Privacy Policy
Last updated: 2026-08-29
TORYMAKER ("we," "us," or "our") processes personal data to provide the AYou mobile app, website, and related services. The official document is published on ayoulog.com.
This Policy applies to:
Features marked as under development or hidden from the production release are not part of the current release scope.
| Feature | What is sent and to whom | AYou storage and deletion |
|---|---|---|
| Selfie Studio (profile and freeform image modes) | The selected or cropped photo, which may include a face, and the generation choices you provide are sent through the AYou API to the OpenAI API to create the requested image. | AYou does not write the original photo or generated result to an AYou database or Supabase Storage. The result is saved in the app's local documents storage until you delete it or remove the app. |
| Current mobile personal past-life generation | If you choose a photo, it, the selected world, and one class card are used for the requested result. The photo is sent through the AYou API to the OpenAI API for the portrait; the text portion may use the AI provider enabled for that request. | AYou does not write the original photo, personal result body, or generated portrait to an AYou database or Supabase Storage. Text results are stored in local SQLite and the portrait in local app documents until you delete the record or remove the app. |
| Sticker Studio | The image you select, which may include a face, and the requested sticker choices are sent through the AYou API to the OpenAI API to create the requested sticker. | AYou does not write the original image or generated sticker to an AYou database or Supabase Storage. The result remains in local app storage until you delete it or remove the app. |
| With together rooms | A selected photo that may include a face and the room's generation choices are sent through the AYou API to the OpenAI API to create a derived portrait. When a host requests the initial completed group/family image or a quality regeneration, the participant portraits already stored in the With room are sent to OpenAI again for that requested group image. | Derived portraits and completed images are stored in the private Supabase generated-images bucket for the room. They remain there until the host deletes the room. The host, room participants, and a person using a valid invitation or share link may receive a time-limited signed URL for the relevant stored output. |
We process personal data to:
Processing may rely on one or more of the following bases:
For users in the EEA, the With bases are assigned by purpose rather than combined into one blanket basis:
EEA legal bases for online ranked Baduk are also separated by purpose:
Another applicable basis, including compliance with a legal obligation, may apply where required by law.
To provide the Service, the following third-party services may process personal data, and data may be processed outside your country.
| Category | Provider | Purpose | Data that may be processed |
|---|---|---|---|
| Auth/DB/storage | Supabase | account authentication, database storage, session handling, star/purchase entitlements, account-based feature storage, online ranked Baduk, and private With output storage | account identifiers, entitlement data, star ledger entries, online ranked Baduk queue, match, seat, ready-state, and timestamp information; internal rating, rating deviation, and completed-match count; game events, scoring, result, and time; a short-lived seat ticket hash and expiry; With message numbers, bodies of messages not yet delivered, delivery/block status, limited-period report evidence, private With derived portraits and completed images, and service data you ask to save to an account; tarot and current mobile personal past-life result bodies, generated portraits, and their follow-up chats are excluded |
| Hosting/API | Vercel | web hosting, API execution, logs | request/response data, diagnostics |
| AI text — current AYou/Fren conversation, personalized friend creation, and Fren custom world | OpenAI API | replying in AYou/Fren chat; creating a requested friend profile or custom Fren world | the scoped message/recent turns/continuation summary; or the friend/world request and only the edited fields described in Section 3.5 |
| AI text — initial Tarot, web initial Saju, and mobile-app initial/Today Saju | the selected public model's OpenAI API or Google Gemini API recipient | interpreting the requested consultation | Tarot concern, selected cards/deck context, question metadata, and optional advisor. Web initial Saju sends only the question, optional advisor, and one minimum five-element balance focus or a general focus; it does not send original birth information or the full chart. Mobile-app initial/Today Saju may send the question or local date/focus area, a locally calculated derived Saju chart, and an optional advisor, but raw Saju birth-profile fields are removed before the AI request as described in Section 3.5. The exact selected provider/model is shown before sending. |
