1. Controller & representatives
The data controller is GENCY, INC., 131 Continental Dr, Suite 305, Newark, DE 19713, USA. Our Korean Privacy Officer (개인정보 보호책임자) is Sung-hoon Kang, reachable at support@studiolab.ai. Our EU representative under GDPR Art. 27 will be appointed before we begin actively offering the Service to consumers in the EEA.
2. What we collect
- Account: email, name, brand name, hashed password or OAuth identifier.
- Your Content: images and text you upload — which may include photographs of identifiable people — and AI-generated outputs.
- Billing identifiers: customer / subscription IDs from our payment partner. We do not store full card numbers.
- Usage data: IP address, approximate location, device / browser, page events, and errors.
- Shopify integration (if you install the GENCY for Shopify app): your Shopify store domain, store / contact email, product data (titles, descriptions, images), and app-subscription identifiers, which Shopify transmits to us so we can provide the app. This data is processed by GENCY, INC. on the same basis as other account data in this policy.
- Shopify storefront analytics (GENCY for Shopify app only): our app web pixel sends us the store domain, an event name, product IDs, a one-character anonymous A/B bucket derived from a one-way hash, and a timestamp. It does not read or transmit any customer name, email address, phone number, postal address, customer ID, or order number, and we store only daily aggregate counts. Full disclosure: /shopify-data.
3. Legal bases (GDPR Art. 6)
We process personal data to perform our contract with you (providing the Service, billing); to pursue legitimate interests (securing accounts and preventing abuse) balanced against your rights; to comply with legal obligations; and, where required, on your consent (non-essential cookies, analytics, and any marketing).
4. Photographs of people & AI processing
Where you upload photographs that identify individuals for face-related or virtual try-on features, this may involve special-category / biometric data. We process such images on your explicit consent and your representation that the depicted person consented; we do not use them to uniquely identify individuals, and you may withdraw consent by deleting the content. We do not use Your Content or prompts to train our own foundation models. To generate your outputs, content is sent to the AI providers listed in Section 6 and is handled under their terms and retention policies.
5. How we use data
To operate the Service (generation, storage, billing), to secure accounts and prevent fraud and abuse, and to improve the Service through aggregated analytics. We do not sell personal data.
6. Sub-processors
We use: Creem (payment processing / Merchant of Record) and Stripe (payment processing); Supabase (authentication, database, storage); Vercel (hosting); Cloudflare R2 (object storage); Anthropic, OpenAI, fal.ai, Replicate, eachlabs, and Segmind (AI model inference); Mixpanel (product analytics); Microsoft Clarity (session replay & heatmaps); Crisp (customer-support chat); Sentry (error & performance monitoring); and Shopify (GENCY for Shopify app integration and app-subscription billing, for merchants who use that app). A current list is maintained at /subprocessors. Content sent to AI providers is governed by their privacy and retention policies.
7. Cookies & analytics
We use cookies and similar storage that are strictly necessary (authentication session, locale) and, subject to consent where required (EEA, UK, Korea), analytics (Mixpanel, Microsoft Clarity) and support-chat (Crisp) storage. In those regions we obtain consent before setting non-essential storage, and you can change your choice at any time via . We do not set third-party advertising cookies.
8. International transfers
Data may be processed in the Republic of Korea, the United States, and other countries where our sub-processors operate. For transfers from the EEA we rely on Standard Contractual Clauses; for transfers of Korean users' data abroad we disclose the recipient, country, items, and purpose and obtain consent where the law requires.
9. Retention
We keep account data and content while your account is active. After a user-facing deletion, content is removed from active systems within 30 days; we retain the records the law requires — payment, contract, and withdrawal records for 5 years and consumer-complaint / dispute records for 3 years (Korean e-commerce law) — and delete other personal data within 1 year of the request. Backups are rotated within 90 days, and we carry out physical erasure on a verified legal request (e.g. GDPR / PIPA erasure).
10. Your rights
Subject to your local law (GDPR, PIPA, CCPA, etc.) you may access, correct, export, restrict, object to, or delete your personal data, and withdraw consent. Email support@studiolab.ai; during the beta we process account-deletion and export requests manually within 7 business days. You may also complain to a supervisory authority — in the EEA, your local DPA; in Korea, KISA (privacy report center 118) or the Personal Information Dispute Mediation Committee (개인정보분쟁조정위원회, 1833-6972).
11. Security
We apply administrative and technical safeguards including encryption in transit, access controls, and least-privilege access to protect personal data.
12. Children
The Service is for adults (18+). We do not knowingly collect data from children under 14 (Korea) or under the age of digital consent in your jurisdiction; if we learn we have, we delete it.
13. Breach notification
If a personal-data breach occurs, we notify affected users and the relevant authorities as and when required by applicable law.
14. California privacy rights (CCPA / CPRA)
California residents have the rights to know, delete, correct, opt out of sale/sharing, limit use of sensitive personal information, and non-discrimination. We do not sell or share personal information for cross-context behavioral advertising and have not done so in the past 12 months. To exercise access/deletion/correction rights, email support@studiolab.ai with the subject "CCPA request"; we respond within 45 days. Authorized agents may submit requests with written authorization.
15. Changes
We notify material changes by email or in-app at least 14 days in advance.