Published: July 23, 2026 · Effective: August 1, 2026 at 12:00 a.m. America/New_York · Version 2026-08-01
This Policy explains how Giz Inc. processes personal information across the integrated GizAI Service. Giz Inc., 24A Trolley Square, #1240, Wilmington, Delaware 19806, United States, is the service provider and controller/business responsible for the processing described here.
AX Solution Inc., #3600, 130 Eoulmadang-ro, Mapo-gu, Seoul, Republic of Korea, provides platform development, maintenance, infrastructure and model operations, cloud/API administration, technical support and customer support under Giz's instructions. It acts as a processor/service provider for those activities. It does not sell or independently advertise with GizAI user data.
1. Scope and roles
This Policy covers GizAI websites, apps, APIs, Chat, generation tools, Characters, Community, Drive, Computer, hosted runtimes, billing and support. Third-party websites, models and apps may have their own policies. If you connect or install one, review its terms.
2. Information we collect
- Account and profile: name, email, password hash, profile, locale, preferences, account state, authentication records and dated records of legal acceptance or communication choices.
- Private service content: prompts, messages, files, inputs, outputs, Drive data, Computer volumes and state, sites, code, tool calls and settings you choose to store or process.
- Public content: Community posts, comments, reactions, profiles, media and publication metadata.
- Billing: product, amount, currency, transaction and subscription identifiers, credits, usage and billing status. Card or cryptocurrency payment processors process payment credentials; Giz does not receive full card numbers or private cryptographic keys. A card processor may provide a payment-method fingerprint, brand and last four digits for payment security, fraud investigation and duplicate-charge handling.
- Support: communications, attachments, diagnostic information and any access you authorize.
- Connected clients: when you connect ChatGPT or another external client through OAuth, Giz records the client, granted scopes, authorization and token lifecycle, and tool requests made through that connection. The client receives only the tool results returned for actions within those scopes. You can revoke the connection from Giz account settings or the connected client.
- Security and operations: IP address, request time, account and session identifiers, device/browser information, security events, errors and access logs.
- Fraud-prevention device signal: a first-party signal derived from browser and rendering characteristics, including user agent, platform, language, timezone, screen, processor/memory class, installed browser plugins, canvas rendering and graphics renderer. The browser hashes these characteristics and the server immediately converts that hash into a keyed pseudonymous identifier; Giz does not store the raw characteristics.
- Service measurement, experiments and attribution: page paths, feature-event names and parameters, selected model, counts, timing, coarse prompt length and media type, account or browser experiment assignment and, when optional storage is enabled, first-party analytics identifiers, referrer, initial URL, browser language, connection class and affiliate attribution. Restricted cookieless measurement does not send your Giz account ID, prompt text, user name, URL query string or media URL to Matomo. The analytics request still necessarily reaches Giz with ordinary network information such as IP address and user agent.
- Federated sign-in: identity and profile fields returned within the scopes shown on the sign-in provider's consent screen.
3. Why we process information
We process data to perform the contract by creating accounts, authenticating, routing prompts, generating output, storing files, running computers, publishing content you select, charging and supporting you. We process information to comply with tax, accounting, sanctions, lawful-request and consumer obligations.
Our legitimate interests include securing the Service, preventing fraud and repeated abuse of free benefits, diagnosing failures, measuring and improving the Service through restricted first-party statistics and low-risk product experiments, enforcing terms, maintaining reliable infrastructure and defending legal claims. We limit the fraud signal to free usage, trial and security decisions and do not use it for advertising or Community ranking. You may object and appeal through support.
We rely on consent where applicable law requires it for analytics or terminal storage, including optional analytics cookies and affiliate attribution in the EEA. In the UK, restricted aggregate service statistics and anonymous A/B assignment operate under the PECR statistical-purposes exception unless you object through Cookie settings; full analytics and affiliate attribution remain off unless you allow them. In other regions, optional analytics storage is enabled by default where permitted and can be disabled in Cookie settings. A signed-in account's product-experiment assignment is stored in the account and remains effective independently of browser analytics cookies.
