version supplied-20260916 · 2026-09-14
Ludyte Privacy Policy
Review edition. The provider schedule contains a substantive proposed framework and explicitly marked facts still requiring verification. Resolve the accompanying release checklist before publication.
Version: v1.0
Publication date: 14 September 2026
Effective date: 14 September 2026
NationA, Inc. · support@ludyte.com
Contents
- Who we are and the scope of this Policy
- Information we collect and its sources
- How and why we use information
- AI processing, shared training, and resulting models
- Public publication of videos and creation materials
- Service operations, support, and security
- Service providers, partners, and other recipients
- Analytics, advertising, marketing, and content promotion
- Retention, deletion, and continuing model use
- International processing
- Security
- Requests, withdrawal, and applicable time limits
- US state rights, regional supplements, and privacy contact
- Adult eligibility and children
- Changes, language, and contact
1. Who we are and the scope of this Policy
NationA, Inc. is responsible for personal information processed through Ludyte. Our address is 2810 N Church St STE 90780, Wilmington, DE 19802, United States. Contact support@ludyte.com for privacy inquiries.
This Policy applies from the initial launch and covers our website, accounts, creation tools, storage, publication and reuse, billing, support, analytics, advertising and marketing, and authorized training and promotional uses. It is drafted primarily for the United States, while preserving mandatory rights in other places where we provide Ludyte.
We explain the data and permissions for each purpose when you make the relevant choice. Once obtained, permission covers continuing use within the explained scope without approval for each training run or promotional placement. Where a specific consent is required, general acceptance of the Terms or this Policy does not replace it. Public publication makes the video and the identified creation materials available together. Sections 4, 5 and 8 explain these uses; sections 9 and 12 explain retention and withdrawal.
Separate services you use directly, including sign-in and payment services, may have their own privacy notices. Service-country restrictions are in section 2 of the Terms. Future changes to this Policy follow section 15.
2. Information we collect and its sources
| Category | Examples and source |
|---|---|
| Identifiers and account information | Email, account and sign-in-provider identifiers, verification state, profile/display name, language and settings; from you and your sign-in provider |
| Creation content and audiovisual information | Prompts, generation-related messages, images, videos, audio and other supported references you submit; frames or transcripts needed for the task; generated results and editing instructions |
| Service and commercial activity | Projects, tasks, bookmarks, publication and reuse settings, job status, quality, duration and scheduling choices, plans, free allowance and credit records |
| Billing information | Customer, subscription, order and payment references, amount, currency, status, and invoice, refund or dispute records; from you and the payment provider |
| Internet, device and network activity | IP address, approximate location inferred from IP, browser/device characteristics, session identifiers, page and interaction events, request and error information; from service operation and, for optional tracking, the choices in section 8 |
| Advertising and inferred interests | Consented advertising or analytics identifiers, referral and campaign information, conversion events and inferred interests based on permitted activity; from your interaction with Ludyte, campaigns and disclosed partners |
| Communications, feedback and permissions | Support messages, reports, feedback, email delivery information, purpose-specific consent and withdrawal records, publication confirmations, and export, deletion or other rights requests |
Payment details are handled by the payment provider identified at checkout and in section 7. Ludyte uses payment references and transaction records; do not send full card numbers or security codes to support.
Materials you submit may contain information about other people or sensitive information. Provide only what you have authority to use and what is necessary. A photograph or voice recording is not automatically a biometric identifier, but using it to identify a person may involve additional legal requirements. General training or promotion consent does not authorize a separate biometric-identification program. We obtain additional permission and apply protections where legally required for sensitive information; unnecessary sensitive records, account credentials and payment secrets are not eligible training, advertising or promotional material. An uploader cannot waive another person's rights simply by checking a box.
3. How and why we use information
| Purpose | Information involved and how the purpose is authorized |
|---|---|
| Provide the requested service | Account, content, library and job information for sign-in, generation, storage, organization and delivery |
| Publish and support reuse | The publication package, public profile and confirmation records when you choose Public under section 5 |
| Manage purchases | Account, transaction and relevant support information for subscriptions, billing, refunds and records |
| Protect the service and meet obligations | Necessary technical, account, job and incident information for security, abuse and DDoS prevention, failure investigation, legal compliance and disputes |
| Support you and respond to rights requests | Information reasonably needed to resolve the request and verify authority where appropriate |
| Develop shared AI models | Covered content and feedback for dataset preparation, evaluation, training and fine-tuning after the training consent in section 4 |
| Product analytics | Consented identifiers and events to understand feature use, reliability and user journeys |
| Advertising and measurement | Consented identifiers, activity, inferred interests and campaign events to deliver or personalize advertising and measure its performance |
| Marketing communications | Consented contact and preference information to send Ludyte news, offers and campaigns |
| Promote NationA’s creative business using content | Covered content, associated public profile information, and included likeness or voice after the specific promotional consent in section 8 |
Necessary information supports the service you request and our legal and security obligations. If it is not provided, the affected feature may not work. Optional training, analytics, targeted advertising, marketing messages and content promotion are not conditions of core video generation. Each choice may be refused or withdrawn independently. Agreeing to one purpose does not automatically authorize another. We use aggregate operational and payment reports where identification is unnecessary.
