Version 2026-10-10.2
Privacy
Effective 2026-10-10. What Vynook stores, who can receive it, and how to ask about your information.
Status of this notice
Draft version 2026-10-10.2, effective 2026-10-10. This page describes how the product works today. It is not a certification of legal compliance.
Who operates Vynook
Needs review before launch
The legal name, postal address, and privacy contact for the operator are not recorded in the product yet. Do not treat a personal email or a social login as that legal identity.
Until those details are confirmed, privacy requests can be sent from Dashboard → Privacy while you are signed in. That records a request. It does not by itself prove a statutory response deadline.
Accounts
Firebase Authentication stores the email, sign-in provider, account id, and whether the email is verified. A password, if you set one, is held by Firebase and is not stored in Vynook's world documents.
The private user record stores the email, whether onboarding finished, and, when you accept them, the Terms version and time. An older stored version is not rewritten when this draft changes. The public creator profile stores the display name, username, bio, and links you choose to publish.
Resend sends transactional mail, such as verification guidance and operator notices, from the verified vynook.com domain. There is no marketing list. Receiving on that domain is off.
Worlds, content, and files
Firestore stores world drafts, published snapshots, content items, and image metadata. Image bytes go to a private Azure Blob container. Visitors see a published world through Vynook, not by browsing that container directly.
A published world, its text, and its images are meant to be seen by anyone with the link. Share cards can include a title and a cover image.
Billing
Stripe can process the Creator subscription in test mode. Live charges stay off until the server commercial gate is approved. A live API key, a success URL, or a client-supplied price does not turn billing on. Vynook stores the plan, status, price, and Stripe customer and subscription ids. Vynook does not store a card number.
Creator checkout is separate from a product, booking, or newsletter link inside a world. Those links go to a site the creator chose. Vynook does not take that payment.
Analytics
Optional PostHog measurement is off until you accept analytics in this browser. Events can include a world id, object id, device class, referrer host, and a coarse campaign label. They are not a record of a completed purchase.
Global Privacy Control and a Do Not Track signal keep analytics off until you make an explicit choice. Rejecting analytics does not sign you out.
Server logs for image upload can be sent to PostHog as operational logs. Those are not visitor pageviews.
Embeds and links
YouTube and Cal.com stay unloaded until you allow optional embeds, or you can open the creator's link in a new tab instead. A thumbnail is not requested from YouTube before that choice.
There is no Vynook marketing pixel. Affiliate, sponsored, and paid-partnership labels are disclosures on creator content, not a Vynook ad network.
Retention, security, and rights
Needs review before launch
Worlds and files stay until you delete them or an administrator finishes a deletion request. Stripe billing records are not erased by the in-product deletion request, because financial records may need to be kept. A sealed Firestore backup can still contain an account after the live documents are removed. Azure blob soft delete is off, and no backup retention period is set, so deletion is not immediate permanent erasure.
Access is limited by Firebase rules, signed upload links, and server checks. That is not a promise that a breach is impossible.
Which privacy rights apply depends on where the operator and the person are. That legal analysis is not finished. The Privacy screen can download your account export or start a deletion request.
Children
Needs review before launch
Vynook is not directed to children. Signup asks you to confirm you are old enough to agree where you live. The product does not collect a birth date or a government id, and that confirmation is not an age-assurance system.
Whether COPPA or another child-privacy rule applies still needs a decision before the product is offered to minors.