Privacy Policy
Effective January 1, 2025 | Last revised September 24, 2026 (connected AI assistants disclosed · in force on posting) | Previous revision September 6, 2026 (in force September 13, 2026)
Fairrium (“GenToon”, “we”, “us”, or “the Company”) provides the GenToon service (the “Service”) and is the controller of personal data processed through it. This Privacy Policy explains what personal data we collect, why and on what legal basis we process it, who we share it with, how long we keep it, how we transfer it internationally, and the rights you have over your data.
For users in the European Economic Area (EEA), the United Kingdom, and Switzerland, we process personal data in accordance with the EU General Data Protection Regulation (GDPR) and the UK GDPR. For users in California and other U.S. states with applicable privacy laws, the disclosures in the “Your U.S. State Privacy Rights” section apply. Country-specific provisions required under Korean law apply only to users in the Republic of Korea and are set out separately below. If you have any question about this Policy or wish to exercise your rights, contact us at service@gentoon.ai.
1. Categories of Personal Information Collected and Methods of Collection
A. Categories Collected
| Category | Required | Optional |
|---|---|---|
| Sign-up | Email address, name (as provided by Google, Apple or Kakao for social login) | Profile image, community nickname and bio |
| Payment | Card brand, last four digits of the card number, the payment identifier issued by the payment provider (for Korean recurring payments via Toss Payments, the card expiry date and billing key are stored in encrypted form) | Tax receipt details (mobile number, business registration number, company name, representative name) |
| Service usage (collected automatically) | IP address and the approximate location inferred from it (country and city), access logs, service usage records, device information (User-Agent, device model, operating system, app version), a device fingerprint (stored only as a one-way hash; the original is not retained) | — |
| Creation and community | — | Generated content, uploaded reference images, posts and comments |
| AI chat and messages | — | Conversations with AI characters and direct messages between users (retention periods in Section 15) |
| Mobile app | Push notification token, device model, operating system, app version | — |
| Affiliate partner settlement | Legal name, mobile number, settlement bank account details, business registration number — for individuals without a business registration, the resident registration number, solely to file withholding tax and payment statements as required by Article 193 of the Enforcement Decree of the Korean Income Tax Act (stored encrypted) | — |
| Business production enquiries | Contact name, company name, phone number, email address, enquiry details | — |
| Social account connection and publishing | — | Identifier, handle, display name and profile picture URL of the connected social account; the access token issued by the platform (stored encrypted); publishing records (post identifier, publication time, caption, image URLs); performance metrics of the published posts (views, likes, comments, shares, saves, reach) |
| Connected AI assistants (MCP connector) | — | The connected app's name, identifier and return address; the permissions you granted (view, create, publish); when the connection was made, last used and revoked; authorization codes, access tokens and refresh tokens (stored only as one-way hashes); the connector's own sign-in session (stored encrypted); what the AI assistant sent to GenToon (story topic, title, dialogue, edit instructions, character names and appearance descriptions, and any photo or public image address you chose to send); tool-call records for troubleshooting (Section 20) |
| Customer support | Email address, enquiry content | Attachments |
We do not collect sensitive information such as beliefs, health or sex life. The resident registration number, a unique identifier under Korean law, is collected only for the affiliate settlement purpose above, only where the law requires it, and only with separate consent.
B. Methods of Collection
- Direct input during sign-up and use of the website and mobile app
- Social login via Google, Apple or Kakao OAuth
- Account details supplied by the platform (Meta, TikTok) when you connect a social account
- What an AI assistant (such as ChatGPT or Claude) sends when you connect GenToon to it and use GenToon features there
- Automatic collection during payment through Polar, Toss Payments or app store in-app purchase
- Automatic generation and collection through cookies, local storage and access logs during service use
- Automatic transmission by the analytics SDKs installed in the web and mobile app (Sections 9 and 17)
- Collection during enquiries made by email, the Help page or the business enquiry form
2. Purposes of Processing Personal Information
- Member management. Identity verification, prevention of unauthorized use, complaint resolution, and delivery of notices
- Service provision. AI image and script generation, project storage, character management, and community operation
- Connected AI assistants. Carrying out what you ask for in an AI assistant you connected (setting up, writing, drawing, viewing, exporting, sharing and publishing webtoons), managing the connection and preventing misuse
- Payment and billing. Subscription payments, credit purchases, refunds, and issuance of tax receipts and invoices
- Service improvement. Usage statistics and product-usage analysis (Google Analytics, Microsoft Clarity, PostHog), error detection (Sentry), and service quality enhancement
- Affiliate partner settlement. Paying referral earnings and filing withholding tax and payment statements
- Business production enquiries. Receiving and answering enquiries, concluding and performing contracts
- Marketing (optional). Event and benefit notifications (only with prior consent)
Legal Bases for Processing (EEA / UK Users)
Where the GDPR or UK GDPR applies, we rely on the following legal bases:
- Performance of a contract (Art. 6(1)(b)). To create and maintain your account, provide AI generation, project storage, character management, the community, and to process payments, subscriptions, credit purchases, and refunds. Without this data we cannot provide the Service.
- Legitimate interests (Art. 6(1)(f)). To secure the Service against fraud and abuse, detect and fix errors, maintain access and audit logs, analyse aggregate usage to improve the Service, and to enforce our Terms. We balance these interests against your rights and you may object as described in the “Your Rights” section.
- Consent (Art. 6(1)(a)). For optional marketing communications, which you opt into separately, and for connecting an AI assistant to GenToon (Section 20), which you allow on GenToon's own connection page. You may withdraw consent at any time without affecting prior processing — for a connected AI assistant, by disconnecting it in Settings › Connected apps.
- Legal obligation (Art. 6(1)(c)). To retain transaction and tax records and to respond to lawful requests, where mandatory law requires it.
Analytics cookies and identifiers — current status
We want to be straightforward about this rather than claim more than we do. Our analytics tools (Google Analytics, Microsoft Clarity, PostHog) load for every visitor as soon as a page loads. We do not currently show a consent banner before they load, and we do not currently detect or act on the Global Privacy Control (GPC) or Do Not Track signals a browser may send. We therefore do not claim that you consented to this processing.
