Privacy Policy
Effective January 1, 2025 | Last revised August 7, 2026
Fairium (“GenToon”, “we”, “us”, or “the Company”) provides the GenToon service (the “Service”) and is the controller of personal data processed through it. This Privacy Policy explains what personal data we collect, why and on what legal basis we process it, who we share it with, how long we keep it, how we transfer it internationally, and the rights you have over your data.
For users in the European Economic Area (EEA), the United Kingdom, and Switzerland, we process personal data in accordance with the EU General Data Protection Regulation (GDPR) and the UK GDPR. For users in California and other U.S. states with applicable privacy laws, the disclosures in the “Your U.S. State Privacy Rights” section apply. Country-specific provisions required under Korean law apply only to users in the Republic of Korea and are set out separately below. If you have any question about this Policy or wish to exercise your rights, contact us at service@gentoon.ai.
1. Categories of Personal Information Collected and Methods of Collection
A. Categories Collected
| Category | Required | Optional |
|---|---|---|
| Sign-up | Email, name (provided via OAuth for social login) | Profile image |
| Payment | Card brand, last four digits of card number (via Polar) | Billing details handled by our payment provider (card brand and last four digits via Polar). We do not store full card numbers. |
| Service usage | IP address, access logs, service usage records, device information (User-Agent) | Generated content, reference images, community nickname and bio |
| Customer support | Email, inquiry content | — |
B. Methods of Collection
- Direct input during sign-up and service use on the website
- Social login via Google or Kakao OAuth
- Automatic collection during payment processing via Polar
- Automatic generation and collection through cookies, logs, and similar technologies during service use
- Collection during customer inquiries via email or the Help page
2. Purposes of Processing Personal Information
- Member management. Identity verification, prevention of unauthorized use, complaint resolution, and delivery of notices
- Service provision. AI image and script generation, project storage, character management, and community operation
- Payment and billing. Subscription payments, credit purchases, refunds, and issuance of tax receipts and invoices
- Service improvement. Usage statistics and product-usage analysis (Google Analytics, Microsoft Clarity, PostHog), error detection (Sentry), and service quality enhancement
- Marketing (optional). Event and benefit notifications (only with prior consent)
Legal Bases for Processing (EEA / UK Users)
Where the GDPR or UK GDPR applies, we rely on the following legal bases:
- Performance of a contract (Art. 6(1)(b)). To create and maintain your account, provide AI generation, project storage, character management, the community, and to process payments, subscriptions, credit purchases, and refunds. Without this data we cannot provide the Service.
- Legitimate interests (Art. 6(1)(f)). To secure the Service against fraud and abuse, detect and fix errors, maintain access and audit logs, analyse aggregate usage to improve the Service, and to enforce our Terms. We balance these interests against your rights and you may object as described in the “Your Rights” section.
- Consent (Art. 6(1)(a)). For optional marketing communications, which you opt into separately. You may withdraw consent at any time without affecting prior processing.
- Legal obligation (Art. 6(1)(c)). To retain transaction and tax records and to respond to lawful requests, where mandatory law requires it.
Analytics cookies and identifiers — current status
We want to be straightforward about this rather than claim more than we do. Our analytics tools (Google Analytics, Microsoft Clarity, PostHog) load for every visitor as soon as a page loads. We do not currently show a consent banner before they load, and we do not currently detect or act on the Global Privacy Control (GPC) or Do Not Track signals a browser may send. We therefore do not claim that you consented to this processing.
If you are in a jurisdiction where consent is required for non-essential analytics cookies and identifiers, or you simply want this to stop, email service@gentoon.ai and we will delete the analytics data linked to your account and act to stop further collection about you. We are reviewing this area, and we will amend this Policy once a consent mechanism and signal-based opt-out are in place.
We do not use your prompts, uploaded reference images, or generated outputs to train AI models, and we do not carry out automated decision-making that produces legal or similarly significant effects on you.
