Version: 2026-10-04
Notice date: October 4, 2026
This revision provides more detail about the information processed, service providers, retention and deletion, and how to exercise privacy rights. It applies to new Members upon registration after publication. Clarifications and protections that do not adversely affect existing Members apply from publication; changes requiring advance notice or separate consent follow the Supplementary Provisions.
Cutib US Inc. (the "Company") processes personal information for the Tacu service (the "Service") under applicable privacy laws. This Policy explains collection, use, sharing, retention, and how users may exercise their rights.
The Company processes the information listed in Article 2 for the purposes below. Changes of purpose follow any notice and consent procedures required by applicable law.
Information needed for registration, authentication, payments, requested features, and support is processed to perform the contract; legally required records are processed to meet legal obligations. Security and abuse-prevention information is processed on the basis of legitimate interests recognized by applicable law. Separate consent is obtained for development, training, or advertising where required.
1. Account management: confirming registration, identifying and authenticating accounts, managing membership, preventing abuse, and providing Service notices.
2. Service provision and contract performance: paid and free features, subscriptions and Credits, payments, settlement and invoices, delivery and provenance of Outputs, and publication, sharing and reuse of projects and templates authorized by the user.
3. Provision of AI Features: processing Input Data provided by users to generate and provide AI Outputs
4. Customer support: reviewing inquiries and complaints, investigating facts, communicating, and providing results.
5. Service and feature development and improvement: usage and quality analysis, troubleshooting, feature development, testing, evaluation and improvement, and model training where needed. Article 3 governs use, opt-outs, and deletion.
6. Advertising and measurement (excluding email): in-Service events and promotions, interest-based advertising, and performance measurement. The Company obtains legally required consent and honors applicable opt-out and withdrawal requests.
7. Legal obligations and rights protection: statutory retention, lawful authority requests, security, abuse prevention, and handling rights infringements and disputes.
8. Email marketing: Email addresses, communication preferences, and consent and opt-out records are used for Tacu feature updates, tips, newsletters, events and promotions, and to honor opt-outs. Where prior consent is legally required, emails are sent only with valid consent or a statutory exception. Users may opt out free of charge through each email’s unsubscribe link or support@cutib.com. These emails are distinct from non-marketing notices under Article 9 of the Terms.
1. Membership Registration and Management
a. Required items: email address, internal Account identifier, automatically generated Username, password authentication information for email/password registration, and the authentication provider and provider account identifier for third-party login
b. Optional items: display name, profile photo (including third-party login profile information authorized by the user), affiliation (company/team), occupation/role, and other information voluntarily provided
2. When Using Paid Services
a. Payment information: partial card numbers, expiry dates, payment-method types, payment tokens and identifiers, transaction status, and related processing information. Processors such as Stripe handle full card numbers and CVC codes; the Company does not store them.
b. Billing information: name, address (including country), contact information (for tax invoice/invoice issuance)
3. When using content creation, editing, and project features
a. Input and Project Data: personal information that may be contained in text, uploaded files, project structure, creative instructions, generation settings, and editing history
b. AI Output Data: personal information that may be contained in images, videos, audio, text, or other materials generated in the Service.
4. Information Automatically Collected During Use of the Service
a. IP address, cookies or similar identifiers, browser/OS/device information, country-level location, usage records (visits, clicks, features, generation, and Credit use), device/visitor identifiers and results for abuse checks, and session-replay information such as screen layout, clicks and scrolling, with masking applied to input information such as passwords
5. AI labels and provenance: generation and export times, feature and model types, content identifiers, watermarks and metadata. Direct identifiers such as email addresses, names and Account IDs are not normally embedded in exported files.
6. Customer Support
a. Inquiry details, email address, phone number, and other information provided by the user
7. Marketing and survey information
a. Responses, interests, and other information voluntarily provided through surveys or events
b. Email marketing: email address, communication preferences, and consent, opt-out, and handling records
8. Collection Methods
a. User registration, Service use, uploads, inquiries and event participation; authorized external account connections; and automatic collection during Service use.
9. The Company does not direct the Service to residents of the European Union (EU), European Economic Area (EEA), or United Kingdom. This Policy still applies to information needed to enforce access restrictions or handle statutory rights requests.
Personal information is retained as needed for its purpose, then deleted or anonymized so individuals cannot be identified. Records subject to separate legal retention duties are kept for the required period.
1. Account information: On withdrawal, the account is deactivated and profile information and unnecessary authentication and email-verification information are deleted or replaced. To prevent repeated claims of signup benefits, the Company retains a non-reversible email identifier instead of the original email address, the account identifier, withdrawal date and retention deadline for up to 365 days after withdrawal. The identifier remains subject to personal-data safeguards. Transaction, refund and dispute records are managed separately under the retention rules below. Information required by law or an ongoing dispute is limited to the scope and period needed for that purpose.
