← Back to navisualguide.com

Privacy Policy

Last updated: 19 July 2026

Navisual (“we”, “us”) is a Windows desktop app that watches your active window and shows you where to click. This policy explains what data the app handles, what leaves your computer, and the third parties involved. The short version: your screenshots are processed to answer your request and are not stored on our servers, and the free tier requires no account.

Navisual is operated from British Columbia, Canada. Because the AI and infrastructure providers below operate globally, data you send (such as a screenshot for a request) may be processed on servers outside Canada, including in the United States.

1. What the app processes

  • Screenshots of your active window. When you ask for guidance, a screenshot of the foreground application window (not your whole desktop) is sent to the AI provider you’ve selected so it can identify the next step. Screenshots are held in memory and are not written to disk at default settings, and are not stored on Navisual’s servers.
  • Window title and size. The focused window’s title and its on-screen position/size are sent with the request to give the AI context.
  • Your request text. What you type or say, plus a short running summary of the task.
  • Voice input (optional). If you enable push-to-talk, your spoken audio is transcribed by the WebView2 Web Speech API, which streams it to Microsoft’s online speech service. This is a separate data flow you can leave disabled.

Element coordinates are matched locally on your machine (Windows UI Automation + built-in OCR). Your screen layout is not used to build any profile of you.

2. Where your screenshot goes (you choose)

The AI provider is your choice in Settings:

  • Managed tier (free / paid) — routed through our relay (see §5) to an AI provider on your behalf.
  • Bring your own key — sent directly to Anthropic, Google, OpenAI, DeepSeek, or Qwen using your own API key; our servers are not involved.
  • Ollama (local) — runs entirely on your own machine or LAN; nothing leaves your network.

Whichever provider receives a request processes it under their privacy policy, and we don’t control how third-party AI providers use it.

Important — the free managed tier uses your data for model training. The free tier is served by free-of-charge AI models — we route to whichever provider(s) currently offer the best reliability and cost for the free tier, and that routing changes from time to time as we improve it. Free-of-charge AI access is commonly offered on the condition that the provider may retain your requests, including the screenshot of your active window, and use them to train and improve their AI models — this is standard practice across the industry for no-cost API tiers, not something specific to whichever provider we currently route to. If you do not want your screen content used for model training, use one of the private options instead:

  • the paid managed tier — routed to paid provider endpoints, whose current API policies state they do not use your data for model training (this is their policy, not a guarantee by us, and a provider may change it — see their terms);
  • a bring-your-own-key provider on a paid plan, under that provider’s current policy (note: a provider’s own free tier — e.g. a free Google AI Studio key — may itself train on your data; check that provider’s policy); or
  • Ollama (local) — nothing leaves your machine (the only option that doesn’t depend on any provider’s policy).

Some providers apply different data-use rules by region — for example, certain providers extend paid-tier-equivalent data protections to free-tier users in the European Economic Area, Switzerland, or the UK, under that provider’s own policy. Check the current upstream provider’s own terms for the specifics that apply to your region.

3. Optional app add-ons (Blender)

For a few applications whose interface Navisual cannot read reliably from the screen alone, we offer an optional add-on that lets the app tell Navisual where its buttons are. Today this exists for Blender. It is entirely optional: Navisual works without it, and nothing about it runs unless you install and enable it yourself.

  • How it gets installed. Navisual can copy the add-on file into Blender’s add-ons folder for you, but only when you click Install on the offer. It is then inert until you tick its checkbox in Blender’s own Preferences → Add-ons panel — that checkbox is the consent step, and Navisual cannot tick it for you.
  • What it does when enabled. It listens on a local network port (127.0.0.1:47611) that is reachable only from your own computer — it does not accept connections from other machines and does not send anything to the internet. Navisual asks it read-only questions such as “where is the tool shelf?”, “which mode is open?”, and “which brush is selected?”.
  • What it can’t do. It is read-only by construction: it cannot click, type, run commands, or change or save your file. This matches Navisual’s core rule — the AI guides, it never acts.
  • What reaches the AI. The interface facts above (mode, tool, brush names, object names in your scene) are included in the request to your chosen AI provider, alongside the screenshot, and are covered by §2. No file contents, geometry, or file paths are sent.
  • Turning it off. Untick it in Blender’s Add-ons panel to stop it, or use Remove there to delete the file. Navisual keeps working without it.

