This Privacy Policy explains how Bizglobal ("we", "us", "our") collects, uses, and protects your information when you use CharaMaker (the "Service") at https://charamaker.app.
1. Information We Collect
1.1 Account information (via Google Sign-In)
When you sign in with Google, we receive:
- Your name and profile picture
- Your email address
- A unique Google account identifier
We do not receive your Google password.
1.2 Content you create
- Character profiles (name, persona, appearance text, generated profile images)
- Generated images and videos
- Reference images and videos you upload
- Prompts and other text you submit
1.3 Usage and technical data
- Credit balance and transaction history (e.g., generations made, plan purchased)
- Browser type, operating system, IP address (collected automatically)
- Approximate location based on IP (country / city level)
- Device and session metadata (for security and abuse prevention)
- Pages visited, time spent, and interaction events (via Google Analytics — see Section 6)
1.4 Payment information
When you make a purchase, payment processing is handled by Polar.sh, our third-party payment provider. We do not store your full credit card details. We only receive payment confirmation, plan information, customer email, and a transaction ID.
Polar's privacy practices are governed by their own privacy policy, available at https://polar.sh/legal/privacy.
2. How We Use Your Information
We use the information we collect to:
- Provide the Service (authenticate you, generate AI content, deliver outputs)
- Track credit balance and process payments
- Display your created content in your private History
- Display content in the public Gallery (only if you explicitly submit and an admin approves)
- Communicate important account or service updates
- Detect and prevent fraud, abuse, and policy violations
- Improve the Service (aggregate analytics, no individual targeting)
- Comply with legal obligations
3. AI Generation and Third-Party Processors
To generate AI content, your prompts and reference images may be transmitted to third-party AI processors that we use as service providers. These providers are contractually bound to process data only on our instructions and to maintain reasonable security.
We do not allow these providers to use your content to train their models for unrelated purposes, where such control is technically possible.
4. How We Store and Protect Your Data
- Account data and content metadata are stored in our database (Supabase) with row-level security — only you (and authorized admins) can access your records.
- Generated images and videos are stored on cloud storage providers (Cloudflare, fal.ai) with industry-standard security.
- We use HTTPS for all data in transit.
- Passwords are not stored — authentication is delegated to Google.
5. Sharing Your Information
We do not sell your personal data. We share information only in these cases:
- Service providers: Cloud hosting (Cloudflare, Supabase), AI generation (fal.ai, Anthropic, Atlas Cloud), payment processing (Polar.sh), and analytics (Google Analytics) — under strict confidentiality.
- Public gallery: Content you explicitly submit and that we approve becomes publicly visible. You can withdraw a submission anytime.
- Legal compliance: If required by law, court order, or to protect our rights and users.
- Business transfers: If we are acquired or merge, your data may transfer under the same protections.
6. Cookies, Tracking, and Analytics
6.1 Cookies we use
We use minimal cookies, primarily for:
- Authentication (keeping you signed in via Google OAuth)
- Service preferences (e.g., aspect ratio selection)
6.2 Google Analytics 4
We use Google Analytics 4 (GA4) to understand how visitors use our Service. GA4 collects information such as:
- Pages visited and time spent
- Approximate location (country/region — IP addresses are anonymized)
- Device type, browser, and operating system
- Referral source (how you found us)
- Interaction events (e.g., button clicks, generations completed)
Google Analytics uses cookies and similar technologies. We have configured GA4 with IP anonymization enabled. Data collected through GA4 is processed by Google in accordance with Google's Privacy Policy.
You can opt out of Google Analytics tracking by installing the Google Analytics Opt-out Browser Add-on, or by blocking cookies/scripts via your browser settings or an ad blocker.
7. Your Rights
You have the following rights:
- Access: Request a copy of personal information we hold about you.
- Correction: Update inaccurate or incomplete information.
- Deletion: Request deletion of your account and content.
- Portability: Receive your generated content in a downloadable format.
- Opt-out: Stop using the Service at any time.
To exercise these rights, contact us at [email protected].
For users in the EU/UK (GDPR)
You also have the right to:
- Object to processing
- Restrict processing
- Lodge a complaint with your local data protection authority
Our legal basis for processing is: (1) performance of a contract (when you use the Service), (2) legitimate interests (improving the Service, fraud prevention), and (3) your consent (e.g., gallery submission).
For users in California (CCPA)
You have the right to know what personal information we collect, request deletion, and not be discriminated against for exercising your rights. We do not sell personal information.
For users in South Korea (PIPA)
We comply with the Personal Information Protection Act of South Korea. You may request access, correction, deletion, or suspension of processing of your personal information through the contact email below. Our personal information protection officer can be reached at [email protected].
8. Data Retention
- Active accounts: Data is kept while your account is active.
- Account deletion: Personal data is deleted within 30 days of your account deletion request, except where legally required to retain (e.g., tax records: 5 years per Korean law).
- Generated content: Public gallery items remain visible until you withdraw them or we remove them.
- Logs: Server logs are typically retained for 90 days for security and debugging.
- Analytics data: Google Analytics retains user-level data for 14 months (configurable).
9. Children
The Service is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us information, please contact us and we will delete it.
10. International Data Transfers
Your data may be processed in countries outside your country of residence, including the United States and Republic of Korea. By using the Service, you consent to such transfers. We use safeguards (such as Standard Contractual Clauses) where required by applicable law.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will post the updated policy here and update the "Last updated" date. For material changes, we will notify you via email or in-product notice.
12. Contact
For questions about this Privacy Policy or our data practices:
- Email: [email protected]
- Business: Bizglobal, Gyeonggi-do, South Korea
- Representative: Jihun Jung
- Business registration: 7604001387