If you are in a jurisdiction where consent is required for non-essential analytics cookies and identifiers, or you simply want this to stop, email service@gentoon.ai and we will delete the analytics data linked to your account and act to stop further collection about you. We are reviewing this area, and we will amend this Policy once a consent mechanism and signal-based opt-out are in place.
We do not use your prompts, uploaded reference images, or generated outputs to train AI models. Our AI processors (Google Gemini, Alibaba Model Studio, OpenAI) do not use data sent through paid API calls to train their models, and we do not build a training dataset of our own.
Some decisions in the Service are made automatically, without a human reviewing them individually: whether a referral reward is granted, whether chat access is temporarily suspended after repeated safety-filter violations, and whether a generation request is blocked by our content-safety filter. These are rule-based checks; they do not use profiling models trained on your data. If a decision affects you, you may ask us to explain it, object to it, or have it reviewed by a person, by emailing service@gentoon.ai. We will respond within 15 days for an explanation and within 30 days for a human review.
3. Retention and Use Periods
The Company destroys personal information without delay once the purpose of processing has been fulfilled. However, where retention is required by applicable law, the information shall be securely stored for the prescribed period before destruction.
| Data | Retention Period | Legal Basis |
|---|---|---|
| Member information | Until account deletion | User consent |
| Contract and payment records | 5 years | Contract and applicable tax/accounting law (varies by jurisdiction) |
| Consumer complaint and dispute resolution records | 3 years | Contract and applicable tax/accounting law (varies by jurisdiction) |
| Access logs | 3 months | Applicable telecommunications / records-retention law |
| Tax receipt and invoice issuance records | 5 years | Applicable tax law |
| Affiliate payment statements and withholding tax records | 5 years | Applicable tax law |
| Records of advertising and marketing claims | 6 months | Korean e-commerce law |
| Service activity records (including access IP and device information) | 1 year | Applicable telecommunications law (see Section 15) |
| Connection records for AI assistants (connected app, permissions, when connected, last used and revoked) | 30 days after you disconnect or delete your account (a connection older than 24 hours with no valid token left is disconnected automatically) | Consent |
| The connector's own sign-in session (encrypted) | Destroyed immediately when the connection ends (including when you disconnect, automatic disconnection because no valid token is left or the sign-in session can no longer be renewed, and account deletion) | Consent |
| Connector authorization codes, access tokens and refresh tokens (hashes) | 7 days after they expire, or when the connection record is destroyed, whichever comes first (validity: authorization code 10 minutes, access token 1 hour, refresh token 90 days; all invalid immediately on disconnect) | Consent |
| Connector tool-call records (without what you asked for; Section 20(2)) | Deleted automatically when the operating-log retention period of our hosting provider (Vercel Inc.) ends (at most 30 days) | Consent; legitimate interests (troubleshooting) |
| Photos sent through the connector but never used to create a character or art style | Deleted by the daily clean-up run once 24 hours have passed since upload (the upload link itself is valid for 10 minutes) | Consent |
Where mandatory local law imposes a specific minimum retention period, we keep the relevant records for that period and no longer. Korea-specific statutory retention periods are set out in the Korean-language Policy for users in the Republic of Korea.
Projects, characters and art styles you create through a connected AI assistant are kept and deleted exactly like those you create on the web (“Member information” and the trash rules), and audit records of connecting and disconnecting (the app name and the permissions you granted) are part of the “Service activity records” above and are kept for 1 year. Security records created when reuse of an authorization code or token is detected and the related tokens are revoked (the app name and the number of tokens revoked) are kept to deal with misuse and are excluded from that 1-year deletion.
4. Provision of Personal Information to Third Parties
The Company does not provide personal information to third parties without the user's consent. However, the minimum necessary information is shared with the following parties for the purpose of providing the Service.
| Recipient | Purpose | Data Provided | Retention |
|---|---|---|---|
| Polar (Global) | Global subscription / credit payment processing and refunds | Payment information, purchase amount | 5 years after transaction completion |
| Polar Software Inc. (merchant of record) | Processes global subscription and credit-pack payments, refunds, and tax handling | Payment information, purchase amount | 5 years after transaction completion |
| Google LLC | Social login, AI image and text generation (Gemini API) | Email and profile (for login); generation prompts and reference images (for AI generation) | Until termination of service use |
| Alibaba Cloud (Model Studio) | AI character chat response generation | Chat conversation content, character settings | Until termination of service use |
| OpenAI, L.L.C. | AI image and text generation (studio assistant chat, scenario and dialogue writing), harmful-content moderation | Generation prompts and reference images; studio assistant chat content, including requests sent through a connected AI assistant; chat content (for moderation) | Until termination of service use |
| Kakao Corp. | Social login | Email, nickname, profile image (as provided by Kakao OAuth) | Until termination of service use |
| Meta Platforms, Inc. Threads, Instagram | Creating and scheduling posts on your behalf on the account you connected, and reading the performance metrics of those posts (views, likes, comments, shares and similar) | Social account identifier, handle, display name and profile image URL; access token; the images, video and text to be published | Access token destroyed immediately on disconnect; other items destroyed when you delete your account |
| TikTok Pte. Ltd. TikTok | Creating and scheduling posts on your behalf on the account you connected | Social account identifier, handle, display name and profile image URL; access token; the images and text to be published | Access token destroyed immediately on disconnect; other items destroyed when you delete your account |
| The provider of the AI assistant you connected GenToon to For example OpenAI, L.L.C. (ChatGPT, Codex); Anthropic, PBC (Claude, Claude Code); Anysphere, Inc. (Cursor); or any other AI assistant you connect yourself | Showing you the results of the webtoon creation, viewing and sharing you ask for in that AI assistant | Nickname; plan; credit balances (monthly, purchased, gifted), monthly usage and renewal date; credits per cut; whether outputs carry a watermark and the custom watermark image address; language setting / your saved characters' names, appearance descriptions and image addresses / art-style names and the addresses of style pictures you saved / each project's title, story topic, status, visibility and language, each cut's scene text and dialogue, cut and combined-image addresses, editor, share and community post addresses, last edited and published times / job progress and credits used or returned / identifiers of your projects, characters, art styles and jobs; when each character was created; how many characters and art styles you have saved and your limits / production settings (number of cuts, quality, aspect ratio, layout, the characters and art style chosen, and the art style's reference image address), the size of the combined image, the community board and whether it was your first post / a one-time photo upload link (valid for 10 minutes) and its upload identifier | Under the recipient's privacy policy and the chat-history settings you chose in that service |
Personal information may also be disclosed where required by law, such as upon presentation of a warrant by investigative authorities.