3. Retention and Use Periods
The Company destroys personal information without delay once the purpose of processing has been fulfilled. However, where retention is required by applicable law, the information shall be securely stored for the prescribed period before destruction.
| Data | Retention Period | Legal Basis |
|---|---|---|
| Member information | Until account deletion | User consent |
| Contract and payment records | 5 years | Contract and applicable tax/accounting law (varies by jurisdiction) |
| Consumer complaint and dispute resolution records | 3 years | Contract and applicable tax/accounting law (varies by jurisdiction) |
| Access logs | 3 months | Applicable telecommunications / records-retention law |
| Tax receipt and invoice issuance records | 5 years | Applicable tax law |
Where mandatory local law imposes a specific minimum retention period, we keep the relevant records for that period and no longer. Korea-specific statutory retention periods are set out in the Korean-language Policy for users in the Republic of Korea.
4. Provision of Personal Information to Third Parties
The Company does not provide personal information to third parties without the user's consent. However, the minimum necessary information is shared with the following parties for the purpose of providing the Service.
| Recipient | Purpose | Data Provided | Retention |
|---|---|---|---|
| Polar (Global) | Global subscription / credit payment processing and refunds | Payment information, purchase amount | 5 years after transaction completion |
| Polar Software Inc. (merchant of record) | Processes global subscription and credit-pack payments, refunds, and tax handling | Payment information, purchase amount | 5 years after transaction completion |
| Google LLC | Social login, AI image generation (Gemini API) | Email and profile (for login); generation prompts and reference images (for AI generation) | Until termination of service use |
| Alibaba Cloud (Model Studio) | AI character chat response generation | Chat conversation content, character settings | Until termination of service use |
| OpenAI, L.L.C. | AI image generation, harmful-content moderation | Generation prompts and reference images; chat content (for moderation) | Until termination of service use |
| Kakao Corp. | Social login | Email, nickname, profile image (as provided by Kakao OAuth) | Until termination of service use |
Personal information may also be disclosed where required by law, such as upon presentation of a warrant by investigative authorities.
5. Entrustment of Personal Information Processing
The Company entrusts the processing of personal information to the following service providers for the purpose of operating the Service. In each entrustment agreement, the Company ensures the safe handling of personal information in accordance with applicable data protection laws.
| Processor | Entrusted Tasks |
|---|---|
| Supabase Inc. | Database hosting, user authentication, and file storage |
| Vercel Inc. | Web application hosting and CDN |
| Google Cloud (Gemini API) | AI image and text generation |
| Alibaba Cloud (Model Studio) | AI character chat response generation |
| OpenAI, L.L.C. | AI image generation, harmful-content moderation |
| Upstash Inc. | Distributed caching and rate limiting (Redis) |
| Functional Software Inc. (Sentry) | Error monitoring and performance tracking |
| Resend Inc. | Email delivery |
| Google LLC (Google Analytics / GA4) | Website usage analytics and service improvement |
| Microsoft Corporation (Clarity) | User behavior analytics (heatmaps and session replay) for service improvement |
| PostHog, Inc. | Product analytics for the website and mobile app (funnel and retention measurement) for service improvement |
🤖 AI Model Training Disclosure
GenToon does not use your prompts, uploaded reference images, or generated outputs to train any AI model. Generation and chat are performed via Google Gemini, Alibaba Model Studio and OpenAI; per each provider's policy, paid API calls are not used for model training. We also do not build any internal training dataset from user content. Any future change to this policy will be notified in advance and require your explicit consent.
International Data Transfers
We operate globally and use trusted infrastructure and service providers located in various countries, including the United States. As a result, your personal data may be transferred to, stored in, and processed in countries other than the one where you live, including countries whose data-protection laws may differ from those of your home country.