Public publication, training and promotion have different consequences: training may use private work without posting it; Public shares the work and its creation package; promotional consent may allow selected private work to be shown externally. We explain those distinctions at the corresponding choice. Where another law requires a legal basis, our bases and additional conditions are described in section 13. We do not use a broad service-improvement statement to bypass a required permission.
4. AI processing, shared training, and resulting models
Requested generation. Our systems and AI/compute providers process the prompts, relevant conversation context and reference media needed to create and deliver your result. This can include extracting frames, audio or transcripts and adapting the material for the selected model.
Shared training from launch. After you give the training permission, we may use eligible creation-related prompts, conversations, images, videos, audio, references, results and feedback, including private work, from that point while the permission is active. We may start at launch or at a later time of our choosing within that permission. No separate start date, approval for each dataset, or fee to you is required for uses within the disclosed scope. Training may include selection, extraction, transformation, labeling, filtering, evaluation, testing, fine-tuning and development of shared AI and company LoRA models, for commercially used NationA AI, creative, and media technology, including Ludyte.
Authorized personnel and contracted providers may process the necessary data for us under purpose and access restrictions. Your permission does not give providers unrestricted rights for their own unrelated model training. We exclude credentials, payment secrets and unnecessary sensitive information and apply additional conditions where legally required. Training permission is separate from publishing the original materials; Public status alone is not the basis for enrolling content.
Retention and models. We retain eligible source data and derived training or evaluation material for as long as reasonably necessary for the disclosed model development, testing, validation, safety and improvement purposes while an appropriate permission or other lawful basis remains. We consider the research and model lifecycle, the need to reproduce or assess results, data relevance, privacy risk and withdrawal or deletion requests. We do not promise to delete every training source immediately after one training run or to keep it forever solely because consent was once given. Section 9 gives the retention criteria and exceptions.
Lawfully developed models, model parameters, aggregate findings and properly de-identified data or improvements that do not remain personal information may be retained and used without a fixed expiration for these purposes, subject to the applicable content license and law. A model or dataset is not automatically anonymous just because it lacks an account name. We maintain safeguards for de-identified information, do not attempt re-identification except where legally permitted to test those safeguards, and impose appropriate restrictions on recipients.
Withdrawal. Contact support@ludyte.com or use available privacy controls. We stop further enrollment and consent-based processing of identifiable covered material as soon as reasonably practicable within the applicable period, and address source files, training copies and provider records under sections 9 and 12. Deleting source files does not necessarily undo model parameters; withdrawal does not automatically require destruction or retraining of an entire lawfully developed model. If a model retains personal information or a legal remedy requires action, we assess and implement the required restriction, deletion or other remedy. We do not guarantee perfect removal of every learned influence or treat models as categorically outside privacy law.
Personal LoRA and persistent personal memory are not currently included in Ludyte. If offered later, they will require your request and appropriate feature information. Conversation context needed for a current generation is not itself a personal-memory feature.
Commercial technology and ownership. Within the training permission, covered material may be combined with other sources to develop annotations, embeddings, evaluations, synthetic examples, and models. We and our affiliates may deploy, license, and commercially provide resulting NationA AI, creative, and media technology. Your content contribution does not itself grant ownership or revenue rights in that technology. This does not authorize a standalone sale of identifiable source datasets, provider use for unrelated models, or publication of private sources without the separate permission. The license and limits are in section 9 of the Terms.
Scope of NationA development. When the corresponding permission is active, the development and promotional scope includes NationA’s AI, creative, and media products and services, including Ludyte, future versions, models, tools, and related commercial offerings. We may carry out contracted research, joint development for these purposes, model/software licensing, and business demonstrations within that scope. Eligible private creation material can be used for authorized development, but training does not automatically publish it. A future connected product or shared account feature is not already active merely because it is within a possible business plan; any additional collection or materially different processing will be explained, with required permission obtained before it begins.
