BefoAftr Studio · Legal
Privacy Policy
Effective and last updated: 2026-08-24
1. Information we process
Account and login: email, password hash or OAuth provider identifiers, workspace name and slug.
Onboarding and workspace profile: business vertical, business contact phone (E.164 and display form), recovery email and/or recovery phone, accepted terms version, and training/benchmark opt-in status and timestamp (off by default).
Service use: uploaded images and generated media URLs; site, pair, job, landing, and showroom metadata; publish and review status; AI generation, review, and usage events; device, access, and log data.
Channel connections: Instagram and YouTube account identifiers, access and refresh tokens (stored encrypted on the server only, not exposed to the browser), and connection or expiry status.
Public suggest/contact forms (for example /suggest): suggestion type, title, details, and optional name, company, email, phone, locale, and source.
Public contact CTA analytics: visits to measured contact links, phone-number reveal, and tap-to-call button events on landings or showrooms, plus anonymous visitor identifiers, source, and referrer host. We do not collect call audio or whether a call was completed.
Support and rights requests: information you send by email or similar channels.
Billing: selected plan identifier (Trial, 8 a month, 12 a month, founding), billing period and charge amount, and payment identifiers handled by PortOne (Korea cards) or Dodo Payments (US cards). We do not store full card numbers as a rule. For manual bank transfer, the minimum transaction details needed to confirm payment.
2. Why we process it
We use data to provide authentication, media generation, storage, publishing, support, fraud prevention, security, billing, service analytics, and legal compliance.
Training use is separate and opt-in; it is not enabled by default.
3. Providers and transfers
We use subprocessors that may process data in the United States, EU, or other countries where they operate. We require appropriate safeguards and disclose data only as needed to provide the service, comply with law, protect rights and security, or complete a corporate transaction.
Supabase (US and other regions): authentication, database, and related storage.
Vercel (US and other regions): web/API hosting, serverless processing, and logs.
Cloudinary (US, EU, and other regions): hosting and transformation of uploaded or generated images and video.
Railway (US and other regions): Shorts worker for video synthesis and job processing.
Google (US and other regions): Gemini image/vision processing; YouTube OAuth and Shorts upload when you connect a channel.
Kling (Singapore, China, and other regions): AI short-form video generation.
Replicate (US and other regions): AI short-form video generation as the primary provider.
fal.ai (US and other regions): AI short-form video generation when the primary provider is unavailable.
Meta/Instagram (US and other regions): Instagram account connection and content publishing when you connect and approve.
PortOne (Korea and other regions): Korea card billing keys and transaction identifiers.
Dodo Payments (provider country): US card charges and settlement identifiers as Merchant of Record.
Categories transferred: account and workspace data, contact details, media and metadata, channel tokens and identifiers, and usage or CTA events as needed for the feature in use.
Timing and method: at signup, upload, generation, channel connect, publish, or support request, via API over encrypted transport.
Retention: per our agreements with providers, their policies, and our Data Deletion notice (/en/legal/data-deletion). On a verified deletion request we ask providers to delete or de-identify data within Studio’s control.
4. Retention schedule
We delete or de-identify data when the periods below end. On account closure or a verified deletion request, the Data Deletion notice (/en/legal/data-deletion) applies first: acknowledgment within 1 business day, in-scope deletion within 7 business days, residual cleanup within 30 days.
Account and workspace profile (email, business and recovery contacts, vertical, terms and training opt-in records): for the life of the account; deleted or de-identified on verified deletion.
Service media and metadata (upload/generated media URLs, sites, pairs, jobs, landings, showrooms): for the life of the account or until the site/asset is deleted; Studio-hosted Cloudinary objects are included on deletion requests.
Channel connections (Instagram/YouTube identifiers, tokens, expiry status): while connected; deleted or de-identified on disconnect or deletion request.
Usage and CTA events (AI generation/usage, contact-link visits and tap-to-call): up to 24 months or until account deletion, whichever is sooner. De-identified aggregates for security or product metrics may be kept longer.
Public suggest/contact form submissions: up to 12 months after handling, or sooner on deletion request. Minimal anti-abuse records may be kept up to 24 months.
Support and rights-report records: up to 3 years for dispute handling, or longer if law requires.
Payment, contract, and transaction records when applicable: up to 5 years where consumer, tax, or similar law requires.
Security, access, and auth logs: up to 12 months, or the period required for communications data where applicable.
Infrastructure backups and residuals: cleaned up or destroyed within 30 days after a deletion request (not retained as a training or marketing corpus).
Training/benchmark opt-in media: while opt-in remains; removed from training retention on opt-out or deletion request.
5. Security and choices
You may request access, correction, deletion, or account disconnection at hello@befoaftr.com. See /en/legal/data-deletion for request steps.
We use access controls, tenant isolation, encrypted transport, and encrypted storage for sensitive channel tokens. No system is completely secure.
6. Contact
Controller: Findgagu Co., Ltd. (주식회사 파인드가구), CEO Jiyoon Kim, 1-dong, 29-2 Gagok-ro 88beon-gil, Hwado-eup, Namyangju-si, Gyeonggi-do, Republic of Korea, business registration number 374-81-02631, online sales registration no. 제2022-화도수동-125호, tel 031-592-7981.
Email privacy requests to hello@befoaftr.com. We may ask for verification before acting on a request.