Sharing with Meta Platforms, Inc. and TikTok Pte. Ltd. happens only if you connect the corresponding social account, and we ask for separate consent that is not bundled with sign-up. You can use every other part of the Service without giving it, and you can withdraw it at any time from the connection screen.
Information is shared with an AI assistant provider only if you connect GenToon to that assistant yourself, and only after you review the permissions that assistant requests on GenToon's own connection page and allow them. What is shared is limited to the results of the GenToon features you run in that assistant; your email address, password and payment details are never shared. How that assistant stores and uses the information is governed by its provider's policy, which the Company does not control. You can use every other part of the Service without connecting, and you can disconnect at any time in Settings › Connected apps to stop any further sharing (Section 20).
5. Entrustment of Personal Information Processing
We entrust the processing of personal information to the following processors in order to operate the Service. Each processor acts only on our instructions and only within the scope of the entrusted work; this is distinct from the disclosures to third parties described in Section 4.
| Processor | Entrusted work |
|---|---|
| Supabase Inc. | Database hosting, user authentication, file storage |
| Vercel Inc. | Web application hosting and CDN |
| Cloudflare, Inc. | Storage and delivery of generated images and uploaded files |
| Amazon Web Services, Inc. | Operation of the AI generation servers (Seoul region, Republic of Korea) |
| Google Cloud (Gemini API) | AI image and text generation |
| OpenAI, L.L.C. | AI image and text generation (studio assistant chat, scenario and dialogue writing), harmful-content filtering |
| Alibaba Cloud (Model Studio) | AI character chat response generation |
| Upstash Inc. | Distributed caching and rate limiting (Redis) |
| Functional Software, Inc. (Sentry) | Error and crash monitoring |
| Resend Inc. | Email delivery |
| 650 Industries, Inc. (Expo) | Mobile push notification relay |
| Google LLC (Firebase Cloud Messaging) | Android push notification delivery |
| Apple Inc. (APNs) | iOS push notification delivery |
| RevenueCat, Inc. | In-app purchase receipt validation and subscription status |
| Discord, Inc. | Customer enquiry notification routing |
| Google LLC (Google Analytics / GA4) | Website usage statistics |
| Microsoft Corporation (Clarity) | Behavioural analytics (heatmaps, session replay) |
| PostHog, Inc. | Product usage analytics for web and mobile (funnels, retention) |
International Data Transfers
We transfer personal information outside the Republic of Korea to the extent necessary to provide the Service. Under Article 28-8(1)3 of the Korean Personal Information Protection Act these transfers are entrustment and storage necessary to perform our contract with you and to improve your experience, and we disclose the details below as that Article requires. Our own AI generation servers run in the Seoul region of the Republic of Korea and are therefore not an overseas transfer, and Korean card payments (Toss Payments) are processed domestically.
| Recipient · contact | Country | Data transferred | Purpose | Retention | When and how |
|---|---|---|---|---|---|
| Supabase Inc. privacy@supabase.io | Republic of Korea (stored in the AWS Seoul region); United States (accessed for operations and support) | Account details, project data, uploaded files | Database, authentication and file storage | Erased within 30 days of account deletion, except records subject to statutory retention | Transmitted over the network as you use the Service |
| Vercel Inc. privacy@vercel.com | United States (global edge) | Access logs, IP address, operating logs (including connector tool-call records) | Web hosting and content delivery | Until the purpose of the entrustment is fulfilled | Transmitted automatically as you use the Service |
| Cloudflare, Inc. privacyquestions@cloudflare.com | United States (global network; storage location assigned automatically) | Generated images, uploaded reference images and attachments | File storage and delivery | Erased within 30 days of account deletion | Transmitted on upload and retrieval |
| Polar Software Inc. privacy@polar.sh | United States (may be stored in the United States, Canada or other destinations) | Payment details, purchase amount, email address | Global subscription and credit payment processing and refunds | 5 years after the transaction | Transmitted at checkout |
| Google LLC (Gemini API) support.google.com/policies | United States | Prompts, reference images | AI image and text generation | Erased after processing; not used for model training | Transmitted on each API call |
| OpenAI, L.L.C. privacy@openai.com | United States | Prompts, reference images, studio assistant chat content (including requests sent through a connected AI assistant), chat content (when filtering) | AI image and text generation (studio assistant chat, scenario and dialogue writing) and harmful-content filtering | Erased after processing; not used for model training | Transmitted on each API call |
| Alibaba Cloud (Model Studio) alibabacloud.com/help | Japan (Tokyo region) | Chat content, character settings | AI character chat response generation | Erased after processing; not used for model training | Transmitted on each API call |
| Google LLC (Google Analytics / GA4) support.google.com/analytics | United States | Cookie-based device identifier (_ga), pages visited and referral source, device, browser and language, IP address and inferred region | Website usage statistics and service improvement | Up to 14 months | Sent automatically by the website tag (gtag.js) |
| Microsoft Corporation (Clarity) privacy.microsoft.com | United States | Interaction recordings (session replay) and heatmaps, pages visited, device and browser details, IP address and inferred region | Behavioural analytics for service improvement | Up to 1 year | Sent automatically by the website tag |
| PostHog, Inc. privacy@posthog.com | European Union (Frankfurt, Germany region) | User identifier, product usage events, acquisition attributes, device and OS details, IP address and inferred country, email address (on web sign-in) — full list in Section 17 | Product usage analytics (funnels, retention) | Up to 7 years (see Section 17) | Sent automatically by the SDK |
| Functional Software, Inc. (Sentry) privacy@sentry.io | United States | Error message and stack trace, app version, device model, OS version (no user identifier or contact details) | Error and crash diagnostics | Per the processor's retention policy | Sent automatically by the SDK |
| Resend Inc. privacy@resend.com | United States | Email address, subject and body of sent email | Email delivery | Per the delivery-log retention period | Transmitted on each API call |