5. Public publication of videos and creation materials
Public publishes the work and its creation materials together by default. After you review and confirm the publication notice, the public package includes the final video, published title and description, relevant public profile information, the prompt used for that generation, and the reference images, reference videos and other user-supplied materials actually used for that work and identified in the preview. It does not include unrelated private conversations or files, account credentials, billing information, or hidden system instructions.
The package is available through discovery, search and shared links. Public viewers may view, copy or download exposed material, and other Ludyte users may reuse it under section 10 of the Terms, including to create commercially used results. Do not publish the package if you want those inputs to remain private or lack permission to disclose them. Keeping a work private prevents this community publication; it does not withdraw an independent training or promotional consent.
You can request publication removal or an end to new reuse through available controls or support@ludyte.com. Library archive/delete and community removal are separate. We stop corresponding service-side access or new reuse after processing, including associated materials, subject to necessary cache propagation. Independently downloaded copies, shares and lawfully created results may remain; applicable rights and remedies still apply.
6. Service operations, support, and security
We use operational, diagnostic and incident-management systems to monitor availability, payment status and trends, processing failures, suspected abuse, and security threats such as DDoS attacks. These systems may process event type and time, status or error information, and relevant account, job, transaction, device or network references. Identifiers that can be linked to a user remain personal information.
Authorized personnel and providers may access information reasonably needed to investigate an issue, respond to support, prevent harm or comply with law. We limit routine notifications to information relevant to the event, apply access restrictions and exclude passwords, authentication secrets and full payment-card information. Specific incidents may require reviewing relevant content; this operational purpose does not itself give permission for unrelated training or advertising. Provider details and retention are addressed in sections 7 and 9.
We may use automated filters and authorized human review of relevant content and metadata for abuse detection, quality and failure investigation, content moderation, and legal compliance. This does not mean that every item is reviewed or certified. We process complaint identifiers, authority and contact information, evidence, and response records for rights or safety reports. Copyright notices or counter-notices may be forwarded as required by the applicable procedure; unnecessary sensitive information is limited. Intimate-image complainants’ identity or evidence is not routinely disclosed to uploaders. We may preserve relevant evidence under a lawful hold, restrict access, and disclose only what is necessary for the permitted legal or protective purpose. Such material is not automatically included in training or advertising.
Requested generation may involve technical normalization, translation, safety filtering, instruction adjustment, and extraction of relevant media features. We may use limited content and metadata for necessary moderation and to determine public-discovery eligibility. These operations do not create permission to use unrelated private material for advertising or shared model training. A safety-related feature extraction is not a promise that every input feature is immediately deleted, nor authorization for biometric identification; the applicable processing, sensitivity, retention, and provider rules still apply.
7. Service providers, partners, and other recipients
We may use affiliated and external providers for hosting, storage, delivery, identity, payments, AI processing, research, communications, diagnostics, security, support, analytics, and advertising. We select and replace providers according to capacity, reliability, cost, quality, safety, and legal requirements. A provider change within the disclosed purpose does not by itself require approval for every technical request, but applicable notices, contractual safeguards, and required consent still apply. A company’s location and the countries where data is stored or remotely accessed are different facts.
7.1 Provider and processing schedule — proposed operational framework. AWS and Stripe use has been confirmed for this draft; the active inventory, exact contracting entities, access countries, backup cycles, and certain product settings have not been verified. Rows marked “to confirm” describe the proposed arrangement or category, not a representation that an unidentified vendor is active or that an unverified country is used. This review annotation must be resolved before customer publication.
