Privacy Policy
Last updated: August 15, 2026
1. Information We Collect
We collect information you provide directly to us when creating an account, updating your profile, or uploading assets. This includes your email address, username, display name, avatar, and social media handles.
2. Authentication & Third-Party Providers
We use Supabase Authentication for managing user sessions. If you log in via Google OAuth, Supabase receives your basic profile information (such as your email address, name, and profile image URL) as authorized by Google. 4nchor does not receive or store your Google password.
If you choose to connect or verify a YouTube channel through Google's authorization flow, 4nchor requests read-only YouTube access only for the user-facing channel verification feature. We may receive and store the YouTube channel ID, channel name, channel profile image, and profile URL needed to display and maintain the verified connection. The temporary Google access token used to perform the YouTube verification request is not stored in 4nchor's database after that connection process.
4nchor's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not sell Google user data, use Google user data for advertising, or use it for purposes unrelated to the user-facing feature for which access was granted.
3. How We Use Data
- To display creator attributions on uploaded scenepacks and presets.
- To enforce platform safety, account suspensions, and prevent abuse.
- To allow password recovery and important account notifications.
4. Data Protection & Security
We use technical and organizational safeguards designed to protect personal and sensitive information against unauthorized access, disclosure, alteration, or destruction. These safeguards include:
- HTTPS-encrypted connections for information transmitted between your browser and 4nchor.
- Supabase Authentication for account and session management rather than storing account passwords directly in the 4nchor application database.
- Server-side authentication, authorization, and access-control checks for protected account, moderation, and administrative operations.
- Secure, HTTP-only cookies where applicable for sensitive OAuth state and session-related information, reducing exposure to client-side scripts.
- OAuth state validation during supported third-party authorization flows to help prevent unauthorized or forged callbacks.
- Limiting Google and YouTube API access to the read-only permissions required for the requested feature and not persistently storing the temporary Google access token used for YouTube verification.
- Restricting administrative and moderation functionality to authorized accounts.
No method of electronic transmission or storage can be guaranteed to be completely secure. We review our safeguards as the Platform evolves and limit access to sensitive information to systems and authorized functions that need it to operate 4nchor.
5. Data Sharing
We do not sell personal information or Google user data. Information may be processed by service providers that help us operate 4nchor, including authentication, database, storage, hosting, and infrastructure providers, only as necessary to provide those services. We may also disclose information when required by law, to protect users or the Platform, or with your direction or consent.
6. Account Deletion & Data Retention
You may request account deletion at any time through Settings. We retain information only for as long as reasonably necessary to provide and secure 4nchor, comply with legal obligations, resolve disputes, and enforce our Terms. Account deletion removes or disassociates account information through the Platform's deletion process, subject to information we may need to retain for security, fraud prevention, legal compliance, dispute resolution, or enforcement.
