Privacy Policy
Last updated: 19 September 2026
Navisual (“we”, “us”) is a Windows desktop app that watches your active window and shows you where to click. This policy explains what data the app handles, what leaves your computer, and the third parties involved. The short version: your screenshots are processed to answer your request and are not stored on our servers, your saved sessions stay on your machine, and the free tier requires no account.
Navisual is operated from British Columbia, Canada. Because the AI and infrastructure providers below operate globally, data you send (such as a screenshot for a request) may be processed on servers outside Canada, including in the United States.
1. What the app processes
- Screenshots of the window you point it at. When you ask for guidance, a screenshot is sent to the AI provider you’ve selected so it can identify the next step. This is a single application window or screen — the one you are being guided through — never your whole desktop. You can choose to share a whole screen instead, from the app picker inside Navisual; if you do, that is what is captured and sent, and it stays that way until you choose a single window again. Any screenshot Navisual saves is saved on your own computer — never uploaded, and never stored on Navisual’s servers.
- Window title and size, and your Windows version. The focused window’s title and its on-screen position/size are sent with the request to give the AI context, together with which version of Windows you are running and its build number — for example “Windows 11 (build 26200)”. Windows versions differ enough in Settings and File Explorer that without it the guidance has to guess which one you are looking at. No other details about your computer are sent: not your hardware, not your drives or free space, not your installed software.
- Your request text. What you type or say, plus a short running summary of the task.
- Your saved sessions (local only). The conversation, your task, the plan and what you clicked are saved on your machine so you can reopen recent sessions. The most recent are kept and older ones are removed automatically. You can export a session to a file in any folder you choose — the file includes the pictures if you enabled them — and open such a file again later. Opening one shows it; it rejoins the recent list only if you carry on working in it. None of this reaches Navisual’s servers.
- The control you last clicked. While a guidance session is active, Navisual records the name and type of the control you click — for example Button “Save” — so the AI knows what you just did instead of having to guess it from pixels. This applies only to clicks inside the app you are being guided in; clicks anywhere else on your screen are discarded immediately and are never stored or sent. The click is also kept with your saved session on your machine, so a reopened session can show what you clicked. Navisual records a control’s name, never its contents: the text inside a box is not read, and a password field is reported only as “(password field)”. Navisual does not monitor your keyboard at all.
- Where your cursor is, in supported apps. Navisual reads the cursor’s page, section and line number, whether text is selected, and the style and text of the paragraph you are in (long ones are shortened). Those words are already in the screenshot you send. A screenshot cannot show a text cursor, so without this the AI cannot tell where you are in a document.
- Voice input (optional). If you enable push-to-talk, your spoken audio is transcribed by the WebView2 Web Speech API, which streams it to Microsoft’s online speech service. This is a separate data flow you can leave disabled.
Cursor position stops the moment guidance stops and is never written to disk unless you turn on prompt logging in Developer settings. Click context is kept with your saved sessions (the most recent ones, on your machine). Neither is collected while capture is paused with the Pause hotkey.
Element coordinates are matched locally on your machine (Windows UI Automation + built-in OCR). Your screen layout is not used to build any profile of you.
2. Where your screenshot goes (you choose)
The AI provider is your choice in Settings:
- Managed tier (free / paid) — routed through our relay (see §5) to an AI provider on your behalf.
- Bring your own key — sent directly to Anthropic, Google, OpenAI, DeepSeek, or Qwen using your own API key; our servers are not involved.
- Ollama (local), or Custom (OpenAI-compatible) pointed at a local server such as LM Studio or llama.cpp — the model runs on your own machine or LAN, and your screenshots and requests never leave your network. (The short step-outcome row in §4 is separate, and carries no screen content.)
Whichever provider receives a request processes it under their privacy policy, and we don’t control how third-party AI providers use it.
