GenPresso Privacy Policy

Effective date: August 18, 2026

Last updated: August 18, 2026

RECON Labs Inc. ("Company", "we") operates GenPresso, an AI studio for generating and editing images, video, and audio (the "Service"). This Privacy Policy explains how we collect, use, share, and protect your personal data, including for users in the European Economic Area (EEA) and the United Kingdom under the GDPR/UK GDPR.

1. Data Controller

The data controller is 주식회사 리콘랩스 (RECON Labs Inc.), 8F, 343 Hakdong-ro, Gangnam-gu, Seoul, Republic of Korea. Contact: privacy@genpresso.ai. An EU representative under Art. 27 GDPR will be designated where required for EEA users; until then, EEA users may contact us at the address above.

2. Data We Collect

  • Account data: email, password (hashed) or social-login profile (email, name), and username (handle).
  • Optional: display name, marketing-consent status.
  • User content: prompts, uploaded images/video/audio/documents, generated outputs, and project/timeline data.
  • Automatically collected: IP address, cookies, device/browser data, usage logs, and payment records.
  • Derived assistant memory: summaries the AI assistant generates from your conversations and work history, describing your recurring production preferences and working methods (e.g. preferred aspect ratio, colour treatment, model choices, recurring revision requests, language). These are stored at two levels — per canvas (project) and per account — and the account-level summary is applied across your other canvases.
  • Assistant usage records: telemetry about assistant turns, including a short excerpt (up to 200 characters) of the prompt text, used to diagnose failures and improve quality.

Payment-instrument details (card numbers, etc.) are processed directly by our payment processor (Stripe) and are not stored by us. We do not collect special-category data.

Derived assistant memory is inferred from your own input. It is not used to train AI models and is not made available to other users for review. On a shared canvas the canvas-level summary is shared among that canvas's members, and because summaries are extracted from the flow of a conversation, content originating from a co-member's message can end up in a summary. You may access or erase this data under Section 6. Your data export covers canvases you own plus canvases you currently take part in; canvases you were already removed from cannot be located.

3. Purposes and Legal Bases (GDPR Art. 6)

  • Providing the Service, account management, and generating your requested outputs — performance of a contract (Art. 6(1)(b)).
  • Billing, security, fraud prevention, and service improvement — legitimate interests (Art. 6(1)(f)).
  • Legal and tax record-keeping — legal obligation (Art. 6(1)(c)).
  • Personalising assistant behaviour from your work history (derived assistant memory, Section 2) — legitimate interests (Art. 6(1)(f)); you may object under Section 6.
  • Statistical purposes and scientific research to improve the Service and advance generative AI, carried out only on pseudonymised or aggregated data — legitimate interests (Art. 6(1)(f)) with the safeguards required by Art. 89(1); you may object under Section 6.
  • Promoting the Service using content you made public yourself — legitimate interests (Art. 6(1)(f)); where you submitted content to a promotion or agreed to a credit under your name, your consent (Art. 6(1)(a)), withdrawable at any time.
  • Marketing communications — your consent (Art. 6(1)(a)), withdrawable at any time.

For statistics and scientific research we first pseudonymise the data so that no individual can be identified without additional information, or aggregate it into statistics that identify no individual, under Art. 28-2 of Korea's Personal Information Protection Act and Art. 89(1) GDPR. The categories involved are those in Section 2 with identifiers removed, retention is as stated in Section 5, and we do not engage any processor for this purpose. We do not attempt to re-identify individuals, we keep the additional information needed for re-identification stored separately under the safeguards in Section 8, and if identifying information is produced during processing we stop immediately and destroy it. This processing does not include training or fine-tuning AI models on your inputs or outputs. You may object at any time by writing to privacy@genpresso.ai; the objection applies to processing from that point onward, since data already pseudonymised can no longer be linked back to you.

Promotional use covers only projects and outputs you made public yourself — by setting visibility to public or creating a public share link — and content you separately agreed to for an event or case study; private content is not used. We do not display your handle, display name, or other identifying information alongside it unless you separately agreed to a credit, and only as agreed. Set the project back to private, or write to privacy@genpresso.ai or support@genpresso.ai, and we stop publishing it on the channels we control without delay; a credit consent can be withdrawn at any time. A takedown cannot reach copies already printed and distributed or reshared on third-party platforms beyond our recall. See Section 8 of the Terms of Service.

4. Processors, Sub-processors and International Transfers

We use the following processors. Where data is transferred outside the EEA/UK, we rely on adequacy decisions or the EU Standard Contractual Clauses (SCCs) as appropriate.

ProcessorPurposeLocation
Supabase, Inc.Authentication and databaseUSA
Cloudflare, Inc.Media storage (R2)USA / global
fal.ai (Features & Labels, Inc.)AI image/video/audio generationUSA / non-EEA
OpenRouter, Inc.AI agent language modelsUSA / non-EEA
Z.ai (Zhipu AI)Fallback language modelsnon-EEA
Stripe, Inc.Payment processingUSA
Vercel Inc.HostingUSA
Resend, Inc.Transactional emailUSA

Your prompts and uploaded/generated media may be transmitted to the AI processors above solely to perform generation you request. Payment is processed by our U.S. subsidiary, RECON Labs Inc., via Stripe.

5. Retention

We keep account data until you delete your account, generated content until you delete it or your account (residual backups purged within 7 days), and transaction records for the periods required by applicable commerce and tax law.

Derived assistant memory and assistant usage records are kept until you close your account. Canvas-level summaries are deleted with the canvas; the account-level summary and usage records are deleted when the account is closed, including entries attributed to you on canvases owned by other members or by your team. Canvases you had already been removed from cannot be located and are excluded, and short excerpts held in our service-improvement analysis reports, which carry no user identifier, are deleted 90 days after the report is created.

Pseudonymised data processed for statistics and scientific research is kept until the research purpose is achieved and in any case no longer than three years from pseudonymisation, after which it and the additional information held separately for re-identification are destroyed. Because it can no longer be linked back to you, it is not covered by per-account deletion when you close your account.

Content used for promotion, and any credit shown with it, is kept in use until you set the project back to private, ask us to stop, or withdraw the credit consent, after which we stop publishing it on the channels we control.

6. Your Rights

Subject to applicable law, you may request access, rectification, erasure, restriction, portability, and object to processing, and withdraw consent at any time. You can edit your profile, delete generated content, and delete your account from the in-app Settings screen. EEA/UK users may also lodge a complaint with their supervisory authority.

  • Email: privacy@genpresso.ai
  • Address: 8F, 343 Hakdong-ro, Gangnam-gu, Seoul, Republic of Korea

7. Cookies

We use cookies to keep you signed in, remember preferences, and analyze usage. You can control cookies in your browser settings; blocking them may limit some functionality such as staying signed in.

8. Security

We apply administrative, technical, and physical safeguards, including access controls, encryption of credentials in storage and transit, row-level-security database policies restricting data to its owner, and secrets kept only in secured environment variables.

9. Children

The Service is intended for users aged 14 and older and is not directed to children below the age of digital consent. We do not knowingly collect data from such children.

10. Changes and Contact

We will post material changes at least 7 days before they take effect. Questions: privacy@genpresso.ai. This policy is effective August 18, 2026.