MIRI Hair AI

LEGAL

Privacy Policy

This policy explains what personal data MIRI Hair AI processes, why it is processed, and when it is deleted.

Effective date: 2026-08-25

1. Data controller

Gyugwang Lee (the ‘Operator’) processes personal data when providing MIRI Hair AI and protects users' personal data in accordance with applicable law.

2. Data, purposes, and retention periods

DataPurposeCurrent retention period
Photos and originals selected for Community publication, messages up to 100 characters, nickname, selected social accounts and links, votes, report reasons, and block recordsPublish Poll and Trend content, support user interactions, reports, blocks, moderation, and dispute handlingPublic display ends when the post is deleted or its images expire. Social links remain until edited or deleted. Internal post, vote, report, and block rows are retained during service use where needed for moderation, integrity, and disputes; account data is deleted six months after an account-deletion request. Image files follow the separate image-retention rules.
Social provider, provider identifier, email and display name (when supplied), nicknameLogin, account maintenance, and linking data after a device changeWhile the Service is used and for six months after an account-deletion request
Random device UUID generated by the app, its HMAC-SHA256 hash, and authentication tokenRestore an existing device account, maintain authentication state, and prevent duplicate sign-up bonuses on one deviceRaw server UUID until account deletion; device hash while the Service operates without a separate expiry; local value until app/browser data is cleared
Original face photo and generated result imagesAI hairstyle and hair-color compositing, and providing results and historyWithout a subscription, original face photos and full generated result images are retained for 90 days after the last successful result completes. While a subscription is active, unexpired files remain protected; after access ends, they are retained for 90 days from the effective time confirmed by the store. Full images are then deleted, while 128px list thumbnails may be retained separately. Manual deletion from History deletes them immediately; account withdrawal and legally required retention follow separate rules.
Selected style and hair color, job status, errors and timestamps, and points usedRun generation, show progress and history, and return points after a failureWhile the Service is used and for six months after an account-deletion request
Point ledger, product, amount and status, random billing-account UUID, store transaction ID, token/signature hashes, subscription and refund informationManage balances, verify store transactions, process subscriptions and refunds, and provide supportPurchased points do not expire while the account is active; subscription points expire at the end of each billing period. Six months after account deletion is requested, purchase records are separated from the account identifier and deleted once five years have passed since creation
HMAC-SHA256 hash of the social identifierPrevent duplicate sign-up bonuses after account deletion and re-registrationCurrently retained for the operation of the Service with no separate expiry

This data is processed only as necessary to enter into and perform the service agreement and respond to user requests. Actual transaction records are stored separately when required by applicable law.

Retention and deletion of images and community data

  • Original face photos and full generated images are processed for AI editing, result delivery, retries, and reuse of past photos. 128px thumbnails, generation metadata, and community references are handled separately.
  • Without a subscription they are retained for 90 days after the last successful result. During a subscription they are retained for the access period and for 90 days after its effective end. Refunds, revocations, and payment holds use the end time confirmed by the store.
  • After full images are deleted, 128px thumbnails and rows required for accounting, integrity, and disputes may remain within the stated purpose, but full-image access and public posts end.
  • A manual delete immediately removes the relevant server originals and full results regardless of the scheduled period. Copies downloaded to a device are outside server deletion.
  • Community posts become non-public when images expire; internal vote and report rows may remain where needed for moderation and integrity.
  • The share-branding choice does not change server retention or collect additional personal data.

3. Collection methods and device storage

  • We receive account information that you authorize from your chosen social login provider.
  • We collect photos, nicknames, styles, and hair colors when you select or enter them.
  • Authentication tokens, a random device UUID, and the page to return to after sign-in may be stored in local app or browser storage. Clearing app or browser data deletes the device-side values.

4. Disclosure to independent third parties

The Operator does not sell personal data or disclose it to an independent third party unless required by law or separately authorized by the user. Social login is initiated directly with the provider selected by the user, which then shares consented account data with the Operator as described below and under its own policy.

5. Data exchange with social-login providers

Authentication data is processed through a provider's screen or SDK only when the user selects that login. Each provider applies its own policy as an independent controller, and the Operator receives only the information needed to authenticate and link the account.

ProviderData processed during authenticationData received by the OperatorOperator retention
Google LLCClient ID, Google-issued ID token, IP address, browser and device informationProvider-specific user ID, email, and name when availableWhile the Service is used and for 6 months after a withdrawal request
Apple Inc.Client or Services ID, redirect data, nonce, Apple-issued ID token, IP address, browser and device informationProvider-specific user ID, email including private relay, and name when supplied on first loginWhile the Service is used and for 6 months after a withdrawal request
Kakao Corp.App ID, redirect data, authorization code or access token, IP address, browser and device informationKakao member ID, nickname, and email when consented and availableWhile the Service is used and for 6 months after a withdrawal request

No authentication data is exchanged with a provider unless that login is selected. Another login option may be used. Disconnecting the provider account does not automatically delete the MIRI Hair AI account; a separate withdrawal request is required. Instagram login is not currently offered.

6. Processing service providers

The Operator may use the following providers to deliver the Service. The original photo and generation instruction are sent only to the AI provider selected for that generation mode.

ProviderProcessing task
Google LLC (Google Cloud)AI hairstyle and hair-color image generation in Gemini mode
Microsoft Corporation (Microsoft Foundry)AI hairstyle and hair-color image generation in FLUX mode
OpenAI OpCo, LLCAI hairstyle and hair-color image generation in Codex mode
Google LLCGoogle Play billing, subscriptions, and refunds
Apple Inc.App Store billing, subscriptions, and refunds

App-market providers may also act as independent controllers for payment processing under their own policies.