| Provider or category / status | Purposes and information | Countries of storage, processing, or access | Retention and permitted use |
|---|---|---|---|
| AWS / use confirmed; contracting entity and enabled services to confirm | Hosting, databases, files, compute, backups; account and job identifiers, content, references, results, necessary technical and transaction records | United States and South Korea: user-confirmed infrastructure locations. Other service-specific or support access locations: to confirm | Governed by NationA’s category rules in section 9 and configured service/backup lifecycle. AWS does not establish one universal retention period for every Ludyte record. Enabled services and contractual data-use options must be checked |
| Stripe / use confirmed; applicable Stripe entity and products to confirm | Payments, subscriptions, invoices, refunds, disputes, fraud prevention; identity/contact and transaction data and necessary device/network signals. Payment details may be collected directly by Stripe | Stripe’s general notice identifies transfers including the United States and India; applicable countries for this merchant, payment method, product and support activity must be confirmed. This is not confirmation that every Ludyte payment is processed in India | For payment provision, regulatory, financial-partner, accounting, fraud and claim requirements as applicable to Stripe’s role. Independent required payment records may remain after Ludyte deletion; NationA does not promise to erase records Stripe must legally retain |
| Sign-in and authentication providers / active names to confirm | Sign-in identifiers, email/profile fields authorized for login, authentication/session and security signals | Actual provider storage and remote-access countries: to confirm before adding to the final schedule | Login/connection duration, token lifecycle, security and lawful provider records; disconnecting future login does not erase all earlier transaction or account records |
| AI/model/GPU providers and contracted research partners / additional providers beyond AWS to confirm | Necessary prompts, reference media, relevant context and results for requested generation; eligible authorized material for evaluation and shared development | Selected compute regions plus authorized staff or subprocessors’ access countries: to confirm | Request completion, necessary documented debugging/safety, or authorized model-development criteria in section 9. No assumed zero retention or unrestricted unrelated vendor training |
| Media delivery, storage and backup providers / additional providers to confirm | Content transmission, cached media, file identifiers, IP/access logs, requested storage and recovery | Origin storage and edge/cache or support countries must be recorded separately; global delivery is not confirmation of storage in every country | Necessary delivery/cache lifecycle and the storage or restricted-backup criteria in section 9; removal and restoration instructions must propagate to relevant copies |
| Email, customer-support and communication providers / active names to confirm | Email/contact details, delivery events, case content and authorized evidence; account messages and consented campaigns | Actual storage and support-access countries: to confirm | Delivery, support resolution, subscription preferences and necessary dispute evidence. Unrelated private support material is not automatically training or promotional material |
| Analytics, advertising, measurement and promotion partners / activation and names to confirm | Consented device/activity/campaign information; eligible content and public identity information only for authorized promotion | Actual recipient and onward-processing countries: to confirm | Consented analysis/campaign, attribution and reporting needs; applicable withdrawal/opt-out, retention settings and suppression records. Their role and any statutory sale/sharing classification must be disclosed |
| Diagnostics, fraud prevention, security and incident systems / active names to confirm | Minimal event, account/job/transaction references, technical errors and network/security signals; relevant evidence when an incident requires it | Actual storage, monitoring and remote-access countries: to confirm | Necessary operation, documented investigation and legal/safety evidence. Content is not included in routine alerts merely because a job exists; restricted records are not a general training or advertising dataset |
The AWS privacy FAQ, Stripe Privacy Policy, and Stripe provider list provide supplier-level information. They do not replace NationA’s responsibility to identify the actual Ludyte arrangement. A supplier’s list covers its broader business and does not mean that every listed entity receives Ludyte information.
7.2 Role and safeguards. Providers processing on our behalf receive access limited to the disclosed work, with appropriate confidentiality, security, permitted-purpose and onward-processing terms. We may authorize necessary subprocessors within those requirements. Independent payment, login or advertising processing is identified separately and subject to its lawful basis and notice. We remain responsible for our applicable provider-management obligations. Another provider’s policy cannot silently expand the training, promotion or disclosure permissions you gave us.
7.3 Other recipients. Within the disclosed purposes and permissions, we may share necessary information with affiliates, research and commercialization partners acting for the authorized work, professional advisers, authorities, and parties to actual or proposed financing, acquisition, reorganization or business transfers. We apply confidentiality, access limits and legally required notice; a successor must respect applicable permissions. Public audiences see the confirmed publication package or an authorized promotional placement. Other users receive only the reuse rights described in the Terms.
7.4 Changes and required details. Before a new or changed transfer begins, the applicable schedule or direct notice must identify the required legal entity/contact, data categories, purpose, actual destination countries including relevant remote access, timing and method, retention period or sufficiently specific criteria, safeguards or legal basis, and how to refuse or withdraw with the effect on the relevant function. Procurement flexibility does not replace required notice or consent. Requests may be sent to support@ludyte.com. Necessary infrastructure processing may be required for the requested feature; optional analytics, training and promotion choices remain independent.
8. Analytics, advertising, marketing, and content promotion
Necessary storage. Sign-in, security and necessary session functions use cookies or similar technologies. These are separate from optional tracking and content promotion.
Analytics and advertising choices. With the relevant prior affirmative choice, we and the disclosed partners use permitted identifiers, activity, inferred interests and campaign information for product analytics, personalized or targeted advertising, audience selection and advertising performance measurement. Targeted advertising can involve activity across different services and may be shown on or off Ludyte. Optional collection and transmission remain off before the relevant consent and stop when it is withdrawn, subject to applicable processing deadlines. Ads that do not use optional tracking may still appear; this does not override your choices about targeted advertising.
Marketing messages. With a prior marketing-message choice, we may send Ludyte news, offers and promotions by email or another specifically selected channel. Unsubscribe through the message, privacy controls or support@ludyte.com. Necessary account, security and transaction communications continue. An email choice does not also authorize text-message marketing.
