Published: July 23, 2026 · Effective: August 15, 2026 at 12:00 a.m. America/New_York · Version 2026-08-15

This Policy explains how Giz Inc. processes personal information across the integrated GizAI Service. Giz Inc., 24A Trolley Square, #1240, Wilmington, Delaware 19806, United States, is the service provider and controller/business responsible for the processing described here.

AX Solution Inc., #3600, 130 Eoulmadang-ro, Mapo-gu, Seoul, Republic of Korea, provides platform development, maintenance, infrastructure and model operations, cloud/API administration, technical support and customer support under Giz's instructions. It acts as a processor/service provider for those activities. It does not sell or independently advertise with GizAI user data.

1. Scope and roles

This Policy covers GizAI websites, apps, APIs, Chat, generation tools, Characters, Community, Drive, Computer, hosted runtimes, billing and support. Third-party websites, models and apps may have their own policies. If you connect or install one, review its terms.

2. Information we collect

  • Account and profile: name, email, password hash, profile, locale, preferences, account state, authentication records and dated records of legal acceptance or communication choices.
  • Private service content: prompts, messages, files, inputs, outputs, Drive data, Computer volumes and state, sites, code, tool calls and settings you choose to store or process.
  • Public content: Community posts, comments, reactions, profiles, media and publication metadata.
  • Billing: product, amount, currency, transaction and subscription identifiers, credits, usage and billing status. Card or cryptocurrency payment processors process payment credentials; Giz does not receive full card numbers or private cryptographic keys. A card processor may provide a payment-method fingerprint, brand and last four digits for payment security, fraud investigation and duplicate-charge handling.
  • Support: communications, attachments, diagnostic information and any access you authorize.
  • Connected clients: when you connect ChatGPT or another external client through OAuth, Giz records the client, granted scopes, authorization and token lifecycle, and tool requests made through that connection. The client receives only the tool results returned for actions within those scopes. You can revoke the connection from Giz account settings or the connected client.
  • Security and operations: IP address, request time, account and session identifiers, device/browser information, security events, errors and access logs.
  • Fraud-prevention device signal: a first-party signal derived from browser and rendering characteristics, including user agent, platform, language, timezone, screen, processor/memory class, installed browser plugins, canvas rendering and graphics renderer. The browser hashes these characteristics and the server immediately converts that hash into a keyed pseudonymous identifier; Giz does not store the raw characteristics.
  • Service measurement, experiments and attribution: page paths, feature-event names and parameters, selected model, counts, timing, coarse prompt length and media type, account or browser experiment assignment and, when optional storage is enabled, first-party analytics identifiers, referrer, initial URL, browser language, connection class and affiliate attribution. Restricted cookieless measurement does not send your Giz account ID, prompt text, user name, URL query string or media URL to Matomo. The analytics request still necessarily reaches Giz with ordinary network information such as IP address and user agent.
  • Federated sign-in: identity and profile fields returned within the scopes shown on the sign-in provider's consent screen.

3. Why we process information

We process data to perform the contract by creating accounts, authenticating, routing prompts, generating output, storing files, running computers, publishing content you select, charging and supporting you. We process information to comply with tax, accounting, sanctions, lawful-request and consumer obligations.

Our legitimate interests include securing the Service, preventing fraud and repeated abuse of free benefits, diagnosing failures, measuring and improving the Service through restricted first-party statistics and low-risk product experiments, enforcing terms, maintaining reliable infrastructure and defending legal claims. We limit the fraud signal to free usage, trial and security decisions and do not use it for advertising or Community ranking. You may object and appeal through support.

We rely on consent where applicable law requires it for analytics or terminal storage, including optional analytics cookies and affiliate attribution in the EEA. In the UK, restricted aggregate service statistics and anonymous A/B assignment operate under the PECR statistical-purposes exception unless you object through Cookie settings; full analytics and affiliate attribution remain off unless you allow them. In other regions, optional analytics storage is enabled by default where permitted and can be disabled in Cookie settings. A signed-in account's product-experiment assignment is stored in the account and remains effective independently of browser analytics cookies.

