Privacy Policy – NinoClip
Last updated: 2026-08-15
Jalloft, a brand operated by an individual in Brazil, operates NinoClip: the Android application ("App"), the browser studio and the website at ninoclip.com. This Policy describes how we handle your personal data when you use any of them. We operate in compliance with Brazilian law, in particular the General Data Protection Law (LGPD), and we honour the equivalent rights granted to users in other countries.
By using NinoClip, you agree to this Policy and to our Terms of Use.
Jalloft is the controller of your data. For any matter related to this Policy, including exercising your rights, write to privacy@ninoclip.com — this is also the channel for our Data Protection Officer.
1. The starting point: drawing requires no account
NinoClip is a frame-by-frame animation editor that exists as an Android app and as a studio in your browser, at ninoclip.com. Creating projects, drawing, recording audio and exporting all work without an account. In that part, your drawings, audio and projects stay with you alone and are never sent to us:
- in the app, in your device's storage — and with no internet needed;
- in the browser studio, in the browser's own storage (IndexedDB). Once the page has loaded, drawing talks to no server at all.
This has a consequence you need to know: we hold no copy of your projects. If you clear the site's data, switch browsers or lose the device, we cannot recover them for you — not because we refuse, but because they were never here. Export the project file (`.nino`) for anything that matters.
An account is required only for the Community — publishing animations, liking, commenting and following other people. Almost everything described below refers to that optional part.
2. What data we collect
2.1. Account
Signing in to the Community is done through Firebase Authentication, in one of two ways, your choice:
- Google Sign-In. From your Google account we receive: email address, display name and profile picture.
- Email and password. You give us an email address, the name you want to use, and a password. The password is stored in encrypted form by Firebase Authentication: we never see it, never receive it, and cannot recover it — that is why changing your password happens through a link sent to your email, and not through us. That same link confirms the address is yours before the account counts in the community.
Your email is stored only in the authentication service, is never written to the App's public database and is never shown to other users. It appears only to you, on your own profile screen.
2.2. Public profile
- Username (@): chosen by you, it is how the community identifies you.
- Display name. Taken from your Google account, or the name you typed when creating the account. You can change it whenever you like.
- Profile picture. It can come from two places. If you signed in with Google, we reuse the address of the picture already there. And at any time you can upload a picture of your own, chosen from your gallery or taken on the spot: the app crops and shrinks the image on your device (512×512), and only that crop is uploaded — the original photo never leaves your phone. The file lives in Cloud Storage and your profile stores only its address. The profile picture is public: it shows to anyone who sees your posts and comments, including people without an account. Replacing it deletes the previous one; deleting your account deletes the picture.
- Bio: a short, optional text you write.
- Counters: number of posts, followers and people you follow.
2.3. Content you publish
When you publish an animation we upload and store: the exported video (MP4 or WebM, depending on what your browser records), a cover image, the title, description and tags you wrote, the visibility you chose (everyone, anyone with the link, or only you) and the permissions you set (allow download, allow remix).
If — and only if — you turn on "allow remix", we also upload the project file (frames, layers and audio) so that other people can open a copy of it in their own editor.
2.4. Community interactions
Likes, comments and replies, who you follow and who follows you, reports you submit, users you block, and the notifications generated by those activities.
2.5. Technical data
- Notification token (Firebase Cloud Messaging): stored in a private area of your profile so we can notify you about likes, comments, replies and new followers. Only you and our systems can access it.
- App verification (Firebase App Check): confirms that requests come from the genuine NinoClip and not from a program impersonating it. In the app this is done by Play Integrity. In the browser, by Google's reCAPTCHA Enterprise, which analyses signals from your browser and your behaviour on the page to tell a person from a bot — including when you are only reading the community, with no account. The data from that check is handled by Google under its own privacy policy; we receive only the result.
- Site usage counts (ours, not a third party's): we keep, in one document per DAY, how many times the studio was opened, a project was created, someone drew, exported, published and visited the community. They are six added-up numbers, with no identifier, no session and no cookie — there is no way back from one of those numbers to a person, not even for us. They tell us whether the product is being used; they feed no advertising and no profile of anyone.
- Website access logs: the hosting service (Firebase Hosting) keeps technical records of requests, such as IP address, date, page requested and browser, in order to operate and protect the service.
- Storage used: the total size in bytes of the media you have published, so we can apply the storage limit described in the Terms.