| Upstash Inc. support@upstash.com | United States | User ID or IP address (hashed) | Distributed caching and rate limiting | Up to 30 days | Transmitted on each API call |
| 650 Industries, Inc. (Expo) privacy@expo.dev | United States | Push notification token, notification title and body | Mobile push notification relay | Erased immediately after delivery | Transmitted when a notification is sent |
| Google LLC (Firebase Cloud Messaging) support.google.com/firebase | United States | Push notification token, notification title and body | Android push notification delivery | Erased immediately after delivery | Transmitted when a notification is sent |
| Apple Inc. apple.com/legal/privacy | United States | Push notification token with title and body; sign-in identifier and email address (Sign in with Apple) | iOS push notification delivery; Apple account sign-in | Erased immediately after delivery / until you stop using the Service | Transmitted when a notification is sent or you sign in |
| RevenueCat, Inc. privacy@revenuecat.com | United States | Account identifier, in-app purchase receipts and purchase history | In-app purchase validation and subscription status | Until you stop using the Service | Transmitted at in-app purchase |
| Meta Platforms, Inc. facebook.com/privacy/policy | United States | Social account identifier, handle, display name and profile image URL; access token; the images, video and text to be published | Connecting your Threads or Instagram account, publishing posts on your behalf, and reading the performance metrics of those posts | Access token destroyed immediately on disconnect; other items destroyed when you delete your account | Transmitted when you connect an account, when a post is published, and when we read a published post's metrics |
| TikTok Pte. Ltd. privacy@tiktok.com | Singapore | Social account identifier, handle, display name and profile image URL; access token; the images and text to be published | Connecting your TikTok account and publishing posts on your behalf | Access token destroyed immediately on disconnect; other items destroyed when you delete your account | Transmitted when you connect an account and when a post is published |
| The provider of the AI assistant you connected OpenAI, L.L.C. (privacy@openai.com), Anthropic, PBC (privacy@anthropic.com), Anysphere, Inc. (hi@cursor.com) and others | United States (for other assistants, the provider's country) | The items listed for “the provider of the AI assistant you connected GenToon to” in Section 4 | Showing the results of the GenToon features you ask for in that assistant | Under the recipient's policy | Sent over an encrypted connection (HTTPS) each time a GenToon feature runs in the assistant you connected |
| Discord, Inc. privacy@discord.com | United States | Enquirer name and email address, part of the enquiry text | Routing customer enquiry notifications | Per the operations channel retention period | Transmitted when an enquiry is received |
How to refuse an international transfer
You may refuse the transfer of your personal information abroad. Email service@gentoon.ai or call +82-70-4571-4025 and we will stop the transfer and request deletion of information already transferred. Refusing a transfer that is essential to the Service — database hosting, payment processing or AI generation — will limit or prevent your use of the corresponding features. Refusing the analytics transfers (Google Analytics, Microsoft Clarity, PostHog) does not affect your use of the Service. Transfers to the provider of an AI assistant stop if you do not connect GenToon to it or disconnect it in Settings › Connected apps; this does not affect the rest of the Service.
Your Rights
Depending on where you live, applicable data-protection law gives you rights over your personal data. Where the GDPR or UK GDPR applies to you, you have the right to:
- Access the personal data we hold about you and obtain a copy.
- Rectify inaccurate or incomplete data.
- Erase your data (“right to be forgotten”), subject to legal retention obligations.
- Restrict processing in certain circumstances.
- Object to processing based on our legitimate interests, and to object to direct marketing at any time.
- Data portability — receive the data you provided to us in a structured, commonly used, machine-readable format, and have it transmitted to another controller where technically feasible.
- Withdraw consent at any time, where processing is based on consent, without affecting the lawfulness of processing before withdrawal.
You can exercise most of these rights directly under Settings > My Account, or by emailing service@gentoon.ai. We will respond without undue delay and within one month of receiving your request; this period may be extended by up to two further months where the request is complex or numerous, in which case we will inform you. We do not charge a fee for a reasonable request, and we verify your identity using your account before acting on a request.
You also have the right to lodge a complaint with your local data-protection supervisory authority (for example, your national authority in the EEA, or the UK Information Commissioner's Office at ico.org.uk). We would, however, appreciate the chance to address your concern first. Additional rights for California and other U.S. state residents are set out in the “Your U.S. State Privacy Rights” section below.
8. Destruction of Personal Information
- Personal information shall be destroyed without delay once the retention period has expired or the processing purpose has been achieved.
- Electronic files: Permanently deleted using methods that prevent recovery.
- Paper documents: Shredded or incinerated.
- Account deletion is processed in the following stages.
- Immediately on deletion — your name, email address, nickname, profile photo, and bio are irreversibly anonymised, and your login account is removed so that you can no longer sign in. Your personal projects are moved to trash.
- 30 days after deletion — projects, generated images, and uploaded files are permanently erased from storage, and the account identifiers on payment records are removed. The transaction records themselves are kept in de-identified form for the period required by Korean e-commerce law, as set out in Section 3.
- Connected social accounts — when you disconnect an account we destroy its access token immediately, cancel any posts scheduled at that moment, and ask the platform (Meta, TikTok) to revoke the permissions you granted us. The account identifier, handle and your past publishing records stay in your account so you can see what was published, and are destroyed together with the token when you delete your account. Records of your consent and its withdrawal are retained as evidence that consent was obtained.