4. AI processing and model training
We send the prompt, selected attachments, instructions and necessary context to the provider or Giz-operated infrastructure that runs the model you select. We do not use private prompts, files or outputs to train Giz general AI models. Third-party providers process requests under their API or business terms, which may include limited retention for security or abuse prevention. The recipient categories below describe those disclosures.
5. Recipients and subprocessors
We disclose only data needed for the stated purpose:
| Recipient/category | Purpose and data |
|---|---|
| AX Solution Inc. (Korea) | Development, operations, infrastructure, model/API administration, technical and customer support; account, content and operational data only as needed |
| ServaRICA (Canada); Solid Systems (United States); Vast.ai (selected host country); bunny.net (global edge locations) | Hosting, standby, GPU capacity, storage and content delivery; service content, account data, volumes, IP and operational logs as applicable |
| OpenAI (United States); Microsoft Azure OpenAI (configured United States, Sweden, Poland and UAE regions); Anthropic (United States); Google model APIs (United States/global); DeepSeek (China); Groq, OpenRouter and DeepInfra (United States) | Text, multimodal, embedding or speech inference; prompt, attachments and necessary output context selected for the request |
| Runware (United Kingdom; processing in the United States, Germany and Romania); Replicate and AtlasCloud (United States); selected model providers used through those routing services (provider processing locations) | Image, video or audio inference; prompt, media inputs, generation options and returned output |
| Serper and Google translation services (provider processing locations) | Search terms, target URLs or text segments and necessary request metadata when you request or enable those functions |
| Stripe (United States/global) and NOWPayments (Saint Vincent and the Grenadines and its service locations) | Card or cryptocurrency checkout, subscriptions, invoices, refunds, payment status, reconciliation and fraud prevention |
| ipquery.io and ip-api.com (provider processing locations) | IP address and necessary request metadata for localization, account security and repeated free-benefit abuse prevention |
| PromoKit (provider processing locations) | Referral and purchase-attribution metadata after permission |
| Google OAuth (United States/global) | Identity and profile fields within the scopes shown on its consent screen |
| Amazon Web Services SES (Australia) | Recipient address, message content and delivery metadata for account, security, billing and support communications |
Model creators displayed in the catalog are not necessarily data recipients. Requests can be routed through an infrastructure provider different from the model creator, and that provider may use the selected model creator as its subprocessor. Providers may be added or removed at any time, and this list may not always reflect the providers currently in use; new recipient categories or materially different uses trigger a Policy update.
Where a routing or infrastructure service selects among frequently changing subprocessors or processing locations, you may request the current recipient, contact and destination before using the feature at support@giz.ai.
We may also disclose information to comply with valid law, protect rights and safety, investigate abuse, or complete a merger, financing or sale subject to appropriate safeguards. We do not sell personal information and do not share it for cross-context behavioral advertising.
6. Human access to private content
Private content is not routinely read by people. Authorized personnel may access the minimum necessary content for support you request and authorize, a specific security or abuse investigation, compliance with law, or incident recovery. Private content is not used for general quality-review datasets or Giz model training without a separate voluntary opt-in.
7. Cookies and similar technologies
Essential storage supports authentication, security, preferences, service continuity and first-party fraud prevention. Visitors in the EEA are asked before optional analytics or affiliate storage is enabled. In the UK, Giz uses restricted aggregate service statistics and anonymous A/B assignment without a consent banner under the statistical-purposes exception, provides this notice, and provides a free objection through Cookie settings. Other regions use the default described in the Cookie Policy. Choosing Reject optional stops optional browser measurement and storage; signed-in product experiments continue from the account's server-side assignment rather than a browser analytics cookie.
