Lets Gen · Legal
개인 정보 보호 정책
This Privacy Policy explains how Buildmind Technology processes information when it operates Lets Gen.
마지막 업데이트: September 6, 2026
1. Information we process
Account information. When you create or access a Lets Gen Account, we process your name, email address, profile image when supplied, authentication records, and account settings. Lets Gen uses one-time email links and supported social providers rather than password authentication.
Google or Discord sign-in. If you select Continue with Google or Continue with Discord, the selected provider shares the account information permitted by the OAuth consent flow, such as your name, email address, and profile image when available. We use it to create or access your Lets Gen Account, keep you signed in, and associate your activity with that Account. We do not sell provider account data or use it for advertising.
Product content. We process Characters, Character drafts, Conversations, messages, voice-call transcripts, uploaded media, generated media, public creations, comments, likes, bookmarks, follows, reports, and related review records to provide the features you choose.
Purchases and subscriptions. When you buy Gems or subscribe to a paid feature, we receive purchase, entitlement, and transaction references from the relevant payment provider. Payment providers process card or storefront payment details; Lets Gen does not store full payment card numbers.
Purchase help and refund requests. If you ask for billing help, we process the selected purchase, request reason, preferred resolution, details you provide, review status, and related Gem or entitlement records. Do not include full card numbers, passwords, or other unnecessary sensitive information.
Reward-abuse prevention. We use a random, signed browser cookie or a resettable app installation identifier to associate Accounts, together with keyed IP hashes, a keyed hash of your email address, referral relationships, and promotional Gem activity. These identifiers are pseudonymous, not anonymous or hardware fingerprints. We use them to detect repeated free-reward claims, hold promotional rewards for human review, and enforce reviewed restrictions. The email hash is used only to keep the one-time new-Account Gem grant to one grant per mailbox, so that subaddressed or otherwise aliased addresses of the same inbox are not treated as new people. Purchased Gems remain available during a reward hold. You can contact support through our Discord to appeal a decision. Inactive browser and installation associations expire after 90 days unless needed for an unresolved reward restriction or manual block, IP-hash associations after 30 days, and email hashes after 90 days unless they belong to an Account that still exists. Manual restrictions and review decisions are retained while needed to enforce the decision and resolve disputes. We do not use these identifiers for advertising.
Security and technical information. Authentication sessions may include IP address and user-agent information. We also receive ordinary request, device, and service information needed to secure, operate, troubleshoot, and prevent abuse on the site and mobile app.
Product analytics. We collect a bounded set of first-party product events with allowlisted properties, and those first-party events are designed to expire after 90 days. Lets Gen does not store page or screen views or route paths in its first-party operational database. On the website and native mobile app, Google Analytics measures aggregate page or screen usage and acquisition, while PostHog receives only a limited set of product and reliability events: generation-start, creation-export, checkout-start, chat send and response timing, and front-end error reports. Front-end error reports contain an error message, a stack trace, and the app surface that failed. After sign-in, PostHog uses an opaque Account identifier and role so sessions remain connected; we do not send names or email addresses. PostHog automatic page views, element autocapture, session replay, heatmaps, and performance monitoring are disabled. Lets Gen does not send prompts, Conversations, uploaded or generated media, names, email addresses, route parameters, or URL query strings in custom Google Analytics or PostHog events.
2. How we use information
Providing the service includes authenticating Accounts, storing the private and public content you choose to create, sending requested prompts and selected reference media for AI processing, returning generated results, maintaining Gem balances, processing purchases, and delivering notifications.
Safety and moderation can include automated checks of prompts, Characters, messages, uploads, generated results, public posts, comments, and reports. Human review is used for public or reported material, support requests, appeals, and focused safety, fraud, security, or legal investigations when reasonably necessary.
Quality analysis means measuring whether a requested feature completed, failed, or produced a technically valid result. Service optimization means improving reliability, usability, pricing, routing, safety controls, and product features from operational and aggregate signals. We do not use private prompts, Conversations, uploads, or generated media to train Lets Gen's own generally available AI models unless we first ask for separate permission.