- What remains, anonymised — posts and comments you made in the community stay visible so that other people's conversations remain intelligible, attributed to “Deleted user”; a stripped account record is retained solely to keep those posts attached. Projects you shared into a workspace remain with that workspace for its other members. If you want these removed, delete them before closing your account or email service@gentoon.ai.
9. Use of Cookies
The Company uses the following cookies:
| Cookie | Purpose | Duration |
|---|---|---|
| Session cookie (Supabase Auth) | Maintaining login state | End of session |
| csrf_token | CSRF attack prevention | 1 hour |
| Language preference cookie | Retaining selected language preference | Session |
| Google Analytics (GA4) cookies | Service usage analytics and service improvement | Up to 2 years |
| Microsoft Clarity cookies | User behavior analytics (heatmaps and session replay) for service improvement | Up to 1 year |
| PostHog cookies (ph_*_posthog) | Product analytics — recognising returning visitors and measuring usage funnels | Up to 1 year |
The analytics cookies listed above are set automatically as soon as a page loads. We do not display a consent banner beforehand, and we do not currently detect or act on Global Privacy Control (GPC) or Do Not Track signals — see “Legal Bases for Processing” above. You may refuse the storage of cookies through your web browser settings. However, blocking cookies may restrict your ability to use certain features, such as logging in, and on its own it does not stop analytics collection; to stop collection, email service@gentoon.ai.
10. Measures to Ensure the Security of Personal Information
The Company implements the following measures in accordance with applicable data protection laws:
- Access control. Access to personal information is restricted to the minimum number of authorized personnel, and administrator accounts are managed via UUID-based whitelisting.
- Encryption. Passwords are stored using one-way hashing, and payment card information is processed by Polar in compliance with PCI-DSS standards. All communications are encrypted using TLS (HTTPS).
- Security headers. Security headers including HSTS, CSP, and X-Frame-Options are applied to prevent web-based attacks.
- Access restrictions. CSRF tokens, API rate limiting, and IP-based anomalous access blocking are implemented.
- Monitoring. Real-time error detection and security event monitoring are performed through Sentry.
Children's Privacy
The Service is not directed to children. You must meet the minimum age required to use online services in your country: at least 13 years old in the United States, and at least the age of digital consent in your country in the EEA and the UK (16, unless your country sets a lower age of 13, 14, or 15). Where applicable law requires it, a parent or guardian must provide or authorise consent. If we learn that we have collected personal data from a child below the applicable age without the required consent, we will delete the account and the data without undue delay. If you believe a child has provided us with personal data, contact service@gentoon.ai.
How to Contact Us About Your Data
For any privacy question, to exercise your rights, or to raise a concern, contact our data-protection officer, who also receives access requests and complaints. Under the Korean Personal Information Protection Act this role is held by the representative of the business.
- Name
- Kim Joong Hwi
- Position
- Representative, Fairrium
- Phone
- +82-70-4571-4025
- service@gentoon.ai
Users in the Republic of Korea may also apply, free of charge, to the Personal Information Dispute Mediation Committee (www.kopico.go.kr, 1833-6972) or report to the Personal Information Infringement Report Center (privacy.kisa.or.kr, 118) if a request is refused or you disagree with how it was handled.
GenToon does not currently maintain a permanent establishment in the EEA or the UK. If we are required to appoint a representative under Article 27 of the GDPR or UK GDPR, we will update this Policy with their details. In the meantime, EEA, UK, and Swiss users may direct all data-protection requests to service@gentoon.ai, which we monitor as our primary data-protection channel.
Lodging a Complaint
You have the right to lodge a complaint with the data-protection supervisory authority in your country or state of residence. For users in the EEA, this is your national Data Protection Authority; in the UK, the Information Commissioner's Office (ICO) at ico.org.uk; in California, the California Privacy Protection Agency or the California Attorney General. You may also contact us first at service@gentoon.ai and we will work to resolve your concern.
Your U.S. State Privacy Rights (California and Other States)
If you are a resident of California or another U.S. state with a comprehensive privacy law, you may have the right to know what personal information we collect and how we use it, to access and delete your personal information, to correct inaccurate information, to limit the use of sensitive personal information, and to opt out of the “sale” or “sharing” of personal information and of targeted advertising.
We do not sell your personal information for money. We do not knowingly “sell” or “share” personal information as those terms are defined under the California Consumer Privacy Act (CCPA), as amended by the CPRA, except that our use of analytics cookies and identifiers (Google Analytics, Microsoft Clarity, PostHog) may be considered “sharing” for cross-context behavioural advertising purposes under California law. To opt out of these analytics cookies, email service@gentoon.ai. We do not currently detect or act on Global Privacy Control (GPC) or Do Not Track signals sent by your browser; sending one will have no effect today. We will update this Policy if and when we implement signal-based opt-out.
We do not sell or share the personal information of consumers we know to be under 16. We will not discriminate against you for exercising any of these rights. To exercise your U.S. state privacy rights, or to opt out, email service@gentoon.ai with the subject line “U.S. Privacy Request” (or “Do Not Sell or Share”); we will verify your request using your account before responding. You may use an authorized agent to submit a request on your behalf. We will respond within the time required by law (generally 45 days, extendable once where permitted).
14. Changes to This Policy
- This Privacy Policy may be amended due to changes in applicable laws, regulations, or internal policies of the Company.
- Any amendments will be announced within the Service at least 7 days prior to the effective date of the change.