Where we transfer personal data of EEA, UK, or Swiss users to a country that has not received an adequacy decision, we put appropriate safeguards in place, primarily the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum where applicable), together with technical measures such as encryption in transit. The categories of recipients and the countries involved are listed in the table below. You may request a copy of the relevant transfer safeguards by contacting service@gentoon.ai.
| Recipient | Country | Data Transferred | Method |
|---|---|---|---|
| Supabase Inc. | United States (AWS ap-northeast-2 region) | Member information, project data, files | Network transmission |
| Vercel Inc. | United States (global edge network) | Service usage logs | Network transmission |
| Google LLC (Gemini API) | United States | Prompts, reference images | Transmitted via API calls |
| Google LLC (Google Analytics / GA4) | United States | Cookie-based device identifier (_ga), the address of the page you visit and how you reached it, device, browser and language information, IP address and the approximate location inferred from it | Automatic website tag (gtag.js) transmission |
| Microsoft Corporation (Clarity) | United States | Screen-interaction recordings (session replay) and heatmaps, the address of the page you visit, device and browser information, IP address and the approximate location inferred from it | Automatic website tag transmission |
| Resend Inc. | United States | Email address, subject and body of the emails we send you | Transmitted via API calls |
| Alibaba Cloud | Japan (Tokyo region) | Chat conversation content, character settings | Transmitted via API calls |
| OpenAI, L.L.C. | United States | Prompts, reference images; chat content (for moderation) | Transmitted via API calls |
| Upstash Inc. | United States | User ID or IP address (hashed) | Transmitted via API calls |
| Sentry (Functional Software Inc.) | United States | Error logs, partial user ID | Automatic SDK transmission |
| PostHog, Inc. | European Union (Frankfurt, Germany region) | User identifier, app and web usage events, acquisition attributes (utm_source, utm_medium, utm_campaign, whether an ad click ID was present, external search-engine name and search term, the public code in a referral link), device and OS information, IP address and the country inferred from it, email address (on web sign-in) — see Section 17 for the full list | Automatic SDK transmission |
Your Rights
Depending on where you live, applicable data-protection law gives you rights over your personal data. Where the GDPR or UK GDPR applies to you, you have the right to:
- Access the personal data we hold about you and obtain a copy.
- Rectify inaccurate or incomplete data.
- Erase your data (“right to be forgotten”), subject to legal retention obligations.
- Restrict processing in certain circumstances.
- Object to processing based on our legitimate interests, and to object to direct marketing at any time.
- Data portability — receive the data you provided to us in a structured, commonly used, machine-readable format, and have it transmitted to another controller where technically feasible.
- Withdraw consent at any time, where processing is based on consent, without affecting the lawfulness of processing before withdrawal.
You can exercise most of these rights directly under Settings > My Account, or by emailing service@gentoon.ai. We will respond without undue delay and within one month of receiving your request; this period may be extended by up to two further months where the request is complex or numerous, in which case we will inform you. We do not charge a fee for a reasonable request, and we verify your identity using your account before acting on a request.
You also have the right to lodge a complaint with your local data-protection supervisory authority (for example, your national authority in the EEA, or the UK Information Commissioner's Office at ico.org.uk). We would, however, appreciate the chance to address your concern first. Additional rights for California and other U.S. state residents are set out in the “Your U.S. State Privacy Rights” section below.
8. Destruction of Personal Information
- Personal information shall be destroyed without delay once the retention period has expired or the processing purpose has been achieved.
- Electronic files: Permanently deleted using methods that prevent recovery.
- Paper documents: Shredded or incinerated.
- Upon account deletion, all projects, characters, generated images, and files stored in the Service are immediately deleted. Trashed projects are permanently deleted after the 30-day retention period has elapsed.
9. Use of Cookies
The Company uses the following cookies:
| Cookie | Purpose | Duration |
|---|---|---|
| Session cookie (Supabase Auth) | Maintaining login state | End of session |
| csrf_token | CSRF attack prevention | 1 hour |
| Language preference cookie | Retaining selected language preference | Session |
| Google Analytics (GA4) cookies | Service usage analytics and service improvement | Up to 2 years |
| Microsoft Clarity cookies | User behavior analytics (heatmaps and session replay) for service improvement | Up to 1 year |
| PostHog cookies (ph_*_posthog) | Product analytics — recognising returning visitors and measuring usage funnels | Up to 1 year |
The analytics cookies listed above are set automatically as soon as a page loads. We do not display a consent banner beforehand, and we do not currently detect or act on Global Privacy Control (GPC) or Do Not Track signals — see “Legal Bases for Processing” above. You may refuse the storage of cookies through your web browser settings. However, blocking cookies may restrict your ability to use certain features, such as logging in, and on its own it does not stop analytics collection; to stop collection, email service@gentoon.ai.
