PRIVACY
Privacy Policy
Effective and last updated: September 11, 2026
1. Scope
This Privacy Policy explains how AIBU Inc. (주식회사 아이부, “AIBU,” “we,” or “us”) handles information when visitors and authorized business users access AIBU websites, Creative Studio, Marketing Intelligence, Knowledge Workspace, and related services (collectively, the “Services”).
2. Information we handle
- Service inquiries: company name, business email, intended use, selected language, source website, submission identifier, and receipt time when a visitor submits an inquiry.
- Account and organization information: email address, organization, role, invitation and sign-in state.
- Service content: prompts, uploaded or connected business materials, generated media, campaign outputs, review decisions, and feedback that users intentionally provide.
- Operations and billing information: feature usage, model and provider usage, costs, delivery status, audit events, error diagnostics, and security logs.
- Integration information: permissions and credentials required to operate integrations that an authorized administrator enables.
3. How we use information
We use information to provide and secure the Services, enforce organization and role boundaries, generate and improve user-requested outputs and workflows, operate integrations, provide support, measure usage and costs, detect failures or abuse, and comply with applicable obligations.
We use inquiry information to review service requests and respond to the provided business email. Inquiry records are available to authorized service administrators.
Customer content and preferences are isolated by organization and are not exposed to other customers. AIBU does not sell personal information or use Google user data for advertising.
4. Google API data
AIBU uses Amazon SES to deliver transactional messages such as account invitations, password-reset links, and operational or billing alerts. Google Drive access is requested separately when an authorized administrator connects customer storage to an AIBU service.
- AIBU does not require Gmail access to send transactional email.
- When Google Drive is connected, AIBU stores the connected account, granted scopes, an encrypted OAuth refresh token, selected folder IDs, and limited synchronization metadata.
- Google Drive data is used only for the customer-authorized service and tenant. It is not sold, used for advertising, or used to train or improve generalized or foundation AI models.
- Access is limited to the systems and authorized personnel needed to operate, secure, and support this feature.
AIBU's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
5. Sharing and service providers
We disclose information only to infrastructure, storage, communication, analytics, and AI providers needed to perform user-directed Services; to authorized members of the applicable customer organization; for security and abuse investigation; or when required by law. Providers receive only the information needed for their assigned function and are subject to applicable contractual and access controls.
6. Retention and deletion
We retain information for as long as needed to provide the Services, maintain security and auditability, resolve disputes, and meet contractual or legal obligations. Retention may vary by data type and customer agreement.
When a customer requests Google Drive disconnection, AIBU removes the stored OAuth credential. The Google Account owner can also revoke access at any time from the Google Account permissions page. Limited delivery, synchronization, and audit metadata may be retained for security and operational accountability.
7. Security
We apply role-based access controls, tenant isolation, encryption or protected secret storage, audit logging, and operational monitoring designed to protect information. No method of transmission or storage is completely secure, but we continually maintain safeguards appropriate to the Services.
8. Your choices
Authorized administrators can manage organization accounts and disconnect enabled integrations. To request access, correction, or deletion where applicable, contact us. Requests may be subject to organization authorization, security verification, and legal retention requirements.
9. Changes and contact
We may update this policy as the Services or applicable requirements change. The effective date above identifies the latest revision. Questions or requests can be sent to aibesideyou@gmail.com.