Privacy Policy
Last Updated: June 4, 2026
1. Introduction
Welcome to Isometic. We are committed to protecting your privacy and ensuring you have a positive experience when using our isometric illustration maker tool and website.
This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website, register an account, and use our canvas-based drawing application. By using our services, you consent to the data practices described in this policy.
2. Information We Collect
We collect only the information necessary to provide and improve our services. The types of information we collect include:
- Account Information: When you register or log in, we collect your email address, name, and a securely hashed version of your password. If you sign in via Google OAuth, we receive your email address, display name, and profile image from Google.
- Session Data: We use session cookies to maintain your authentication state and keep you signed in across page visits.
What we do NOT collect: Your illustrations, drawings, canvas data, and custom shapes are processed and stored entirely in your browser and are never sent to our servers. We do not log your drawing activities, canvas settings, or usage patterns. We do not collect device information, browser details, screen resolution, or operating system data.
3. How We Use Information
We use the information we collect for the following specific purposes:
- Account Management: To create and maintain your account, authenticate your identity, and provide access to the editor features.
- Security: To verify user sessions on protected API endpoints and prevent unauthorized access.
- Communication: To send account-related emails such as password reset links and security notifications. We do not send marketing emails.
- Support: To respond to your inquiries and provide technical or billing assistance when requested.
4. Data Storage & Security
Your account data is stored securely using Neon serverless PostgreSQL. We implement technical and administrative security measures, including:
- Encryption of data in transit using HTTPS/TLS.
- Parameterized database queries to prevent SQL injection.
- Session verification on all sensitive API endpoints.
- Passwords are securely hashed using industry-standard algorithms (handled by Better Auth).
Data Retention: We retain your account information for as long as your account is active. When you delete your account, we will remove your personal data from our active systems. Some data may persist in backups for a limited period for disaster recovery purposes.
Please remember that no method of transmission over the Internet, or method of electronic storage, is 100% secure. While we strive to use commercially acceptable means to protect your personal information, we cannot guarantee its absolute security.
5. Third-Party Services
We use the following third-party services that may process limited data on our behalf:
- Google OAuth:If you choose to sign in with Google, Google provides us with your email address, display name, and profile image according to their privacy policy. You can review Google's privacy policy at policies.google.com/privacy.
- Neon (PostgreSQL):Our database is hosted on Neon's serverless PostgreSQL platform. Data is stored in encrypted databases with access restricted to our application servers.
We do not sell, rent, or share your personal information with third parties for their marketing purposes.
6. Your Rights & Choices
You have several choices regarding the management of your personal data:
- Access: You can view your account information by signing in to your account.
- Export: You can export your illustrations as PNG, JPEG, or SVG files directly from the editor at any time. These exports are generated entirely in your browser.
- Deletion: You can request deletion of your account and associated data by contacting us at the email address below.
- Withdraw Consent: You may stop using our services at any time. You can sign out of your account to end your session.
For EU/EEA residents (GDPR): You have additional rights under the General Data Protection Regulation, including the right to rectification, data portability, and the right to lodge a complaint with a supervisory authority.
For California residents (CCPA): We do not sell personal information. You have the right to know what personal information we collect, request deletion, and opt out of any sale of personal information (which we do not engage in).
7. Children's Privacy
Our services are not intended for individuals under the age of 13 (or the applicable age of digital consent in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will promptly delete it.
9. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last Updated" date at the top of this page. We encourage you to review this policy periodically. Continued use of our services after changes are posted constitutes your acceptance of the updated policy.
10. Contact Us
If you have any questions, comments, or concerns regarding this Privacy Policy or our data practices, please reach out to us at:
Email: vermamridul@outlook.com