Using your content to promote NationA and its AI, creative, and media products and services. With a separate affirmative promotional choice, NationA may select and use covered Input and Output, including private videos, prompts and reference materials, together with the public profile name or handle and any likeness or voice contained in the material, in NationA and Ludyte websites, demonstrations, social posts, email campaigns, press materials and paid advertisements. This may make otherwise private content visible to the public. The permission covers eligible content submitted or generated while that choice is active, beginning at launch once permission is obtained. It permits compliant selection, editing and publication without separate payment or approval for each use, as described in section 9 of the Terms.
We do not use that permission for fabricated testimonials, false endorsements of unrelated products, disclosure of credentials or billing details, or material for which necessary third-party permissions are missing. Partners receive only the content and related data needed for the promotion and its measurement. Permission to show a face or voice in a promotion is not permission for a separate biometric-identification program. Unrelated private communications are not promotional material solely because they were sent to support.
Changing your choices. Manage each purpose independently through privacy controls or support@ludyte.com. Withdrawing promotional permission stops selection for new campaigns and initiates stopping active campaigns and removal from placements we or our agents control, under section 9 and applicable deadlines. Independently shared or previously distributed copies may not all be recoverable. Withdrawing marketing emails does not, on its own, withdraw a separate content-promotion or training choice; each is available through the same contact route.
US sale, sharing, and opt-out rights. Disclosing identifiers or activity for cross-context behavioral advertising may constitute “sharing,” “sale” or targeted advertising under an applicable state law even without a cash payment. Our actual practices, categories and partners are stated in section 7; we do not infer them merely from the name of a tool. Where required, we provide an accessible “Your Privacy Choices” or “Do Not Sell or Share My Personal Information” control and honor recognized signals such as Global Privacy Control. A prior opt-in does not remove later opt-out rights or permit us to ignore a legally applicable signal. These choices are available without creating a new account, and exercising protected rights does not remove core generation.
The active technologies, partners, processing roles and applicable retention and sale/sharing disclosures are provided in section 7. Retention follows section 9, and requests and applicable deadlines follow section 12.
Within the permission you give, promotional material may be adapted for different formats, languages, audiences, and media placements, and an authorized campaign may continue without separate approval for each edit or placement. We may use contracted creative and distribution partners for those activities. Permission does not guarantee that we will feature a work or give attribution or payment. Your right to withdraw and the handling of already distributed material remain as described above; marketing-email unsubscribe, advertising opt-out, and content-promotion withdrawal address different uses. Do Not Track is not itself an authorization signal; legally recognized opt-out signals, including applicable GPC signals, are honored.
Cookie and similar-technology categories. We may use session or persistent cookies, local storage, pixels and comparable technologies. Necessary authentication, requested functionality, security and preference records support those functions. Optional analytics and advertising technologies require the corresponding choices described above. Persistent identifiers expire or are deleted according to their actual documented lifetime; browser storage expiration does not by itself determine the separate retention of server-side records. The final technology inventory must identify active provider/name, purpose, first- or third-party role, lifetime or criteria, and the applicable control. We do not represent that third-party tracking is absent without checking the active integrations. Removing browser data may reset preferences; any required permission must be obtained again before optional processing restarts.
9. Retention, deletion, and continuing model use
We retain each category of information for no longer than reasonably necessary and proportionate for its disclosed purposes, unless a specific law requires or permits limited additional retention. Where a fixed period is not reasonably possible, we use the criteria below. Retention is not unlimited merely because you once consented, and we periodically assess whether the purpose and need remain. Requests are handled under section 12; a shorter mandatory period takes precedence.