10. Measures to Ensure the Security of Personal Information
The Company implements the following measures in accordance with applicable data protection laws:
- Access control. Access to personal information is restricted to the minimum number of authorized personnel, and administrator accounts are managed via UUID-based whitelisting.
- Encryption. Passwords are stored using one-way hashing, and payment card information is processed by Polar in compliance with PCI-DSS standards. All communications are encrypted using TLS (HTTPS).
- Security headers. Security headers including HSTS, CSP, and X-Frame-Options are applied to prevent web-based attacks.
- Access restrictions. CSRF tokens, API rate limiting, and IP-based anomalous access blocking are implemented.
- Monitoring. Real-time error detection and security event monitoring are performed through Sentry.
Children's Privacy
The Service is not directed to children. You must meet the minimum age required to use online services in your country: at least 13 years old in the United States, and at least the age of digital consent in your country in the EEA and the UK (16, unless your country sets a lower age of 13, 14, or 15). Where applicable law requires it, a parent or guardian must provide or authorise consent. If we learn that we have collected personal data from a child below the applicable age without the required consent, we will delete the account and the data without undue delay. If you believe a child has provided us with personal data, contact service@gentoon.ai.
How to Contact Us About Your Data
For any privacy question, to exercise your rights, or to raise a concern, contact our data-protection contact at service@gentoon.ai. We will route your request to the person responsible for data protection and respond within the timeframe set out in the “Your Rights” section.
GenToon does not currently maintain a permanent establishment in the EEA or the UK. If we are required to appoint a representative under Article 27 of the GDPR or UK GDPR, we will update this Policy with their details. In the meantime, EEA, UK, and Swiss users may direct all data-protection requests to service@gentoon.ai, which we monitor as our primary data-protection channel.
Lodging a Complaint
You have the right to lodge a complaint with the data-protection supervisory authority in your country or state of residence. For users in the EEA, this is your national Data Protection Authority; in the UK, the Information Commissioner's Office (ICO) at ico.org.uk; in California, the California Privacy Protection Agency or the California Attorney General. You may also contact us first at service@gentoon.ai and we will work to resolve your concern.
Your U.S. State Privacy Rights (California and Other States)
If you are a resident of California or another U.S. state with a comprehensive privacy law, you may have the right to know what personal information we collect and how we use it, to access and delete your personal information, to correct inaccurate information, to limit the use of sensitive personal information, and to opt out of the “sale” or “sharing” of personal information and of targeted advertising.
We do not sell your personal information for money. We do not knowingly “sell” or “share” personal information as those terms are defined under the California Consumer Privacy Act (CCPA), as amended by the CPRA, except that our use of analytics cookies and identifiers (Google Analytics, Microsoft Clarity, PostHog) may be considered “sharing” for cross-context behavioural advertising purposes under California law. To opt out of these analytics cookies, email service@gentoon.ai. We do not currently detect or act on Global Privacy Control (GPC) or Do Not Track signals sent by your browser; sending one will have no effect today. We will update this Policy if and when we implement signal-based opt-out.
We do not sell or share the personal information of consumers we know to be under 16. We will not discriminate against you for exercising any of these rights. To exercise your U.S. state privacy rights, or to opt out, email service@gentoon.ai with the subject line “U.S. Privacy Request” (or “Do Not Sell or Share”); we will verify your request using your account before responding. You may use an authorized agent to submit a request on your behalf. We will respond within the time required by law (generally 45 days, extendable once where permitted).
14. Changes to This Policy
- This Privacy Policy may be amended due to changes in applicable laws, regulations, or internal policies of the Company.
- Any amendments will be announced within the Service at least 7 days prior to the effective date of the change.
