nmancreative
Log in Get AutoVAT
AutoVAT Tutorials Download Pricing FAQ Documentation Log in

Privacy Policy

Effective date: August 1, 2026

Overview

AutoVAT is operated by NMAN CREATIVE LLC. This policy explains what information is collected when you use the AutoVAT website, account system, desktop application login, downloads, updates, support tools, and related services.

This policy is intended to describe current data practices in clear terms. It is not legal advice to users or customers.

Information We Collect

When you create or use an account, we collect your email address, display name, password hash if you use password login, email verification status, linked Google subject identifier, linked Discord user ID, newsletter preference, terms acceptance timestamp, account status flags, account timestamps, Stripe customer identifier if created, and last login time.

For email verification and password reset, we store hashed verification or reset tokens, expiration and usage timestamps, and, for password reset requests, the requesting IP address. Passwords are not stored in plain text.

For website sessions, we use server-side sessions and cookies needed to keep you logged in, protect forms, remember OAuth state, and display account messages.

For desktop application access, we store hashed desktop session tokens, token creation, expiration, last-seen and revocation timestamps, IP address, and user agent information used to validate login sessions. Desktop OAuth codes are also stored in hashed form with short expiration windows, IP address, and user agent information.

For trial usage and product analytics, AutoVAT stores bake event records such as account ID, whether the account was paid at the time, bake mode, bake count, aggregate batch job counts, material generation counts, export mode, client version, timestamp, and a private hashed IP bucket. The hashed IP bucket helps prevent repeated-account trial abuse without storing the raw IP address in bake event records.

For authenticated downloads, AutoVAT stores download start records with account ID, release ID, source, and timestamp. These records count when a valid download begins; they do not prove the file fully downloaded.

For purchases, AutoVAT stores Stripe customer identifiers, checkout session identifiers, payment intent identifiers, purchase status, amount, currency, and purchase timestamps. Payment card details are processed by Stripe and are not stored by AutoVAT.

For Fab purchase verification, AutoVAT may store the Fab order ID you submit, normalized order ID, submission timestamps, review status, administrator review metadata, and any related review action notes.

For bug reports and support tickets submitted from the desktop app, AutoVAT stores the ticket subject, message body, app version, ticket status, email notification preference, message history, timestamps, and administrator replies or status actions.

For newsletter and account email delivery, AutoVAT may store newsletter campaigns, recipient email addresses, delivery status, email type, queued message subject and body, attempt counts, error messages, lock tokens, and sent or failure timestamps.

For abuse prevention, we store signup attempt IP addresses and timestamps, password reset rate-limit IP addresses, hashed email addresses, and timestamps.

Google Sign-In

If you sign in with Google, Google provides account information such as your email address, email verification state, display name, and permanent Google subject identifier. AutoVAT uses the Google subject identifier to link and recognize your Google account.

Discord Sign-In

If you sign in with or link Discord, Discord provides information such as your Discord user ID, verified email address when available, username or global display name, and verification state. AutoVAT uses the Discord user ID to link and recognize your Discord account.

Desktop App Data

The AutoVAT desktop application sends account login data, session tokens, client version, license and trial-check requests, successful bake event summaries, update download requests, checkout requests, and bug ticket content to AutoVAT servers as needed for those features.

Your model files, VAT files, project files, exports, editor paths, engine paths, and other creative project content are processed locally by the desktop app unless you choose to include that content in a support ticket or use an external engine, project, or integration feature that writes to your local project or communicates with that external software.

The desktop app stores local preferences in vatbuilder-settings.json, including engine paths, project folders, output folders, UEFN bridge host, port, password, custom reference model path, viewport preferences, and related workflow settings. The desktop app also stores session and license metadata in the operating system's user preferences under the AutoVAT account area.

Site Analytics

AutoVAT records limited pageview analytics for public pages such as the homepage, documentation, tutorials, privacy policy, terms, and 404 page. These records may include the visited path, referrer host, a hashed IP address, broad user agent family, bot indicator, and timestamp. Account, API, billing, OAuth, dashboard, registration, and static asset paths are excluded from this pageview analytics tracker. AutoVAT also uses aggregate bake and download-start metrics to understand product usage, improve performance, plan releases, and administer trial limits.

Email

AutoVAT uses email to send verification messages, password reset links, account-related notices, purchase activation messages, support ticket replies, and newsletter messages if you opt in. Email delivery may be handled through Amazon SES or another email delivery provider.

How We Use Information

We use information to create and secure accounts, verify email addresses, process logins, link Google or Discord accounts, remember terms and newsletter preferences, enable desktop application access, validate license, trial, and update eligibility, provide downloads, process purchases, review Fab order claims, send account and newsletter emails, operate support tickets, prevent abuse, troubleshoot issues, maintain security, improve public site content, understand product performance, and administer the service.

Sharing

We do not sell your account information. Information may be processed by service providers needed to operate AutoVAT, including website hosting, MySQL database hosting, Google OAuth, Discord OAuth, Stripe payment processing, email delivery providers, and infrastructure or security providers.

We may disclose information when required by law, to protect AutoVAT, users, or the public, to investigate abuse or security issues, or in connection with a business transfer such as a merger, acquisition, or asset sale.

Retention

We keep information for as long as needed to provide accounts, downloads, licenses, updates, support, purchase records, security, fraud prevention, legal compliance, and business administration. Some records, such as purchase, tax, security, email, and support records, may be kept after account closure when reasonably necessary.

Security

AutoVAT uses password hashing, token hashing for server-side tokens, secure sessions, server-side validation, CSRF protection for web forms, and provider-side payment processing. No internet service can be guaranteed perfectly secure, so you should use a strong password and keep your Google, Discord, email, and desktop device accounts secure.

Your Choices

You may update your display name, change password settings where available, link Discord, manage newsletter preferences, or contact support for account updates or deletion. AutoVAT may verify, disable, delete, or modify accounts to operate and protect the service.

You can clear local desktop session information by signing out or clearing the desktop app's saved session. You can edit or remove local app settings by changing preferences or deleting the local settings file, though doing so may reset workflow configuration.

Children

AutoVAT is not intended for children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided personal information, contact us so we can review and remove it where appropriate.

Changes

We may update this policy from time to time. The effective date above shows when this version took effect. Continued use of AutoVAT after a policy update means the updated policy applies to your continued use.

Contact

Questions about this policy can be sent to help@nmancreative.com.

nmancreative
AutoVAT Download Pricing FAQ Documentation Account Contact Privacy Terms
Nman Creative LLC © 2026
Unreal, Unreal Engine, Unreal Editor for Fortnite (UEFN), and Fortnite are trademarks or registered trademarks of Epic Games, Inc. in the United States of America and elsewhere. Unity is a trademark or registered trademark of Unity Technologies or its affiliates in the U.S. and elsewhere. Godot and Godot Engine are trademarks of the Godot Foundation. AutoVAT is not sponsored by, affiliated with, or endorsed by Epic Games, Unity Technologies or its affiliates, or the Godot Foundation.