Privacy Policy

Effective Date: February 25, 2026

aigpts.ai (hereinafter referred to as "we") attaches great importance to and is committed to protecting the security of your personal information. This Privacy Policy explains how we collect, use, store, disclose and protect your personal data when you access or use our website https://aigpts.ai/ (hereinafter referred to as "the Service").

We commit to processing your information in a legal, legitimate and transparent manner and taking reasonable measures to protect your right to privacy; your use of the Service constitutes your reading, understanding and agreement to all contents of this Privacy Policy.

I.Definitions

In this Privacy Policy:

● "We" refers to aigpts.ai;

● "Service" refers to the products and functions we provide through the website https://aigpts.ai/;

● "User" or "you" refers to an individual or entity that accesses or uses the Service;

● "Personal Data" refers to information that can identify or be used to identify a specific individual (in line with the definition of Personal Data under relevant U.S. state privacy laws and the EU GDPR);

● "Usage Data" refers to technical data automatically collected during the use of the Service, such as IP address and access behavior;

● "Cookies" refers to small data files stored on the user's device;

● "User Content" refers to any content you upload, submit or generate;

● "Generated Content" refers to content generated by AI Services based on user input;

● "AI Services" refers to functions driven by artificial intelligence or machine learning technologies;

● "Third-Party Service Providers" refers to third parties that provide technical or processing capabilities to support the Service, including AI service providers, payment service providers and cloud service providers;

● "Third-Party Social Media Services" refers to service providers (such as Google) that allow you to register or log in to the Service using a third-party account. When logging in through such services, we will receive basic information related to your account (such as name, email address or avatar) based on the scope of your authorization;

● "Applicable Law" refers to the data protection and privacy-related laws and regulations applicable to this Privacy Policy, including but not limited to relevant U.S. state privacy laws (such as the California Consumer Privacy Act (CCPA), the Virginia Consumer Data Protection Act (CDPA), etc.) and the EU General Data Protection Regulation (GDPR) and its implementation legislation in member states.

II.Information We Collect

We will collect the following types of information in accordance with the "principle of minimal necessity", and all collection activities comply with the requirements of Applicable Law:

1.Account Information: Such as email address (For the purpose of preventing duplicate registrations or abuse of the service, certain information may be processed and stored in an encrypted or hashed form, so that it cannot be used to directly identify individuals.), username, login credentials and account profile information, used for registration, login and account management. The collection is based on your consent to use the Service or the necessity of performing the service contract.

2.Third-Party Login Information: When you use a third-party authentication service such as Google Login, we will receive basic public information related to your account (such as name, avatar and email address) based on the scope of your authorization.

3.Usage Data: Technical data such as IP address, access time, browser type, device model, operating system version, page access records, usage duration and interaction behavior. Such data is only used for service optimization and not for identifying individual users; if it involves information that can identify individuals, we will strictly follow the requirements of Applicable Law to ensure legal and compliant data processing.

4.Payment Information: We do not directly store complete payment card information. Payments are securely processed by third-party payment service providers (such as Stripe), which will comply with both the U.S. PCI DSS standard and the requirements of the EU GDPR on payment data protection. We only receive transaction confirmation and subscription status information.

5.Communication Information: Email correspondence between you and us, customer service inquiries, feedback information and related attachments, used to handle your inquiries and feedback and improve service quality. The collection is based on your consent or the necessity of performing the service contract and protecting your legitimate rights and interests.

III. How We Use Your Information

1.Use:

We use your information only within the scope permitted by law, ensuring that the purpose of use is legal, clear and consistent with the purpose of collection, mainly for:

● Providing, maintaining and improving our Service;

● Managing user accounts and ensuring account security;

● Processing subscription and payment related matters;

● Providing customer support and responding to your inquiries and needs;

● Sending service-related notifications (such as account updates, service changes, etc.);

● Sending marketing information with your explicit consent, and you can unsubscribe at any time;

● Preventing fraud, abuse and security risks to ensure the normal operation of the Service;

● Analyzing service usage to optimize product experience and service functions.

We rely on our legitimate interests as the legal basis to process the above information, for the purposes of safeguarding the fair use of our services and preventing fraud or abuse.

Unless otherwise explicitly stated and with your written consent, we will not use your personal data to train artificial intelligence models.

2.Retention:

We retain Personal Data only for as long as necessary to achieve the purposes described in this Policy (or in accordance with the retention requirements of Applicable Law). After the expiration of the retention period, we will take security measures to delete or anonymize your Personal Data.

3.Deletion:

You have the right to delete or request us to assist in deleting the Personal Data we have collected about you (except as otherwise provided by law). You may exercise this right in the following ways:

① Directly delete some information within the Service (such as removing data from application settings);

② Update, modify or delete your personal information in the account settings after logging in to your account;

③ Contact us through the contact information at the end of this Policy to request access to, correction of, or deletion of your personal information. We will respond to your request within the time limit specified by Applicable Law.