2. Transaction and dispute records: where Article 6 of Korea’s Electronic Commerce Act Enforcement Decree applies, contract, withdrawal, payment and supply records are retained for 5 years; complaint and dispute records for 3 years; and advertising records for 6 months. Where legally required, automatic-renewal consent records are retained for at least 3 years or 1 year after contract termination, whichever is longer.
3. Input, Project, and Output Data:
a. Service-provision materials: on project or content deletion or account closure, use and display through the affected account stop. Personal information that is no longer needed because its service-provision purpose has ended is deleted or irreversibly anonymized under Article 6. Shared materials lawfully used by other active projects and minimum records needed for law, settlement, refunds, tax, payment disputes or rights claims are retained only to the extent and for the period needed for those purposes. Backups and other copies that cannot be deleted immediately have access and use restricted and are deleted through the cleanup process. Independently saved, published and reused materials follow item d.
b. Development and improvement materials: Inputs, Outputs, Project Data, usage and quality information, and feedback may be used for development, testing, evaluation, improvement and model training on a lawful basis and with any required consent. After an opt-out, deletion of the materials or account closure, new development and training use of the affected source materials containing personal information stops. Lawfully used anonymous or aggregated data and statistical, analytical or improvement results that do not identify, and cannot reasonably be used to re-identify, an individual may continue to be used. Third-party rights and contractual restrictions remain applicable. Registration, this Policy amendment or continued use does not constitute separate consent to development or training where such consent is required.
c. Enterprise and separately contracted materials: the applicable agreement takes priority for private materials. Development and improvement require permission under that agreement or express authorization from an authorized person that does not conflict with it. External AI processing follows the relevant provider agreement.
d. Independently saved, published and reused materials: separately saved templates, lawfully acquired copies and necessary provenance records may remain after source deletion or account closure. Personal information is retained only as needed for authorized use and rights verification. Article 14 of the Terms governs withdrawal of publication and rights in copies.
4. Service and security records: retained as needed for operation, troubleshooting, abuse prevention and disputes. Internet logs and access-location records subject to a statutory three-month retention duty are retained for that period.
5. Marketing information: email-marketing use stops on opt-out, withdrawal of consent where applicable, or account closure. Other consent-based marketing information is also retained until consent withdrawal or account closure. Minimum identifiers and records needed to honor opt-outs and comply with law are retained separately for as long as necessary and are not used to send marketing.
6. Other statutory obligations: until the period prescribed by the applicable law
The Company discloses personal information only for the sharing and processing described here or as permitted by law. Where separate consent is required, it identifies the recipient, purpose, information and retention period and obtains consent. Contact details and the contents of infringement notices or counter-notices may be forwarded to the other party as required or permitted by law.
When a project or creative template is published or shared, other users may view, copy and use the content, creative instructions, generation settings, assets and attribution, such as public Usernames, included in that feature’s sharing scope. Public materials may be viewed by non-members and copied or stored elsewhere. Private materials are not made public without that choice, and team sharing follows assigned permissions.
The Company entrusts the activities identified as processor activities in Appendix A to the relevant providers under processing agreements and oversight required by law. Cutib US Inc. remains the entity responsible for personal information under this Policy. Cutib Inc. in the Republic of Korea performs the development, operations, customer support and other activities entrusted to it. A provider’s independent processing for payments, external account connections or advertising is distinguished from processing on the Company’s instructions and follows the applicable basis under Articles 4 and 12 and that provider’s privacy policy.
AI providers receive only the materials needed for the selected feature, and the model brand may differ from the processing provider. Changes in processing scope follow required notice and consent procedures.
1. The Company destroys personal information without delay when it becomes unnecessary, such as upon expiration of the retention period or achievement of the processing purpose.
2. Legally required records are retained separately from other personal information.
3. Electronic files are securely deleted or encryption keys are destroyed. Backups are access-restricted and deleted through the applicable cleanup process. Paper records are shredded or incinerated.
Users, personally or through an authorized representative, may request access, portability, correction, deletion, restriction or withdrawal of consent under applicable law. Requests, including development and improvement opt-outs, may be submitted to support@cutib.com or through available Service features. After any necessary identity or authority checks, the Company communicates its response within the applicable statutory periods and procedures. If it limits or refuses a request, it explains the legal grounds and how to challenge that decision.
1. The Company uses cookies and similar technologies for login, security, analytics and advertising. Fingerprint supports signup checks and abuse prevention; PostHog supports analytics and session replay with input masking, including passwords; and Sentry supports error collection and troubleshooting. Contentsquare/Hotjar and Google Analytics support usage analytics. Meta Pixel and connected Google advertising tools support advertising and conversion measurement. Appendix A describes the providers’ information, roles and locations. Optional analytics and advertising are processed within the scope of any required separate consent, and applicable opt-out and withdrawal requests are honored.
