Legal

Privacy Notice

Version 2026-09-01.1 · Effective September 1, 2026

Controller: Jason Mirsch · c/o Block Services, Stuttgarter Str. 106, 70736 Fellbach, Germany · contact@asgine.de

At a glance

We process data needed for accounts, AI stories, security, support and purchases. Prompts and relevant context go to selected AI infrastructure. We do not sell personal data or use third-party advertising trackers in the application. Account Center supports export and deletion; GDPR requests can be made through Support or the email above.

1. Data categories

Account: username, email, password hash, verification/recovery state, age confirmations, accepted notice versions and optional Google identifier/display name. Content: personas, characters, stories, universes, chats, messages, uploads, generated images, preferences, onboarding answers and continuity state. Technical/security: session identifiers, HMAC-protected IP and user-agent fingerprints, timestamps, limits, security events and request/error information. Commerce: order references/snapshots, product, amount, currency, provider state, token ledger, memberships, discounts, gifts, reversals and support records. We do not store payment-card or PayPal credentials.

2. Purposes and legal bases

Account administration, requested AI processing, storage, continuity, support and purchases use Art. 6(1)(b) GDPR. Accounting, tax, regulatory responses and required records use Art. 6(1)(c). Fraud prevention, security, abuse detection, debugging, aggregated product improvement and legal claims use Art. 6(1)(f); our interests are a secure, reliable and economically operable service. Optional external-account connection and processing explicitly presented as consent use Art. 6(1)(a), withdrawable prospectively. Public content is processed at your request under Art. 6(1)(b), not as consent to unrelated use.

3. AI processing

Runware receives prompts plus the minimum relevant story, persona, character, preference or chat context for the requested text or image operation and may route it to the model displayed by AsgineAI. Do not enter credentials or unnecessary sensitive information. AsgineAI stores returned output when the feature or your save action requires it. We do not provide inputs or outputs for unrelated advertising.

4. Recipients

Data is disclosed as needed to Runware for AI inference; OVHcloud for VPS/server infrastructure; Scaleway for transactional email; Google when you choose Google authentication (openid, email and profile only); and checkout providers, currently PayPal and, where enabled, Verotel, for payment, recurring billing, fraud checks, refunds and disputes. Advisers, authorities or counterparties receive data only where legally required or necessary for claims. Processors act under applicable data-protection terms; independent providers also apply their own notices.

5. International transfers

Core hosting runs on OVHcloud infrastructure in France. Runware states that its service may process data in the United States, Germany and Romania; actual routing can depend on model and configuration. Google, PayPal and other providers may process outside the EEA. Where GDPR Chapter V applies, transfers rely on an adequacy decision or appropriate safeguards such as Standard Contractual Clauses and supplementary measures where required.

6. Retention

Account and private creative data remain while the account exists or until the item is deleted. Public copies and permitted duplicates can remain independently. Sessions expire under the security lifecycle and end on logout, revocation or fingerprint mismatch. Verification, recovery, pending-order and rate-limit records expire after their operational window. Unreferenced uploads are deleted after a cleanup grace period. Support/security records remain only for the case, prevention or claims. Commercial and tax records are generally kept for applicable statutory periods, potentially up to ten years in Germany. Backups age out through their backup cycle.

7. Public content, gifts and preferences

Publishing exposes fields needed for the public page; anyone with an unlisted link may access it. Duplication permits an independent copy of the warned scope. Gift parties see counterpart username, product, delivery state and optional message, not credentials or unrelated billing. Preference weights inferred from choices tailor creation and are not used to personalize prices.

8. Cookies and browser storage

An essential HTTP-only cookie maintains sign-in/security. CSRF and OAuth transaction data protect requests. Browser storage remembers functional choices including interface state, model mode, token source, mascot settings and checkout recovery. AsgineAI currently uses no third-party behavioural advertising cookies; legally required consent will be requested before any future activation.

9. Security

Measures include password hashing, encrypted transport, access controls, origin/CSRF checks, OAuth state and PKCE, upload validation, rate limiting, session revocation, HMAC-protected fingerprints, server-owned prices and signed payment webhooks. No system is risk-free; report suspected compromise through Support.

10. Your rights

Subject to legal conditions, you have rights of access, rectification, erasure, restriction, portability and objection, including to Art. 6(1)(f) processing. You may withdraw consent prospectively and complain to a supervisory authority. Account Center offers correction, session revocation, export and deletion. Use Support Center or the controller email. The generally competent authority is the State Commissioner for Data Protection and Freedom of Information Baden-Württemberg; you may also contact the authority at your habitual residence.

11. Required data and automation

Account, security and feature inputs are required to provide the requested service; payment-provider data is required for purchases. AI creates content and automated controls can rate-limit, flag or temporarily block suspicious activity, but AsgineAI does not make solely automated decisions producing legal or similarly significant effects under Art. 22 GDPR. Material actions can be challenged through Support.

12. Changes

The version and effective date identify the current notice. Material changes are surfaced in-product and may require renewed acknowledgement before a later purchase.