| AI text — Today Tarot, Link AI digest, and emotion essay | OpenAI API or Google Gemini API resolved in a data-free recipient preflight | interpreting three selected tarot cards; digesting a public webpage; or writing an emotion essay | Today Tarot: three selected cards and deck context, with no concern/profile/advisor. Link digest: selected URL plus the public title, description, and readable body fetched by AYou. Emotion essay: no more than 80 selected records' short note, emoji, valence, recorded time, and category. The exact recipient is shown before sending and is revalidated/pinned for the request as described in Section 3.5. |
| AI text — result follow-up | OpenAI API, Google Gemini API, or the provider named for a pinned public consultation model | answering a new question about the current result | new question, current result context, recent follow-up turns, continuation summary when present, and any selected cards/advisor needed for that result. A web Saju follow-up uses only the minimum balance consultation profile rather than the full chart; the exact recipient is stated before sending as described in Section 3.5. |
| Other AI text generation | Google Gemini API, OpenAI API, Anthropic Claude API | a separately scoped AI feature that identifies its actual provider before processing | only the inputs described in that feature's notice and needed for the request |
| AI image generation and face-data photo processing | OpenAI API | current mobile Selfie Studio, personal past-life portrait, Sticker Studio, and With portrait or group/family-image generation | selected or cropped photo pixels that may include a face, stored With participant portraits, generation choices, and the minimum visual context needed for the requested image; the retention in Section 3.4 may apply |
| Legacy account-linked personal past-life image | OpenAI API and Supabase | the compatibility /api/past-life/[id]/image route, which is not called by the submitted current binary | optional selected photo, account-linked narrative/draft and generation metadata, and the generated portrait/storage path, as described in Section 3.2 |
| Legacy account-linked relationship past-life | Google Gemini API and Supabase | the compatibility /api/past-life-relationship route, which is not called by the submitted current binary | selected shared photo, narrative inputs, generated narrative, generated images, and related account record/storage paths, as described in Section 3.2 |
| AI Beauty product search | OpenAI API | checking a product you request through GPT-5.6 Luna public-web search and returning source-linked editable candidates | product name; optional brand, size/version and purchase or sales country; device language; and the first public product URL you entered in the product materials or added from a search-result draft. Local skin-condition notes, subjective usage experience, and product notes are excluded |
| YouTube link metadata | YouTube/Google | retrieving the public title, channel, and thumbnail when you save a link | the YouTube link or video identifier you save and standard network/request information; video, audio, and caption content are excluded |
| Analytics/Push | Google Firebase (Analytics, Cloud Messaging) | usage analytics, push notifications, diagnostics | device/app-instance identifiers, event logs, push tokens |
| Ads/consent | Google Mobile Ads, User Messaging Platform | optional rewarded ads, regional consent and advertising privacy choices, completed-ad and reward-delivery confirmation | advertising identifiers, IP-based approximate location, device/app information, ad request/impression/interaction and reward-confirmation data, consent status |
| Billing/entitlements | RevenueCat | subscription and purchase entitlement checks, restore purchases, and—when the separately configured Firebase measurement integration is enabled—sending purchase lifecycle events to Google Firebase Analytics | an anonymous app user identifier before optional account connection, an account app user identifier after connection, Firebase app-instance identifier used only for that measurement link, purchase status, transaction metadata, and purchase-event value/currency |
| Payment processing | Apple App Store, Google Play | in-app billing, refunds, subscription cancellations | payment and transaction data |
| OAuth login | Google, Apple, Facebook, Kakao, and similar providers | social login authentication | OAuth identifiers, limited account profile fields |
We do not sell personal data for unrelated purposes without a legal basis or your consent.
Subject to applicable law, you may exercise the following rights:
To request account deletion, use in-app account settings, follow the guidance at https://ayoulog.com/delete-account, or contact torymakerapp@gmail.com. We will process requests according to applicable law and identity verification requirements.
Account deletion also applies to the account-linked profile, queue, and participant information for online ranked Baduk. Section 9 governs a completed game record after account identifiers have been removed.
For face-data photo processing, you can decline the next just-in-time consent notice to stop a future user-requested transfer. To remove an already-created result, delete the local result in its originating feature, ask the With host to delete the room when applicable, or contact us using Section 17 for a request relating to legacy account-linked personal or relationship data.
We apply reasonable technical and organizational safeguards, including: