Minari, the operator of Mallangi, handles your personal data with care. In this policy, "we" refers to Minari. In particular, uploaded parent photos are not stored after generation, while generated result images and videos are managed in your account library.
01
Data we collect
Account: social sign-in identifier, nickname, and email address (if you consent)
Apps in Toss account link: numeric Toss userKey, the Mallangi account link, and an internal account ID derived from the userKey with a keyed hash. We do not store Toss access or refresh tokens.
Uploaded photos: processed temporarily to generate your result (see 02)
Generated results: images, videos, and naming or generation metadata saved in your account library
Payment: payment approval result, order ID, and credit transaction history (card details are handled by the payment provider)
Referral and Toss promotion records: web share-link token, Toss invite token, inviter and referred-account attribution, campaign version, reward kind and source, amount, processing status, provider key, provider error code, attempt count, and timestamps
Usage records: access and error logs
Service analytics: sign-in provider and outcome, country or market, whether a payment screen was shown, and an opaque analytics ID derived from a server-side internal ID using a secret-keyed HMAC
02
How photos are handled (important)
π΄ Parent photos are used only while processing your generation request and the originals are not stored afterward. Generated result images and videos are saved in your account library until you delete the item or close your account. A share preview is stored separately for up to 90 days only if you create a share link.
03
Storage and transmission
We operate on Cloudflare and Google Cloud infrastructure, and use the Google Gemini API to process face generation. Data is encrypted in transit.
We use Google Firebase and Google Analytics for sign-in, payment-funnel, and service-usage analytics. We do not send email addresses, names, tokens, or raw social-provider IDs to these analytics services. For account-level analytics, we use an opaque analytics ID derived from a server-side internal ID using a secret-keyed HMAC. Advertising storage and personalized advertising are disabled.
04
Purpose
Providing generated results and operating sign-in, credits, and payments
Linking Apps in Toss accounts, attributing invites, checking campaign eligibility, and issuing Toss points
Preventing duplicate web or Apps in Toss rewards, checking campaign caps and budget, reconciling provider payout results, and handling errors
Analyzing sign-in and payment funnels and service usage
Responding to inquiries, handling errors, and improving the service
05
Retention and deletion
Account and Apps in Toss userKey link: deleted without undue delay when you close your account
Uploaded parent photo originals: deleted immediately after generation
Generated result images, videos, and library metadata: retained until you delete the item or close your account
Web share previews: automatically deleted within 90 days
Web referral links: disabled after 90 days and cleaned up when that expired link is visited or referral processing handles it
Apps in Toss invite links: valid for up to 30 days after creation or until the campaign ends, and not used for new attribution after expiration
Web referral attribution: deleted when either the inviter or referred account is closed
Apps in Toss referral attribution: deleted when either the inviter or referred account is closed
Web and Apps in Toss reward ledgers: deleted when the related account is closed, except that records needed for campaign settlement or required by law are retained for the necessary period and then deleted
Payment records: retained for the periods required by applicable law
06
Third parties
We do not provide your data to third parties except where permitted or required by law. For service operations, we use cloud service providers (Cloudflare and Google), Google Firebase and Google Analytics, payment providers (Paddle and, where enabled, KakaoPay), and integrate with the Apps in Toss login and Toss-points promotion API (Toss). We do not store Toss access or refresh tokens on our server.
07
Your rights
You may request access, correction, deletion, or restriction of processing by contacting support@minari.io.