and the service has been approved for that use.
09 · Changes and contact
Make the policy follow the product.
This notice will need revision when the production entity, providers, regions, retention schedule, deletion and export workflows, or operational capabilities change. A new effective date should accompany material changes.
Privacy questions or requestsData controller: CT Studio, Texas, United States.support@naratake.comInclude the workspace name and the type of request. Do not email passwords, payment-card details, or secrets.