- This Policy has been in effect since January 1, 2025. The revision dated May 9, 2026 takes effect on the same date. The revision dated August 7, 2026 (adding PostHog, Inc. as a product-analytics processor and disclosing the resulting transfer to the European Union) takes effect on the same date.
15۔ پیغامات کی برقراری کی پالیسی
کمپنی سروس کے اندر تبادلہ ہونے والے پیغامات کی نوعیت کے مطابق مختلف برقراری کی مدتیں لاگو کرتی ہے۔
AI کردار چیٹ
AI کرداروں کے ساتھ گفتگو اس وقت تک محفوظ رہتی ہے جب تک آپ خود اسے حذف نہ کر دیں۔ اسٹوریج کی کارکردگی برقرار رکھنے کے لیے، ایک سال (365 دن) سے غیر فعال سیشن خودکار طور پر آرکائیو میں منتقل ہو جاتے ہیں، اور دو سال (730 دن) سے غیر فعال انفرادی پیغامات خودکار اور مستقل طور پر حذف کر دیے جاتے ہیں۔ آپ کے پن کیے گئے (پسندیدہ) پیغامات خودکار حذف سے مستثنیٰ رہتے ہیں اور ان پن کرنے تک محفوظ رہتے ہیں۔
صارف سے صارف ڈائریکٹ میسجز (DMs)
صارفین کے درمیان تبادلہ ہونے والے ڈائریکٹ میسجز بھیجے جانے کے 180 دن بعد خودکار اور مستقل طور پر حذف ہو جاتے ہیں۔ جن پیغامات کی شرائطِ سروس کی خلاف ورزی پر شکایت کی گئی ہو یا جنہیں نگرانی کے لیے فلیگ کیا گیا ہو، انہیں شکایت حل ہونے تک، یا تنازعات کے حل اور قانونی تعمیل کے لیے قابلِ اطلاق قانون کے تحت درکار کسی بھی طویل مدت تک، علیحدہ رکھا جاتا ہے۔
صارف کی جانب سے حذف
جب آپ کوئی پیغام، گفتگو، یا اپنا اکاؤنٹ حذف کرتے ہیں، تو متعلقہ ڈیٹا بیک اپس سمیت بلا تاخیر مستقل طور پر حذف (ہارڈ ڈیلیٹ) کر دیا جاتا ہے۔ ادائیگی اور لین دین کے وہ ریکارڈز جنہیں قابلِ اطلاق اکاؤنٹنگ، ٹیکس یا تنازعات کے حل کے قوانین کے تحت برقرار رکھنا ضروری ہے، اس پالیسی کے سیکشن 3 کے مطابق علیحدہ رکھے جاتے ہیں۔
رسائی لاگز (AuditLog)
رسائی لاگز—بشمول IP ایڈریس، User-Agent اور ٹائم اسٹیمپ—کوریائی مواصلاتی رازداری کے تحفظ کے قانون کی دفعہ 15-2 کے تحت تفتیشی حکام کی قانونی درخواستوں کا جواب دینے کے لیے ایک (1) سال تک محفوظ رکھے جاتے ہیں، جس کے بعد خودکار طور پر حذف ہو جاتے ہیں۔ یہ شق سیکشن 3 میں بیان کردہ رسائی لاگز کی تین ماہ کی برقراری کی مدت کی جگہ لیتی ہے (9 مئی 2026 کو ترمیم شدہ)۔
16۔ قانون نافذ کرنے والے اور سرکاری اداروں کے ساتھ تعاون
کمپنی صارفین کی ذاتی معلومات کے تحفظ کے لیے پُرعزم ہے؛ تاہم، جہاں کوئی سرکاری ادارہ مناسب قانونی طریقہ کار کے بعد جائز درخواست پیش کرے، وہاں کمپنی قابلِ اطلاق قانون کے دائرے میں تعاون کرے گی۔
