logo
Privacy PolicyTerms of Service

Privacy Policy

February 2026

Morpheus Studio (“we”, “us”, or the “Company”) provides AICRON (https://aicron.io, the “Service”) to users in multiple countries. We comply with the privacy laws that apply where the Service is offered. This Privacy Policy explains what personal data we process, why we process it, who we share or entrust it with, and what rights you have.

Use of the Service is also governed by our Terms of Service. If this Privacy Policy and the Terms conflict on a specific point, the more specific document controls.

We may update this Privacy Policy. If we make a material change, we will notify you in the Service or by email. The effective date is shown at the top of this page.

1. Data Controller

We are the Data Controller of personal data processed to provide the Service.

ItemDetails
ServiceAICRON
OperatorMorpheus Studio
Address2F, 28 World Cup-ro 14-gil, Mapo-gu, Seoul, Korea
Contactsupport@aicron.io

You may use the email above for privacy questions, requests, or to exercise your rights.

This Privacy Policy applies to aicron.io and related Service domains.

2. Purposes and Legal Bases

We process personal data only as needed for the purposes below. Our legal bases are typically performance of a contract, legitimate interests, consent, and legal obligations.

2.1 Accounts and Service Use

We process data to register and sign you in, identify your account, provide workspaces, projects, and generation history, and provide support.

  • Legal basis: contract, legitimate interests (operating the Service)
  • Data: email, name or display name, profile image, username, account identifiers, social login identifiers, and account settings such as language and time zone

You may sign up with an external account such as Google. In that case we receive identifiers the platform shares with us (for example email, name, and profile image) to create your account. Changes or deletion on that platform must be handled there as well.

2.2 Generative AI and Creative Features

In the node editor, chat, timeline, templates, Instant AI, MCP, and similar features, we process inputs (prompts, uploads, reference media) and generate, store, and display outputs (images, video, audio, text, 3D, and similar).

  • Legal basis: contract
  • Data: content you enter or upload, generated outputs, model and parameter choices, generation time, credit usage, project graphs, and related metadata

See Section 4 for additional rules on generative AI.

2.3 Payments and Subscriptions

We process payment-related data for paid plans, Teams, Cron (credit) purchases, promo codes, and invoices.

  • Legal basis: contract, legal obligations (payments, tax, accounting)
  • Data: purchase history, subscription status, payment identifiers, billing country, and receipt information. Sensitive payment-method details such as card numbers are handled by the payment processor and are not stored by us as a rule.

2.4 Security, Abuse Prevention, and Reliability

We process data to detect account takeover, credit abuse, automated attacks, and Terms violations, and to keep the Service stable.

  • Legal basis: legitimate interests, legal obligations
  • Data: IP address, browser and device information, access logs, and request metadata. We may process device or browser identifiers when needed.

2.5 Product Improvement and Statistics

We may analyze usage in pseudonymized or aggregated form to understand feature use and improve performance.

  • Legal basis: legitimate interests
  • Data: page visits, feature-use events, and error or performance metrics

2.6 Support and Notices

We use data to answer inquiries, send outage or security notices, notify you of policy changes, and send Service messages you have agreed to receive.

  • Legal basis: contract, consent, legitimate interests
  • Data: inquiry content, contact details, account information, and language settings

Marketing emails are sent only with your consent or where permitted by law, and you may opt out.

2.7 Legal Compliance

We process data as needed to respond to lawful requests, handle disputes, and meet accounting or tax obligations.

3. Categories of Personal Data

3.1 Data You Provide

  • Account: email, name, username, profile information
  • Contact and identification data related to billing (including data collected during payment processing)
  • Support inquiries
  • Optional information you enter, such as a referral code

3.2 Data Created Through Use of the Service

  • Projects, node graphs, prompts, uploaded files, outputs, and generation history
  • Share links, Teams membership, and projects you publish to the community
  • Credit balance and subscription or purchase history
  • Chat and AI assistant conversations
  • Local project snapshots stored in your browser. These are stored on your device and are designed to be deleted when you sign out.

3.3 Data Collected Automatically

  • IP address, browser type, device and OS, language, and referring URL
  • Identifiers collected through cookies and similar technologies
  • Usage data (page views, feature use, error logs)

We do not intentionally collect sensitive data (such as beliefs, health, or biometrics). Content you upload may still include a third party’s face, voice, or location. Responsibility in those cases follows Section 4 and the Terms of Service.

4. Generative AI

When you send prompts, images, video, audio, text, or similar (“Input”), we generate results (“Output”) through the AI model you select.

4.1 Roles

  • You: You are primarily responsible for personal data in your Inputs (your own or a third party’s face, voice, name, and similar). If you upload someone else’s personal data or create Output that resembles them, you need a valid legal basis, such as notice and consent.
  • We: We collect, store, transmit, and display Inputs and Outputs as needed to provide the Service. The third-party model provider you select processes Inputs to run that model.

4.2 No Training Use

We do not use data you submit, or data generated through the Service, for separate model training. This is our policy.

Each model on the Service is also subject to the policy of the company that develops and operates it. Retention, training use, and commercial-use terms may differ by model. We cannot set or change those policies.

Review the developer’s terms and privacy policy before you choose a model. If our policy and the model developer’s policy differ, the developer’s policy applies to that model’s processing.

