Skip to content
DRAWMINT · TRUST & TRANSPARENCY

Privacy Policy

How your account, creations and delivery details are handled.

Pre-launch review draftPrepared September 21, 2026Effective date: pending
This is a review draft, not the final published policy.

Our contact details, processing locations, retention schedule and regional privacy procedures still need to be finalized. This page does not certify legal compliance. Do not submit sensitive personal information to the preview.

ON THIS PAGE01 · Who we are02 · Information we process03 · Why we use it04 · Artwork & AI05 · Service providers06 · Cookies & storage07 · Retention & security08 · Your choices & rights09 · International processing10 · Children & families11 · Changes12 · Contact

1. Who we are and what this covers

Drawmint is operated by Connetcting Inc (“Drawmint,” “we,” “us”). For the activities described here, Connetcting Inc is the organization responsible for deciding how platform personal information is used, subject to the roles of independent service providers.

This draft covers the Drawmint website, Google sign-in, private creative studio, saved bundle preferences, shipping address book, reviewed community sharing and payment functions when enabled. It does not automatically cover a future hardware camera, companion app, child profile, animation service or music service. Those features will require appropriate notices before launch.

Registered business address and any required regional representative: to be confirmed before this policy takes effect.

2. Information we process

  • Account details: your Google account identifier, name and verified email address, plus the bundle preference you choose to save. We do not receive your Google password or access to Gmail or Drive through this sign-in.
  • Your creations: drawings you save or submit for polishing, titles, thumbnails, original and AI versions, favorites, trash status and related generation records such as mode, provider, model and time.
  • Community activity: selected artwork previews, public creator names, titles, descriptions, categories, AI-assistance labels, publication confirmations, review decisions, saved inspiration and reports. Published works share an opaque creator identifier so visitors can browse the same creator’s work. Account email addresses and private originals are not included in public gallery responses.
  • Delivery details: recipient name, international phone number, country or region, street address, apartment or unit, city, state or province and postal code, together with the time and notice version recorded when you save.
  • Transactions, when enabled: order and checkout identifiers, selected bundle, amount, currency, payment status, refunds and disputes. Card details entered in Stripe's hosted checkout are handled by Stripe; the current Drawmint application does not collect or store full card numbers or security codes.
  • Referrals, when used: an opaque referral identifier, the referring channel, attribution dates and order-linked commission records. A saved referral can be associated with your signed-in account.
  • Technical and support information: session identifiers, security and administrative events, request information needed to operate the service, and information you choose to include in a support request. Hosting and service providers may also process connection and device information under their own notices.

We receive information directly from you, from Google when you sign in, from Stripe when a payment status changes, and from our configured AI provider when it returns a result. Please do not upload identification documents, payment credentials, health records, precise location information or another person's private details into the drawing tools.

3. Why we use information

We use account and artwork information to provide sign-in, save and retrieve your work, perform the polishing you request and keep versions connected. Delivery information supports order preparation and, once connected, fulfillment. Transaction information supports payments, reconciliation, refunds, accounting and fraud prevention. Referral information supports channel attribution and commission administration.

Security data helps protect accounts, enforce usage limits, investigate abuse and resolve problems. We do not treat signing in, saving a bundle or entering an address as permission to send marketing emails.

Where European or UK data protection law applies, the intended legal grounds are performance of a contract or requested pre-contract steps for core services; legal obligations for required records; legitimate interests, subject to balancing your rights, for proportionate security and administration; and consent where required for optional tracking or marketing. Clicking an AI-processing checkbox is not blanket consent to unrelated processing. The final policy must confirm the applicable basis for each enabled activity.

4. Your artwork and AI processing

The current studio sends a selected drawing to MiniMax only when you confirm AI processing and request polishing. The request may include the image, the selected mode and processing instructions; the returned image and generation metadata are saved with your account. Saving a drawing alone does not request AI polishing.

Private studio work is not automatically published in a community or used in a public backer card. Community submission requires separate, explicit publication confirmation and administrator approval. The public gallery displays a resized, watermarked preview and the information you select for publication. Viewers may still copy or screenshot a preview; a watermark cannot prevent this. Shipping addresses are not included in the artwork-generation request. Our current application does not operate a model-training pipeline using your private artwork, and this draft does not grant a general advertising or training license.

We cannot promise zero retention or no training by an external provider without confirming the applicable service agreement. Provider retention, training settings, subcontractors and processing region must be verified before public AI processing is enabled. Avoid submitting confidential or sensitive material.

5. Who may receive information

Information is shared only as relevant to the function being used: Google for authentication, MiniMax for requested AI processing, Stripe for checkout and payment administration, and the hosting, database or infrastructure providers needed to operate the service. Authorized personnel may access relevant records for support, security or administration; “private artwork” means it is not publicly accessible, not that operational access is impossible.

