GenStudio Privacy Policy
⚠ This document is a draft template and has not been reviewed by legal counsel. Before it takes effect, it must be reviewed and approved by legal counsel engaged by [主体名称]; the publication date and effective date will be filled in when the text is finalized. "[主体名称]" is a placeholder for the operating entity's registered name.
Publication date: [TBD]
Effective date: [TBD]
1. Introduction and Scope
1.1 This Privacy Policy explains how [主体名称] ("we", "us" or "our"), when providing services to you through GenStudio (gen.yaspost.com, the "Platform"), collects, uses, shares, stores and protects your personal information, as well as which rights you have in respect of your personal information and how to exercise them.
1.2 This Policy applies to all of your use of the Platform's web pages, account system and open API. This Policy, together with the Terms of Service and the Refund Policy (linked in the page footer), constitutes the entire agreement; on matters concerning the handling of personal information, this Policy prevails.
1.3 Please read this Policy in full before using the Services. By continuing to use the Services, you confirm that you have read and understood the handling described in this Policy.
2. Information We Collect
We collect only the information necessary to provide the Services, namely:
2.1 Account information: the email address you provide when registering, the login password you set, and the invitation code you submit under invitation-based registration. Passwords are stored only in an irreversible encrypted (hashed) form; we cannot read your password in plain text. You may also set an interface language preference, which is stored together with your account so that it takes effect across devices.
2.2 Generation job data: the prompts and other generation parameters you submit, the image materials you upload, and the outputs produced from them (images, videos and so on), together with records such as job status and failure reasons.
2.3 Usage and accounting records: the ledger of credits granted, held, settled and expired; subscription status and periods; invoice and order records; and your open API call volume and quota usage.
2.4 Credentials and security information: the API Keys you create and your webhook endpoint configuration, together with the login time, IP address and User-Agent (browser and device identifier) in your session records — the latter three are used to identify devices and to detect abnormal logins and replays. The two kinds of credentials are stored in different forms, which we disclose truthfully:
- API Keys are stored only in an irreversible encrypted (hashed) form; after being shown to you once at creation, we cannot present the plain text to you again;
- webhook signing secrets are stored in a recoverable form because signature computation requires it — the HMAC signature of an outbound notification must be computed with the plain-text secret, and an irreversible hash cannot be used for signing. The product interface shows the secret only once, at creation and at rotation.
2.5 Log information: when handling requests, the server records operational logs such as access time, request path, response status and error messages, used for troubleshooting, security auditing and abuse prevention.
2.6 Payment information: payments are handled by a third-party payment channel (currently Alipay cross-border acquiring). We do not collect or store your bank card number, payment account password or other payment credentials; we retain only outcome information such as the order number, amount, currency, payment status and payment time, for accounting reconciliation.
2.7 We do not proactively collect information unrelated to providing the Services, and we do not require you to provide identity document numbers, biometric information or precise geolocation.
2.8 Information relating to anonymous trial access: when the platform offers anonymous
trial access (this feature is disabled by default), we collect a derived device
fingerprint hash — it is derived from your User-Agent (after truncation) and your IP
network segment, and is stored as a single fixed-length hash computed with a server-side key
using HMAC. That hash does not uniquely identify any particular device, and its use is
limited to abuse forensics and trial-budget attribution. At the same time, we create a
shadow account for the anonymous visitor (an internal account with no email address) to
hold the records created during the trial; if you register later you can claim that account,
and once claimed it becomes a regular account. The gs_anon cookie that carries the visitor
session identity is described in Section 4.9, and the retention periods for both of the
above items are described in Section 6.6.
3. How We Use Information
3.1 Providing the Services: creating and maintaining your account, verifying your login, executing the generation jobs you submit, delivering outputs to you, and storing your history and preferences.
3.2 Billing and settlement: holding and settling credits according to the model and specification you select, issuing and reconciling invoices, and handling subscription activation, renewal and cancellation.