Important — the free managed tier uses your data for model training. The free tier is served by free-of-charge AI models — we route to whichever provider(s) currently offer the best reliability and cost for the free tier, and that routing changes from time to time as we improve it. Free-of-charge AI access is commonly offered on the condition that the provider may retain your requests, including the screenshot of your active window, and use them to train and improve their AI models — this is standard practice across the industry for no-cost API tiers, not something specific to whichever provider we currently route to. If you do not want your screen content used for model training, use one of the private options instead:
- the paid managed tier — routed to paid provider endpoints, whose current API policies state they do not use your data for model training (this is their policy, not a guarantee by us, and a provider may change it — see their terms);
- a bring-your-own-key provider on a paid plan, under that provider’s current policy (note: a provider’s own free tier — e.g. a free Google AI Studio key — may itself train on your data; check that provider’s policy); or
- Ollama, or Custom pointed at a local server (local) — your screenshots and requests never leave your machine, so no provider policy applies to them at all.
Some providers apply different data-use rules by region — for example, certain providers extend paid-tier-equivalent data protections to free-tier users in the European Economic Area, Switzerland, or the UK, under that provider’s own policy. Check the current upstream provider’s own terms for the specifics that apply to your region.
3. Optional app add-ons (Blender)
For a few applications whose interface Navisual cannot read reliably from the screen alone, we offer an optional add-on that lets the app tell Navisual where its buttons are. Today this exists for Blender. It is entirely optional: Navisual works without it, and nothing about it runs unless you install and enable it yourself.
- How it gets installed. Navisual can copy the add-on file into Blender’s add-ons folder for you, but only when you click Install on the offer. It is then inert until you tick its checkbox in Blender’s own Preferences → Add-ons panel — that checkbox is the consent step, and Navisual cannot tick it for you.
- What it does when enabled. It listens on a local network port
(
127.0.0.1:47611) that is reachable only from your own computer — it does not accept connections from other machines and does not send anything to the internet. Navisual asks it read-only questions such as “where is the tool shelf?”, “which mode is open?”, and “which brush is selected?”. - What it can’t do. It is read-only by construction: it cannot click, type, run commands, or change or save your file. This matches Navisual’s core rule — the AI guides, it never acts.
- What reaches the AI. The interface facts above (mode, tool, brush names, object names in your scene) are included in the request to your chosen AI provider, alongside the screenshot, and are covered by §2. No file contents, geometry, or file paths are sent.
- Turning it off. Untick it in Blender’s Add-ons panel to stop it, or use Remove there to delete the file. Navisual keeps working without it.
4. Data we store
On your computer (under %LOCALAPPDATA%\com.navisual.app):
your settings and any API keys you enter, your sign-in token, conversation/session files
(including each step’s screenshot, if you turn that on), and (only if you turn on debug
logging) diagnostic logs. These never leave your machine
unless you send them to us.
On our servers (Supabase) — the first two apply to the managed tier only; the third applies whichever provider you use:
- Account record — an anonymous user id, your request count, coin balance, tier, and (after a purchase) your Stripe customer id. The free tier uses anonymous sign-in, so it holds no name or email until you register (Google or email) to buy coins.
- Free-tier device count — to keep the 30 free requests per device
(rather than per throwaway anonymous session), the app sends a one-way hash of a
Windows machine identifier with managed-tier requests, and we store that hash alongside a
request count only to enforce the free limit. The hash cannot be reversed
to identify your machine or you; paid requests bill by coins and ignore it, and
bring-your-own-key or local providers never receive it.
Alongside it we record the IP address that device was first seen from. It is written once, when a device is new to us, and never updated afterwards — it answers “where did this device first appear”, not “where is it now”. Its only use is anti-abuse: it lets us notice one network minting many fresh free allowances, and refuse them. It is not used to locate you, is never attached to your requests or to what is on your screen, and is not linked to your account record. - Request records (managed tier only) — one short operational row per managed request: which provider and model answered, whether a fallback was used, how long it took, the outcome (served, provider error, quota reached, refused), and your anonymous user id and device hash. It is how we notice a provider failing or requests being refused for the wrong reason. No screenshots, no request text, and no instruction — the detail it keeps is status codes. Deleted after 90 days.