- This Policy has been in effect since January 1, 2025. The revision dated May 9, 2026 takes effect on the same date. The revision dated August 1, 2026 (adding Alibaba Cloud and OpenAI as AI processors) takes effect on the same date. The revision dated August 7, 2026 (adding PostHog, Inc. as a product-analytics processor and disclosing the resulting transfer to the European Union) takes effect on the same date. The revision dated September 1, 2026 (social publishing — new collected categories, third-party sharing with and international transfers to Meta Platforms, Inc. in the United States and TikTok Pte. Ltd. in Singapore, and destruction of connection data — the access token on disconnect, everything on account deletion) takes effect on September 8, 2026, seven days after it was posted, in line with paragraph 2 above. The revision dated September 6, 2026 (per-post performance metrics — adding the metrics of published posts to the categories collected, and adding the reading of those metrics to the purpose of sharing with and transferring to Meta Platforms, Inc.) takes effect on September 13, 2026 under the same paragraph.
- The revision dated September 24, 2026 (connected AI assistants (MCP connector) — new collected categories, collection method and purpose; retention periods for connection records, the connector's session and connector tokens; third-party sharing with and international transfers to the provider of the AI assistant you connect (such as OpenAI, L.L.C., Anthropic, PBC and Anysphere, Inc.); text generation (studio assistant chat and scenarios) added to the work entrusted to OpenAI, L.L.C. and Google; new Section 20) takes effect on the same date. It describes processing that already takes place in the connector feature the Service already offers and specifies the troubleshooting records the Company keeps, and it neither restricts your rights nor adds obligations, so, like the revisions of August 1 and August 7, 2026, it takes effect when posted.
15. Mesaj Saklama Politikası
Şirket, hizmet içinde alınıp verilen mesaj türüne göre farklı saklama süreleri uygular.
Yapay Zeka Karakter Sohbeti
AI karakterlerle yapılan konuşmalar, sen silene kadar süresiz olarak saklanır. Depolama verimliliği için bir yıl (365 gün) boyunca aktif olmayan oturumlar otomatik olarak arşive taşınır; iki yıl (730 gün) boyunca aktif olmayan mesajlar ise otomatik ve kalıcı olarak silinir. Sabitlediğin (favorilediğin) mesajlar otomatik silinmeden muaf tutulur ve sabitlemeni kaldırana kadar saklanır.
Kullanıcılar Arası Doğrudan Mesajlar (DM)
Kullanıcılar arasında gönderilen doğrudan mesajlar, gönderilmesinin üzerinden 180 gün geçtikten sonra otomatik ve kalıcı olarak silinir. Hizmet şartlarını ihlal ettiği bildirilen veya denetim için işaretlenen mesajlar, raporun çözüme kavuşturulmasına ya da uygulanabilir hukuk kapsamında uyuşmazlık çözümü ve yasal uyum için gereken daha uzun süreye kadar ayrıca saklanır.
Kullanıcı Tarafından Silme
Mesajları ve sohbet odalarını kendin sildiğinde ilgili veriler anında ve kalıcı olarak silinir. Hesabını sildiğinde adın, e-posta adresin, takma adın ve profil fotoğrafın hesabın kapatıldığı anda geri döndürülemez biçimde anonim hale getirilir; kayıtlı projelerin, oluşturulan görsellerin ve yüklediğin dosyalar ise hesabın kapatılmasının üzerinden 30 gün geçtikten sonra depolamadan kalıcı olarak silinir. Ancak toplulukta paylaştığın gönderiler ve yorumlar, diğer kullanıcıların konuşma bağlamını korumak amacıyla yazar bilgisi ‘Silinmiş kullanıcı’ olarak değiştirilmiş anonim halde kalır; bunun için kimlik bilgileri çıkarılmış bir hesap kaydı da birlikte saklanır. Muhasebe, vergi ve uyuşmazlık çözümü amacıyla ilgili mevzuatın saklanmasını zorunlu kıldığı ödeme ve işlem bilgileri ise bu Politikanın 3. Bölümü uyarınca kimliksizleştirilmiş biçimde ayrıca saklanır.
Erişim Günlükleri (AuditLog)
Hizmeti kullanmanız sonucunda oluşan erişim IP adresi, Kullanıcı Aracısı (User-Agent) ve erişim zamanı gibi etkinlik kayıtları, İletişim Gizliliğinin Korunması Kanunu'nun (Protection of Communications Secrets Act) 15-2. maddesi uyarınca ve soruşturma mercilerinin hukuka uygun taleplerine yanıt verebilmek amacıyla bir (1) yıl boyunca saklanır ve bu sürenin ardından otomatik olarak silinir. Ancak ihbar/şikâyet alındı kayıtları ile hesap silme talebi kayıtları, uyuşmazlıkların çözümü ve silme hakkının yerine getirildiğinin kanıtlanması amacıyla; ciddi güvenlik olaylarına ilişkin kayıtlar ise tekrarının önlenmesi amacıyla bu sürenin ardından da saklanır. Yeniden kayıt kısıtlamasının uygulanabilmesi için saklanan, üyeliği sonlandırılmış e-posta adresine ait eşleştirme değeri (özet/hash), kısıtlama süresi sona erdiğinde silinir. Bu madde, işbu Politikanın 3. Bölümünde yer alan erişim günlükleri (üç ay) maddesine göre önceliklidir.
16. Kolluk Kuvvetleri ve Devlet Makamlarıyla İşbirliği
Şirket, kullanıcıların kişisel bilgilerini korumayı taahhüt eder; ancak bir devlet makamı usule uygun yasal bir talep ilettiğinde Şirket, yürürlükteki mevzuatın izin verdiği ölçüde işbirliği yapar.
Yasal Süreç
Bir soruşturma makamı, mahkeme veya diğer devlet kurumu arama kararı, mahkeme kararı ya da başka yasal bir belgeyle veri talep ettiğinde Şirket, başta Kişisel Verilerin Korunması Kanunu, Kişisel Verilerin Korunması Kanunu'nun 15-2. maddesi ve Elektronik Haberleşme Kanunu'nun 83. maddesi olmak üzere yürürlükteki mevzuatın izin verdiği ölçüde yalnızca asgari düzeyde gerekli bilgiyi sağlar. Şirket, arama kararı veya mahkeme kararı eşlik etmeyen gayri resmi taleplere yanıt vermez.
