Privacy Policy
Revised August 14, 2026
1. Who this applies to (data subjects)
This policy applies to visitors to our website, people who submit the contact form, Design Partner applicants, and users of the Service.
2. Categories of data we collect
- Contact details such as name, company, and email address
- Inquiry content, planned timing, and expected volume
- Usage metadata (usage volume, cost, audit logs)
- Access logs, cookies, and device information
3. Purposes
We use collected information to (1) respond to inquiries, (2) provide and operate the Service, (3) perform contracts and billing, (4) improve the Service, and (5) comply with law and prevent abuse. We never use your data to train AI models.
4. Logs
We keep access and audit logs. The default audit-log retention is 30 days, configurable from 90 to 365 days per contract. Audit logs never contain prompts or generated content.
5. Cookies
Our website uses session cookies necessary for it to function. If we use analytics cookies, we will state so separately.
6. Retention
We keep inquiry data only as long as needed to respond, and delete it when no longer required, subject to legal obligations.
7. Cross-border transfers
Data needed for AI inference may be sent to the selected model providers (regions differ by model). See the Connected Models page.
8. Subprocessors
The model providers we use are listed in the AI Data Policy.
9. Security measures
We apply encryption in transit and at rest, role-based access control, audit logs, and periodic access reviews. GSCORA-issued tokens are stored only as non-reversible verifiers; BYOK credentials are encrypted with KMS.
10. Your rights
To request access, correction, deletion, or restriction, contact us below. We will respond as required by law.
11. Contact
For privacy inquiries, contact privacy@gscora.com. Operator: GSCORA Inc. (Representative: Representative Director: Zexin Yan, Address: 3-7-26 Ariake, Koto-ku, Tokyo 135-0063, Japan)