SERVICE INFORMATION
Privacy policy
욱스데브(dev) explains the information Earto processes, external processing and how you can exercise your rights.
Effective / updated
AI data notice: model-improvement use is enabled on the currently connected AI account. Text, images, models and results sent to OpenAI may be used to improve its models. Do not submit sensitive personal information or material you lack permission to share.
1. Information and purposes
| Information | Purpose |
|---|---|
| Google/Firebase identifier, email, display name/photo and authentication state | Sign-in, account/project ownership and access eligibility |
| Prompts, reference/annotation images, conversations, models, textures and versions | AI generation/editing, storage and resuming work |
| Public name, published metadata/previews and acquisition records | Store display, access rights and retaining acquired versions |
| Order/transaction references, currency/amounts and credit/refund/usage records | Payment verification, balances, reconciliation and refunds |
| Support contact details, messages and relevant order references | Support, rights requests and disputes |
| IP address, request time, browser/connection and error information | Delivery, security and incident response |
We process information provided by users or needed when they use the service, on the applicable basis of service performance, legal obligations, legitimate interests or consent where required. Publishing this policy is not a substitute for separate consent when the law requires it.
Card numbers and security codes are entered into Paddle checkout, not an Earto card-entry form. Earto does not collect your Google password.
2. Retention and deletion
Account and private-project material is retained while needed for the account or project service. Project deletion removes its conversations, versions and work data from the service database. Running or paused work may need to be ended first.
Public versions already lawfully acquired by other users and minimal entitlement records are retained separately for redownload rights. Project deletion does not automatically erase those records or external downloaded copies. Unpublication stops new acquisitions.
You can request account closure, access, correction, deletion or restriction through the contact below. After verifying the requester, information whose purpose has ended is deleted or made irrecoverable without undue delay; records legally required for retention are kept separately.
Where the Korean e-commerce retention rules apply, advertising records are retained for six months, contracts/cancellation and payment/supply records for five years, and consumer complaint/dispute records for three years. Only information needed for those purposes is retained.
Error/security records and access-restricted recovery backups may contain some processing data. We review relevant copies on a deletion request and destroy material when its retention purpose ends. External AI retention and erasure also follow the provider's account conditions, so deleting an Earto project does not instantly erase all external copies.
3. AI processing and model improvement
AI requests send the necessary prompts, conversation context, reference/annotation images, models, textures and outputs to OpenAI's Codex account-based service. Model-improvement use is currently enabled. Inputs and outputs may be used to improve models.
The provider may retain data for security, legal obligations and its own policy purposes. Contact Earto about AI-data processing or deletion so we can review the processing path. We cannot universally guarantee withdrawal of data already de-identified or incorporated into training.
If you do not want AI transmission, do not submit material for generation or editing; you can still browse public pages. Studio access is currently invitation-only.
4. External services and international processing
| Provider and role | Information and transfer | Location and retention |
|---|---|---|
| Google / Firebase Authentication — authentication | Account identifier, email and authentication data, transmitted at sign-in | United States; authentication service period and Google/Firebase deletion/security conditions |
| Oracle Cloud — Earto hosting | Project data, account identifiers, payment and usage records stored during service use | Tokyo, Japan; Earto retention/deletion criteria above |
| Cloudflare — connectivity and security | IP, connection and traffic information during website/API access | Global network locations; service/security purposes and Cloudflare policy |
| OpenAI — AI processing | Necessary input, images, models and results sent on AI requests | United States and other locations described by OpenAI; account settings and privacy/retention conditions |
| Paddle — merchant of record and purchase support | Checkout email, purchase, payment-method and transaction information | The Paddle entity shown on the transaction and policy locations; transaction, tax and dispute retention duties |
These processes support the functions described. You may refrain from the relevant function or ask for restriction/account closure if you do not want international processing; this can prevent delivery of the affected function. Transfers requiring separate legal consent must follow that consent process.
Paddle processes purchase and support data under its own privacy policy as merchant of record. The linked official policies give further information about processing locations, retention and provider contact channels.
5. Public content and browser storage
Only explicitly published model versions and public names are shared. Private conversations, references and account emails are excluded from Store previews. Personal information you place inside public material can nevertheless be seen or downloaded by others.
The browser may store sign-in state, language/preferences, local drafts and pending-payment recovery data. You can sign out or remove site storage through browser settings; doing so may erase device-local drafts and recovery information. Authentication/payment providers use their own necessary cookies and storage.
This policy does not itself subscribe you to advertising personalization or marketing emails.
6. Safeguards, rights and contact
Earto uses HTTPS, account ownership checks, restricted private configuration access and payment signature verification. Rights requests use the minimum necessary identity checks; we do not ask for passwords or card security codes.
Privacy contact: 유정욱, vojougae35@gmail.com, +82 10 7199 1442. Use the subject ‘Privacy request’ and identify the account and requested action. If a legal reason limits a request, we explain it.
In Korea, you may contact the Personal Information Infringement Report Center at 118 or the Personal Information Dispute Mediation Committee at 1833-6972. Member services currently target adults aged 19 or older; when we learn of ineligible use, we review it and take appropriate action.
Updates are announced on this page with their effective date. Additional notice or consent is provided where the law requires it.