3. AI and media processing
When you ask Lets Gen to generate or edit content, we send the prompt, requested settings, and only the reference images, video, audio, Character material, or Conversation context needed for that request to reviewed AI and media-processing services. Image services receive image prompts and selected visual references; video services receive video prompts and selected frames or references; speech and transcription services receive the audio or text needed to provide the requested voice feature; and safety services receive the content needed to classify the request or result.
These services process the material to produce the requested output, perform a safety check, transcribe audio, synthesize speech, or return a technical status. The model family and execution service used for an individual request are operational details and may change without changing the customer-facing Lets Gen feature.
We also use service providers for hosting, storage, database, authentication, email, payments, aggregate analytics, and reliability. Depending on the feature, these include Cloudflare; Google and Discord for optional sign-in; Google Analytics and PostHog for the limited analytics described above; Stripe and applicable mobile storefront or subscription services for payments; and reviewed AI, speech, transcription, and media-processing services.
4. Other sharing
We do not sell personal information and do not use information received from Google or Discord for targeted advertising. We may disclose information when required by law, to respond to valid legal process, to enforce our Terms, or to protect users, Lets Gen, or the public.
5. Cookies and local storage
Lets Gen uses essential cookies and similar storage for authentication, security, and session continuity. Our reward-security browser cookie lasts up to 90 days and survives logout; the mobile installation identifier is stored separately from sign-in credentials. Clearing this storage resets the identifier but does not remove restrictions on an existing Account. The web app may also use browser session or local storage for limited product state, such as an analytics identifier or a dismissed daily-reward prompt. Google Analytics and PostHog may use cookies or similar technologies on the website, and the native Google Analytics SDK may use an app-instance identifier and device storage, for the limited analytics described above. You can control or delete browser cookies through your browser and reset or limit mobile identifiers through device settings, but disabling essential storage may prevent sign-in or other features from working.
6. Private, shared, and public content
Private by default. Draft Characters, private Conversations, private generations, saved private media, and ordinary uploads are available to your Account and the services needed to provide the feature. They do not become Community posts merely because they were created or uploaded.
Shared by link. When you enable a share link, anyone who has the link may view the material included in that shared page until sharing is disabled or the underlying material is deleted. Do not put information in a shared page that you do not want link recipients to see.
Public. Published Characters, approved Community posts, public prompts selected for publication, creator profiles, and visible comments can appear on public pages, feeds, creator pages, search within Lets Gen, external search results, and links shared by other people. Likes, follows, and other social activity may also be visible where the product says so.
Account deletion. Private Account material is removed subject to the limited records below. A public post that remains available is detached from the deleted profile and shown as written by Anonymous user without the former name, avatar, or profile link.
Lets Gen may link to Google, Discord, payment providers, AI providers, or other third-party services. Their own privacy policies apply when you use those services.
7. Retention and deletion
Account information, saved private media, private Characters, and private Conversations are kept while the Account or content remains active, unless you delete them sooner. Temporary Studio attachments are scheduled to expire after 7 days. Ordinary unsaved generated or uploaded media is scheduled to expire after 30 days. Saved media remains until it is unsaved, deleted, or the Account is deleted; active public posts and enabled share links can keep their included media available.
After media expires, generation records are reduced after 90 days by removing prompts, input locations, provider task references, and error details. Deleted-media tombstones used to prevent stale references are retained for up to 180 days. First-party product analytics are designed to expire after 90 days. Read notifications may be retained for up to 180 days and other notifications for up to one year.
Deletion can leave limited billing, transaction, moderation, fraud-prevention, security, legal, and dispute records where they remain necessary. Payment providers, app stores, and other processors may keep their own legally required records under their policies.
Purchase and refund records may be retained for accounting, fraud prevention, dispute resolution, and legal compliance even after other Account content is deleted.
You can stop Google or Discord sign-in by disconnecting or no longer using that provider to access your Account. You can request access, correction, or deletion of personal information by emailing support@letsgen.app. We may need to verify the request.
8. Security and changes
We use access controls, scoped service bindings, signed media delivery, encrypted transport, and other reasonable safeguards. No internet service can guarantee absolute security.
We may update this Privacy Policy when the service, providers, or legal requirements change. The date at the top identifies the latest version. Continued use after an update means the updated policy applies to future use.
이 문서 또는 개인 정보 보호 요청에 대한 질문? Email support@letsgen.app.