4. Data we store

On your computer (under %LOCALAPPDATA%\com.navisual.app): your settings and any API keys you enter, your sign-in token, conversation/session files, and (only if you turn on debug logging) diagnostic logs. These never leave your machine unless you send them to us.

On our servers (Supabase), only for the managed tier:

  • Account record — an anonymous user id, your request count, coin balance, tier, and (after a purchase) your Stripe customer id. The free tier uses anonymous sign-in, so it holds no name or email until you register (Google or email) to buy coins.
  • Free-tier device count — to keep the 30 free requests per device (rather than per throwaway anonymous session), the app sends a one-way hash of a Windows machine identifier with managed-tier requests, and we store that hash alongside a request count only to enforce the free limit. The hash cannot be reversed to identify your machine or you; paid requests bill by coins and ignore it, and bring-your-own-key or local (Ollama) providers never receive it.
  • Feedback — if you tap a “wrong” reason or send feedback, we store the category, the AI’s instruction/target, the provider/model, and any note you type. No screenshots and no request text are included.

5. Third-party processors

ProcessorPurposeWhat they receive
SupabaseAccount, quota database, and the managed AI relayYour account record; the request payload passes through the relay in transit
Free-tier AI provider(s) — may change over timeUpstream for the free managed tierThe request payload (screenshot + text). May be retained and used to train the model provider’s AI — see §2
Paid AI provider endpoints — may change over timeUpstream for the paid managed tiersThe request payload. Not used for training under their current paid-API policies (subject to change by those providers)
StripePaymentsYour email and payment details — never your screenshots. Card data goes directly to Stripe (PCI); we never see card numbers.
MicrosoftVoice transcription (only if you enable push-to-talk)Your spoken audio
GitHubApp downloads and updatesStandard request metadata when you download

6. International data transfers

Our managed services run on infrastructure provided by Supabase and the upstream AI providers listed above. Your account record and the request payloads you send (a screenshot of your active window plus your text) may be transferred to and processed in the United States or other jurisdictions where these providers operate. By using the managed tier, you consent to this transfer. If you prefer that no data leave your machine, use a local provider such as Ollama, which sends nothing to us or to any third party.

7. Payments

Coin purchases are processed by Stripe. We receive a confirmation that a payment succeeded (to credit your balance) and store your Stripe customer id; we do not receive or store your card number. Stripe’s handling of your payment data is governed by Stripe’s Privacy Policy.

8. Retention & deletion

On Navisual’s servers, managed-tier requests pass through the relay in transit and are not retained after the response. Upstream AI providers, however, may retain them: the free tier’s models may keep your request and use it to train their AI (see §2), while the paid tier’s providers, under their current paid-API policies, state they do not use it for training (their policy, which they may change). Your account record and any feedback rows persist until you ask us to delete them. Local files live on your machine until you uninstall or delete them. To request deletion of your managed-tier account data, contact us (§11).

9. Your rights

Depending on where you live (e.g. GDPR in the EU/UK, CCPA in California), you may have the right to access, correct, or delete the data we hold about you, and to object to or restrict its processing. The free tier is anonymous, so we typically hold no information that identifies you until you make a purchase. Contact us to exercise any of these rights.

10. Children

Navisual is not directed to children under 13 (or the minimum age in your country), and we do not knowingly collect their data.

11. Contact

Questions or requests: support@navisualguide.com, or open an issue at github.com/NavisualGuide/navisual.

12. Changes

We’ll update this page when our practices change and revise the “last updated” date above.

See also our Terms of Service.

navisualguide.com · Guide · Privacy · Terms · GitHub · FSL-1.1-Apache-2.0