2. Users may exercise advertising and analytics rights through browser settings, available controls or support@cutib.com. Browser settings alone do not stop all tracking, and blocking essential cookies may limit login or other features. Legally recognized opt-out signals, including GPC, are honored where required by applicable law.
1. Administrative measures: limiting access to personal information, staff training, and operating management procedures.
2. Technical measures: access authorization and control, encryption, security programs, retention of access logs, and measures to prevent alteration or tampering
3. Physical measures: access controls for locations where personal information is stored.
Privacy Officer: Donghyuk Choi
Email: support@cutib.com
Phone: +1 302-800-9533
The Company publishes the changes, reasons and effective date. Non-adverse changes may apply on publication; adverse changes receive individual advance notice. Notice periods required by law or existing commitments are respected. Changes requiring separate consent apply only after it is obtained.
Appendix A at the end of this document forms part of this Policy and identifies external providers’ roles, processing countries, information, purposes and retention criteria. Necessary information is transmitted through encrypted connections when registration, authentication, payment, generation requests, inquiry submissions or the relevant analytics or advertising collection takes place. Processing depends on the selected feature and applicable conditions; not all information is sent to every provider or country.
Appendix A identifies the countries where Korean users’ information is directly collected and processed, and the countries and recipients for subsequent disclosure, entrusted processing or storage with other overseas providers.
Internationally entrusted processing or storage necessary to enter into or perform a contract with the data subject relies on Article 28-8(1)(3) of Korea’s Personal Information Protection Act and disclosure of the matters in Article 28-8(2) in this Policy and Appendix A. This basis does not automatically cover independent third-party disclosures, optional advertising or analytics, or development or training. Where separate consent is required for a disclosure or transfer, the Company first discloses the recipient, purposes, information, countries, timing and method, retention, and refusal procedure and consequences, and obtains that consent. Other processing must have its own applicable legal basis.
Users may request refusal or withdrawal of consent through support@cutib.com or available settings, identifying the provider or feature concerned. The Company handles the request after any necessary identity checks and communicates the result. Refusal of processing necessary to perform the contract may limit the relevant feature; refusing optional advertising or analytics does not affect access to the Service.
Unnecessary information held in Stripe is also deleted, de-identified or submitted for deletion. Records Stripe retains independently for financial regulation, accounting, security or fraud prevention follow applicable law and Stripe’s privacy policy.
The English version controls. If a translation conflicts with it, the English version prevails to the extent permitted by law, without limiting non-waivable rights or mandatory disclosures.
Questions, complaints and requests for reconsideration may be sent to the contact in Article 10. Users may also complain to, or seek dispute resolution from, a competent privacy authority independently of contacting the Company.
1. The actual notice date and application date of this revised Policy are stated in the amendment notice in the Service. Changes requiring advance public or individual notice under applicable law or an existing commitment apply only after the required notice period has elapsed. Uses requiring separate consent apply only within the consent obtained. Application is not backdated to a time before actual notice or consent. This schedule does not postpone legal duties or user protections that already apply.
2. Prior versions and their effective dates are retained and may be requested at support@cutib.com.
3. Existing optional marketing and analytics consent, opt-out and withdrawal choices remain in effect. This amendment alone does not add addresses requiring optional consent under the previous Policy to marketing mailing lists. It does not constitute consent to new development, training or advertising processing requiring separate consent.
This Appendix forms part of the Policy under Articles 5 and 12. Company-held copies follow Article 3; refusal, deletion and other rights follow Articles 7, 8 and 12. Country descriptions include providers’ published processing scope that applies according to the feature, storage location or support request. Not every user’s information is sent to every country or provider. Linked official information identifies the relevant services, countries, activities and subprocessors. Processing on instructions is distinguished from a provider’s independent processing; processing other than internationally entrusted processing or storage needed for the contract requires any necessary separate consent or its own legal basis. Information is deleted, returned or anonymized when its retention period ends or a valid deletion request is implemented. Retention for legal duties, ongoing disputes or other justified grounds is limited to what those grounds require.
support@cutib.com
aws-korea-privacy@amazon.com
privacy@stripe.com
support.google.com/policies
googlekrsupport@google.com
support.google.com/policies
privacy@byteplus.com
cloudlegalnotices@tencent.com
privacy@openai.com
privacy@blackforestlabs.ai
legal@elevenlabs.io
api-support@mureka.ai
privacy+enterprise@x.ai
privacy@topazlabs.com
support@fingerprint.com
privacy@posthog.com
facebook.com/privacy/policy
privacy@vercel.com
sentry.io/legal/privacy/
privacy@contentsquare.com
support.google.com/policies
hello@tally.so