2.6. Usage statistics and crash reports
This section applies to the Android application. On the website and in the studio the measurement is a different one, it depends on your consent, and it is described in 2.10. Crashlytics does not exist on the web.
We use Firebase Analytics to understand how the App is used and Firebase Crashlytics to receive error reports.
Analytics records facts and measurements, never content or identity: that a project was created (with its format and frames per second), that an animation was exported (format, resolution, number of frames), that a post was published (chosen visibility, whether remix was allowed, whether it had tags), that someone signed in, liked, commented or followed. We do not send your project names, your comment text, your post titles or your account identifier.
Crashlytics automatically receives the technical data of a failure: device model, Android version, App version and the error stack. We also record there errors the App handled but that should not happen, such as a failed export.
Both services are Google's and use their own installation identifiers, which are not your email or your account.
2.7. Advertising
This section applies to the Android application. The browser studio and the website show no ads.
NinoClip shows Google AdMob ads to stay free. They appear: when you open the app, between community posts, on the home screen, when you open a project, on the export screen and when an export finishes. Every ad is labelled "Sponsored".
We do not hand your data to advertisers. Ads are served by Google, which may use device identifiers — in particular the Android advertising ID — to choose what to show and to measure results. You can limit or delete that identifier in your Android settings (Google → Ads).
Google's practices for advertising partners: <https://policies.google.com/technologies/partner-sites>.
If you are in the European Economic Area or the United Kingdom, the App will ask for your choice about personalised ads before showing them, as required by applicable rules.
2.8. Audio library
Sound searches in the library go through a server of ours, which queries the Freesound archive. We send the archive only the search term — never your identity, your account or the content of your project. The chosen sound is downloaded directly from the archive's public server.
2.10. Usage measurement on the website and the studio (with consent)
Nothing is measured before you say yes. On the first visit a question appears with two answers of equal weight, Accept and Decline. While it is unanswered — and forever, if the answer is Decline — Google Analytics is not even downloaded by the page: no cookie is written, no identifier is created, no request is made to it.
If you accept, we use Google Analytics (Firebase Analytics) to know how many people arrive, which pages they pass through, where they came from and which steps they took: that the studio was opened, that a project was created, that someone drew, exported, published or opened the community. The step's name goes and nothing else — not the format, not the size, not the title of what was made. It writes a cookie of its own and creates a BROWSER identifier — which is not your account, not your email, and not tied to your profile by us.
What does not go there: the content of your drawings, the names of your projects, the text you write, and your account identifier. The studio keeps projects on your own device, and none of that passes through the measurement.
Declining takes nothing away. The studio, the account, publishing and the community all work the same — the measurement is for us, not for you, and that is why it asks instead of announcing.
Changing your mind: the Cookies link, in the footer of any page, brings the question back. Declining after having accepted stops the measurement from that point on; to erase what was already collected, contact us through the channels in section 14.
The legal basis here is your consent (LGPD, art. 7, I), and not legitimate interest — measuring a product is not necessary for the page to work, so the page asks.
2.9. What we do NOT collect
To be explicit, because this matters in an app used by children:
- We do not sell or hand your data to advertisers. Advertising works as described in section 2.7, through Google.
- There are no in-app purchases — we neither receive nor process payment data.
- We do not collect your location, your contacts or your files. Camera and gallery access happens through the Android system picker and only reaches the image you pick.
- The microphone is used only while you record audio in the editor, at your initiative, and that recording stays on your device.
3. What other people can see
NinoClip has a social side. Anyone — including people without an account — can see: your username, display name, picture and bio; your animations published as "everyone"; your comments; and the counts of posts, followers and likes.
Animations set to "anyone with the link" do not appear in the feed but can be opened by whoever receives the address. Animations set to "only me" are visible only to you.
Never shown to other users: your email, your notification token, your block list and the storage you occupy.
4. Why we use your data
- To provide, operate and maintain the App and the Community;
- To create and maintain your account and public profile;
- To publish, display and distribute the animations you chose to make public;
- To send notifications about likes, comments, replies and new followers;
- To moderate the Community: filter comments, investigate reports, remove content and suspend accounts that break the Terms;
- To understand how the App is used and fix failures (section 2.6);
- To keep the App free through advertising (section 2.7);
- To apply the storage limit;
- To prevent fraud and abuse;
- To comply with legal obligations.
