Privacy Notice
Version 2026-07-19.1 · Effective July 19, 2026
Commercial launch blocker: Controller identity, address and privacy contact are not configured. Checkout remains unavailable until these details are supplied.
1. Data we process
Account data includes email, username, password hash, verification state, minimum-age acknowledgement, optional adult-content confirmation and policy versions. Product data includes personas, characters, stories, universes, chats, messages, uploads, generated images, preferences and state used to keep roleplay coherent. Operational data includes session records, HMAC-protected network-address and user-agent fingerprints, session-security and rate-limit events, AI usage, token activity, policy decisions and support conversations. Commerce data includes order snapshots, prices, token grants, membership periods, discount reservations/redemptions and the purchaser/recipient relationship, product and optional message for gifts.
2. Why it is processed
We process data to create and secure accounts, provide requested AI and creation features, preserve chat state, deliver purchases, prevent abuse, answer support requests, meet financial obligations and improve service reliability. The operator must confirm the precise legal bases for its jurisdiction; typical bases include contract performance, legal obligations, legitimate security interests and consent where specifically requested.
3. AI, payment and service providers
Prompts and relevant creator/chat context are sent to the configured DeepSeek-compatible AI provider to generate or review text. Image prompts are sent to the configured Runware-compatible image provider. Payment, email, hosting and database providers process the information necessary for their roles. A payment provider receives the server-owned order reference, amount, currency and product information; payment credentials are handled by that provider and are not stored in AsgineAI’s order tables. Do not enter passwords, full card numbers or unnecessary sensitive personal data in prompts or gift messages.
4. International processing
Provider locations and transfer safeguards depend on the operator’s final vendor contracts and deployment region. These must be documented before commercial launch. Contact the configured privacy address for the current provider list and applicable safeguards.
5. Public content and duplication
Private creator fields are not intentionally displayed on public pages. Public or unlisted items expose only the sections selected by the creator and the fields naturally required for the public page. When duplication is enabled, another user can copy the warned scope into their own private item.
6. Retention
Active account and creation data remain while needed to provide the service. Session records expire automatically and security events are retained only as long as reasonably needed to investigate abuse and protect accounts. Discount reservations are released after failed, cancelled or stale orders. Account deletion removes the account and connected creative data through the deletion workflow. Financial, discount and gift ledger records may be retained in minimized form where required for accounting, fraud prevention, dispute handling or legal obligations. Unreferenced uploads are cleaned after a grace period; verification and recovery tokens expire automatically.
7. Your controls and rights
Account Center supports correction, session revocation, machine-readable export and permanent deletion. Depending on applicable law, you may also request access, rectification, erasure, restriction, portability or objection and may complain to a supervisory authority. Use Support Center or the configured privacy email. The requirements for transparent privacy information are set out in Articles 13 and 14 GDPR.
8. Cookies, local storage and IP-bound sessions
AsgineAI uses an HTTP-only session cookie for sign-in and security. Each signed-in session is bound to an HMAC fingerprint of its current network address; the raw address is not written into the session-security table. A mismatch ends the session. Browser storage remembers interface preferences such as model mode, token source and pending checkout recovery. These preferences are not used to personalize prices.
9. Gift visibility
A gift purchaser supplies the recipient’s exact username and can see the order and delivery state. The recipient sees the purchaser username, gifted product and optional message. Neither side receives the other person’s email, payment credentials or unrelated billing history. Administrators can inspect gift and discount records where needed for support, fraud prevention and platform operation.
10. Security and changes
Security measures include password hashing, IP-bound session invalidation, origin checks, server-side input validation, distributed rate limits, upload validation, access controls, server-owned price snapshots and signed, amount-verified payment webhooks. No system is risk-free. Material notice changes use a new version and can require renewed acceptance.