3.3 Security, risk control and abuse prevention: detecting abnormal logins and credential leakage, limiting over-quota use and automated abuse, and maintaining the availability and integrity of the Services.
3.4 Content moderation: in order to comply with applicable law and the Platform Rules, we may carry out necessary technical processing and human review of input content and generated outputs.
3.5 Improving the Services: compiling statistics on feature usage and failure rates in order to locate defects, optimize performance and adjust the shape of the product. Analysis for this purpose is carried out in aggregated or de-identified form.
3.6 Notices and contact: sending you notices directly related to the Services (such as account verification, invoices, allowance-expiry reminders and announcements of material changes).
3.7 Cooperating with regulators as required by law: providing necessary information to the extent required by laws and regulations or lawfully required by a competent authority.
3.8 If we need to use your personal information for a purpose not stated in this Policy, we will obtain your consent separately.
3.9 Trial abuse prevention and budget attribution (where the platform offers anonymous trial access): using the derived device fingerprint hash described in Section 2.8 to recognize repeated trials by the same visitor, to attribute the limited free trial budget to a single visitor, and to retain forensic evidence where abuse occurs.
4. Notice on Cookies and Terminal Storage
The Platform does not use a cookie pop-up banner; the full notice in this chapter takes its place. We place mainly the following items in your browser (items relating to anonymous trial access are described separately in Section 4.9), and all of them serve either a strictly necessary function or the remembering of a preference, and none of them is used for cross-site tracking:
4.1 Login-state credential (cookie): named gs_rt, it stores a refresh credential used
to renew your login state. It carries the HttpOnly attribute (page scripts cannot read
it) and the SameSite=Strict attribute (it is not sent with cross-site requests), its path
is limited to /api/v1/auth (so it is sent only with authentication requests under that
path, such as login, renewal and logout), and it carries the Secure attribute when HTTPS
is used (the local development environment being the only exception).
It is strictly necessary for maintaining your login state.
4.2 Short-lived access tokens are not persisted: the access token used to call the API is kept only in the page's memory and sent in a request header; it is not written to a cookie, not written to localStorage and not written to sessionStorage. The cost of this is that after you refresh the page a new token must be obtained silently using the credential described in Section 4.1.
4.3 Language preference (cookie): named NEXT_LOCALE, it stores the interface language
you have chosen; its path is the site root, it is SameSite=Lax, and it is valid for one
year. Visitors who are not logged in also need to be able to switch language, so this item
is written on the browser side. It is not a credential.
4.4 Theme preference (localStorage): keyed theme, it stores your choice of light,
dark or system appearance. It is used to apply your choice before the page renders, so as
to avoid a flash.
4.5 Submission anti-duplication key (sessionStorage): keyed
genstudio.submit.nonce, it stores a random string used to prevent the same generation job
from being submitted twice (and therefore billed twice) when you refresh the page or click
repeatedly. It disappears when the tab is closed.
4.6 Credentials shown once are not persisted: when you create an API Key or a webhook secret, its plain text is shown once, in that page's memory only, and is not written to any browser storage.
4.7 No third-party advertising or analytics cookies: as of the publication date of this Policy, the Platform's pages do not load third-party advertising, social plugins or third-party analytics scripts, and therefore no such cookies exist. If any are introduced later, we will first revise this chapter and publish the revision.
4.8 Consequences of disabling: you may clear or block the above storage through your browser settings. Clearing or blocking the item in Section 4.1 will make it impossible for you to stay logged in (you will have to log in again on every page refresh); clearing or blocking the items in Sections 4.3 to 4.5 will only reset the corresponding preferences to their defaults, or disable the anti-duplication protection; clearing the item in Section 4.9 will mean that the browser can no longer continue to use its existing anonymous trial session identity.