5. Where your data is stored
- Cloud Firestore (Google), São Paulo region, Brazil: profile, posts, comments, likes and other records.
- Cloud Storage (Google), United States: videos, covers, project packages and profile pictures.
- Cloud Functions (Google), São Paulo region, Brazil: moderation routines, counters and account deletion.
- Firebase Authentication (Google): account credentials and email.
- In your own browser, when you use the web studio: the projects, in IndexedDB, and your editor preferences. That data never leaves it — not to us, not to Google — until you choose to publish.
6. Who we share with
- With other users, exactly to the extent described in section 3.
- Google (Firebase / Google Cloud): hosting, authentication, database, storage and notifications.
- Postmark: an email delivery service, used in two situations. To alert our moderation team about reports — those emails contain the alert and a reference to the reported content, not the personal data of whoever reported it. And to deliver the messages you send through the site's contact and report forms — those carry what you wrote yourself, along with the email address you give us for a reply.
- Google AdMob: serves the ads and receives, from the device itself, the identifiers described in section 2.7.
- Firebase Analytics and Crashlytics (Google): usage statistics and crash reports, as described in section 2.6.
- Freesound: receives only the audio library search term, as described in section 2.8.
- Public authorities, solely upon a valid legal order.
We do not sell your personal data.
7. Our legal bases
- Performance of a contract — providing the App, your account and the Community.
- Consent — publishing content, writing a bio, sending notifications and recording audio. You may withdraw it at any time by not publishing, deleting what you published, turning notifications off in your system settings, or deleting your account.
- Legitimate interest — moderation, community safety, abuse prevention, protection of children and teenagers, fixing failures, and the advertising that keeps the App free.
- Legal obligation — where the law requires us to keep or disclose something.
8. Your rights
At any time you may:
- Confirm whether we process your data and access it;
- Correct incomplete, inaccurate or outdated data;
- Request anonymisation, blocking or deletion of unnecessary data;
- Request data portability;
- Request deletion of data processed on the basis of consent;
- Learn who we share your data with;
- Withdraw consent;
- Object to processing you consider unlawful.
Directly in the App you can also:
- Edit your profile (Profile → Edit profile): change your username and bio.
- Delete a post at any time — it leaves the Community for everyone, and the project on your device stays untouched.
- Delete your account (Profile → settings → Delete account) or through our self-service deletion page: this erases your posts, media, comments, likes, profile and sign-in account. Projects stored on your device are not touched.
- Manage notifications through your device settings.
To exercise any of these rights, write to privacy@ninoclip.com. We reply within 15 days.
9. How long we keep data
We keep your data while your account exists. When you delete the account, data is erased within 30 days, unless the law requires longer retention. Moderation records (for example, the history of an investigated report) may be kept in minimised form for as long as needed to prevent repeat offences and protect the community.
10. Security
Access to data is controlled by server-side rules, not by the app: each person can only write to what is theirs. Requests are verified by Firebase App Check, data is encrypted in transit and at rest, and moderation actions are logged. No system is absolutely secure.
If an incident occurs that may pose a relevant risk to you, we will notify you directly and take the appropriate measures.
11. Children and teenagers
You must be 13 or older to create a Community account — or the minimum age required by the law of your country, where it is higher. Creating animations and using the editor requires no account and no minimum age.
Because we know children use this kind of app, we apply specific protections:
- Comments pass through an automatic filter before appearing. Text that looks like contact information — links, website addresses, social handles, phone-number sequences or messaging app names — does not go live on its own: it is held for human review.
- The same check applies to profile name and bio, to prevent anyone using a profile as bait to move children into conversations outside the App.
- There are no private messages between users in NinoClip.
- Anyone can report a post or a comment, and reports reach moderation immediately.
- Advertising exists, but it does not build a profile of a child: the App does not use your account or content data to choose ads, and the "rewarded" format (the one that trades a prize for watching) does not exist here.
If you are a parent or guardian and find that we have collected data improperly, write to privacy@ninoclip.com and we will erase it.
12. International transfers
Your data may be processed in countries other than yours, particularly in the United States (Google Cloud, Google AdMob and Postmark). We select partners recognised for their commitment to data protection and offering adequate contractual safeguards for those transfers.
13. Changes to this Policy
We may update this Policy from time to time. Significant changes will be announced in the App. The "Last updated" date at the top indicates the current version.
14. Contact
Email: privacy@ninoclip.com