When you delete your account, we will delete or irreversibly anonymize your personal information. We may, however, retain limited de-identified data where necessary for compliance with legal obligations, financial record-keeping, or the prevention of fraud and abuse (such as determining whether a free trial has already been used). This data cannot be used to identify you.

IV.Third-Party AI Processing Content

To provide artificial intelligence-driven functions (such as text generation, image generation, etc.), we may call relevant model capabilities through third-party AI service providers ("AI Service Providers"), which will complete relevant processing based on their own or cooperative models and technologies.

(1) Scope of Data Sharing: We only share the minimum scope of data necessary to realize the relevant functions, including but not limited to: user input content (such as text prompts), media files uploaded by users (such as images or videos), and relevant generation parameters or preference settings.

(2)Data Protection Measures:

① We will not take the initiative to provide third-party AI Service Providers with information that can directly identify you (such as name, email address or account ID);

② When technically feasible, we will de-identify or minimize the data to ensure that third-party AI Service Providers cannot identify individual users;

③ For EU users' data, if the third-party AI Service Provider is located outside the EU (including the U.S.), we will ensure that data transfer complies with the requirements of the EU GDPR on cross-border data transfer (such as signing EU Standard Contractual Clauses (SCCs)); for U.S. users' data, it will comply with the restrictions on third-party data sharing under U.S. state privacy laws.

(3)Important Notes:

① Third-party AI Service Providers will process relevant data in accordance with their own privacy policies, and we will require them to comply with relevant U.S. privacy laws, the EU GDPR and industry standards;

② We will select AI Service Providers that meet data protection standards within a reasonable scope and sign Data Processing Agreements (DPA) with them to clarify their data protection obligations (since we cannot fully control the behavior of third parties);

③ By using the Service, you indicate that you have understood and agreed to the above data processing methods;

④ You can control the data processing method by selecting different models or functions; if you do not want your data to be processed by a specific third party, you can choose other models or avoid using the functions supported by that provider.

V.Content Restrictions

To ensure the safe, legal and compliant use of the Service, you shall not engage in the following behaviors when using the Service (including AI functions):

1.Prohibition of Illegal and Inappropriate Content: Generate, upload, post or disseminate any illegal, fraudulent, misleading, harassing, hateful, violent, pornographic or other inappropriate content, including but not limited to content that violates the U.S. Computer Fraud and Abuse Act (CFAA), the EU Digital Services Act (DSA) and the provisions of the GDPR on the prohibition of abuse of personal data.

2.Intellectual Property and Privacy Protection: Prohibit posting or disseminating any content that infringes on others' intellectual property rights (copyright, trademark rights, patent rights, etc.) or privacy rights (including unauthorized use of others' works, portraits or personal information). Violators shall bear corresponding legal responsibilities.

3.False and Misleading Behavior: Do not impersonate others or institutions, or generate or disseminate deepfakes or other synthetic content that may mislead the public, especially not for fraudulent, defamatory or other illegal purposes.

4.AI Usage Restrictions:

a.When using AI functions, do not input or process sensitive personal information (such as race, religion, health or sexual orientation, etc.) unless you obtain your explicit written consent;

b.Do not use AI to generate content that may cause harm, mislead or be illegal;

c.Do not identify AI-generated content as human-created content without reasonable disclosure, and do not use it for commercial fraud or misleading consumers.

5.Prohibition of Service Abuse: Do not use the Service to engage in any illegal activities or abusive behaviors, including but not limited to using automated programs (bots) to interfere with the system, disrupt the normal operation of the Service, or access any part of the Service without authorization.

6.User Responsibility: You shall bear full responsibility for all content generated, uploaded or disseminated through the Service. If your actions cause losses to us or third parties, you shall bear compensation liability.

7.Enforcement Measures: If we reasonably believe that you have violated the above provisions, we have the right to take the following measures without prior notice: delete relevant content, restrict or suspend Service access, terminate your account; if necessary, we will report to the relevant regulatory or law enforcement authorities (including relevant U.S. and EU authorities) and cooperate with investigations.

VI.Cookies and Tracking Technologies

We use Cookies and similar tracking technologies (such as web beacons) to maintain user login status, analyze traffic and usage trends, improve functions and user experience, and provide personalized services.

Our use of such technologies will comply with both the requirements of U.S. state privacy laws on Cookie notifications and user choices, and the provisions of the EU GDPR and the ePrivacy Directive on the need to obtain explicit user consent for Cookie use. You can manage or disable Cookies through your browser settings, but disabling them may affect the normal operation of some functions (such as being unable to maintain login status, unable to use personalized services, etc.). We will not collect your sensitive personal information through Cookies, nor will we use them for purposes not explicitly stated in this Policy.

VII. Data Storage and Security

Your data will be stored on secure cloud servers (such as AWS or Google Cloud) that comply with U.S. data security standards and the EU GDPR data security requirements (including technical and organizational security measures).

