LEGAL / PRIVACY

everyais studio Privacy Policy

This policy explains what information everyais studio handles, why and how long we keep it, and the rights available to you.

Version
v1.1.0
Effective
August 29, 2026

1. Scope

BROZ Inc. (the "Company," "we," "us," or "our") publishes this Privacy Policy to protect personal information and respond promptly to privacy concerns under the Personal Information Protection Act of Korea and other applicable law. It applies to everyais studio (the "Service") at studio.everyais.com.

2. Why We Process Information

  • confirm registration, authenticate through Firebase, and manage accounts and consent records;
  • generate and edit images from prompts and settings and provide job progress, outputs, and history;
  • manage Credits, payments, subscriptions, coupons, generated-data retention, and transaction records;
  • review and publish eligible free-credit outputs in the gallery and process consent withdrawals;
  • handle business inquiries, feature and model requests, support, and service notices;
  • measure usage and advertising performance and improve and market the Service where consent or another lawful basis applies;
  • detect and prevent abuse, duplicate benefits, security threats, and incidents; and
  • comply with legal obligations and handle disputes.

3. Information We Process and How We Collect It

CategoryInformation
Account and profileEmail, name, Firebase UID and authentication provider; optional account type, company, business number, country, and phone; and records of terms, Credit Pricing Policy, marketing-email, and gallery-publication consent and withdrawal
Image generationPrompts, input images, model, resolution, output count and other settings; generated images, previews, and thumbnails; job state, errors, Credits used, folder names, and timestamps
Payment and subscriptionsOrder and transaction IDs, amount, currency, status and time, purchased product or subscription, Credit ledger, masked card number and issuer, and encrypted recurring-payment key
Inquiries and requestsCompany and contact name, email, message, and optional phone, expected volume, funding program, use case, and reference URL
Acquisition and marketingUTM values, ad click IDs (gclid and fbclid), first landing path, referrer and time, coupon code, marketing consent and email-delivery history, and in-service events
Automatically collectedIP address, browser, operating-system and device information, access, request and security logs, cookies, time of use, and page information

We collect information you enter on registration, profile, generation, checkout, and inquiry screens; information created automatically when you use the Service; and information received from connected providers such as Firebase and our payment processor. We do not directly store your full card number or password.

4. Retention

InformationRetention period
Account, profile, consent, and generation-job recordsUntil account deletion or the purpose is complete, except records needed by law or to resolve a dispute
Generated images and thumbnails30 days after completion for welcome, coupon, and ordinary admin Credits; 365 days for purchased Credits; for subscription Credits, the earlier of 365 days and 30 days after all paid access ends. Mixed settlement uses the longest right actually charged. Gallery Studio publication is exempt while published, subject to consent withdrawal, delisting, or account deletion
In-progress previewsUp to 1 day after serving generation progress
B2B inquiries and feature requests3 years after completion or the separately agreed period
First-touch cookieUp to 90 days in the browser; linked acquisition data until account deletion after signup
Welcome-Credit duplicate-prevention recordFor the operating life of the Service while abuse and duplicate-grant prevention remains necessary
Contract, cancellation, and payment records5 years under Korean e-commerce law
Consumer complaint and dispute records3 years under Korean e-commerce law
Access logsAt least 3 months under applicable communications law
Marketing consent and withdrawal evidenceFor the period required by applicable law or reasonably needed to resolve a dispute

Where the law requires continued retention, we segregate the record and use it only for that purpose. User-generated data is excluded from cross-account backup; after access is blocked at expiry, every object version and delete marker is permanently removed by the next deletion job.

5. Disclosure to Third Parties

We do not disclose personal information to third parties except with your consent or as permitted by law. The following disclosures occur when necessary to complete a generation or payment you request.

RecipientInformationPurposeRetention
Google LLC (Gemini)Prompt, input image, and generation settingsAI image generation and editingFor processing and as provided by the provider's policy
Hecto Financial Co., Ltd.Order, amount, purchaser, and payment information needed for authorizationCard and recurring-payment processingUnder applicable electronic-finance law and the provider's policy

6. Service Providers

ProviderProcessing
Google Cloud and FirebaseAuthentication, server, database and task-queue operations, and AI image generation
Amazon Web ServicesGenerated-image storage and delivery and service-email delivery
Vercel Inc.Website hosting and deployment
Hecto Financial Co., Ltd.Payment and recurring-payment method processing
Cloudflare, Inc.Bot verification for B2B inquiries
Google LLC and Meta Platforms, Inc.Web analytics, advertising measurement, and conversion analysis when configured

We use contractual and operational controls to require service providers to protect personal information and disclose changes to providers or processing through this Policy.

7. International Transfers

Recipient and countryInformationPurpose and methodRetention
Google LLC · United States and service-processing regionsAccount identifiers, prompts, input images, generation settings, and access informationEncrypted transfer as needed for authentication, AI processing, and cloud operationsFor service delivery or under Google's policy
Vercel Inc. · United StatesIP, device, and access logsEncrypted transfer on access to deliver the websiteFor service delivery and under Vercel's policy
Cloudflare, Inc. · United StatesIP, browser information, and verification tokenEncrypted transfer when an inquiry is submitted to verify human useFor verification and under Cloudflare's policy
Google LLC and Meta Platforms, Inc. · United States and other regionsCookies, ad identifiers, page and conversion eventsEncrypted transfer on access when analytics or advertising is configuredUnder each provider's policy

You may object by stopping the relevant feature or requesting account deletion. Essential transfers are required for features such as authentication and image generation, so refusing them means those features cannot be provided.

8. Cookies, Analytics, and Advertising

  • A language cookie remembers your choice for up to one year.
  • A first-touch cookie measures campaign and signup attribution for up to 90 days.
  • Firebase may use storage or tokens necessary for authentication state and security.
  • Depending on production configuration, Google Analytics, Google Ads, and Meta Pixel may process page-view, registration, purchase, and related events.
  • You can delete or block cookies in your browser and limit personalized advertising in the relevant platform settings. Blocking essential cookies may prevent sign-in and other features from working.

10. Your Rights

  • request access, portability, correction, deletion, or restriction and withdraw consent;
  • withdraw marketing-email and gallery-publication consent in Settings; and
  • exercise rights through a lawful representative.

Submit a request through Settings or to portal@everyais.com. After verifying you or your authorized representative, we respond within the period required by law. A request may be limited where retention is required by law or it would infringe another person's rights.

11. Deletion and Security

We delete personal information without undue delay when its retention period expires or its purpose is complete. Electronic files are deleted using methods designed to prevent recovery, paper is shredded or incinerated, and records required by law are segregated.

Our safeguards include encryption in transit, least-privilege access, database access controls, encryption and key management for payment keys, abnormal-request controls, audit logs, private image storage, and expiring signed delivery URLs.

12. Privacy Contact and Remedies

  • Privacy officer: Seungyun Kim
  • Title: Representative director
  • Email: nilk@broz.co.kr
  • Phone: +82-10-2798-3438
  • Company: BROZ Inc.
  • Business registration no.: 288-81-02136
  • Address: Suite 503, 5F, 465 Dongdaegu-ro, Dong-gu, Daegu, Republic of Korea

In Korea, you may also contact the Personal Information Dispute Mediation Committee (1833-6972), the Privacy Infringement Report Center (118), the Supreme Prosecutors' Office (1301), or the National Police Agency (182).

13. Changes to This Policy

We announce additions, deletions, or amendments at least 7 days before they take effect. We provide at least 30 days' notice of a change that materially affects User rights and obtain renewed consent where required.

This Policy takes effect on August 6, 2026.