The Operator shares personal data only with processors whose contracts, policies, and account settings provide the same or equivalent purpose limitation, transmission security, retention and deletion, and training restrictions described in this Policy.

7. AI processing and international transfer

Photos are not sent to Google Gemini when the default test provider (‘Mock’) or an Operator-managed ComfyUI environment is used. The following applies only when the server is configured in Gemini mode.

Recipient
Google LLC (Google Cloud privacy inquiries)
Data transferred
Original face photo and English-language generation instructions reflecting the selected style and hair color
Countries
The United States and other countries or regions where Google or its agents operate processing infrastructure (the global endpoint does not guarantee a processing location)
Timing and method
API transmission over an encrypted network when generation is requested
Purpose
Generate an AI hairstyle and hair-color image
Google retention period
Default in-memory caching for up to 24 hours (which can be disabled for the project); prompts flagged as suspicious may be stored for abuse review for up to 90 days
Basis
Processing needed to provide the Service, as described in this Policy
How to opt out and what happens
No transfer occurs if you do not request photo generation. If you refuse, you may view public style information but cannot use image generation that relies on Gemini.

Google Cloud states that customer data is not used to train or fine-tune AI/ML models without prior permission or instruction. Separate retention conditions may apply to abuse-monitoring logs.

8. Overseas transfer to Microsoft Foundry FLUX

When the server is configured for FLUX mode, the following data is sent to FLUX.2-pro deployed in Microsoft Foundry.

Recipient and contact
Microsoft Corporation (https://aka.ms/privacyresponse)
Data transferred
Original face photo and an English generation instruction reflecting the selected style and hair color
Country
Azure regions worldwide used by Global Standard processing (stored data remains in the United States Azure geography)
Timing and method
On an image-generation request, through an encrypted HTTPS API to Microsoft Foundry
Purpose
Generate an AI hairstyle and hair-color image
Retention
Not stored in the inference model and processing ends after the request. Inputs or outputs flagged for abuse may be retained separately for safety review under Microsoft policy, contract, and account configuration
Transfer basis
Processing and storage necessary to perform the service contract, with disclosure in this Policy (Article 28-8(1)3(a) of Korea's Personal Information Protection Act)
How to refuse and effect
No transfer occurs if you do not request image generation. You can still view public style information, but cannot use image generation that relies on FLUX.

Microsoft states that Foundry inputs and outputs are not shared with model providers and are not used to train Microsoft or third-party models without explicit permission. Global Standard does not guarantee a specific processing country.

9. Overseas transfer to OpenAI Codex

When the server is configured for Codex mode, the following data is sent to OpenAI through the Operator-managed Codex app-server.

Recipient and contact
OpenAI OpCo, LLC (privacy@openai.com)
Data transferred
Original face photo and an English generation instruction reflecting the selected style and hair color
Country
The United States and countries or regions where OpenAI affiliates, partners, or service providers operate processing facilities
Timing and method
On an image-generation request, through the Operator-managed Codex app-server to OpenAI services
Purpose
Generate an AI hairstyle and hair-color image
Retention
According to the OpenAI account settings and policy. Stored content may remain until the Operator deletes it and is generally deleted within 30 days after deletion, subject to security and legal exceptions
Transfer basis
Processing and storage necessary to perform the service contract, with disclosure in this Policy (Article 28-8(1)3(a) of Korea's Personal Information Protection Act)
How to refuse and effect
No transfer occurs if you do not request image generation. You can still view public style information, but cannot use image generation that relies on Codex.

For individual ChatGPT and Codex services, submitted content may be used to improve models depending on the Operator account's data-control settings. Before processing user photos, the Operator must disable model training or apply a business agreement or another condition that restricts use beyond the requested processing.

10. Deletion procedure and method

Account access currently stops as soon as deletion is requested. Six months later, an automated process deletes the account records and folders containing the original and generated images. Actual transaction records are separated from the account identifier and deleted when the legally required period ends. The HMAC-SHA256 hash used to control sign-up bonuses remains instead of the original social identifier, but it is used to check re-registration and is therefore not treated as anonymous data.

11. Your rights and how to exercise them

  • You can edit your display name, sign out, or request account deletion from the Account screen.
  • You may request access, correction, deletion, restriction of processing, or raise an objection through the privacy contact below.
  • Some requests may be restricted when retention is required by law or another person's rights may be affected.
  • Individual images can be deleted from History. Data export and other privacy rights may be requested through the contact below.

12. Children's personal data

The account service is not directed to anyone under 13. If a user processes a photo containing a minor, lawful permission from both the photo subject and the legal guardian is required. If you learn that a photo was processed without the required permission, request deletion through the contact below.

13. Security measures

In production, data is encrypted in transit, the original identifier used to detect duplicate sign-up bonuses is converted to an HMAC-SHA256 hash using a server secret key, and transaction records retained by law are separated from account data. Report any suspected security weakness or data breach through the privacy contact below.

14. Privacy contact

Privacy contact
이규광
Privacy officer email
mirihairai@gmail.com
Operator
Gyugwang Lee
Company
Digitalnative
Email
mirihairai@gmail.com

15. Changes to this policy

If this policy changes, the effective date and main changes will be announced in the app. Material changes affecting user rights, including data items, purposes, retention periods, or international transfers, will be made easy to review before they take effect.