قانونی طریقہ کار
جہاں کوئی تفتیشی ادارہ، عدالت، یا دیگر سرکاری ادارہ وارنٹ، عدالتی حکم، یا دیگر جائز دستاویز پیش کر کے ڈیٹا طلب کرے، کمپنی قابلِ اطلاق قانون کے دائرے میں—بشمول کوریائی ذاتی معلومات تحفظ قانون، مواصلاتی رازداری تحفظ قانون کی دفعہ 15-2، اور ٹیلی کمیونیکیشن بزنس قانون کی دفعہ 83—صرف کم سے کم ضروری معلومات فراہم کرتی ہے۔ کمپنی وارنٹ یا حکم کے بغیر محض غیر رسمی درخواستوں کا جواب نہیں دیتی۔
صارف کو اطلاع
جب کمپنی کسی سرکاری ادارے کو صارف کی معلومات فراہم کرتی ہے، تو وہ مواصلاتی رازداری تحفظ قانون اور ذاتی معلومات تحفظ قانون کی اجازت کی حد تک متاثرہ صارف کو مطلع کرنے کی معقول کوشش کرے گی۔ ایسی اطلاع میں تاخیر کی جا سکتی ہے یا اسے چھوڑا جا سکتا ہے جہاں کوئی تفتیشی ادارہ عدم انکشاف کا حکم دے، جہاں اطلاع سے کسی تفتیش یا عدالتی کارروائی میں نمایاں رکاوٹ پڑ سکتی ہو، یا جہاں قانون کے تحت اطلاع ممنوع یا محدود ہو۔
صارف کے حقوق
صارفین ذاتی معلومات تحفظ قانون کی دفعہ 35 کے تحت سرکاری اداروں کو کیے گئے انکشافات کے ریکارڈز تک رسائی کی درخواست کر سکتے ہیں۔ جہاں صارف کو یقین ہو کہ کوئی انکشاف غیر قانونی تھا، وہ قانونی چارہ جوئی کر سکتا ہے، بشمول اسی قانون کی دفعہ 43 کے تحت ثالثی اور دفعہ 39 کے تحت ہرجانہ۔ متعلقہ سوالات کے لیے، براہِ کرم اس پالیسی کے سیکشن 12 میں نامزد ڈیٹا پروٹیکشن آفیسر سے رابطہ کریں۔
17۔ پروڈکٹ کے استعمال کا تجزیہ (PostHog)
ہم GenToon کی ویب سائٹ اور موبائل ایپ پر پروڈکٹ اینالیٹکس کا آلہ PostHog استعمال کرتے ہیں تاکہ یہ سمجھ سکیں کہ سروس کیسے استعمال ہوتی ہے اور اسے بہتر بنا سکیں۔ PostHog اس ڈیٹا کو یورپی یونین (فرینکفرٹ، جرمنی) میں واقع سرورز پر پروسیس کرتا ہے، اس لیے درج ذیل امور ذاتی ڈیٹا کی بین الاقوامی منتقلی ہیں۔
مقصد
سائن اپ سے لے کر ویب ٹون کی تخلیق اور ادائیگی تک استعمال کے بہاؤ (فنل) اور دوبارہ آنے کی شرح ناپنے، ہر فیچر کے استعمال کے اعداد و شمار مرتب کرنے، اور چھوڑ جانے کے مقامات و خرابیوں کی نشاندہی کر کے سروس کو بہتر بنانے کے لیے۔ ہم یہ بھی ریکارڈ کرتے ہیں کہ آپ کس ذریعے سے GenToon تک پہنچے (نیچے «منتقل کیا جانے والا ڈیٹا» دیکھیں)، تاکہ مختلف ذرائع سے آنے والے صارفین کے استعمال کا موازنہ کیا جا سکے۔ ہم اس ڈیٹا کو اشتہاری ٹارگٹنگ کے لیے استعمال نہیں کرتے، اور نہ ہی ایسے خودکار فیصلوں کے لیے جو آپ پر قانونی یا اسی نوعیت کے نمایاں اثرات مرتب کریں۔