| Category | Retention period or determining criteria |
|---|---|
| Account, projects, generation content, references and results | While needed for the account, requested storage, publication and other authorized uses. Account deletion includes a 30-day recovery period unless a shorter law requires otherwise, followed by final cleanup within applicable request deadlines; the recovery period does not restart or extend those deadlines |
| Identifiable training sources, labeled or transformed copies, evaluation sets and linked feedback | While the relevant permission or other applicable lawful basis remains and the material is reasonably needed for the model-development, testing, validation, safety or improvement cycle. Consider relevance, reproduction of results, the model lifecycle and privacy risk. Withdrawal stops further consent-based processing within its applicable deadline, followed by deletion or permitted restricted retention |
| Lawfully developed models and properly de-identified data or aggregate improvements that are no longer personal information | No fixed expiration while useful for the disclosed purposes and permitted by the content license and law. Models retaining personal information remain subject to applicable rights and remedies |
| Advertising identifiers, activity, inferred interests and measurement | While reasonably necessary for the consented campaign, attribution, measurement and reporting purposes, within the tool-specific period or criteria in section 7; applicable opt-outs and withdrawals prevail |
| Promotional originals, edits and placements | While promotional permission remains and reasonably needed to select, prepare, distribute, assess and manage authorized campaigns. On withdrawal, stop new selection and address active campaigns and controlled placements within the applicable deadline; retain only justified legal or permission evidence thereafter |
| Marketing contacts and preferences | Until the relevant choice is withdrawn or the purpose ends, with minimal suppression records retained as needed to avoid sending unwanted messages |
| Consent, publication-permission, rights-request and suppression records | For as long as reasonably needed to demonstrate permissions and compliance, honor continuing restrictions and resolve a relevant claim, considering applicable statutory record periods and limitation periods. These records are not an alternative training or marketing dataset |
| Billing, invoices, refunds and disputes | While necessary to process and reconcile the transaction and satisfy applicable tax, accounting, fraud, dispute and legal-record requirements. Only relevant information is retained under such requirements |
| Operational, diagnostic and security records | While reasonably needed to investigate, protect and stabilize the service and handle the relevant incident, subject to the provider-specific rules in section 7 and documented legal or security exceptions |
| Prepared account export | Download access lasts seven days after preparation; expired working copies are removed through scheduled cleanup and applicable request rules |
| Specified technical billing-event records and restricted request-audit records | Scheduled cleanup of processed/skipped billing events after 90 days and the defined restricted audit archive after 180 days, subject to unresolved incidents or lawful holds. These periods do not govern every financial record or all content |
| Restricted backups and archives | Removed or overwritten through the applicable backup cycle identified in section 7. Where law permits deferred deletion from inactive backups, they remain restricted, are not used for ordinary generation, training or advertising, and deletion instructions are applied before a restored copy returns to ordinary use |
Withdrawal and deletion are different steps. We stop processing covered by a withdrawal within the applicable shorter deadline; a normal deletion-response window is not extra permission for optional use. We may verify a request where permitted, restrict or isolate data during necessary technical cleanup, and retain only records covered by a lawful exception. We do not use a new, incompatible legal basis merely to continue the same optional processing after consent withdrawal. Account deletion withdraws future consent-based training and promotion as well as initiating deletion.
Models and other copies. An already trained model is not simply a directory of source files. Source deletion does not necessarily reverse every learned parameter, and no automatic destruction or retraining of every model is promised. Continuing use is limited by the conditions in section 4 and applicable law; if personal information remains, required rights and remedies still apply. Independent public copies, previously authorized user results and distributed promotional copies may not all be retrievable. We continue to address lawful removal and rights requests.
Limited retained records. A binding legal duty, reasonably necessary defense of a claim or documented security incident may justify keeping relevant records for the applicable period. They remain access-restricted and used for that purpose, rather than for unrelated training or advertising. Where Korean e-commerce record rules apply, the relevant advertising records are retained six months, contract/withdrawal and payment/supply records five years, and consumer complaint/dispute records three years. Those periods do not require storing all videos or prompts.
When a retention purpose ends and no exception applies, we delete the data or properly de-identify it using methods appropriate to its storage. Removing an account name alone is not de-identification. Provider-specific periods and backup cycles are stated in the section 7 schedule.
Retention assessment and exceptions. We may consider model usefulness and lifecycle, dataset relevance and reproducibility, service continuity, the nature and sensitivity of the data, fraud patterns, outstanding disputes, limitation periods, legal duties, and technically necessary backup cycles. An exception preserves only the information reasonably needed for its purpose. Properly de-identified data that is no longer personal information may be used and disclosed without a fixed end date for lawful research, product development, security, aggregate reporting, and business purposes within the applicable content license. We maintain non-reidentification safeguards and appropriate recipient restrictions. Neither encryption, removal of a name, nor conversion to an embedding automatically makes information non-personal.
Provider-specific retention rule. Our category-level rules apply across providers processing for us. A hosting, inference, email or analytics supplier is not given an unlimited independent retention right merely because its commercial contract continues. We may retain information needed for an authorized development cycle, reproduce or audit results, protect against repeat abuse, resolve a claim, or satisfy a record obligation, considering necessity and proportionality and recording the relevant reason. We may separate active records, restricted legal evidence and backups; moving a record into an archive does not change its permitted purposes. When a provider independently determines a legally required payment or security record, its own lawful obligations may require a different period. For inactive backups where deferred deletion is legally permitted, access is restricted until the documented deletion/overwrite cycle, and deletion instructions apply before restored copies return to ordinary use. No universal supplier-wide deletion date, zero-retention promise, or automatic minimum period for all personal content is created by this Policy.
