Privacy Policy
Status: Draft
Effective date: August 30, 2026
Last updated: August 30, 2026
This Privacy Policy explains how Far Star Studio Ltd. (遠星工作室有限公司) ("Far Star Studio", "we", "us"), a company incorporated in Taiwan (Republic of China), collects, uses, and protects personal data when you use Content Forger (the "Service") or join our waitlist. We are the data controller for the personal data described here.
Contact for all privacy matters: [email protected]
This policy is written to comply with Taiwan's Personal Data Protection Act (PDPA) and, where applicable to you, the EU/UK General Data Protection Regulation (GDPR). We aim to describe only what the Service actually does today; when the Service changes, this policy will be updated.
1. Data We Collect
1.1 Account data
- Email address (required)
- Full name (required at sign-up)
- Password — stored only as a secure hash by our authentication provider (Supabase); we never see your plaintext password
- Profile picture and account identifiers from Google or GitHub, if you choose to sign in with those providers
1.2 Waitlist and invitations
If you join the waitlist or redeem an invitation code, we collect:
- Your email address
- Your answers to the waitlist questions (free-form survey responses)
- How you found us (referral source) and, for invitation codes, the campaign the code belongs to
We use this to manage early access and understand who is interested in the Service.
1.3 Content and generation history
- Your content: projects (including project context/guidelines), workflows, entry set data, and uploaded assets
- Generation history: the Service stores the complete inputs and outputs of each generation step — including your prompts, the project context sent with them, and the full generated text or images — so that you can review past runs
1.4 Usage and billing-related data
- Credit balance and a ledger of credit transactions (when credits were granted and spent, and on what)
- We do not currently collect any payment or billing information — the Service has no paid plans
1.5 Technical data
- We do not run any analytics or advertising trackers (see the Cookie Policy)
- Our hosting and infrastructure providers keep standard server logs (IP address, browser user-agent, request timestamps) for security and operations
- When you upload or view assets, your browser communicates directly with our storage provider (Cloudflare), which therefore sees your IP address as part of serving those requests
2. How We Use Data
We use personal data to:
- Provide and operate the Service (accounts, projects, generation, credit accounting)
- Send transactional emails through our authentication provider (e.g., sign-up confirmation, password reset). We do not currently send marketing emails.
- Manage waitlist access and invitations
- Secure the Service, prevent abuse and fraud, and enforce our Terms of Service
- Comply with legal obligations
We do not sell personal data, use it for advertising, or use your content to train AI models.
For users in the EEA/UK, our legal bases are: performance of a contract (operating the Service for you), legitimate interests (security, abuse prevention, service improvement), consent (waitlist participation), and compliance with legal obligations.
3. Who We Share Data With
We share data only with the processors needed to run the Service:
| Provider | What they process | Location |
|---|---|---|
| Supabase | Authentication (email, password hash, OAuth identities) and our database (all data in Sections 1.1–1.4) | United States |
| Cloudflare | Asset storage — files you upload and images you generate; sees your IP when your browser uploads/downloads assets | United States (global network) |
| OpenAI | Text generation — receives your prompts and the project context attached to them | United States |
| fal.ai | Image generation — receives your image prompts and parameters. Note: image models labeled "OpenAI" in the app are also routed through fal.ai | United States |
| Railway | Application hosting and server logs | United States |
| Google / GitHub | Sign-in, only if you choose OAuth login; they process your login per their own privacy policies | United States |
Under their current API policies, OpenAI and fal.ai do not use API-submitted content to train their models by default.
We may also disclose data where required by law, court order, or to protect the rights and safety of users or the public (including mandatory reporting of child sexual abuse material).
If the Company is involved in a merger, acquisition, or asset sale, personal data may be transferred as part of that transaction; we will notify you of any such change.
4. International Transfers
We are a Taiwan company, and our infrastructure currently stores and processes data in the United States through the providers listed above. We may additionally use infrastructure in Singapore in the future; if we do, we will update this policy.
Where GDPR applies, transfers to these providers rely on appropriate safeguards such as the providers' standard contractual clauses and data processing agreements. By using the Service you acknowledge that your data is processed in the locations described above.
5. Retention
-
Account, content, and generation history: retained while your account is active. Where the app offers deletion (e.g., deleting an asset or a workflow), deleted content is removed from the live database and storage.
-
Waitlist data: retained while we operate the waitlist, so we can grant access later.
-
After account deletion (Section 6): we delete your personal data from live systems within 30 days of verifying your request. Residual copies in encrypted backups are purged on our providers' backup rotation schedules.
-
Server logs: retained on our infrastructure providers' standard short-term schedules.
-
We may retain limited data longer where required by law or needed to resolve disputes or enforce agreements.
6. Your Rights
Subject to applicable law (including the Taiwan PDPA and, where applicable, GDPR), you have the right to:
- Access the personal data we hold about you
- Correct inaccurate data (much of this you can do in account settings)
- Delete your account and personal data
- Export your data in a machine-readable format (portability)
- Object to or restrict certain processing, and withdraw consent where processing is based on consent
How to exercise these rights: email [email protected] from the email address registered to your account (we verify requests this way to protect your data). Self-service account deletion and data export are not yet available in the app, so these requests are currently handled manually — we respond within 30 days.
If you believe we have not handled your data lawfully, you may lodge a complaint with your local data protection authority (for EEA/UK users) or the competent Taiwan authority.
Note for California residents: we do not sell or share personal information for cross-context behavioral advertising.
7. Security
We protect data using encryption in transit (TLS), passwords stored only as secure hashes, scoped access credentials for infrastructure, and application-level authorization that restricts every request to the requesting user's own workspace, with row-level security policies additionally defined in the database. No online service can guarantee absolute security; we recommend using a strong, unique password.
If a data breach occurs that is likely to result in a risk to your rights, we will notify affected users and the competent authorities as required by applicable law, without undue delay.
8. Children
The Service is not directed to anyone under 18, and we do not knowingly collect data from them. If you believe a minor has provided us data, contact [email protected] and we will delete it.
9. Cookies
We use only essential and functional cookies — no analytics or advertising cookies. See the Cookie Policy for the full list.
10. Changes to This Policy
We will update this policy as the Service evolves (for example, when payment processing or analytics are introduced). Material changes will be announced on the website and the date at the top updated. The English version of this policy governs; translations, if provided, are for reference only.
11. Contact
Far Star Studio Ltd. (遠星工作室有限公司)
Taiwan (R.O.C.)
Email: [email protected]