Goblin3D legal

Privacy Policy

This Policy explains how colinkoko handles personal information when people use Goblin3D, including account, generation, community, API, desktop, support, and billing features.

Last updated
August 13, 2026
Effective
August 12, 2026

1. Who is responsible for your information

The office below handles privacy requests and related complaints for Goblin3D. Statutory business disclosures are available in the website footer.

ItemDetails
Business / servicecolinkoko / Goblin3D
Privacy contactGoblin3D Privacy Office · privacy@goblin3d.ai
Telephone070-4571-5764

2. Information we collect

  • Account and profile: email address, authentication provider and identifiers, display name, username, avatar, locale, account preferences, and consent records.
  • Creation content: text prompts, uploaded or reference images, generated images, sprite frames and sheets, 3D models, titles, visibility settings, technical generation settings, provider task IDs, and related error or processing records.
  • Community activity: content that you deliberately publish, creator profile details, likes, listings, and publication dates.
  • Billing and credits: Paddle customer, checkout, subscription, invoice, refund, credit balance, reservation, usage, and ledger records. Goblin3D does not store full payment card numbers.
  • API and desktop access: API key name, prefix, last four characters and one-way hash, usage timestamps, device name, platform, hashed desktop session tokens, and assets synchronized to the desktop app.
  • Technical and support data: IP address, browser/device data, request and security logs, rate-limit events, page/feature involved, messages, screenshots, and other information you send to support.

We collect information directly from you, automatically from your use of the Service, from Google, Apple, or GitHub if you choose the corresponding sign-in method, and from Paddle for payment status and transaction administration.

3. Why we use information

PurposeTypical informationLegal basis where required
Create accounts and authenticate usersEmail and authentication identifiersContract; consent where required
Generate, store, preview, export, and synchronize assetsPrompts, uploads, outputs, settings, task recordsContract and user request
Publish content chosen for CommunityPublic asset and creator profileUser request/consent
Operate subscriptions, credits, refunds, and supportBilling, ledger, account, and support recordsContract and legal obligations
Protect users and the ServiceIP/device data, logs, rate limits, security eventsLegitimate interests and legal obligations
Debug and improve reliabilityErrors, task metadata, and de-identified or aggregated usage informationLegitimate interests; consent where required

Goblin3D does not use user prompts, private uploads, or private generated content to train its own AI models. External generation providers may process that content only as described in this Policy and their applicable business/API terms.

4. Private work and public Community content

Source images and prompts remain private unless you separately publish them. On the Free plan, generated outputs are public and may be listed in Community; the Visibility control shows this before generation. Paid plans may offer private output visibility. A public creator page may show your chosen display name, username, avatar, and published assets.

Do not publish personal, confidential, or third-party material that you do not have the right to disclose. Search engines, visitors, and other services may copy or cache public content. Removing or unlisting content stops future display by Goblin3D, but copies made by others may remain outside our control.

5. How long we keep information

RecordRetention
Account, profile, private content, and generation historyWhile the account is active or until the content/deletion request is processed, unless a longer period is legally required
Public Community contentUntil it is unpublished, deleted, or the account is closed; short-lived caches may take additional time to clear
API key and desktop authorization recordsUntil revoked, expired, or the account is closed; one-way hashes may be retained briefly for security investigation
Contracts and cancellation/withdrawal records5 years under Korean e-commerce law
Account closure audit tied to a paid accountOnly the minimal closure, contract, and payment references required for legal claims, up to 5 years
Payment and supply records5 years under Korean e-commerce law
Consumer complaints and dispute handling3 years under Korean e-commerce law
Advertising display records, if applicable6 months under Korean e-commerce law
Provider-side generation dataAs shown in the overseas processing table below and the applicable provider agreement

When retention ends, electronic records are securely deleted or irreversibly anonymized. Residual copies in protected backups are isolated and removed according to the relevant backup cycle, unless law requires preservation.

6. Service providers and overseas processing

Goblin3D uses the providers below to run the Service. A generation provider receives content only when its corresponding feature or model is used. Optional processors are listed only when their integration is configured. Destination countries must match the production region and the current provider agreement.

