LEGAL
Privacy Policy
This policy explains what personal data MIRI Hair AI processes, why it is processed, and when it is deleted.
Effective date: 2026-08-25
1. Data controller
Gyugwang Lee (the ‘Operator’) processes personal data when providing MIRI Hair AI and protects users' personal data in accordance with applicable law.
2. Data, purposes, and retention periods
| Data | Purpose | Current retention period |
|---|---|---|
| Photos and originals selected for Community publication, messages up to 100 characters, nickname, selected social accounts and links, votes, report reasons, and block records | Publish Poll and Trend content, support user interactions, reports, blocks, moderation, and dispute handling | Public display ends when the post is deleted or its images expire. Social links remain until edited or deleted. Internal post, vote, report, and block rows are retained during service use where needed for moderation, integrity, and disputes; account data is deleted six months after an account-deletion request. Image files follow the separate image-retention rules. |
| Social provider, provider identifier, email and display name (when supplied), nickname | Login, account maintenance, and linking data after a device change | While the Service is used and for six months after an account-deletion request |
| Random device UUID generated by the app, its HMAC-SHA256 hash, and authentication token | Restore an existing device account, maintain authentication state, and prevent duplicate sign-up bonuses on one device | Raw server UUID until account deletion; device hash while the Service operates without a separate expiry; local value until app/browser data is cleared |
| Original face photo and generated result images | AI hairstyle and hair-color compositing, and providing results and history | Without a subscription, original face photos and full generated result images are retained for 90 days after the last successful result completes. While a subscription is active, unexpired files remain protected; after access ends, they are retained for 90 days from the effective time confirmed by the store. Full images are then deleted, while 128px list thumbnails may be retained separately. Manual deletion from History deletes them immediately; account withdrawal and legally required retention follow separate rules. |
| Selected style and hair color, job status, errors and timestamps, and points used | Run generation, show progress and history, and return points after a failure | While the Service is used and for six months after an account-deletion request |
| Point ledger, product, amount and status, random billing-account UUID, store transaction ID, token/signature hashes, subscription and refund information | Manage balances, verify store transactions, process subscriptions and refunds, and provide support | Purchased points do not expire while the account is active; subscription points expire at the end of each billing period. Six months after account deletion is requested, purchase records are separated from the account identifier and deleted once five years have passed since creation |
| HMAC-SHA256 hash of the social identifier | Prevent duplicate sign-up bonuses after account deletion and re-registration | Currently retained for the operation of the Service with no separate expiry |
This data is processed only as necessary to enter into and perform the service agreement and respond to user requests. Actual transaction records are stored separately when required by applicable law.
Retention and deletion of images and community data
- Original face photos and full generated images are processed for AI editing, result delivery, retries, and reuse of past photos. 128px thumbnails, generation metadata, and community references are handled separately.
- Without a subscription they are retained for 90 days after the last successful result. During a subscription they are retained for the access period and for 90 days after its effective end. Refunds, revocations, and payment holds use the end time confirmed by the store.
- After full images are deleted, 128px thumbnails and rows required for accounting, integrity, and disputes may remain within the stated purpose, but full-image access and public posts end.
- A manual delete immediately removes the relevant server originals and full results regardless of the scheduled period. Copies downloaded to a device are outside server deletion.
- Community posts become non-public when images expire; internal vote and report rows may remain where needed for moderation and integrity.
- The share-branding choice does not change server retention or collect additional personal data.
3. Collection methods and device storage
- We receive account information that you authorize from your chosen social login provider.
- We collect photos, nicknames, styles, and hair colors when you select or enter them.
- Authentication tokens, a random device UUID, and the page to return to after sign-in may be stored in local app or browser storage. Clearing app or browser data deletes the device-side values.
4. Disclosure to independent third parties
The Operator does not sell personal data or disclose it to an independent third party unless required by law or separately authorized by the user. Social login is initiated directly with the provider selected by the user, which then shares consented account data with the Operator as described below and under its own policy.
5. Data exchange with social-login providers
Authentication data is processed through a provider's screen or SDK only when the user selects that login. Each provider applies its own policy as an independent controller, and the Operator receives only the information needed to authenticate and link the account.
| Provider | Data processed during authentication | Data received by the Operator | Operator retention |
|---|---|---|---|
| Google LLC | Client ID, Google-issued ID token, IP address, browser and device information | Provider-specific user ID, email, and name when available | While the Service is used and for 6 months after a withdrawal request |
| Apple Inc. | Client or Services ID, redirect data, nonce, Apple-issued ID token, IP address, browser and device information | Provider-specific user ID, email including private relay, and name when supplied on first login | While the Service is used and for 6 months after a withdrawal request |
| Kakao Corp. | App ID, redirect data, authorization code or access token, IP address, browser and device information | Kakao member ID, nickname, and email when consented and available | While the Service is used and for 6 months after a withdrawal request |
No authentication data is exchanged with a provider unless that login is selected. Another login option may be used. Disconnecting the provider account does not automatically delete the MIRI Hair AI account; a separate withdrawal request is required. Instagram login is not currently offered.
6. Processing service providers
The Operator may use the following providers to deliver the Service. The original photo and generation instruction are sent only to the AI provider selected for that generation mode.
| Provider | Processing task |
|---|---|
| Google LLC (Google Cloud) | AI hairstyle and hair-color image generation in Gemini mode |
| Microsoft Corporation (Microsoft Foundry) | AI hairstyle and hair-color image generation in FLUX mode |
| OpenAI OpCo, LLC | AI hairstyle and hair-color image generation in Codex mode |
| Google LLC | Google Play billing, subscriptions, and refunds |
| Apple Inc. | App Store billing, subscriptions, and refunds |
App-market providers may also act as independent controllers for payment processing under their own policies.