منتقل کیا جانے والا ڈیٹا
صارف شناخت کنندہ (آپ کا اندرونی GenToon اکاؤنٹ ID — وہی شناخت کنندہ جو ہمارا ڈیٹابیس استعمال کرتا ہے)؛ ویب پر سائن اِن کرنے پر آپ کا ای میل پتہ؛ اکاؤنٹ کی خصوصیات (سبسکرپشن پلان، زبان، ادائیگی کا ملک، سائن اپ کی تاریخ، سائن اپ پلیٹ فارم، اور ذریعۂ آمد کی خصوصیات — utm_source، utm_medium، utm_campaign، آیا آپ کسی معاوضہ دار اشتہار کے کلک سے آئے، اور آیا آپ کو کسی ایفیلی ایٹ یا دوسرے صارف نے ریفر کیا؛ gclid اور fbclid جیسے اشتہاری کلک ID کی قدر بھیجنے سے پہلے چھپا دی جاتی ہے، اس لیے خود ID منتقل نہیں ہوتی، البتہ یہ حقیقت کہ کوئی کلک ID موجود تھی، منتقل ہوتی ہے)؛ استعمال کے ایونٹس (اسکرین کے مشاہدے، انتخاب، اور تخلیق یا ادائیگی مکمل کرنے جیسے اعمال کا ریکارڈ)؛ ویب سائٹ پر خودکار طور پر محفوظ ہونے والے تعاملات — جن بٹنوں اور لنکس پر آپ کلک کرتے ہیں ان پر نظر آنے والا متن، اور جس صفحے پر آپ ہیں اس کا پتہ بشمول اس میں شامل اقدار، مثلاً کمیونٹی میں آپ کا لکھا ہوا تلاش کا لفظ؛ اگر آپ کسی بیرونی تلاش سے آئے ہیں تو اس سرچ انجن کا نام (Google، Bing، Yahoo یا DuckDuckGo) اور، جب آپ کا براؤزر پچھلے صفحے کے پتے میں تلاش کا لفظ بھیجتا ہے، تو اس سرچ انجن میں آپ کا لکھا ہوا لفظ؛ اگر آپ کسی ریفرل یا دعوتی لنک سے آئے ہیں تو اس لنک کا عوامی کوڈ (پتے میں موجود ref·via کی قدر — یہ کوڈ ریفر کرنے والے کے اکاؤنٹ سے جوڑا جا سکتا ہے، اس لیے ہم یہ دعویٰ نہیں کرتے کہ اس کا ریفر کرنے والے کی شناخت سے کوئی تعلق نہیں)؛ ڈیوائس، آپریٹنگ سسٹم اور ایپ ورژن کی معلومات؛ اور آپ کا IP پتہ اور اس سے اخذ کردہ ملک۔ آپ کا تخلیق کردہ مواد ہم منتقل نہیں کرتے: پرامپٹ کا اصل متن، کردار کے ساتھ چیٹ کی گفتگو، اور اپ لوڈ کی گئی یا تخلیق کردہ تصویری فائلیں PostHog کو نہیں بھیجی جاتیں۔
وصول کنندہ، ملک، وقت اور منتقلی کا طریقہ
وصول کنندہ PostHog, Inc. ہے (رابطہ: privacy@posthog.com) اور منزل یورپی یونین (فرینکفرٹ، جرمنی ریجن) ہے۔ جس وقت آپ سروس استعمال کرتے ہیں، اُسی وقت اینالیٹکس SDK کے ذریعے خفیہ کردہ نیٹ ورک کنکشن (HTTPS) پر ڈیٹا بھیجا جاتا ہے۔
وصول کنندہ کا مقصد اور مدتِ حفاظت
PostHog ڈیٹا کو صرف اوپر بیان کردہ مقاصد کے لیے پروسیس کرتا ہے۔ برقراری کی مدت PostHog کی ڈیٹا برقراری پالیسی کے مطابق زیادہ سے زیادہ 7 سال ہے (PostHog کی شائع کردہ معلومات کے مطابق، 7 اگست 2026 کو تصدیق شدہ)۔ آپ کا GenToon اکاؤنٹ حذف کرنے سے وہ ڈیٹا خود بخود حذف نہیں ہوتا جو پہلے ہی PostHog کو بھیجا جا چکا ہے — اسے حذف کرانے کے لیے براہ کرم نیچے «اعتراض کیسے کریں» میں بیان کردہ طریقے سے الگ درخواست دیں۔