Kullanıcıya Bildirim
Şirket, kullanıcı bilgilerini bir devlet makamına ifşa ettiğinde, Kişisel Verilerin Korunması Kanunu ve ilgili mevzuatın izin verdiği ölçüde etkilenen kullanıcıyı makul çabalarla bilgilendirmeye çalışır. Söz konusu bildirim; bir soruşturma makamının ifşayı yasaklaması, bildirimin bir soruşturma veya yargı sürecini esaslı ölçüde sekteye uğratabilecek olması ya da bildirimin başka bir şekilde yasa veya düzenlemeler tarafından yasaklanmış ya da kısıtlanmış olması durumunda geciktirilebilir veya yapılmayabilir.
Kullanıcı Hakları
Kullanıcılar, Kişisel Verilerin Korunması Kanunu'nun 35. maddesi kapsamında devlet makamlarına yapılan ifşa kayıtlarına erişim talebinde bulunabilir. Kullanıcı, herhangi bir ifşanın hukuka aykırı olduğuna inanıyorsa aynı Kanun'un 43. maddesi kapsamında arabuluculuk ve 39. maddesi kapsamında tazminat dahil yasal yollara başvurabilir. İlgili sorularınız için lütfen bu Politikanın 12. Bölümünde belirlenen Veri Koruma Sorumlusu ile iletişime geçin.
17. Ürün Kullanım Analizi (PostHog)
Hizmetin nasıl kullanıldığını anlamak ve geliştirmek amacıyla GenToon web sitesinde ve mobil uygulamasında ürün analizi aracı olan PostHog'u kullanıyoruz. PostHog bu verileri Avrupa Birliği'nde (Frankfurt, Almanya) bulunan sunucularda işlediğinden, aşağıda açıklananlar kişisel verilerin yurt dışına aktarılması niteliğindedir.
Amaç
Kayıttan webtoon üretimine ve ödemeye uzanan kullanım akışını (huniyi) ve geri dönüş oranını ölçmek, özellik bazında kullanım istatistikleri derlemek, ayrılma noktalarını ve hataları tespit ederek Hizmet'i iyileştirmek amacıyla. Ayrıca GenToon'a hangi kanaldan ulaştığınızı da kaydediyoruz (aşağıdaki «Aktarılan veriler» bölümüne bakınız); böylece farklı kanallardan gelen kullanıcıların Hizmet'i nasıl kullandığını karşılaştırabiliyoruz. Bu verileri reklam hedeflemesi için kullanmıyoruz; sizin üzerinizde hukuki sonuç doğuran veya benzer şekilde önemli etki yaratan otomatik karar alma süreçlerinde de kullanmıyoruz.
Aktarılan veriler
Bir kullanıcı tanımlayıcısı (GenToon hesabınızın dahili kimliği — veri tabanımızın kullandığı tanımlayıcının aynısı); web üzerinden oturum açtığınızda e-posta adresiniz; hesap nitelikleri (abonelik planı, dil, ödeme ülkesi, kayıt tarihi, kayıt platformu ve edinim nitelikleri — utm_source, utm_medium, utm_campaign, ücretli bir reklam tıklamasıyla gelip gelmediğiniz ve bir iş ortağı ya da başka bir kullanıcı tarafından yönlendirilip yönlendirilmediğiniz; gclid ve fbclid gibi reklam tıklama kimlikleri aktarımdan önce maskelenir, dolayısıyla kimliğin kendisi gönderilmez, ancak bir tıklama kimliğinin var olduğu bilgisi gönderilir); kullanım olayları (ekran görüntülemeleri, seçimler ve bir üretimin veya ödemenin tamamlanması gibi eylem kayıtları); web sitesinde otomatik olarak yakalanan etkileşimler — tıkladığınız düğme ve bağlantıların üzerindeki görünür metin ile bulunduğunuz sayfanın adresi ve bu adreste yer alan değerler, örneğin toplulukta yazdığınız bir arama terimi; harici bir aramadan geldiyseniz o arama motorunun adı (Google, Bing, Yahoo veya DuckDuckGo) ve tarayıcınız arama terimini bir önceki sayfanın adresi içinde ilettiğinde o arama motoruna yazdığınız terim; bir tavsiye veya davet bağlantısıyla geldiyseniz o bağlantının herkese açık kodu (adresteki ref·via değeri — bu kod, yönlendiren hesapla eşleştirilebildiği için yönlendiren kişinin kimliğiyle ilgisiz olduğunu iddia etmiyoruz); cihaz, işletim sistemi ve uygulama sürümü bilgileri; ayrıca IP adresiniz ve bundan çıkarılan ülke bilgisi. Oluşturduğunuz içerikleri aktarmıyoruz: istemler (prompt), karakter sohbeti mesajları ve yüklenen veya üretilen görsel dosyaları PostHog'a gönderilmez.
Alıcı, ülke, aktarım zamanı ve yöntemi
Alıcı PostHog, Inc.'tir (iletişim: privacy@posthog.com) ve varış yeri Avrupa Birliği'dir (Frankfurt, Almanya bölgesi). Veriler, Hizmeti kullandığınız anda analiz SDK'sı aracılığıyla şifreli ağ bağlantıları (HTTPS) üzerinden iletilir.
Alıcının amacı ve saklama süresi
PostHog verileri yalnızca yukarıda açıklanan amaçlarla işler. Saklama süresi PostHog'un veri saklama politikasına tabidir ve en fazla 7 yıldır (PostHog'un yayımladığı bilgilere göre, 7 Ağustos 2026 tarihinde doğrulanmıştır). GenToon hesabınızı silmeniz, PostHog'a daha önce gönderilmiş verileri kendiliğinden silmez — bunların silinmesi için lütfen aşağıdaki «Nasıl itiraz edilir» bölümünde açıklandığı şekilde ayrıca talepte bulunun.