4.9 Visitor session credential (cookie, set only where anonymous trial access is offered
and you use it): named gs_anon, it stores a 256-bit random value used to carry your
session identity as an anonymous visitor; the server stores only the hash of that value and
its mapping to the shadow account described in Section 2.8. It carries the HttpOnly
attribute (page scripts cannot read it) and the SameSite=Strict attribute (it is not sent
with cross-site requests), and it is valid for a fixed 30-day period from the creation of the shadow account,
not extended by use. Anonymous trial access is disabled by default: where the feature is not
offered, or where you do not use anonymous trial access, this item does not exist in your
browser.
5. Sharing of Information
Apart from the situations listed in this chapter, we do not provide your personal information to third parties. We do not sell your personal information.
5.1 Upstream model services (an inherent characteristic of the Services): the Platform does not train models itself; the generation capability is provided by third-party model providers. When you submit a generation job, your prompt, generation parameters and the image materials you upload are sent to the relevant upstream model provider in order to complete that generation; the outputs are retrieved by us and stored in our object storage. Upstream providers include self-hosted nodes and external commercial model services, and which provider handles a given job depends on the model you select. Upstream providers apply their own privacy and data-handling rules to the data they receive. If you do not want a particular piece of content to be sent to an upstream provider, please do not submit it as input.
5.2 Payment channels: in order to collect payment, we provide the third-party payment channel with information necessary for the transaction, such as the order number, amount and currency. The payment channel applies its own privacy policy to the payment information it collects.
5.3 Infrastructure providers: we use third-party servers, networks and storage facilities to host the Services. Such providers process data only on our instructions and may not use it for their own purposes.
5.4 Disclosure required by law: we may disclose necessary information where required by laws and regulations, where lawfully required by a judicial or administrative authority, or where necessary to protect the lawful rights and interests, life or property of us or of others.
5.5 Change of entity: in the event of a merger, division, reorganization or transfer of assets, we will require the recipient to remain bound by this Policy, or will obtain your consent separately before the change.
6. Storage and Retention
6.1 Location and form of storage: your account information, job records, usage records and accounting ledger are stored in our database; the materials you upload and the outputs generated are stored in our object storage. Outputs and materials are shown and downloaded to you personally via time-limited signed links, and are not publicly accessible.
6.2 Retention periods: account information is retained for as long as your account exists; job records, usage records and the accounting ledger are retained for as long as the Services exist, with the accounting ledger retained for the period required by applicable law for financial and compliance reasons; operational logs are retained for the period required for troubleshooting and auditing.
6.3 Temporary uploaded files: temporary files that you upload but do not use for generation are automatically cleared by lifecycle rules on the object storage side.
6.4 Handling after account deletion: account deletion takes the form of anonymization plus content erasure, specifically:
- your email address and account identifier are replaced with derived values that are non-routable and cannot be traced back to a natural person, your password is cleared, and the account is deactivated with the deletion time recorded;
- all of your login sessions are revoked and all of your API Keys are revoked (with the revocation record retained so that it can later be verified that "this credential was revoked at deletion"), and credential records relating to login and authorization are deleted;
- your generated outputs and persistent materials are deleted from object storage and the corresponding records are marked as erased; text content you entered within the Platform is cleared. Where an anomaly occurs (for example, an individual object that could not be fully cleaned up because of an external storage failure), the work is completed by manual review — we do not claim that this step completes unconditionally in a single pass in every situation;
- the account record itself and the accounting ledger are not physically deleted: they are the referents of the ledger and of historical jobs, and deleting them would break the integrity of the accounts. After the anonymization described above, what is retained in them is amounts and times, and the identifiers to which they correspond can no longer be traced back to you;
- session records (including IP address and User-Agent) are retained as evidence for security investigation and are handled under the log retention period in Section 6.2.
6.5 Deletion is irreversible. After deletion you cannot recover the account, historical outputs or unused credits.
6.6 Retention of records relating to anonymous trial access: the derived device fingerprint hash described in Section 2.8 is retained for 90 days and is then cleared by a reclamation job; a shadow account is anonymized and reclaimed where it has not been claimed within 90 days, and its fingerprint hash is cleared along with it. Once you have claimed (registered) that account it becomes a regular account and is handled under the other provisions of this chapter.