- Step outcomes and feedback (any provider, including
your own API key or a local model) — each time you advance a step
(→ Next, or an Autopilot advance), and whenever you tap a “wrong” reason or send
feedback, we store one short row: the outcome category, the task you
typed, the instruction the AI gave and the on-screen target it named, the name
of the app being guided, whether the pointer was placed, the provider/model, and any
note you type. It is what tells us how often the guidance is right, and what people
actually use Navisual for. No screenshots — ever.
The task you typed is your own words, so read this bit. It is stored as you wrote it, trimmed to 500 characters, which means anything you put in the box goes with it — a file name, a link, a customer's name. Don't type something into Navisual you would not want us to hold. You can switch it off in Settings ▸ Screen Guide ▸ What you type, and everything else in the row keeps working.
If the AI runs on your own machine or network, we never receive it — whatever that setting says. Navisual looks at the address it is calling: a model onlocalhost, or on a machine at a private address such as192.168.x.x, answers you without your words ever leaving your network, so there is nothing for us to be given a copy of. Using your own API key with a provider like Anthropic or OpenAI is the other case — that request already crosses the internet to them, so the task text is logged unless you switch it off.
5. Third-party processors
| Processor | Purpose | What they receive |
|---|---|---|
| Supabase | Account, quota database, and the managed AI relay | Your account record; the request payload passes through the relay in transit |
| Free-tier AI provider(s) — may change over time | Upstream for the free managed tier | The request payload (screenshot + text). May be retained and used to train the model provider’s AI — see §2 |
| Paid AI provider endpoints — may change over time | Upstream for the paid managed tiers | The request payload. Not used for training under their current paid-API policies (subject to change by those providers) |
| Stripe | Payments | Your email and payment details — never your screenshots. Card data goes directly to Stripe (PCI); we never see card numbers. |
| Microsoft | Voice transcription (only if you enable push-to-talk) | Your spoken audio |
| GitHub | App downloads and updates | Standard request metadata when you download |
6. International data transfers
Our managed services run on infrastructure provided by Supabase and the upstream AI providers listed above. Your account record and the request payloads you send (a screenshot of your active window plus your text) may be transferred to and processed in the United States or other jurisdictions where these providers operate. By using the managed tier, you consent to this transfer. If you prefer that what is on your screen never leaves your machine, use a local provider — Ollama, or Custom (OpenAI-compatible) pointed at a local server. Your screenshots and requests then go nowhere: not to us, not to any AI provider.
7. Payments
Coin purchases are processed by Stripe. We receive a confirmation that a payment succeeded (to credit your balance) and store your Stripe customer id; we do not receive or store your card number. Stripe’s handling of your payment data is governed by Stripe’s Privacy Policy.
8. Retention & deletion
On Navisual’s servers, managed-tier requests pass through the relay in transit and are not retained after the response. Upstream AI providers, however, may retain them: the free tier’s models may keep your request and use it to train their AI (see §2), while the paid tier’s providers, under their current paid-API policies, state they do not use it for training (their policy, which they may change). Request records are deleted after 90 days. Anything you wrote on a feedback row — the task you typed and any note you added — is erased after 12 months, and the row itself is deleted after 24 — your own words have the shorter life of the two, because what is useful to us about an old row is the outcome, not the wording. Your account record and the remaining feedback rows persist until you ask us to delete them — deleting your account removes the account record, and detaches your id from any feedback or request records that remain, so what is left is no longer linked to you. The device row behind the free limit (§4) is keyed to a machine rather than an account, so it is not reached by account deletion; ask us (§11) if you want it cleared too. Local files live on your machine until you uninstall or delete them. To request deletion of your managed-tier account data, contact us (§11).
9. Your rights
Depending on where you live (e.g. GDPR in the EU/UK, CCPA in California), you may have the right to access, correct, or delete the data we hold about you, and to object to or restrict its processing. The free tier is anonymous, so we typically hold no information that identifies you until you make a purchase. Contact us to exercise any of these rights.
10. Children
Navisual is not directed to children under 13 (or the minimum age in your country), and we do not knowingly collect their data.
11. Contact
Questions or requests: support@navisualguide.com, or open an issue at github.com/NavisualGuide/navisual.
12. Changes
We’ll update this page when our practices change and revise the “last updated” date above.
See also our Terms of Service.