LEGALPrivacy Policy
Effective: January 1, 2026
Overview
OGShot ("we," "us," or "our") is committed to protecting your personal information. This Privacy Policy explains how we collect, use, disclose, and protect information when you use our OG image generation service.
1. Information We Collect
We collect the following information:
- Account Information: Email address and password (stored as a bcrypt hash — we never store plaintext passwords)
- Usage Data: API call logs, image generation counts, and timestamps
- Technical Data: IP addresses, browser type, access logs, and API key identifiers (stored as SHA-256 hashes)
2. How We Use Your Information
We use collected information to:
- Create and manage your account, and verify your identity
- Provide the service — issuing API keys, tracking usage, processing payments
- Respond to support requests and resolve disputes
- Detect and prevent fraud, abuse, or unauthorized access
- Analyze aggregate usage to improve the service
3. Information Sharing
We do not sell your personal information to any third party.
We share information only with:
- Service Providers: Supabase Inc. (database & authentication, United States), Lemon Squeezy (payment processing, United States)
- Legal Requirements: When required by applicable law, court order, or valid legal process
4. Data Retention
We retain data for the following periods:
- Account data: Until account deletion
- API usage logs: 90 days
- Payment records: 5 years (legal requirement)
- Access logs: 3 months
5. Your Rights
Depending on your location, you may have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you
- Correction: Request correction of inaccurate data
- Deletion: Request deletion of your personal data ("right to be forgotten")
- Portability: Receive your data in a structured, machine-readable format (GDPR)
- Opt-out: Opt out of sale or sharing of personal information (CCPA)
To exercise these rights, contact us at hello@planhub.kr or use your dashboard settings. We will respond within 10 business days.
6. Cookies
We use only essential cookies for authentication and session management. We do not use tracking, advertising, or analytics cookies.
7. Security
We employ industry-standard security measures:
- All data in transit is encrypted using TLS/HTTPS
- Passwords are hashed with bcrypt (one-way, salted)
- API keys are stored as SHA-256 hashes; key secrets are stored separately for HMAC signing only
- Access to production systems is restricted to authorized personnel
8. International Data Transfers
OGShot operates from South Korea. Your data may be processed in other countries (including the United States via Supabase and Lemon Squeezy). We ensure that appropriate safeguards are in place for such transfers, in compliance with applicable data protection laws.
9. Children's Privacy
OGShot is not directed to children under the age of 13. We do not knowingly collect personal information from children.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes at least 7 days before they take effect via a notice on our service.
11. Contact
For privacy-related inquiries: hello@planhub.kr
OGShot is operated by igiidos. For data subject requests under GDPR or CCPA, please include your account email in your request.