7. Your Rights
7.1 Access and correction: once logged in, you can view your account information, your credits balance and held amount, your subscription status and current period, your usage totals by model, and your historical jobs and outputs, and can change the editable preference items yourself. The specific items available for viewing are as actually displayed on the Platform. For information you cannot view or change yourself, you may contact us as provided in Article 11.
7.2 Deletion (account deletion): you may request deletion of your account; the precise
meaning and consequences of deletion are described in Section 6.4. After logging in, you may
self-initiate deletion in the danger zone of the "Account Settings" page
(/account/settings), which takes effect immediately. If you are unable to log in, you may
instead send an email to support@yaspost.com to request deletion, and we will carry it out
within a reasonable period after verifying your control of that account.
7.3 Data export (access and portability): the Platform currently does not provide an online self-service export feature. You may send an email to support@yaspost.com to request access or export, and we will handle it within a reasonable period after verifying your identity, providing the information we hold about you in an appropriate common format. This Section does not constitute a commitment to any automated export feature.
7.4 Withdrawal of consent: for processing carried out on the basis of your consent, you may withdraw your consent at any time; withdrawal does not affect processing already carried out before the withdrawal. Some processing is necessary in order to provide the Services (such as login state and accounting records), and withdrawing consent to it will make it impossible for you to continue using the Services.
7.5 Opting out of marketing notices: we do not send you marketing emails unrelated to the Services. Necessary notices directly related to the Services (account security, invoices, material changes) cannot be unsubscribed from separately.
7.6 Complaints channel: if you consider that our processing has infringed your rights and interests in your personal information, you may raise the matter by email to support@yaspost.com, and we will reply within a reasonable period. You also have the right to complain to a competent personal-information-protection regulator.
7.7 When you exercise the above rights, we may need to verify your identity first, so as to avoid disclosing your information to a person who is not entitled to it. For requests that are manifestly unfounded or repetitive, we may decline to act after explaining our reasons.
8. Minors
8.1 The Platform does not provide paid services to persons under 18 years of age. Users under 18 years of age should use the Services under the guidance of their guardian.
8.2 If you are a guardian and discover that the person under your guardianship has registered or paid without your consent, you may send an email to support@yaspost.com, and after verification we will deal with the relevant account and information according to the actual circumstances.
8.3 We do not knowingly collect the personal information of persons under 18 years of age; if we discover such information without a guardian's consent, we will delete or anonymize it after verification.
9. Cross-Border Transfers and Jurisdiction Notice
9.1 The Platform provides its services to users in several languages (currently Simplified Chinese, English and Spanish interfaces), and your information may be transferred to, and processed and stored in, the countries or regions in which we and our service providers are located. Your input content will also be sent to upstream model providers as described in Section 5.1, and those providers may be located in other countries or regions.
9.2 Your personal information is processed by [主体名称] in accordance with the law applicable at its place of registration.
9.3 Users located in the European Union or the European Economic Area have, in respect of their personal information, the rights of access, rectification, erasure, restriction of processing, data portability and objection to processing under the General Data Protection Regulation (GDPR); these are exercised as described in Article 7, and the rights of access and portability in particular are exercised as described in Section 7.3.
10. Changes to This Policy
10.1 We may revise this Policy because of changes in laws and regulations, adjustments to the shape of the Services, or security needs. A revised version takes effect on the date it is published on the Platform.
10.2 Where a material change concerns the purposes of processing, the means of processing or the recipients of sharing, we will bring it to your attention by appropriate means (such as an in-site notice or an email) and, where necessary, obtain your consent again.
10.3 Please review the latest version of this Policy from time to time.
11. Contact
11.1 If you have any question, comment or complaint regarding this Policy, or need to exercise the rights described in Article 7, please send an email to: support@yaspost.com.
11.2 We will verify and reply within a reasonable period after receiving your message.