8. Retention
| Data | Normal retention |
|---|---|
| Account, profile and private content | While the account or requested feature is active; deleted or de-identified after account closure when no longer needed for the purposes below |
| Drive and Computer volumes | While the storage or hosted service is active; deletion can begin after user deletion or service termination |
| Anonymous generation inputs and outputs | 24 hours from file creation; not saved to an account |
| Published Community content | While published; removed from active display when deleted, subject to content others already shared or lawfully archived |
| Anonymous/free abuse pseudonym | 30 days |
| Signup/trial abuse pseudonym | 90 days |
| Confirmed abuse, security and access records | While needed to prevent repeated abuse, investigate incidents, enforce the Terms or defend claims |
| Service measurement, experiments and attribution | While the information is needed for the stated measurement, improvement or reconciliation purpose |
| Support communications | While needed to resolve the request and related disputes |
| Legal acceptance and communication-choice history | While needed to prove the applicable agreement or honor and demonstrate the latest communication choice |
| Contracts, invoices, payment and tax records | For the period required by applicable accounting, tax, payment and legal obligations |
| Replicated and recovery copies | Until overwritten in the ordinary recovery cycle; used only for recovery |
Provider retention can differ under its API/business agreement. We retain information longer only where necessary for law, disputes, security or fraud prevention and restrict it to that purpose.
9. Deletion and account closure
After account deletion, Giz deletes or de-identifies account-linked personal information when it is no longer needed for the purposes in the retention table. Public posts you delete are removed from active display; copies already shared by others or lawfully archived may remain outside Giz's control. Payment, fraud and legal records may remain for their stated purposes. Recovery copies expire through the ordinary overwrite cycle.
10. International transfers
Giz is based in the United States and operates with AX Solution in Korea. Data may be processed in the United States, Korea, Canada, Australia, the configured Azure regions, the location of a selected GPU host, and other countries where a selected model or infrastructure provider operates. For EEA transfers we use applicable adequacy decisions or Standard Contractual Clauses and supplementary measures; for UK transfers we use adequacy or the UK transfer mechanism. Korea's adequacy status is used only where its scope covers the transfer. You can request information about the relevant safeguard or current provider contact details.
For users in Korea, necessary overseas processing and storage are performed to enter into or perform the Service contract under Article 28-8(1)(3) of the Korean Personal Information Protection Act. Information is transferred over an encrypted network when you use the relevant model, search, translation, sign-in, payment, support or email function, or continuously while hosting, storage, delivery or security processing is active. The recipient, destination and purpose are identified in Section 5 and this Section. A recipient retains information only for the requested processing and delivery, the active hosted service, or any limited security, payment, dispute or legal period described in Section 8 or its applicable API/business terms, and then deletes or de-identifies it. You may decline an optional transfer by not selecting that feature or by withdrawing optional consent. A transfer necessary to provide a selected model, payment, sign-in, hosted storage or other requested function cannot be refused while still receiving that function; you may instead use an available Giz-operated alternative or discontinue the affected function.
11. Security
We use TLS in transit, authentication, access controls and operational security measures appropriate to the data and risk. No system is completely secure.
12. Your choices and rights
Depending on applicable law, you may request access, correction, deletion, portability or restriction; object to legitimate-interest processing; withdraw consent; appeal an automated or abuse decision; and complain to a regulator. Where California privacy law applies, California residents may request categories, sources, purposes, recipients and specific information, correction or deletion, and may not be discriminated against for exercising rights. We do not sell or share personal information for cross-context behavioral advertising.
Send requests to support@giz.ai. We may verify identity. Authorized agents must provide authority. We respond within the period required by applicable law.
13. Children
The Service is not directed to children under 13 and paid or hosted-compute services require legal capacity described in the Terms. We do not knowingly collect personal information from a child below the applicable digital-consent age without valid parental authorization. Contact us to request removal.
14. Changes and contact
We post the version and effective date, give prominent notice of material changes and seek renewed consent where required. We do not retroactively use previously collected private content for Giz model training or advertising through a Policy change alone.
Controller: Giz Inc., 24A Trolley Square, #1240, Wilmington, DE 19806, United States · support@giz.ai
Chief Privacy Officer and responsible executive: Kyungtae Kim, CEO · support@giz.ai
Korean operations processor: AX Solution Inc., #3600, 130 Eoulmadang-ro, Mapo-gu, Seoul, Republic of Korea