اسکرین ریکارڈنگ (سیشن ری پلے)
PostHog کی سیشن ری پلے (اسکرین ریکارڈنگ) سہولت ہماری ویب سائٹ اور موبائل ایپ دونوں میں بند ہے، اس لیے PostHog آپ کی اسکرین ریکارڈ نہیں کرتا۔ اس سے الگ، ہماری ویب سائٹ — لیکن ہماری موبائل ایپ نہیں — Microsoft Clarity استعمال کرتی ہے، جو واقعی اسکرین کے تعاملات (سیشن ری پلے) اور ہیٹ میپ ریکارڈ کرتی ہے؛ تفصیل کے لیے اس پالیسی کا پروسیسر جدول، بین الاقوامی منتقلی کا جدول اور کوکیز کا حصہ دیکھیں۔ اگر ہم کبھی PostHog میں سیشن ری پلے فعال کریں تو پہلے اس پالیسی میں ترمیم کریں گے اور اطلاع دیں گے۔
اعتراض کیسے کریں
آپ کو اس پروسیسنگ اور منتقلی پر اعتراض کرنے، اسے روکنے اور ڈیٹا حذف کرانے کا حق حاصل ہے۔ service@gentoon.ai پر ای میل کریں؛ ہم PostHog میں آپ کے اکاؤنٹ شناخت کنندہ سے منسلک تجزیاتی ڈیٹا حذف کر دیں گے اور آپ کے بارے میں مزید جمع آوری روکنے کے لیے اقدام کریں گے؛ یہ کام دستی طور پر ہوتا ہے، اس لیے براہ کرم کارروائی کے لیے کچھ وقت دیں، اور اکاؤنٹ حذف کرنے سے یہ خود بخود نہیں ہوتا۔ براؤزر میں کوکیز اور لوکل اسٹوریج بلاک کرنے سے مختلف وزٹ کے دوران آپ کو پہچاننا مشکل ہو جاتا ہے، مگر صرف اس سے جمع آوری نہیں رکتی — قابلِ اعتماد راستہ مذکورہ بالا ای میل درخواست ہے۔ نیز نوٹ فرمائیں کہ ہم صفحہ کھلتے ہی اپنے تجزیاتی آلات لوڈ کر دیتے ہیں، اس سے پہلے رضامندی کا کوئی بینر نہیں دکھاتے، اور آپ کا براؤزر جو Global Privacy Control (GPC) یا Do Not Track سگنل بھیج سکتا ہے، فی الحال ہم اسے نہ پہچانتے ہیں نہ اس پر عمل کرتے ہیں۔ اعتراض کرنے سے سروس کے استعمال پر کوئی پابندی نہیں لگتی۔
18۔ آپ کی پروفائل تصویر کو ویب ٹون کردار میں تبدیل کرنا
جب آپ کسی گفتگو کو ویب ٹون میں تبدیل کرتے ہیں، تو آپ کی پروفائل تصویر ویب ٹون طرز کا کردار بنانے (اسٹائلائزیشن) کے لیے استعمال ہوتی ہے۔ یہ آپ کی شناخت کرنے یا بایومیٹرک ڈیٹا نکالنے، محفوظ کرنے یا ملان کرنے کے لیے استعمال نہیں ہوتی — صرف تبدیل شدہ کردار کی تصویر محفوظ کی جاتی ہے۔ اگر آپ کے پاس پروفائل تصویر نہیں ہے یا تبدیلی ناکام ہو جائے تو ایک ڈیفالٹ کردار استعمال کیا جاتا ہے۔ آپ اپنی پروفائل تصویر تبدیل یا حذف کر کے کسی بھی وقت یہ استعمال روک سکتے ہیں۔