4. AI processing and model training

When you use an AI feature, we transmit only the content reasonably necessary to provide it—including your prompt, relevant conversation context, selected files and attachments, images, audio, video, tool inputs, instructions, generation settings and returned output needed for delivery—to Giz-operated infrastructure and/or the third-party model provider, API infrastructure provider or routing service selected for that request. A routing service may transmit that content to its downstream model or infrastructure provider.

We may select among multiple providers based on the requested model, availability, region, performance, cost and other operational factors. If an initial provider is unavailable or rejects the request, the request may be attempted with another provider; necessary content may therefore be transmitted to more than one provider for a single request.

We do not use private prompts, files or outputs to train Giz general AI models. Section 5 identifies recipient categories and purposes, Section 8 describes retention, and Section 10 describes processing locations and international transfers.

5. Recipients and subprocessors

We disclose only data needed for the stated purpose:

Recipient/category Purpose and data
AX Solution Inc. (Korea) Development, operations, infrastructure, model/API administration, technical and customer support; account, content and operational data only as needed
ServaRICA (Canada); Solid Systems (United States); Vast.ai (selected host country); bunny.net (global edge locations) Hosting, standby, GPU capacity, storage and content delivery; service content, account data, volumes, IP and operational logs as applicable
OpenAI (United States); Microsoft Azure OpenAI (configured United States, Sweden, Poland and UAE regions); Anthropic (United States); Google model APIs (United States/global); DeepSeek (China); Groq and DeepInfra (United States) AI inference; content described in Section 4
OpenRouter (United States; selected downstream model and infrastructure provider locations) AI inference and routing; content described in Section 4
Runware (United Kingdom; processing in the United States, Germany and Romania); Replicate and AtlasCloud (United States); selected downstream model providers in their processing locations AI inference and routing; content described in Section 4
Serper and Google translation services (provider processing locations) Search terms, target URLs or text segments and necessary request metadata when you request or enable those functions
Stripe (United States/global) and NOWPayments (Saint Vincent and the Grenadines and its service locations) Card or cryptocurrency checkout, subscriptions, invoices, refunds, payment status, reconciliation and fraud prevention
ipquery.io and ip-api.com (provider processing locations) IP address and necessary request metadata for localization, account security and repeated free-benefit abuse prevention
Google OAuth (United States/global) Identity and profile fields within the scopes shown on its consent screen
Amazon Web Services SES (Australia) Recipient address, message content and delivery metadata for account, security, billing and support communications

Model creators displayed in the catalog are not necessarily data recipients. We update this Policy when we use a new recipient category or materially different purpose.

Where a routing or infrastructure service selects among frequently changing subprocessors or processing locations, you may request the current recipient, contact and destination before using the feature at support@giz.ai.

We may also disclose information to comply with valid law, protect rights and safety, investigate abuse, or complete a merger, financing or sale subject to appropriate safeguards. We do not sell personal information and do not share it for cross-context behavioral advertising.

6. Human access to private content

Private content is not routinely read by people. Authorized personnel may access the minimum necessary content for support you request and authorize, a specific security or abuse investigation, compliance with law, or incident recovery. We do not permit routine human review of private content for general quality datasets without a separate voluntary opt-in.

7. Cookies and similar technologies

Essential storage supports authentication, security, preferences, service continuity and first-party fraud prevention. Visitors in the EEA are asked before optional analytics or affiliate storage is enabled. In the UK, Giz uses restricted aggregate service statistics and anonymous A/B assignment without a consent banner under the statistical-purposes exception, provides this notice, and provides a free objection through Cookie settings. Other regions use the default described in the Cookie Policy. Choosing Reject optional stops optional browser measurement and storage; signed-in product experiments continue from the account's server-side assignment rather than a browser analytics cookie.