The Operator shares personal data only with processors whose contracts, policies, and account settings provide the same or equivalent purpose limitation, transmission security, retention and deletion, and training restrictions described in this Policy.
7. AI processing and international transfer
Photos are not sent to Google Gemini when the default test provider (‘Mock’) or an Operator-managed ComfyUI environment is used. The following applies only when the server is configured in Gemini mode.
- Recipient
- Google LLC (Google Cloud privacy inquiries)
- Data transferred
- Original face photo and English-language generation instructions reflecting the selected style and hair color
- Countries
- The United States and other countries or regions where Google or its agents operate processing infrastructure (the global endpoint does not guarantee a processing location)
- Timing and method
- API transmission over an encrypted network when generation is requested
- Purpose
- Generate an AI hairstyle and hair-color image
- Google retention period
- Default in-memory caching for up to 24 hours (which can be disabled for the project); prompts flagged as suspicious may be stored for abuse review for up to 90 days
- Basis
- Processing needed to provide the Service, as described in this Policy
- How to opt out and what happens
- No transfer occurs if you do not request photo generation. If you refuse, you may view public style information but cannot use image generation that relies on Gemini.
Google Cloud states that customer data is not used to train or fine-tune AI/ML models without prior permission or instruction. Separate retention conditions may apply to abuse-monitoring logs.
8. Overseas transfer to Microsoft Foundry FLUX
When the server is configured for FLUX mode, the following data is sent to FLUX.2-pro deployed in Microsoft Foundry.
- Recipient and contact
- Microsoft Corporation (https://aka.ms/privacyresponse)
- Data transferred
- Original face photo and an English generation instruction reflecting the selected style and hair color
- Country
- Azure regions worldwide used by Global Standard processing (stored data remains in the United States Azure geography)
- Timing and method
- On an image-generation request, through an encrypted HTTPS API to Microsoft Foundry
- Purpose
- Generate an AI hairstyle and hair-color image
- Retention
- Not stored in the inference model and processing ends after the request. Inputs or outputs flagged for abuse may be retained separately for safety review under Microsoft policy, contract, and account configuration
- Transfer basis
- Processing and storage necessary to perform the service contract, with disclosure in this Policy (Article 28-8(1)3(a) of Korea's Personal Information Protection Act)
- How to refuse and effect
- No transfer occurs if you do not request image generation. You can still view public style information, but cannot use image generation that relies on FLUX.
Microsoft states that Foundry inputs and outputs are not shared with model providers and are not used to train Microsoft or third-party models without explicit permission. Global Standard does not guarantee a specific processing country.
9. Overseas transfer to OpenAI Codex
When the server is configured for Codex mode, the following data is sent to OpenAI through the Operator-managed Codex app-server.
- Recipient and contact
- OpenAI OpCo, LLC (privacy@openai.com)
- Data transferred
- Original face photo and an English generation instruction reflecting the selected style and hair color
- Country
- The United States and countries or regions where OpenAI affiliates, partners, or service providers operate processing facilities
- Timing and method
- On an image-generation request, through the Operator-managed Codex app-server to OpenAI services
- Purpose
- Generate an AI hairstyle and hair-color image
- Retention
- According to the OpenAI account settings and policy. Stored content may remain until the Operator deletes it and is generally deleted within 30 days after deletion, subject to security and legal exceptions
- Transfer basis
- Processing and storage necessary to perform the service contract, with disclosure in this Policy (Article 28-8(1)3(a) of Korea's Personal Information Protection Act)
- How to refuse and effect
- No transfer occurs if you do not request image generation. You can still view public style information, but cannot use image generation that relies on Codex.
For individual ChatGPT and Codex services, submitted content may be used to improve models depending on the Operator account's data-control settings. Before processing user photos, the Operator must disable model training or apply a business agreement or another condition that restricts use beyond the requested processing.
10. Deletion procedure and method
Account access currently stops as soon as deletion is requested. Six months later, an automated process deletes the account records and folders containing the original and generated images. Actual transaction records are separated from the account identifier and deleted when the legally required period ends. The HMAC-SHA256 hash used to control sign-up bonuses remains instead of the original social identifier, but it is used to check re-registration and is therefore not treated as anonymous data.
11. Your rights and how to exercise them
- You can edit your display name, sign out, or request account deletion from the Account screen.
- You may request access, correction, deletion, restriction of processing, or raise an objection through the privacy contact below.
- Some requests may be restricted when retention is required by law or another person's rights may be affected.
- Individual images can be deleted from History. Data export and other privacy rights may be requested through the contact below.
12. Children's personal data
The account service is not directed to anyone under 13. If a user processes a photo containing a minor, lawful permission from both the photo subject and the legal guardian is required. If you learn that a photo was processed without the required permission, request deletion through the contact below.
13. Security measures
In production, data is encrypted in transit, the original identifier used to detect duplicate sign-up bonuses is converted to an HMAC-SHA256 hash using a server secret key, and transaction records retained by law are separated from account data. Report any suspected security weakness or data breach through the privacy contact below.
14. Privacy contact
- Privacy contact
- 이규광
- Privacy officer email
- mirihairai@gmail.com
- Operator
- Gyugwang Lee
- Company
- Digitalnative
- mirihairai@gmail.com
15. Changes to this policy
If this policy changes, the effective date and main changes will be announced in the app. Material changes affecting user rights, including data items, purposes, retention periods, or international transfers, will be made easy to review before they take effect.