Ai-KomaCUSTOM MANGA STUDIO

Privacy policy

This English version is a courtesy translation. The French version prevails.

Version of 7 October 2026. What we record, why, on what legal basis, with whom, for how long, and how to exercise your rights (General Data Protection Regulation, “GDPR”, and the French Data Protection Act).

1. Controller

Florent Puccini EI (entrepreneur individuel), Chemin de la Daby, 83330 Le Beausset, France, publisher of Ai-Koma, is the controller. Contact for any question or to exercise your rights: contact@ai-koma.com. Ai-Koma has not appointed a data protection officer; this contact acts as such.

2. What we record, why and for how long

The information requested at sign-up (email address, password, date of birth) is mandatory: without it, we cannot open an account. We do not ask for your name or postal address, except your first and last name if you withdraw from a purchase. No advertising, no commercial profiling, no data resale, no marketing email.

3. Stories that may be intimate: explicit consent

The stories you write may reveal your sex life or sexual orientation, which are specially protected data (GDPR, art. 9). For any sensual or sexual romance story (level 2 and above), we ask for your explicit consent, through a box separate from the terms and conditions, before processing it; the date of that consent is kept with the project. You withdraw it at any time by deleting the project or your account, with no effect on your other projects. Your stories are used only to produce your pages; the team reads them only when necessary (support you ask for, a report, checking a safety refusal); they are never published and we do not use them to train models. Write fiction: do not include data identifying a real person.

4. Who receives your data

Apart from the team and Stripe, these recipients are our processors (GDPR, art. 28): they process your data on our behalf, on our instructions and only for the task described.

Transfers outside the European Union. Render, Cloudflare and Stripe are certified under the EU–US Data Privacy Framework (adequacy decision of 10 July 2023), complemented by the European Commission’s standard contractual clauses. For Supabase (Singapore), for SpicyAPI and its models, and for Resend, transfers rely on the European Commission’s standard contractual clauses. You can obtain a copy of these safeguards by writing to contact@ai-koma.com.

5. Automated decisions

Stories, storyboards and every page are checked automatically to enforce the service’s prohibitions: a story may be refused, a page redrawn and then removed (and refunded), and repeated refusals in one day may suspend an account while a person reviews the situation. You are told the reason each time. On simple request to contact@ai-koma.com, a person reviews any automated decision concerning you and you can express your point of view.

6. Minors

The service is open from age 15, the age of digital consent in France (Data Protection Act, art. 45). An account aged 15 to 17 only accesses all-audience content, and nothing sensual is offered to it. A person who signed up as a minor may ask at any time for the erasure of the data collected while a minor (art. 51): deleting the account from “My account” does it immediately.

7. Your rights

You may access your data, have it corrected or erased, restrict its processing, object to processing based on our legitimate interest, withdraw your consent at any time and get your data back in a reusable format: “My account” → “Download my data” (account, credits, purchases, projects), the export of each project and the download of the pages. You may also set instructions on what happens to your data after your death (art. 85). Write to contact@ai-koma.com: we answer within one month. You may lodge a complaint with the CNIL, 3 place de Fontenoy, 75007 Paris, France (cnil.fr).

8. Cookies

Only strictly necessary cookies, with no tracker or audience measurement, hence no consent banner: your session cookie (HttpOnly, thirty days); the one that remembers the chosen language (one year); the one that keeps the age proof of your session (erased when the browser closes, one hour at most without use); after a sign-up refused because the date of birth shows an age under 15, a technical cookie with no identifier that remembers that refusal for one day; and, where applicable, Cloudflare’s security cookies that protect the site against bots (a few minutes).

9. Security and incidents

Encrypted connection (HTTPS), hashed passwords, pages stored in a private space reachable only through your account, restricted admin access, backups at our hosting providers. In the event of a data breach, we record it, notify the CNIL within 72 hours when it presents a risk, and inform you if the risk is high.

10. Changes to this policy

A significant change is announced on the site before it takes effect. The version in force is always the one on this page.

Legal notice · Terms and conditions · Back