1. Who is responsible for your information
The office below handles privacy requests and related complaints for Goblin3D. Statutory business disclosures are available in the website footer.
| Item | Details |
|---|---|
| Business / service | colinkoko / Goblin3D |
| Privacy contact | Goblin3D Privacy Office · privacy@goblin3d.ai |
| Telephone | 070-4571-5764 |
2. Information we collect
- Account and profile: email address, authentication provider and identifiers, display name, username, avatar, locale, account preferences, and consent records.
- Creation content: text prompts, uploaded or reference images, generated images, sprite frames and sheets, 3D models, titles, visibility settings, technical generation settings, provider task IDs, and related error or processing records.
- Community activity: content that you deliberately publish, creator profile details, likes, listings, and publication dates.
- Billing and credits: Paddle customer, checkout, subscription, invoice, refund, credit balance, reservation, usage, and ledger records. Goblin3D does not store full payment card numbers.
- API and desktop access: API key name, prefix, last four characters and one-way hash, usage timestamps, device name, platform, hashed desktop session tokens, and assets synchronized to the desktop app.
- Technical and support data: IP address, browser/device data, request and security logs, rate-limit events, page/feature involved, messages, screenshots, and other information you send to support.
We collect information directly from you, automatically from your use of the Service, from Google, Apple, or GitHub if you choose the corresponding sign-in method, and from Paddle for payment status and transaction administration.
3. Why we use information
| Purpose | Typical information | Legal basis where required |
|---|---|---|
| Create accounts and authenticate users | Email and authentication identifiers | Contract; consent where required |
| Generate, store, preview, export, and synchronize assets | Prompts, uploads, outputs, settings, task records | Contract and user request |
| Publish content chosen for Community | Public asset and creator profile | User request/consent |
| Operate subscriptions, credits, refunds, and support | Billing, ledger, account, and support records | Contract and legal obligations |
| Protect users and the Service | IP/device data, logs, rate limits, security events | Legitimate interests and legal obligations |
| Debug and improve reliability | Errors, task metadata, and de-identified or aggregated usage information | Legitimate interests; consent where required |
Goblin3D does not use user prompts, private uploads, or private generated content to train its own AI models. External generation providers may process that content only as described in this Policy and their applicable business/API terms.
4. Private work and public Community content
Source images and prompts remain private unless you separately publish them. On the Free plan, generated outputs are public and may be listed in Community; the Visibility control shows this before generation. Paid plans may offer private output visibility. A public creator page may show your chosen display name, username, avatar, and published assets.
Do not publish personal, confidential, or third-party material that you do not have the right to disclose. Search engines, visitors, and other services may copy or cache public content. Removing or unlisting content stops future display by Goblin3D, but copies made by others may remain outside our control.
5. How long we keep information
| Record | Retention |
|---|---|
| Account, profile, private content, and generation history | While the account is active or until the content/deletion request is processed, unless a longer period is legally required |
| Public Community content | Until it is unpublished, deleted, or the account is closed; short-lived caches may take additional time to clear |
| API key and desktop authorization records | Until revoked, expired, or the account is closed; one-way hashes may be retained briefly for security investigation |
| Contracts and cancellation/withdrawal records | 5 years under Korean e-commerce law |
| Account closure audit tied to a paid account | Only the minimal closure, contract, and payment references required for legal claims, up to 5 years |
| Payment and supply records | 5 years under Korean e-commerce law |
| Consumer complaints and dispute handling | 3 years under Korean e-commerce law |
| Advertising display records, if applicable | 6 months under Korean e-commerce law |
| Provider-side generation data | As shown in the overseas processing table below and the applicable provider agreement |
When retention ends, electronic records are securely deleted or irreversibly anonymized. Residual copies in protected backups are isolated and removed according to the relevant backup cycle, unless law requires preservation.
