PREPARED AUGUST 31, 2026
Privacy Policy
Last Updated: [[LAST_UPDATED_DATE]]
Effective Date: [[EFFECTIVE_DATE]]
This draft sets out the privacy framework planned for the Service. Unresolved operational details are deliberately visible rather than assumed.
1. Scope and privacy controller
This policy applies to the SakuVio mobile application, its public website, and related support channels (the “Service”). The data controller is [[OPERATOR_LEGAL_NAME]], registered at [[REGISTERED_ADDRESS]].
2. Information under review
The working data map covers login information, submitted content, generated content, payment-related status, device diagnostics, and communications. It must be narrowed or expanded only after engineering confirmation.
3. Why information is processed
The current purpose map covers delivering features, managing access, protecting users and systems, resolving technical issues, handling requests, and satisfying applicable law. Production analytics and advertising practices remain an open question.
4. AI content handling
User-selected content may be processed by [[AI_MODEL_PROVIDERS]] using [[CLOUD_INFRASTRUCTURE_PROVIDERS]] to return the requested result. Provider identity, location, access controls, retention, and training rights are unresolved launch facts.
Do not upload content you lack the right or authority to use. Content is not treated as biometric identification data unless the final product deliberately performs that function; confirm the shipping behavior.
5. Providers and disclosures
Information may be disclosed to contracted vendors that support hosting, AI processing, authentication, analytics, crash reporting, payments, and customer care. Record the final vendors in [[PRODUCTION_VENDOR_LIST]]. Disclosure may also occur to protect users, comply with binding legal process, or complete a corporate transaction with appropriate safeguards.
6. Retention
Account, content, output, diagnostic, purchase, and support records must follow the confirmed schedule in [[RETENTION_SCHEDULE]]. Data may be kept longer only when necessary for security, disputes, legal duties, or documented backup cycles.
7. Security and international transfer
Reasonable organizational and technical measures should protect information in transit, at rest, and during vendor processing. No system is perfectly secure. If information moves across borders, the operator must use a lawful transfer mechanism suited to the launch markets.
8. Your choices and rights
Subject to applicable law, users may request access, correction, deletion, restriction, portability, or an objection to certain processing. Requests must be sent through [[PRIVACY_REQUEST_CHANNEL]]. Identity verification and legally permitted retention may apply.
9. Account and data deletion
The verified deletion route is [[ACCOUNT_DELETION_URL_OR_EMAIL]]. The final page must explain which account and content records are erased, what is retained, and the expected handling time. Uninstalling the app does not itself submit a deletion request or cancel a store-managed subscription.
10. Children and age requirement
The minimum permitted age is [[MINIMUM_AGE]]. The released wording must match the store rating, sign-up flow, safety controls, and target markets. If information from an ineligible child is identified, the operator should take appropriate steps to remove it.
11. Regional disclosures
Before publication, add the notices and rights required for [[TARGET_MARKETS]], including any lawful-basis, sale/share, targeted-advertising, appeal, or authorized-agent disclosures that actually apply.
12. Policy changes
Material changes should be described with an updated date and any notice or consent required by law. Earlier versions should be retained according to the operator’s recordkeeping policy.
13. Contact
Privacy requests: [[PRIVACY_EMAIL]]
Support: [[SUPPORT_EMAIL]]
Operator: [[OPERATOR_LEGAL_NAME]]
Address: [[REGISTERED_ADDRESS]]