We will take reasonable technical and organizational measures to protect your personal information, including but not limited to data encryption (transmission and storage encryption), access control (principle of least privilege), security monitoring, regular security audits and employee security training, to prevent your personal data from being unauthorized access, use, disclosure or tampering.

Although we have taken the above protection measures, internet transmission and storage cannot be guaranteed to be absolutely secure. You understand and agree to bear the relevant risks, and we shall not be liable for data leakage caused by force majeure, hacker attacks, third-party faults and other reasons not attributable to us.

VIII. Data Sharing

We will not sell, rent or share your personal information to any third party for marketing purposes. We may share your information in the following circumstances, and all sharing activities comply with the requirements of Applicable Law:

● To fulfill legal obligations or respond to legitimate government requests (such as court subpoenas, law enforcement investigations, etc.), including requests from relevant U.S. and EU regulatory and law enforcement authorities;

● Cooperate with contract-bound service providers (such as payment processing, cloud storage or data analysis). Such third parties may only use your information within the scope of providing services for us and must comply with this Policy and Applicable Law;

● Share with third parties designated by you with your explicit authorization or consent;

● In the case of corporate restructuring such as merger, acquisition or asset sale, share with the relevant transferee, who must continue to comply with the provisions of this Privacy Policy.

IX.Data Disclosure for the Use of Google Products and Services

Pursuant to Google's requirements, we hereby state: When you use the Service, it may involve data collection and processing behaviors of Google products and services (including collecting information through Cookies, web beacons, IP addresses or other identifiers), which will comply with Google's privacy policy and the requirements of Applicable Law.

Such information will be used for: data analysis to understand service usage, advertising delivery and effect measurement, and performance monitoring and optimization to improve service stability. Third parties (including Google) may place or read Cookies in your browser, or use web beacons and IP addresses to collect relevant information. To learn how Google uses data collected through partner websites or apps, please visit: https://policies.google.com/technologies/partner-sites

X.User Consent and Withdrawal

● Opt-in (Active Consent):

When you use our Service for the first time or enable specific functions (such as marketing information push, third-party AI data processing), we will request your explicit consent (in writing or electronic form). We will not carry out relevant data processing activities without your consent.

● Opt-out (Withdrawal of Consent):

You may turn off relevant functions through personal settings at any time, or withdraw your consent through the contact information at the end of this Policy. The withdrawal of consent will not affect the legal data processing activities carried out based on your consent before the withdrawal, nor will it affect the data processing we carry out based on legal obligations.

XI.Children's Privacy Protection

Our Service is not directed to children under the age of 13 (in compliance with U.S. COPPA) or children under the age of 16 (in compliance with EU GDPR), and we will not actively collect or store personal information of children in this age group.

If we discover that we have mistakenly collected information of children in the above age group, we will delete the relevant data immediately. If a parent or guardian believes that we have mistakenly collected children's information, please contact us at [email protected], and we will respond and handle it within 3 working days after receiving the request (in compliance with the requirements of COPPA and the EU GDPR on the deletion of children's data).

XII. Your Rights

To the extent permitted by Applicable Law, you have the right to exercise the following rights, and we will provide reasonable convenience for you to exercise your rights:

● Access your personal information and understand how we collect and use your personal data;

● Correct your personal information to ensure its accuracy and completeness;

● Delete your personal information (except as otherwise provided by law);

● Withdraw consent to data processing;

● Request export of your personal data so that you can transfer it to other service providers;

● Object to or restrict certain types of data processing (such as data processing for marketing purposes or automated decision-making).

You may exercise the above rights in the following ways:

① Directly delete or correct relevant information in the account settings;

② Contact us via email: [email protected]

XIII. Cross-Border Data Transfer

Your information may be transferred to servers outside your country or region for storage and processing. We will take reasonable safeguards to ensure that cross-border transferred data is properly protected:

① Sign data processing agreements with recipients and adopt encryption technologies that meet international standards;

② For the transfer of EU users' data to countries/regions outside the EU, ensure that the level of data protection is not lower than the EU requirements by signing EU Standard Contractual Clauses (SCCs), confirming that the recipient's country/region has an "adequacy decision", etc.;

③ For the cross-border transfer of U.S. users' data, comply with the restrictions of relevant U.S. state privacy laws.

XIV. Updates to This Privacy Policy

We may update this Privacy Policy from time to time to adapt to legal changes, service upgrades or business adjustments. The updated version will be posted on our website (https://aigpts.ai/) and marked with a new effective date, which will take effect on the date of posting.

If there are material changes (such as significant adjustments to the scope of data collection, purpose of use, or method of sharing), we will notify you through a website announcement, email or other reasonable means to ensure that you have sufficient time to understand the changes.

XV.Contact Us

If you have any questions, suggestions or complaints about this Privacy Policy, or wish to exercise your relevant rights, please contact us in the following way:

Email: [email protected]

For EU users, if you believe that our personal data processing behavior violates the EU GDPR, you have the right to file a complaint with the data protection authority of your member state.