Legal

Privacy Notice

Version 2026-07-19.1 · Effective July 19, 2026

Commercial launch blocker: Controller identity, address and privacy contact are not configured. Checkout remains unavailable until these details are supplied.

1. Data we process

Account data includes email, username, password hash, verification state, minimum-age acknowledgement, optional adult-content confirmation and policy versions. Product data includes personas, characters, stories, universes, chats, messages, uploads, generated images, preferences and state used to keep roleplay coherent. Operational data includes session records, HMAC-protected network-address and user-agent fingerprints, session-security and rate-limit events, AI usage, token activity, policy decisions and support conversations. Commerce data includes order snapshots, prices, token grants, membership periods, discount reservations/redemptions and the purchaser/recipient relationship, product and optional message for gifts.

2. Why it is processed

We process data to create and secure accounts, provide requested AI and creation features, preserve chat state, deliver purchases, prevent abuse, answer support requests, meet financial obligations and improve service reliability. The operator must confirm the precise legal bases for its jurisdiction; typical bases include contract performance, legal obligations, legitimate security interests and consent where specifically requested.

3. AI, payment and service providers

Prompts and relevant creator/chat context are sent to the configured DeepSeek-compatible AI provider to generate or review text. Image prompts are sent to the configured Runware-compatible image provider. Payment, email, hosting and database providers process the information necessary for their roles. A payment provider receives the server-owned order reference, amount, currency and product information; payment credentials are handled by that provider and are not stored in AsgineAI’s order tables. Do not enter passwords, full card numbers or unnecessary sensitive personal data in prompts or gift messages.

4. International processing

Provider locations and transfer safeguards depend on the operator’s final vendor contracts and deployment region. These must be documented before commercial launch. Contact the configured privacy address for the current provider list and applicable safeguards.

5. Public content and duplication

Private creator fields are not intentionally displayed on public pages. Public or unlisted items expose only the sections selected by the creator and the fields naturally required for the public page. When duplication is enabled, another user can copy the warned scope into their own private item.

6. Retention

Active account and creation data remain while needed to provide the service. Session records expire automatically and security events are retained only as long as reasonably needed to investigate abuse and protect accounts. Discount reservations are released after failed, cancelled or stale orders. Account deletion removes the account and connected creative data through the deletion workflow. Financial, discount and gift ledger records may be retained in minimized form where required for accounting, fraud prevention, dispute handling or legal obligations. Unreferenced uploads are cleaned after a grace period; verification and recovery tokens expire automatically.

7. Your controls and rights

Account Center supports correction, session revocation, machine-readable export and permanent deletion. Depending on applicable law, you may also request access, rectification, erasure, restriction, portability or objection and may complain to a supervisory authority. Use Support Center or the configured privacy email. The requirements for transparent privacy information are set out in Articles 13 and 14 GDPR.

8. Cookies, local storage and IP-bound sessions

AsgineAI uses an HTTP-only session cookie for sign-in and security. Each signed-in session is bound to an HMAC fingerprint of its current network address; the raw address is not written into the session-security table. A mismatch ends the session. Browser storage remembers interface preferences such as model mode, token source and pending checkout recovery. These preferences are not used to personalize prices.

9. Gift visibility

A gift purchaser supplies the recipient’s exact username and can see the order and delivery state. The recipient sees the purchaser username, gifted product and optional message. Neither side receives the other person’s email, payment credentials or unrelated billing history. Administrators can inspect gift and discount records where needed for support, fraud prevention and platform operation.

10. Security and changes

Security measures include password hashing, IP-bound session invalidation, origin checks, server-side input validation, distributed rate limits, upload validation, access controls, server-owned price snapshots and signed, amount-verified payment webhooks. No system is risk-free. Material notice changes use a new version and can require renewed acceptance.