10. International processing
NationA is a US company. The user-confirmed AWS infrastructure locations for Ludyte are the United States and South Korea. Information may be stored, processed or remotely accessed outside your home country. A provider’s headquarters, hosting region, cache location, support location and subprocessor access are distinct and may differ.
For infrastructure growth, continuity, regional performance, cost, safety, research and support, we may select other countries in which our affiliates or contracted providers operate. Such flexibility is subject to applicable transfer restrictions, contractual safeguards, notices and required permission. The existence of a global cloud region, a competitor’s country list, or a supplier’s group-wide location list does not establish that Ludyte currently transfers data there. Prospective locations become actual processing destinations only after the necessary checks and disclosures. This does not alter the service-availability restrictions in section 2 of the Terms.
Section 7 provides the working provider schedule and identifies facts still requiring confirmation in this review edition. The final schedule or required direct notice must specify applicable recipients and contacts, data, purpose, actual countries including relevant remote access, timing and method, retention, safeguards or basis, and refusal/withdrawal effects. A general reference to worldwide providers does not replace specific information required by applicable law. Contact support@ludyte.com for transfer inquiries or a copy of safeguards you are entitled to receive; permitted confidentiality redactions must not hide required information.
We use an applicable lawful transfer route. For South Korea, necessary contractual entrusted processing or storage may use the legally permitted disclosure/notice route when its conditions are met; other cases may require separate transfer consent or another applicable route. For EEA/UK transfers requiring safeguards, these may include an applicable adequacy decision or properly executed standard contractual clauses and UK addendum or other approved mechanism, with supplementary measures where needed. We do not claim a certification or local representative that has not actually been established. A legally required transfer consent must identify its scope before processing and cannot be replaced by broad Terms acceptance.
Refusing a transfer necessary for the requested feature may prevent that feature, while declining an optional transfer does not prevent unrelated core functionality. We update actual provider and destination information and provide the notice or consent required for a change. Retention and backups follow section 9 even when information is stored abroad.
11. Security
We use access restrictions, authentication controls, secure credential handling and measures to limit unnecessary personal information in diagnostics. Access by personnel is limited to their responsibilities. No service can guarantee absolute security, and Ludyte is not an end-to-end encrypted messaging service.
Report suspected exposure or unauthorized access to support@ludyte.com. We investigate and provide notices required by applicable breach-notification law.
No internet service can guarantee absolute confidentiality, uninterrupted storage, or complete prevention of unauthorized access. You should protect your account and avoid submitting unnecessary sensitive material. These limitations do not waive our statutory security or breach-notification duties or make you responsible for a breach caused by us.
12. Requests, withdrawal, and applicable time limits
Use available privacy/account controls or email support@ludyte.com to request access, correction, deletion, portability, information about recipients, or other rights available under applicable law. You can independently change or withdraw training, analytics, targeted-advertising, marketing-message and promotional choices. Declining optional choices does not prevent core generation; a requested feature may require the information or permission necessary for it. You do not need to create a new account to exercise rights.
Ordinary requests. Unless a shorter period applies, we generally respond to access, correction and deletion requests within 45 calendar days after receipt. Where reasonably necessary and legally permitted, we may extend by up to a further 45 calendar days, for a total of 90 days, after giving the required notice and reasons within the initial period. Verification does not restart the clock. Where California's acknowledgment rule applies, we confirm receipt within 10 business days. Extensions are not automatic or a reason to delay unnecessarily.
Consent withdrawal and advertising opt-outs. These may have shorter limits than ordinary requests. We implement them as soon as reasonably practicable within the applicable deadline. Where Delaware's consent-withdrawal rule applies, consent-based processing stops no later than 15 calendar days after receipt. Where California's sale/sharing or sensitive-information limitation rule applies, the applicable request is implemented as soon as feasibly possible and no later than 15 business days. Other applicable shorter deadlines prevail. Marketing emails can be stopped using the unsubscribe mechanism, and applicable marketing-law time limits are respected. The 45/90-day ordinary request window does not extend these limits.
Verification and exceptions. We request only information reasonably needed to verify a request that requires verification or an agent's authority, and do not impose verification on an opt-out when prohibited. We may deny or limit a request only as law permits, explain the reason and process the remainder where required. Necessary legal, security, dispute and recordkeeping exceptions are limited as described in section 9; they are not broad permission for continued optional use. We do not discriminate for exercising protected rights. Applicable sale/sharing, targeted-advertising, profiling and sensitive-information rights and recognized preference signals are respected as described in section 8.