8. Retention

Data Normal retention
Account, profile and private content While the account or requested feature is active; deleted or de-identified after account closure when no longer needed for the purposes below
Drive and Computer volumes While the storage or hosted service is active; deletion can begin after user deletion or service termination
Anonymous generation inputs and outputs 24 hours from file creation; not saved to an account
Published Community content While published; removed from active display when deleted, subject to content others already shared or lawfully archived
Anonymous/free abuse pseudonym 30 days
Signup/trial abuse pseudonym 90 days
Confirmed abuse, security and access records While needed to prevent repeated abuse, investigate incidents, enforce the Terms or defend claims
Service measurement, experiments and attribution While the information is needed for the stated measurement, improvement or reconciliation purpose
Support communications While needed to resolve the request and related disputes
Legal acceptance and communication-choice history While needed to prove the applicable agreement or honor and demonstrate the latest communication choice
Contracts, invoices, payment and tax records For the period required by applicable accounting, tax, payment and legal obligations
Replicated and recovery copies Until overwritten in the ordinary recovery cycle; used only for recovery

Third-party AI recipient retention differs under the applicable API or business agreement, data policy and routing configuration. The applicable recipient determines its retention period; you may request the current terms available to Giz at support@giz.ai. Giz retains information longer than the periods above only where necessary for law, disputes, security or fraud prevention and restricts it to that purpose.

9. Deletion and account closure

After account deletion, Giz deletes or de-identifies account-linked personal information when it is no longer needed for the purposes in the retention table. Public posts you delete are removed from active display; copies already shared by others or lawfully archived may remain outside Giz's control. Payment, fraud and legal records may remain for their stated purposes. Recovery copies expire through the ordinary overwrite cycle.

10. International transfers

Giz is based in the United States and operates with AX Solution in Korea. Data may be processed in the United States, Korea, Canada, Australia, the configured Azure regions, the location of a selected GPU host, and other countries where a selected model or infrastructure provider operates. When a routing service selects a downstream provider, the destination may include both the routing service's country and the downstream provider's processing country and may vary by request. For EEA transfers we use applicable adequacy decisions or Standard Contractual Clauses and supplementary measures; for UK transfers we use adequacy or the UK transfer mechanism. Korea's adequacy status is used only where its scope covers the transfer. You can request information about the relevant transfer safeguard.

For users in Korea, necessary overseas processing and storage are performed to enter into or perform the Service contract under Article 28-8(1)(3) of the Korean Personal Information Protection Act. Information is transferred over an encrypted network when you use the relevant model, search, translation, sign-in, payment, support or email function, or continuously while hosting, storage, delivery or security processing is active. Section 4 identifies the transferred AI content, Section 5 the recipient and purpose, this Section the destination and transfer method, and Section 8 the retention terms. You may decline an optional transfer by not selecting that feature or by withdrawing optional consent. A transfer necessary to provide a selected model, payment, sign-in, hosted storage or other requested function cannot be refused while still receiving that function; you may instead use an available Giz-operated alternative or discontinue the affected function.

11. Security

We use TLS in transit, authentication, access controls and operational security measures appropriate to the data and risk. No system is completely secure.

12. Your choices and rights

Depending on applicable law, you may request access, correction, deletion, portability or restriction; object to legitimate-interest processing; withdraw consent; appeal an automated or abuse decision; and complain to a regulator. Where California privacy law applies, California residents may request categories, sources, purposes, recipients and specific information, correction or deletion, and may not be discriminated against for exercising rights. We do not sell or share personal information for cross-context behavioral advertising.

Send requests to support@giz.ai. We may verify identity. Authorized agents must provide authority. We respond within the period required by applicable law.

13. Children

The Service is not directed to children under 13 and paid or hosted-compute services require legal capacity described in the Terms. We do not knowingly collect personal information from a child below the applicable digital-consent age without valid parental authorization. Contact us to request removal.

14. Changes and contact

We post the version and effective date, give prominent notice of material changes and seek renewed consent where required. We do not retroactively use previously collected private content for Giz model training or advertising through a Policy change alone.

Controller: Giz Inc., 24A Trolley Square, #1240, Wilmington, DE 19806, United States · support@giz.ai

Chief Privacy Officer and responsible executive: Kyungtae Kim, CEO · support@giz.ai

Korean operations processor: AX Solution Inc., #3600, 130 Eoulmadang-ro, Mapo-gu, Seoul, Republic of Korea