Privacy Policy
Veizik is a local runtime: your models run on your GPU, and your prompts, input media and rendered outputs never leave your device. This policy covers the limited account, licensing and website data we do process — what it is, why we process it, on what legal basis, how long we keep it, who it is shared with, and how to exercise your rights. No marketing language, no surprises.
1Who we are (data controller)
The controller of the personal data described below is 링크픽 (LinkPick), operating the brand Veizik, Republic of Korea. Business registration no. 148-14-02554 · Representative: Bak Malgeum (박맑음). Our billing partner Polar acts as an independent Merchant of Record and controller for payment data.
| Role | Contact |
|---|---|
| Registered address | 경기도 광주시 경안천로 91, 101동 1402호 (송정동) / 101-1402, 91 Gyeongancheon-ro, Gwangju-si, Gyeonggi-do, Republic of Korea |
| Privacy Officer PIPA 개인정보 보호책임자 |
이동구 (Lee DongKoo) · 개인정보 보호책임자 |
| Privacy & data-request contact | support@veizik.com A dedicated privacy@veizik.com alias is planned; support@veizik.com is the live channel today and reaches the same people |
| EU representative GDPR Art. 27 |
Not yet appointed — the Service does not currently target EU users (see §6); required before that changes |
| UK representative UK GDPR Art. 27 |
Not yet appointed — the Service does not currently target UK users (see §6); required before that changes |
| Security reports | security@veizik.com · security.txt |
2What we never collect
The runtime never uploads your creative work or the contents of your machine. Specifically, we do not collect:
- ×Input images or videos you feed into the runtime
- ×Prompts or any other generation parameters that describe your content
- ×Rendered outputs — frames, videos, or intermediate latents
- ×Local file paths, filenames, or directory listings from your machine
- ×IP addresses attached to your account, API keys, sessions, devices, or runtime telemetry — none of those records carry an IP field. One exception exists and we disclose it rather than hide it: requests to our install script are logged with the requesting IP (see §3 and §7)
- ×Advertising or cross-site trackers, and we do not sell or "share" personal data as those terms are used in CCPA/CPRA
All generation happens on hardware you own. There is no media-upload path in the runtime.
3What we do collect, why, and on what legal basis
| Data | Purpose | GDPR / UK GDPR basis | PIPA basis |
|---|---|---|---|
| Email address (at signup) | Create and manage your account, deliver API keys, support | Art. 6(1)(b) contract | Necessary to perform the service |
| API key records — hashed key, key id, tier, status, last used | Issue and validate your licence | Art. 6(1)(b) contract | Service performance |
| Pseudonymous device id, session/lease id, tier, protocol version | Enforce seat limits and prevent licence abuse | Art. 6(1)(f) legitimate interest | Legitimate interest / service performance |
| Payment and billing data — card, billing address, tax id | Take payment, invoice, refund | Processed by Polar (MoR) | Processed by Polar — we never see card numbers |
Website analytics events — random anonymous_id, event name, timestamp, minimal properties |
Understand which pages help and where signup breaks | Art. 6(1)(a) consent | Consent via the cookie banner |
| Crash and run diagnostics — runtime and hardware information, installation id | Stability, support, refund verification | Art. 6(1)(f) / (b) | Service performance |
| Install/download request logs — IP address, user-agent, referrer, country | Abuse prevention and launch analytics for /install.sh |
Art. 6(1)(f) legitimate interest | Legitimate interest |
| Network metadata (IP) processed transiently by our edge provider | Delivery, TLS, rate-limiting, bot and DDoS protection | Art. 6(1)(f) legitimate interest | Legitimate interest |
IP note — stated to match what the code actually does. Our edge provider (Cloudflare)
processes your IP address to deliver and secure the service. We do not store your IP against your account,
keys, sessions, devices or runtime telemetry. Exception: a request for our install script
(/install.sh) currently writes the requesting IP, user-agent, referrer and country into our
analytics event store, where it is readable by the operator. Reducing what that route stores and shortening
its retention is a tracked change — see §7. We will not claim IPs are hashed or short-lived before the code
behaves that way.
4Cookies and similar technologies
We use a small number of cookies and local-storage items, in two categories.
Strictly-necessary items run without consent because the site cannot work without them:
your edge-security and load-balancing cookies, and the record of your cookie choice itself
(vzk_consent). Optional analytics — a random id (vzk_aid) and event
beacons to /api/event on our own domain — are off until you accept them, on every
visit from every country. Rejecting is one click, the same size and on the same layer as accepting, and
rejecting or withdrawing deletes the id. We honour Do Not Track and Global Privacy Control
signals as a refusal, and we show no banner when your browser sends one.
There are no advertising cookies, no Google Analytics, no social pixels and no third-party JavaScript on this site. Checkout is hosted by Polar on Polar's own domain under Polar's cookie policy.
The same "Cookie settings" link sits in the footer of every page, so you can change or withdraw your choice at any time. Withdrawing is as easy as giving consent and has no effect on the lawfulness of processing before you withdrew.