6. Service providers and overseas processing
Goblin3D uses the providers below to run the Service. A generation provider receives content only when its corresponding feature or model is used. Optional processors are listed only when their integration is configured. Destination countries must match the production region and the current provider agreement.
| Recipient / contact | Purpose and data | Country | When and how | Retention |
|---|---|---|---|---|
| Supabase, Inc. (supabase.com/privacy) | Authentication, account database, and service records. Email, account identifiers, profile, content metadata, billing and usage records | Republic of Korea | Continuously while the account/service is used, over an encrypted network | For the account/service retention period; backups follow the provider cycle |
| Cloudflare, Inc. (privacyquestions@cloudflare.com) | Private/public object storage, CDN delivery, and Turnstile security checks when enabled. Uploaded images, generated files, thumbnails, IP/device and security signals | United States and European Economic Area; R2 storage uses the Asia-Pacific location hint | When files or requests are stored, delivered, or security-checked, over an encrypted network | Until content deletion; security data follows the provider retention period |
| Vercel, Inc. (privacy@vercel.com) | Application hosting, request delivery, and operational security logs. Request data, IP address, device/browser information, and operational logs | United States | When the site or API is accessed, over an encrypted network | For the configured hosting and log retention period |
| Paddle.com Market Limited and relevant Paddle affiliates (privacy@paddle.com) | Merchant-of-record checkout, subscription, tax, payment, refund, and fraud prevention. Account email, customer and transaction identifiers, billing and payment information | United States and United Kingdom | At checkout and during billing, subscription, refund, or fraud events, over an encrypted network | For the payment relationship and periods required by financial or e-commerce law |
| Google LLC (policies.google.com/privacy) | Google sign-in selected by the user. Email address and Google authentication identifiers | United States | When the user chooses Google sign-in, through encrypted OAuth communication | For the linked sign-in relationship or until unlinking/deletion |
| Apple Inc. (apple.com/legal/privacy) | Apple sign-in selected by the user. Email or private relay email and Apple authentication identifiers | United States | When the user chooses Apple sign-in, through encrypted OAuth communication | For the linked sign-in relationship or until unlinking/deletion |
| GitHub, Inc. (docs.github.com/site-policy/privacy-policies) | GitHub sign-in selected by the user. Email, GitHub account information, and authentication identifiers | United States | When the user chooses GitHub sign-in, through encrypted OAuth communication | For the linked sign-in relationship or until unlinking/deletion |
| OpenAI, L.L.C. (privacy@openai.com) | Community asset classification when AI tagging is configured. Public asset title, prompt, technical facts, and thumbnail | United States | When a Community asset is classified, over an encrypted API connection | Under the configured OpenAI business/API data controls and retention terms |
| PixelLab (support@pixellab.ai) | Pixel-art character and animation generation. Prompts, reference images, skeleton/animation settings, and generated frames | Sweden | When the user requests the corresponding sprite feature, over an encrypted API connection | For as long as needed to provide and support the generation under the provider policy |
| RunPod, Inc. (privacy@runpod.io) | Serverless rigging, remeshing, or thumbnail processing when configured. Reference images, 3D files, task settings, and generated outputs | Czech Republic, France, United Kingdom, Norway, Romania, or United States (dynamically scheduled) | When the corresponding processing job runs, using encrypted signed transfer links | For the period needed to complete and troubleshoot the processing under the provider agreement |
You may refuse overseas processing by not using the relevant sign-in, payment, generation, publishing, or processing feature, or by requesting account/content deletion through privacy@goblin3d.ai. Refusal may make that feature or the Service unavailable where the transfer is necessary to perform the requested contract. Statutory retention and records already lawfully processed may still apply.
8. Your privacy rights
Depending on where you live, you may request access, correction, deletion, restriction, objection, portability, or withdrawal of consent, and may complain to the competent privacy authority. Email privacy@goblin3d.ai from your account email and describe the request. We may verify identity before acting and may retain records that law requires us to keep.
Korean users may also seek help from the Personal Information Infringement Report Center (118) or the Personal Information Dispute Mediation Committee. EEA/UK users may contact their local supervisory authority, and users elsewhere may use remedies available under local law.
9. Children and minors
Goblin3D is not intended for children under 14 or below the minimum digital-consent age in their country, whichever is higher. We do not knowingly create accounts for those users. A minor below the local age of majority must have permission from a parent or legal guardian. Paid purchases may be made only by an adult or with valid guardian authorization. In Korea, the age of majority is 19.
Contact privacy@goblin3d.ai if you believe a child provided information without the required consent. We will investigate and delete it when legally required.
10. Security and changes to this Policy
We use access controls, one-way hashing for API and desktop tokens, private object storage paths, encryption in transit, least-privilege service credentials, rate limits, and monitoring appropriate to the Service. No online system can guarantee absolute security, so users should keep sign-in links, devices, and API keys secure.
We may update this Policy when the Service, providers, or law changes. Material changes will be announced in the Service or by email before they take effect where required. The version and date at the top identify the applicable Policy.