4.3 How We Use Inputs and Outputs

  • Generating, previewing, storing, keeping history of, sharing, and downloading requested Output
  • Measuring usage and credits, fixing errors, and detecting abuse or illegal content
  • Maintaining security and checking compliance with the Terms

These purposes are for providing the Service, not for separate model training.

4.4 Ownership of Outputs

Ownership of all outputs generated through AICRON belongs to the user who created them, and that creator may use the outputs commercially. See Section 8 of the Terms of Service.

4.5 Your Responsibility for Third-Party Content

If you use someone else’s photos, voice, trademarks, or copyrighted works as Input, you must have the rights and consents required. We may remove content that is unlawful or violates the Terms, and we may cooperate with competent authorities.

5. Retention

We delete personal data without undue delay when the purpose of processing is complete. We may retain data for the periods below.

CategoryPeriod
Account and Service-use recordsUntil account deletion, and then as needed to handle disputes or abuse
Projects, Inputs/Outputs, and generation historyWhile the account remains active; deleted within a reasonable time after you delete them or close the account
Payment, contract, and accounting recordsAs required by applicable tax, accounting, and consumer-protection laws
Support recordsUp to 3 years after the inquiry is resolved, or until a dispute ends
Access logs and security or abuse recordsUp to 1 year. Identifiers used for sanctions may be kept for the minimum time needed to prevent recurrence
Marketing preferencesUntil you opt out or withdraw consent
CookiesUntil each cookie expires or you delete it

Data we must keep by law is deleted after that period ends.

6. Sharing with Third Parties

We do not share personal data with third parties without your consent, except:

  • when you have agreed in advance
  • when required by law or by a lawful request from authorities
  • when needed to settle charges or provide the Service and you have agreed to that sharing

If you share a project by link, Teams, or the community, project information and previews are visible to people in that scope. You control the sharing settings.

7. Processors

We engage processors to operate the Service. We enter into contracts and supervise them so personal data is handled securely.

CategoryWork
Authentication and account servicesSign-up, sign-in, session and account management
Payment processorsSubscription and credit payments, receipts, customer portal
Cloud infrastructure and storageFile uploads, content storage and delivery, infrastructure security
Web hosting and analyticsService operation, usage statistics, performance measurement
Third-party AI model providersProcessing Inputs and generating Outputs for the model you select

AI model providers depend on the model you choose in a node or chat. We select providers we consider reliable, but each provider’s processing location and retention follow that provider’s policy.

You may request a more detailed list of processors at support@aicron.io.

8. International Processing

AICRON is a global service for users in many countries. Personal data is processed where we, our infrastructure, and our processors operate the Service. The default is not an “export” from one country to another.

Account, payment, content, and generation requests may be processed in the country where the relevant processor is located. Inputs to the AI model you select may be processed where that model’s operator processes data. We cannot designate or change that location.

If the laws of your country regulate cross-border transfers, the processing below may count as an international transfer under those laws.

ItemProcessorPurpose
AccountsAuthentication and account processorSign-in and account management
PaymentsPayment processorPayment processing
Files and outputsCloud infrastructure processorStorage and delivery
Generation inputsSelected AI model providerOutput generation
Usage statisticsAnalytics processorStatistics and performance

9. Your Rights

You may ask us to:

  • access, correct, delete, or restrict processing of your personal data
  • withdraw consent
  • explain how we process your data
  • port your data, where technically feasible

How to exercise these rights:

  • edit or delete your account in account settings or your profile
  • email support@aicron.io

We will verify that the requester is you, then handle the request without undue delay. We may limit a request if we must keep data by law or if it would harm another person’s rights.

If you live in the EEA or the UK, you may have rights of access, rectification, erasure, restriction, portability, objection, and the right to lodge a complaint with a supervisory authority, to the extent those laws apply. Residents of certain U.S. states, including California, may have additional rights under state law. The contact channel is the same.

10. Cookies and Similar Technologies

We use cookies, local storage, and similar identifiers to keep you signed in, protect the Service, remember preferences, and measure usage.

TypePurposeRequired
Authentication and security cookiesKeep you signed in and protect the ServiceRequired
Feature storageEditor settings and local project snapshotsNeeded for those features
AnalyticsUsage statistics and performanceProduct improvement; you may limit this in your browser

If we introduce advertising tracking, we will update this section and our consent method.

Blocking cookies may prevent some features, including sign-in, from working.

11. Deletion

When a retention period ends or the purpose of processing is complete, we delete personal data without undue delay.

  • Electronic files: deleted so they cannot reasonably be recovered
  • Paper records: shredded or incinerated

Data kept by law is stored separately from other personal data.

12. Security

We implement measures such as:

  • encryption in transit
  • least-privilege access and authentication
  • access logging and monitoring for attacks
  • contracts with and oversight of processors
  • internal access controls

Internet transmission and third-party model calls have inherent risks. We are responsible only to the extent we have taken reasonable measures.

13. Contact and Supervisory Authorities

For privacy questions, requests, or to exercise your rights, email support@aicron.io.

If you are not satisfied with our response, or where the law allows, you may lodge a complaint with the privacy authority in your country or region.

14. Changes

This Privacy Policy is effective from February 2026. When we change it, we will announce the reason and the effective date. For material changes that are unfavorable to you, we will give reasonable notice.