Draw2Life
How it worksPricingSupportStart free

← Draw2Life

Privacy Policy

Last updated: June 2026

Draw2Life is built for children’s drawings, so privacy is a design constraint, not fine print. This policy explains, plainly, what we do and do not collect.

Draft — not legal advice. This document was drafted by the Draw2Life team and has not been reviewed by a lawyer. It describes how the product is intended to work and is provided for transparency while we prepare for launch. It is not a substitute for professional legal advice and may change before and after general release.

The short version

  • No photos are ever uploaded. The camera frame is processed on the guest’s phone; only the flat, de-skewed drawing cutout leaves the device. There is no raw-photo storage to breach.
  • Guests have no accounts. Scanning is anonymous — no sign-in, no email, no name beyond an optional first name shown as a label.
  • Everything expires. Rooms expire, and cutouts and creature records are purged about a week after a room ends. Hosts can purge a room instantly.
  • We use a third-party analytics script, site-wide, to understand traffic and usage. We do not run advertising SDKs or sell personal information.

Who is responsible for your data

The controller responsible for the personal data described in this policy is [Company legal name and registered address to be added]. For any privacy question or request, the fastest path is email: support@draw2life.com.

No raw photos leave the phone

When a guest scans a drawing, the camera image is read and processed entirely in their phone’s browser. The app finds the printed corner markers, straightens the page, and cuts out just the colored artwork. Only that flat cutout image is sent to us — never a photo of the child, the room, or anything else in frame. We operate no raw-photo bucket, because the raw camera frame never leaves the device.

Guests are anonymous

Guests never create an account. When someone opens a room link to scan, a silent anonymous session is created so we can apply room permissions and rate limits — it carries no email and no personal profile. The only optional information a guest may add is a first name, shown as a label next to their creature. It is optional, is not linked to any account or other identifier, and a name that fails a profanity filter is rejected. Hosts running rooms for schools can leave the name field off entirely.

What we collect from hosts

To run host accounts and billing, we hold a small amount of data:

  • Account email — so you can log in and we can contact you about your rooms.
  • A Stripe customer identifier — so we can associate your purchases and subscription with your account. Stripe processes payments; we do not store your card details. Stripe handles your payment information under its own privacy policy.
  • Room and event data you create — room settings, plan and credit balances, moderation choices, and the drawings submitted to your rooms.

Drawings and the live display

To make the shared scene update in real time, each submitted drawing becomes a creature record and a cutout image stored with public read access under a random identifier. These are kids’ drawings of fish referenced by unguessable IDs, with no names attached to any account. This public-read design is what lets a display receive new creatures instantly over a live connection.

Everything expires

Data does not stick around. Every room has a lifetime; once it ends, its cutouts and creature records are automatically purged by our housekeeping process about seven days after the room expires. A host can also purge a room’s content instantly at any time. Host account and billing records are kept for as long as your account stays open, plus whatever additional time we are required to keep them for tax and accounting purposes; we have not yet finalized the specific retention period that applies after an account is closed — [specific host/billing data retention period to be added before launch].

Analytics, tracking, and advertising

We use Rybbit analytics, served from analytics.navcache.com, on every page of the site, including the guest-facing scan and display experiences, to measure traffic and usage. This analytics does not run advertising, and we do not sell personal information. We do not show ads.

Guest-facing pages (scanning and the live display) and host-facing pages (the marketing site, dashboard, and account pages) report to separate analytics properties. We may enable session recording and similar product-analytics features on host-facing pages only, to understand and improve the dashboard experience — guest-facing pages never receive session recording.

Children’s privacy

Draw2Life is designed so that we collect no personal information from children. Children participate only as anonymous guests: their phone processes the image locally, no account is created, and no email or contact details are collected. The single edge case is the optional first-name label, which is attached to no identifier; we keep it optional and recommend hosts turn it off for school rooms.

Hosts — parents, teachers, librarians, and venue staff — are the adults responsible for the events where children participate, as described in our Terms of Service. We intend this approach to align with children’s-privacy rules such as COPPA, and we will obtain a formal legal review before charging schools or marketing specifically to children.

Service providers

We rely on a small number of providers to run the service, including a backend platform for authentication, database, storage, and real-time messaging, and Stripe for payments. These providers process data on our behalf to deliver the service and are bound by their own terms and privacy policies.

Where your data is processed

Draw2Life is used globally — we have confirmed hosts and guests joining rooms from Australia, Korea, the Netherlands, Canada, the UK, and elsewhere. The product runs on a self-hosted Appwrite instance that we operate ourselves rather than Appwrite’s own cloud, and we have not yet documented which country or region that infrastructure runs in: [country/region where the Appwrite instance and its data are hosted to be added]. Stripe processes payment data under its own privacy policy and may process or store it in countries other than your own. Where we transfer personal data internationally, we intend to rely on appropriate safeguards (such as the EU Standard Contractual Clauses) once the hosting location above is finalized.

Legal basis for processing

If you are in the EU, UK, or EEA, the GDPR requires us to state the legal basis for each way we use personal data:

  • Performance of a contract — running your host account, provisioning rooms, and billing (the account email, Stripe customer identifier, and room/event data described in “What we collect from hosts” above) rely on this basis: we cannot provide the service you signed up for without them.
  • Legitimate interests — we rely on our legitimate interest in keeping the service safe and available for the anonymous, IP-based rate limiting applied to API requests (a short-lived, in-memory counter, not a stored profile — see our Terms of Service for how abuse is handled), and for the site-wide analytics described above, which helps us understand traffic and improve the product. You can object to processing based on legitimate interests; see “Your data protection rights” below.
  • Consent — the optional first-name label a guest may add to their creature is processed only because the guest (or the host running the room) chose to add it. Leaving it blank means nothing is collected, and hosts can disable the field entirely for a room.

Your data protection rights

Hosts can purge a room’s content at any time, and all room content expires automatically. Beyond that, if data protection law applies to you, you have the following rights over your personal data, to the extent applicable:

  • Access — ask for a copy of the personal data we hold about you.
  • Rectification — ask us to correct inaccurate or incomplete data.
  • Erasure — ask us to delete your data, subject to any legal or tax retention obligations described above.
  • Restriction — ask us to limit how we use your data while a request is being resolved.
  • Portability — ask for the data you provided us, in a structured, commonly used format, where technically feasible.
  • Objection — object to processing we base on legitimate interests, such as the rate limiting or analytics described above.

To exercise any of these, or for any other privacy request or question, email support@draw2life.com and we will respond. Because guests are anonymous and their content expires quickly, we generally cannot identify an individual guest’s submission, but a host can remove any drawing from their room at any time.

You can also complain to a supervisory authority. If you are in the EU, UK, or EEA, you have the right to lodge a complaint with your local data protection authority at any time — regardless of whether you have first contacted us, and regardless of how we resolve (or fail to resolve) your request.

Changes to this policy

We may update this policy as the product evolves. Material changes will be reflected in the “Last updated” date below.

Contact

Privacy questions or requests: support@draw2life.com.


Last updated: June 2026.

Draw2Life
How it worksPricingSupportTermsPrivacysupport@draw2life.com
Color it in. Scan it. Watch it swim.