5Who we share data with (sub-processors)
We keep the list short and publish it. Today it is Cloudflare (hosting, database, CDN, backups, edge security) and Polar (Merchant of Record — checkout, payments, tax, invoicing). Each is bound by a data-processing agreement. The current list, with the data each one touches, where it is processed and the transfer basis, is on our sub-processor page. We do not sell personal data, we do not "share" it for cross-context behavioural advertising, and we do not send it to advertising networks or data brokers.
6International transfers
We operate from the Republic of Korea. Where personal data of EU/EEA or UK residents is processed, transfers rely on (i) the European Commission's adequacy decision for the Republic of Korea, and/or (ii) Standard Contractual Clauses (UK: the IDTA/UK Addendum) with our sub-processors where data is processed outside the EEA, the UK or Korea. Our infrastructure runs on a global edge network, so we do not currently claim that data is pinned to any single region — see the sub-processor page for what each processor does and where. A copy of the relevant transfer safeguards is available on request.
For Korean users: use of overseas processors constitutes 국외이전 under PIPA; the recipient, purpose, data categories, retention and objection route are set out on the sub-processor page.
7Retention
We keep personal data only as long as the purpose above requires, then delete or anonymise it.
| Data | Retention |
|---|---|
| Account data (email, API key records) | For the life of the account; deleted within 30 days of a verified deletion request |
| Session and device records | Until the seat is released, then 90 days |
| Website analytics events | 12 months |
| Crash logs / run diagnostics | 90 days |
| Install/download request logs (IP, user-agent, referrer, country) | Held with website analytics events — up to 12 months today. We intend to reduce what is stored and shorten this window to 30 days, with IPs hashed rather than stored raw |
| Payment records (held by Polar; we keep tier and status only) | As required by Korean tax and commercial law — typically 5 years |
Your cookie choice (vzk_consent) |
In your browser until you withdraw it or the policy version changes |
Backups. Deletion from live systems is immediate; backups are purged on a rolling 30-day cycle (point-in-time recovery plus nightly dumps), so a deletion is fully propagated within 30 days. We do not restore a pre-deletion backup without re-applying the deletion.
8Your rights
Depending on where you live, you have the right to access, rectify, delete, restrict or object to processing of your personal data, to data portability, and to withdraw consent at any time. Korean users additionally have PIPA 정보주체 rights including 열람, 정정·삭제 and 처리정지. California residents have the right to know, delete and correct, to opt out of "sale"/"sharing" — we do neither, so the opt-out is honoured as a no-op and confirmed in writing — and not to be discriminated against for exercising any right.
How to exercise them. Email support@veizik.com, or read how data requests work first. Because accounts are keyed to an email address, we verify a request by sending a one-time link to that address — we do not ask for a government ID for a routine access or deletion request. Analytics events carry a random id and no account link, so they generally cannot be traced back to a person; tell us the id if you want those rows removed too.
| Regime | We respond within |
|---|---|
| GDPR / UK GDPR | 1 month (extendable by 2 months for complex requests, with notice) |
| PIPA | Access: 10 days · other requests: without delay, target 30 days |
| CCPA / CPRA | 45 days (extendable by 45, with notice) |
Operating target: acknowledge within 3 business days, complete within 30 days, and within 10 days for access requests.
Complaints. You can lodge a complaint with a supervisory authority. In Korea: the Personal Information Protection Commission (개인정보보호위원회) and the KISA privacy call centre (privacy.go.kr, 118). In the EU/EEA: your local Data Protection Authority. In the UK: the Information Commissioner's Office (ICO). We would rather hear from you first, but you do not have to contact us before contacting them.
9Automated decision-making
We do not make decisions producing legal or similarly significant effects about you based solely on automated processing, and we do not profile you for advertising. Licence-abuse checks (seat limits, duplicate-device detection) are rule-based, affect only licence enforcement, and are reviewed by a human on request — write to support@veizik.com if one affected you.
10Children
Veizik is a professional tool and is not directed to children — under 14 in Korea, under 16 (or the applicable national age, which varies between 13 and 16) in the EU/EEA, and under 13 in the United States. We do not knowingly collect personal data from children below the applicable age. If you believe a child has given us data, write to support@veizik.com and we will delete it.
11Security
Encryption in transit, API keys stored hashed rather than in plaintext, least-privilege access to the database, and our edge provider's WAF and bot controls. Report a vulnerability to security@veizik.com — see security.txt. If a personal-data breach occurs we follow our breach runbook, which is built to PIPA and GDPR notification timelines (regulator without undue delay and within 72 hours where the GDPR requires it; affected users notified where the law requires it).
12Changes
If this policy changes we update the version number and effective date at the top of this page. Material changes that expand what we collect are announced before they take effect, and a change to the cookie policy bumps the consent version, which re-asks for your cookie choice instead of silently keeping the old one.
13Contact
링크픽 (LinkPick) — brand Veizik, Republic of Korea · business registration no.
148-14-02554 · Representative Bak Malgeum (박맑음).
Privacy and data requests: support@veizik.com ·
Security: security@veizik.com ·
Billing (Merchant of Record: Polar): billing@veizik.com
Registered address, Privacy Officer, and EU/UK representatives are listed in §1.