Privacy Policy

Effective June 25, 2026

Compliant with Thailand's Personal Data Protection Act B.E. 2562 (PDPA)

In short: we collect only what we need, never sell your data, our team does not read your chats, and you can delete your data anytime.

1. Data Controller

Pinkora acts as the data controller under the PDPA for the collection, use, and disclosure of your personal data as described in this policy.

Data Protection Officer (DPO) contact: privacy@pinkora.com

2. Data We Collect

Data you provide directly:

  • Email and password (for sign-up and login)
  • Display name and username
  • Profile picture you upload
  • 18+ age verification
  • Payment info (processed by Stripe — we never store your card number)

Data generated by usage:

  • Messages exchanged with AI characters (stored for the AI's memory)
  • Characters you create and images you upload
  • Intimacy level and relationship status with characters
  • Kora transaction history
  • Access logs (IP address, device type, timestamp)

Data collected automatically:

  • Cookies and Local Storage for session management
  • Usage analytics (anonymous, non-identifying)

3. Purpose and Legal Basis of Processing

PurposeLegal basis
Providing the AI chat platformPerformance of a contract (§24(3))
Processing paymentsPerformance of a contract
Sending essential notification emailsPerformance of a contract
Improving AI service qualityLegitimate interest (§24(5))
Preventing fraud and misuseLegitimate interest
Sending news and promotions (marketing)Consent (§19) — withdrawable anytime
Complying with legal requirementsLegal obligation (§24(6))

4. Disclosure to Third Parties

We do not sell your personal data. We disclose data only in the following cases:

  • Service providers: Supabase (database/auth), Stripe (payment), Vercel (hosting), OpenAI/OpenRouter (AI processing) — all under data protection agreements
  • Court or government order: when there is a valid subpoena or lawful legal order
  • Merger or acquisition: if the business is sold or merged, you will be notified in advance and may delete your data

Your chat data is not read by our team, except where necessary for a legal investigation or system security.

5. Your Rights as a Data Subject (PDPA)

As a data subject, you have the following rights:

Right of access

Request a copy of the data we hold about you

Right to rectification

Request correction of inaccurate data

Right to erasure

Request deletion of your personal data

Right to object

Object to certain processing of your data

Right to portability

Receive your data in a transferable format

Right to withdraw consent

Unsubscribe from marketing email instantly

Exercise these rights via My Profile or contact privacy@pinkora.com — we respond within 30 days.

6. Data Retention

Data typeRetention period
Account dataLifetime of the account + 90 days after deletion
Chat history (messages)Lifetime of the account (deletable in Settings)
AI photos sent in chat45 days, then the file is auto-deleted (message stays)
Payment records5 years (accounting & tax law)
Access logs90 days
Marketing dataUntil consent is withdrawn

7. Data Security

We use industry-standard security measures, including:

  • HTTPS/TLS encryption for data in transit
  • Encryption at rest in the database
  • Row Level Security (RLS) — each user can access only their own data
  • Passwords hashed with bcrypt before storage
  • Two-factor authentication (2FA) for team accounts

While we use best-in-class measures, no system is 100% secure. In the event of a data breach, we will notify you within 72 hours as required by the PDPA.

8. Cookies and Tracking

We use cookies to:

  • Session cookies: required for login (cannot be disabled)
  • Preference cookies: remember your settings
  • Analytics cookies: track usage anonymously to improve the service

You can decline analytics cookies in Settings without affecting core functionality.

9. International Data Transfers

Our service uses infrastructure from international providers, so your data may be processed in the United States and the European Union.

Every provider we use meets international security standards (SOC 2, ISO 27001 or equivalent) and has a Data Processing Agreement (DPA) with us.

10. Changes to This Policy

If we make material changes to this policy, we will notify you via your registered email at least 30 days in advance. Continued use constitutes acceptance of the updated policy.

Contact the Data Protection Officer (DPO)

For questions, complaints, or to exercise your PDPA rights, contact privacy@pinkora.com — we respond within 30 days.

If you do not receive a response, you may lodge a complaint with Thailand's Personal Data Protection Committee (PDPC).