When physical fulfillment or transactional card email is launched, the necessary delivery or email information may be supplied to the relevant delivery or email provider. Those providers and arrangements are not yet finalized. Referral and payout operations use order, channel and payment records; they do not require publishing your address on a card or in a community.

We may disclose information when legally required, to address fraud or threats, or in a business transfer with appropriate notice and safeguards. The current application has no personal-data sale feature or advertising audience export. This is not a blanket finding about every vendor's practices; applicable sale, sharing and targeted-advertising obligations must be assessed before launch.

6. Cookies and browser storage

Drawmint uses a sign-in session cookie. In the current implementation, an unauthenticated sign-in session expires after about 10 minutes and an authenticated session after about 7 days. Signing out invalidates that session. These are session validity periods, not a promise that every related record is erased at exactly that time.

Browser-local storage remembers concept inspiration on older site views; signed-in community favorites are stored with your account in the database. Checkout session storage can retain a request identifier to avoid repeated checkout creation. These are not a cloud artwork library. You can remove local preferences using your browser's controls, although removing cookies can sign you out.

Visiting an active referral link can set a 30-day attribution cookie and associate the referring channel with a later account or order. Referral attribution is separate from essential sign-in. The current application does not include advertising pixels or audience analytics, but Google sign-in and Stripe checkout have their own storage and privacy behavior.

Launch requirement: complete the cookie inventory and any required regional opt-in, withdrawal and browser privacy-signal handling before using optional attribution where consent is required. A privacy-policy link is not a substitute for those controls.

7. Retention and security

Account and saved artwork records currently remain in the database until an authorized deletion process is carried out. Moving an artwork to Trash hides it from the active library and allows restoration; it is not permanent erasure. Withdrawing a community submission hides it from public gallery access but retains the submission and review records. Trashing its source also withdraws it; restoring the source does not republish it. Copies already made by viewers cannot be recalled. Updating your address replaces the current address-book entry. Separate order, security or backup records may require separate handling.

The intended retention approach is to keep data only as needed for the service, support, security or legal recordkeeping, then delete or de-identify it. Specific periods for accounts, artwork, abandoned checkouts, transaction records, logs and backups have not yet been finalized. There is no general automatic deletion schedule to promise in this draft.

The application uses authenticated ownership checks for private artwork and addresses, protected session cookies and controlled administrator access. Production hosting, encryption, backup security and incident-response arrangements must be verified before launch. No system can guarantee absolute security.

8. Your choices and privacy rights

You can choose not to sign in, avoid AI polishing, edit your saved address, remove a saved bundle preference, download artwork or clear local browser preferences. There is currently no self-service permanent account-deletion control. The privacy request channel below must be configured before public collection begins.

Depending on your location and applicable law, you may request access, correction, deletion, restriction or portability of your data, object to certain uses, and withdraw consent without affecting prior lawful processing. Some records may be retained where legally required. We may need proportionate identity verification and will apply the relevant response deadlines. You may also complain to your competent data protection authority.

California residents may have rights to know, delete or correct personal information, opt out of sale or sharing, limit certain sensitive-information uses, and receive non-discriminatory treatment, where the relevant law applies. Authorized-agent requests and other US state rights will be handled as required. Applicability, request channels and signal handling must be confirmed before launch.

9. International processing

Our providers may process information outside your country. The selected AI region and actual hosting, database, support and payment arrangements determine the locations involved. Selecting a provider's “global” region does not itself establish where data is stored or which transfer safeguards apply.

Before international launch, confirm provider entities, processing countries, contractual arrangements and any required transfer mechanisms. This draft does not claim that standard contractual clauses, an adequacy decision or any other mechanism has already been put in place.

10. Children and family use

The current account and crowdfunding experience is intended for adults aged 18 or older, or the higher age of majority where they live. Child accounts, verified parental consent and parent-managed profiles are not currently available. Adults should not submit a child's identifying information or recognizable likeness through the preview.

A product's family-friendly positioning does not replace children's privacy safeguards. Before a child-facing service or device feature is introduced, we must assess age assurance, parental consent, data minimization and the notices required for that experience. Any suspected collection of children's personal information should be raised through the privacy contact once configured.

11. Changes to this policy

The final policy will state its effective date. Material changes to purposes, providers or privacy choices will be explained through appropriate notice, with renewed consent where required. Planned animation, music or commercial licensing will not silently expand the uses of existing private artwork.

12. Contact and requests

Connetcting Inc · Drawmint

Privacy and support email: not configured yet
Postal contact address: to be confirmed

This preview does not submit a privacy request. A working request channel must be provided before this policy takes effect.

Read the Terms of Service →