Recipient / contactPurpose and dataCountryWhen and howRetention
Supabase, Inc. (supabase.com/privacy)Authentication, account database, and service records. Email, account identifiers, profile, content metadata, billing and usage recordsRepublic of KoreaContinuously while the account/service is used, over an encrypted networkFor the account/service retention period; backups follow the provider cycle
Cloudflare, Inc. (privacyquestions@cloudflare.com)Private/public object storage, CDN delivery, and Turnstile security checks when enabled. Uploaded images, generated files, thumbnails, IP/device and security signalsUnited States and European Economic Area; R2 storage uses the Asia-Pacific location hintWhen files or requests are stored, delivered, or security-checked, over an encrypted networkUntil content deletion; security data follows the provider retention period
Vercel, Inc. (privacy@vercel.com)Application hosting, request delivery, and operational security logs. Request data, IP address, device/browser information, and operational logsUnited StatesWhen the site or API is accessed, over an encrypted networkFor the configured hosting and log retention period
Paddle.com Market Limited and relevant Paddle affiliates (privacy@paddle.com)Merchant-of-record checkout, subscription, tax, payment, refund, and fraud prevention. Account email, customer and transaction identifiers, billing and payment informationUnited States and United KingdomAt checkout and during billing, subscription, refund, or fraud events, over an encrypted networkFor the payment relationship and periods required by financial or e-commerce law
Google LLC (policies.google.com/privacy)Google sign-in selected by the user. Email address and Google authentication identifiersUnited StatesWhen the user chooses Google sign-in, through encrypted OAuth communicationFor the linked sign-in relationship or until unlinking/deletion
Apple Inc. (apple.com/legal/privacy)Apple sign-in selected by the user. Email or private relay email and Apple authentication identifiersUnited StatesWhen the user chooses Apple sign-in, through encrypted OAuth communicationFor the linked sign-in relationship or until unlinking/deletion
GitHub, Inc. (docs.github.com/site-policy/privacy-policies)GitHub sign-in selected by the user. Email, GitHub account information, and authentication identifiersUnited StatesWhen the user chooses GitHub sign-in, through encrypted OAuth communicationFor the linked sign-in relationship or until unlinking/deletion
OpenAI, L.L.C. (privacy@openai.com)Community asset classification when AI tagging is configured. Public asset title, prompt, technical facts, and thumbnailUnited StatesWhen a Community asset is classified, over an encrypted API connectionUnder the configured OpenAI business/API data controls and retention terms
PixelLab (support@pixellab.ai)Pixel-art character and animation generation. Prompts, reference images, skeleton/animation settings, and generated framesSwedenWhen the user requests the corresponding sprite feature, over an encrypted API connectionFor as long as needed to provide and support the generation under the provider policy
RunPod, Inc. (privacy@runpod.io)Serverless rigging, remeshing, or thumbnail processing when configured. Reference images, 3D files, task settings, and generated outputsCzech Republic, France, United Kingdom, Norway, Romania, or United States (dynamically scheduled)When the corresponding processing job runs, using encrypted signed transfer linksFor the period needed to complete and troubleshoot the processing under the provider agreement

You may refuse overseas processing by not using the relevant sign-in, payment, generation, publishing, or processing feature, or by requesting account/content deletion through privacy@goblin3d.ai. Refusal may make that feature or the Service unavailable where the transfer is necessary to perform the requested contract. Statutory retention and records already lawfully processed may still apply.

7. Cookies and similar technologies

Goblin3D uses strictly necessary cookies or local storage for Supabase authentication, security, locale preferences, and continuity of a requested workflow. Cloudflare Turnstile may process security signals when enabled. Goblin3D currently does not run behavioral advertising or third-party marketing analytics cookies. If that changes, we will update this Policy and request consent where required.

8. Your privacy rights

Depending on where you live, you may request access, correction, deletion, restriction, objection, portability, or withdrawal of consent, and may complain to the competent privacy authority. Email privacy@goblin3d.ai from your account email and describe the request. We may verify identity before acting and may retain records that law requires us to keep.

Korean users may also seek help from the Personal Information Infringement Report Center (118) or the Personal Information Dispute Mediation Committee. EEA/UK users may contact their local supervisory authority, and users elsewhere may use remedies available under local law.

9. Children and minors

Goblin3D is not intended for children under 14 or below the minimum digital-consent age in their country, whichever is higher. We do not knowingly create accounts for those users. A minor below the local age of majority must have permission from a parent or legal guardian. Paid purchases may be made only by an adult or with valid guardian authorization. In Korea, the age of majority is 19.

Contact privacy@goblin3d.ai if you believe a child provided information without the required consent. We will investigate and delete it when legally required.

10. Security and changes to this Policy

We use access controls, one-way hashing for API and desktop tokens, private object storage paths, encryption in transit, least-privilege service credentials, rate limits, and monitoring appropriate to the Service. No online system can guarantee absolute security, so users should keep sign-in links, devices, and API keys secure.

We may update this Policy when the Service, providers, or law changes. Material changes will be announced in the Service or by email before they take effect where required. The version and date at the top identify the applicable Policy.