Ai-KomaCUSTOM MANGA STUDIO

Privacy policy

This English version is a courtesy translation. The French version prevails.

Version of 6 October 2026. What we record, why, on what legal basis, with whom, for how long, and how to exercise your rights (General Data Protection Regulation, “GDPR”, and the French Data Protection Act).

1. Controller

Florent Puccini EI (entrepreneur individuel), 83330 Le Beausset, France, publisher of Ai-Koma, is the controller. Contact for any question or to exercise your rights: [to be completed: contact email address]. Ai-Koma has not appointed a data protection officer; this contact acts as such.

2. What we record, why and for how long

The information requested at sign-up (email address, password, date of birth) is mandatory: without it, we cannot open an account. We do not ask for your name or postal address, except your first and last name if you withdraw from a purchase. No advertising, no commercial profiling, no data resale, no marketing email.

3. Stories that may be intimate: explicit consent

The stories you write may reveal your sex life or sexual orientation, which are specially protected data (GDPR, art. 9). For any sensual or sexual romance story (level 2 and above), we ask for your explicit consent, through a box separate from the terms and conditions, before processing it; the date of that consent is kept with the project. You withdraw it at any time by deleting the project or your account, with no effect on your other projects. Your stories are used only to produce your pages; the team reads them only when necessary (support you ask for, a report, checking a safety refusal); they are never published and we do not use them to train models. Write fiction: do not include data identifying a real person.

4. Who receives your data

Transfers outside the European Union. Render, Cloudflare and Stripe are certified under the EU–US Data Privacy Framework (adequacy decision of 10 July 2023), complemented by the European Commission’s standard contractual clauses. For Supabase (Singapore) and for SpicyAPI and its models, transfers rely on the European Commission’s standard contractual clauses. You can obtain a copy of these safeguards by writing to [to be completed: contact email address].

5. Automated decisions

Stories, storyboards and every page are checked automatically to enforce the service’s prohibitions: a story may be refused, a page redrawn and then removed (and refunded), and repeated refusals in one day may suspend an account while a person reviews the situation. You are told the reason each time. On simple request to [to be completed: contact email address], a person reviews any automated decision concerning you and you can express your point of view.

6. Minors

The service is open from age 15, the age of digital consent in France (Data Protection Act, art. 45). An account aged 15 to 17 only accesses all-audience content, and nothing sensual is offered to it. A person who signed up as a minor may ask at any time for the erasure of the data collected while a minor (art. 51): deleting the account from “My account” does it immediately.

7. Your rights

You may access your data, have it corrected or erased, restrict its processing, object to processing based on our legitimate interest, withdraw your consent at any time and get your data back in a reusable format: “My account” → “Download my data” (account, credits, purchases, projects), the export of each project and the download of the pages. You may also set instructions on what happens to your data after your death (art. 85). Write to [to be completed: contact email address]: we answer within one month. You may lodge a complaint with the CNIL, 3 place de Fontenoy, 75007 Paris, France (cnil.fr).

8. Cookies

Only strictly necessary cookies, with no tracker or audience measurement, hence no consent banner: your session cookie (HttpOnly, thirty days); the one that remembers the chosen language (one year); after a sign-up refused because the date of birth shows an age under 15, a technical cookie with no identifier that remembers that refusal for one day; and, where applicable, Cloudflare’s security cookies that protect the site against bots (a few minutes).

9. Security and incidents

Encrypted connection (HTTPS), hashed passwords, pages stored in a private space reachable only through your account, restricted admin access, backups at our hosting providers. In the event of a data breach, we record it, notify the CNIL within 72 hours when it presents a risk, and inform you if the risk is high.

10. Changes to this policy

A significant change is announced on the site before it takes effect. The version in force is always the one on this page.

Legal notice · Terms and conditions · Back