Ekran kaydı (oturum tekrarı)
PostHog'un oturum tekrarı (ekran kaydı) özelliği hem web sitemizde hem de mobil uygulamamızda kapalıdır; dolayısıyla PostHog ekranınızı kaydetmez. Bundan ayrı olarak web sitemiz — ancak mobil uygulamamız değil — ekran etkileşimlerini (oturum tekrarı) ve ısı haritalarını gerçekten kaydeden Microsoft Clarity'yi kullanmaktadır; ayrıntılar için bu Politika'daki veri işleyenler tablosuna, yurt dışı aktarım tablosuna ve çerezler bölümüne bakınız. İleride PostHog'da oturum tekrarını etkinleştirmemiz hâlinde bu Politika'yı önceden değiştirir ve bildirimde bulunuruz.
İtiraz yolu
Bu işleme ve aktarıma itiraz etme, durdurulmasını ve verilerin silinmesini talep etme hakkına sahipsiniz. service@gentoon.ai adresine e-posta gönderin; PostHog'da hesap tanımlayıcınıza bağlı analiz verilerini siler ve hakkınızda daha fazla veri toplanmasını durdurmak için gerekli adımları atarız. Bu işlem elle yapıldığından lütfen işleme için bize biraz süre tanıyın; hesabınızı silmeniz bunu otomatik olarak gerçekleştirmez. Tarayıcınızda çerezleri ve yerel depolamayı engellemek, ziyaretler arasında tanınmanızı zorlaştırır; ancak tek başına veri toplamayı durdurmaz — güvenilir yol yukarıdaki e-posta talebidir. Ayrıca, analiz araçlarımızı sayfa açılır açılmaz yüklediğimizi, öncesinde bir onay bandı göstermediğimizi ve tarayıcınızın gönderebileceği Global Privacy Control (GPC) veya Do Not Track sinyallerini şu anda algılamadığımızı ve bunlara göre işlem yapmadığımızı belirtmek isteriz. İtiraz etmeniz Hizmet'i kullanmanızı kısıtlamaz.
18. Profil fotoğrafınızın webtoon karakterine dönüştürülmesi
Bir sohbeti webtoona dönüştürdüğünüzde, profil fotoğrafınız webtoon tarzında bir karakter oluşturmak (stilizasyon) için kullanılır. Bu işlem sizi kimliklendirmek ya da biyometrik veri çıkarmak, saklamak veya eşleştirmek amacıyla yapılmaz. Şirket bu süreçte oluşturulan karakter görselini, karakterin çizilebilmesi için yapay zekânın çıkardığı kısa görünüm tarifi metnini ve oluşturma anındaki profil fotoğrafının adresini (URL) saklar; bunlar aynı karakter yeniden çizildiğinde tekrar kullanılır. Profil fotoğrafınız yoksa veya dönüştürme başarısız olursa, bunun yerine varsayılan bir karakter kullanılır. Yüz içeren bir fotoğrafın analiz edilmesi için ve grup sohbetinin webtoona dönüştürülmesi sırasında diğer katılımcıların mesajlarının yapay zekâya iletilmesi için, Hizmet içinde bunların her biri bakımından ayrı ayrı açık rızanız alınır. Profil fotoğrafınızı değiştirerek veya kaldırarak ya da service@gentoon.ai adresine talep göndererek bu kullanımı istediğiniz zaman durdurabilir; saklanan karakter görselinin ve görünüm tarifinin silinmesini talep edebilirsiniz.
20. Connected AI Assistants (MCP Connector)
Section numbers follow the Korean-language version of this Policy.
- (1) You can connect GenToon to an AI assistant such as ChatGPT or Claude through the Model Context Protocol (MCP), at https://www.gentoon.ai/api/mcp, and, inside it, set up, write and draw webtoons, look up your saved characters and projects, and export, share or publish the results. A connection is made when you review the permissions the AI assistant requests (view, create, publish) on GenToon's own sign-in and consent page and allow them. The Company never gives your password to the AI assistant.
- (2) What the Company keeps. The connected app's name, identifier and return address; the permissions you granted; when the connection was made, last used and revoked; the connector's own sign-in session (stored encrypted and deleted as soon as the connection ends); authorization codes and access and refresh tokens (one-way hashes only); audit records of connecting and disconnecting (the app name and the permissions you granted — kept for 1 year as Service activity records, Section 3); and tool-call records for troubleshooting (the feature used, how long it took and whether it succeeded or its error code, the first part of the project identifier, whether it was called from a card view, the first 40 characters of the app name, version, operating system, device model and similar information the AI assistant reports, and a one-way hash of the assistant's conversation identifier). Tool-call records do not contain what you asked for; they are kept not in our database but in the operating logs of our hosting provider (Vercel Inc.) and are deleted when that operating-log retention period ends (at most 30 days). What the AI assistant sends (story topics, dialogue, edit instructions, character descriptions, photos you chose to send and so on) is saved as your projects, characters and art styles and is handled like anything you create on the web.
- (3) What is passed to the AI assistant. The items listed for “the provider of the AI assistant you connected GenToon to” in Section 4. Your email address, password and payment details are never passed. How the assistant stores and uses that information is governed by its provider's policy (for example OpenAI, L.L.C. for ChatGPT and Codex, Anthropic, PBC for Claude and Claude Code, and Anysphere, Inc. for Cursor). The Company does not request or collect your conversation with the AI assistant; it processes only what the assistant sends to GenToon. Generated images, and photos you send through the connector, are stored at their own addresses (photos never used to create a character or art style are deleted after the period in Section 3), and anyone who has an address can open that image without signing in (the same as images you create on the web).
- (4) Creating through the connector uses the same credits as on the web, and no payment takes place inside the connector.
- (5) You can disconnect at any time in Settings › Connected apps. Disconnecting invalidates that connection's tokens immediately and ends and deletes the connector's session, and the connection record is destroyed 30 days later. Each device or app has its own connection, so disconnecting one leaves the others in place; disconnecting every connection listed in Connected apps ends them all. A connection older than 24 hours with no valid token left, and a connection whose connector sign-in session can no longer be renewed, are disconnected automatically, and deleting your account disconnects every connection (retention periods in Section 3).