Appeal and review. Reply to our decision or email support with the request reference to seek review. Where an appeal right applies, we follow its procedure and deadline, including a response within 60 days under applicable Delaware law, and explain the result and complaint route. Where law grants rights concerning solely automated decisions with legal or similarly significant effects, you may request the required information, challenge or human review. You can contact the competent regulator or pursue an available legal remedy without first completing our internal process.
Withdrawal does not retroactively invalidate lawful earlier processing. Sections 4 and 9 explain already developed models, de-identified information, backups and retained records; sections 5 and 8 address publication and promotion. One request may address several choices if you identify them.
Legally permitted limits. We may decline requests we cannot reasonably verify where verification is allowed, or requests subject to a statutory exception. We may charge a reasonable fee or decline a manifestly unfounded, excessive, or repetitive request only to the extent the applicable law permits and after giving the required explanation. For EEA/UK rights requests, the ordinary response period is one month, extendable by up to two further months when legally justified with notice within the first month; shorter applicable rules prevail. Urgent intimate-image removal and other special legal processes are not governed by the ordinary 45/90-day privacy-request window. Nothing in the Terms’ arbitration or liability provisions prevents an applicable regulatory complaint or waives a non-waivable privacy remedy.
13. US state rights, regional supplements, and privacy contact
US state laws. The rights that apply depend on your residence, the processing involved and the law's scope, including applicable thresholds and exceptions. Where relevant, sections 2–3 identify categories, sources and purposes; section 7 identifies recipients; section 8 addresses sale, sharing and targeted advertising; section 9 explains retention; and section 12 explains rights, verification and appeal. Additional applicable collection, recipient, sale/sharing and sensitive-information disclosures appear in section 7. A prior consent does not waive a protected right. Delaware residents can also contact the Delaware Department of Justice; California residents can consult the California Attorney General's privacy information.
Privacy contact. Ludyte Customer Support Team; contact person: Jay. Email support@ludyte.com or write to NationA, Inc., 2810 N Church St STE 90780, Wilmington, DE 19802, United States. This identifies our inquiry team and does not represent that we have appointed a statutory data protection officer in every jurisdiction. We provide additional legally required contact methods or local-representative information in the service where applicable.
South Korea. Where Korean law applies, collection/use, entrusted processing, overseas transfers, security, disposal and individual rights follow its applicable requirements in addition to this Policy. The transaction-record periods in section 9 apply only where the relevant Korean law applies, not to every US user's content. Additional legally required notices or consents for optional processing, sensitive information or overseas transfers are not replaced by general Terms acceptance. For complaints, consult the Personal Information Protection Commission. Any applicable rule favoring the data subject where a policy and contract conflict is preserved.
EEA and UK. Where the GDPR or UK GDPR applies, we rely on contract for requested account, generation, storage and publication features; legal obligations for required records and rights compliance; and proportionate legitimate interests, where permitted, for security, abuse prevention and disputes. The optional training, analytics, targeted-advertising, marketing and promotional uses in this Policy rely on the corresponding consent. We assess necessity and balance legitimate interests against individual rights; this does not replace additional conditions for sensitive information. You may withdraw consent, object where applicable, seek restriction and exercise the rights in section 12. International transfers use the applicable safeguards described in section 10. You may complain to your supervisory authority; UK users can contact the Information Commissioner's Office.
California residents may also request applicable disclosures about third-party direct marketing under the state’s Shine the Light law. We provide a required free contact method and any legally required representative or officer details when applicable; the general support email alone is not a representation that every regional procedural requirement has been fulfilled. Where a separate business data-processing agreement applies, it governs processing performed solely on the business customer’s documented instructions within its scope; it does not automatically cover an ordinary individual account.
14. Adult eligibility and children
Ludyte is offered only to people who are at least 18 years old and have reached the legal age of majority in their country of residence. Ludyte does not offer access to minors through parental permission.
If you believe we have received information from an ineligible minor, contact support@ludyte.com. We will investigate and take appropriate steps, including restricting the account and deleting information where required, subject to applicable legal retention requirements.
15. Changes, language, and contact
We identify the effective date and give at least 30 days' advance notice of material changes to this Policy, or a longer period required by law. Urgent changes necessary for legal compliance or security may take effect sooner, with the reason and notice as soon as reasonably practicable. If a new purpose requires consent, we obtain it before that use begins; notice of a change does not itself provide consent.
We provide an English original and an official Korean translation. The English text controls to the extent permitted by law, without limiting mandatory local-language requirements or privacy and consumer rights.
NationA, Inc. 2810 N Church St STE 90780 Wilmington, DE 19802 United States
Privacy contact: support@ludyte.com
© 2026 NationA, Inc. · 2810 N Church St, STE 90780, Wilmington, DE 19802, USA