Skip to content

Privacy Policy

Effective Date: July 26, 2026
Last Updated: August 14, 2026

This Privacy Policy describes how AI Castle Inc. ("Company," "we," "us," or "our") collects, uses, entrusts, provides, and protects your personal information when you use the Physicar AI platform and related services (the "Services").


1. Information We Collect

1.1 Information You Provide

Category Data Purpose
Account Information Email address (a normalized copy is also stored to detect duplicate accounts), username (auto-generated if not chosen), password (stored only as a cryptographic hash) Account creation, authentication
Age Attestation Confirmation that you meet the minimum age for your jurisdiction, and the time of attestation Age verification per jurisdiction
Payment Information Collected directly by our payment provider Paddle; we do not receive or store your card number Credit purchases

About date of birth: We do not collect or store your date of birth or real name. If an older client application submits a date of birth, it is used solely to determine whether you meet the age requirement and is immediately discarded — it is never stored.

1.2 Information Collected Automatically

Category Data Purpose
Sign-up Records IP address, country (derived from your connection), browser language, sign-up time Security, age verification by jurisdiction, localization
Sign-in Records IP address, country, language, sign-in time (updated at each login) Security, fraud prevention
Usage Data Credit transactions and usage records, feature usage Billing, service improvement
Bot Verification At sign-up, a Cloudflare Turnstile token and your IP address are verified through Cloudflare; the token is not stored Bot and abuse prevention

1.3 Information Generated During Use

Category Data Notes
Chat Content Messages you send, attached images, AI responses, automatic conversation summaries Stored for 7 days for multi-turn context, then automatically deleted
Realtime Voice Sessions Text transcripts of voice conversations The voice audio itself is not stored
Uploaded Files Files you upload to your storage (models, tracks, etc.) Deleted upon account deletion
Simulator Workspace Files and data inside your cloud simulator (volumes, images, snapshots) Permanently deleted after 30 days without use
Credit Gift Records When you send or receive a credit gift, the other party's email address is recorded in both parties' transaction history Transaction transparency and dispute handling

1.4 Guest (Non-Logged-In) Use

You may try the AI chat without an account. For guests, your IP address serves as the identifier:

  • Guest conversations are stored under an IP-based key for 7 days.
  • Daily usage-limit counters per IP are kept for 24 hours.
  • IP-based rate limiting applies to all requests.

1.5 Information from Third Parties

We do not collect personal information from third-party sources.

2. How We Use Your Information

We use your information for the following purposes:

  • Providing Services: Processing your requests, generating AI responses, operating cloud simulators, managing your account
  • Authentication & Security: Verifying your identity, preventing fraud and abuse, enforcing rate limits
  • Age Verification: Determining minimum age requirements based on your jurisdiction
  • Billing: Metering credit usage, processing credit purchases and gifts
  • Classroom Management: Enabling educators to manage student access and usage
  • Communication: Sending verification emails, password reset links, and service notifications
  • Service Improvement: Analyzing usage patterns to improve platform features (aggregated data)
  • Legal Compliance: Meeting our obligations under applicable laws and regulations

3. Processing Entrustment (Processors)

We entrust the following processors with data processing necessary to operate the Services:

Processor Entrusted Work Location
Cloudflare, Inc. Platform hosting, CDN, data storage (D1, KV, R2), AI request routing (AI Gateway), on-platform AI inference (Workers AI), bot prevention (Turnstile), security United States (global edge network)
Resend, Inc. Transactional email delivery (verification, password reset, notifications) United States
Amazon Web Services, Inc. Cloud simulator hosting (EC2) and storage of simulator workspaces (volumes, images, snapshots); your email address is included in resource tags for operational identification Republic of Korea (Seoul, for users in Korea); Japan (Tokyo); United States

All AI model requests are routed through Cloudflare AI Gateway. Some AI models run directly on Cloudflare Workers AI, in which case your conversation is processed within Cloudflare's infrastructure under this entrustment.

4. Third-Party Provision of Personal Information

4.1 AI Model Providers

To generate AI responses, your conversation content is transmitted to the AI provider of the model you use:

Recipient Data Provided Purpose Location
OpenAI, L.L.C. Chat messages and attached images, conversation summarization input, AI response text for speech synthesis (TTS), realtime voice sessions (audio, text, images) GPT-series responses, TTS, realtime voice conversation United States
Google LLC Chat messages and attached images, realtime voice sessions (audio, text) Gemini-series responses, realtime voice conversation United States
Anthropic, PBC Chat messages and attached images Claude-series responses United States

Retention by these recipients follows each provider's API data policy (for example, OpenAI may retain data for up to 30 days for abuse monitoring).

4.2 Payment Processing (Paddle)

When you purchase credits, payment is processed by Paddle as merchant of record:

Recipient Data Provided Purpose Location
Paddle.com Market Limited Purchase amount, user ID, client IP address at checkout; payment method details are collected directly by Paddle Payment processing, tax handling, invoicing United Kingdom / United States

This provision occurs only when you initiate a purchase. We do not receive or store your card number.

4.3 Classroom Educators

If you join a Classroom, the educator (teacher) can see:

  • Your email address and username
  • Your credit usage within the Classroom (allowance and deductions)
  • Your join date

Educators cannot view the content of your chats. Usage information is shared with the educator because student usage within a Classroom is billed to the educator's credits.

We may disclose your information when required by law, court order, or governmental authority.

4.5 Business Transfers

In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of the transaction.

5. International Data Transfers

Physicar AI is a global service, and your data is transferred abroad in two distinct ways:

  • Provision to third parties (consent-based): Conversation content to AI providers (OpenAI, Google, Anthropic — United States) and payment data to Paddle (United Kingdom / United States), as described in Section 4.
  • Entrustment and storage (disclosed in this policy): Infrastructure processing by Cloudflare (United States, global edge), Resend (United States), and AWS (simulators are placed in the Seoul region for users in Korea where available, otherwise Tokyo or US regions; default US), as described in Section 3.

We ensure appropriate safeguards for international transfers, including encryption in transit and data processing agreements, in compliance with applicable data protection laws.

For users in the Republic of Korea: Please refer to our Cross-Border Transfer Consent for the details required under the Personal Information Protection Act (PIPA).

6. Data Retention

Data Type Retention Period
Account information Until account deletion is completed (deletion takes effect 7 days after your request; see Section 8)
Chat data (messages, images, AI responses, summaries, realtime transcripts) 7 days from last update, then automatically deleted
Session data 7 days (session list: 30 days)
API key authentication data 30 days (only a hash of the key is stored)
Email verification tokens 24 hours; password reset and email change tokens: 1 hour
Guest records Conversations: 7 days; daily usage counters: 24 hours
Simulator data (workspace, images, snapshots) Permanently deleted after 30 days without a simulator run — this data cannot be recovered
Uploaded files Until account deletion
Credit transaction records 5 years (in line with e-commerce consumer protection requirements)
Minimal record of deleted accounts (email, deletion date, reason) 5 years to prevent fraudulent re-registration, then destroyed
Classroom membership history (join/leave/removal) For the duration of service operation (classroom administration and dispute handling)
Internal operational alerts Automatically deleted after 90 days

7. Destruction of Personal Information

  • Procedure: Personal information is destroyed without delay once its retention period expires or its processing purpose is achieved. Account deletion is executed after the 7-day grace period described in Section 8.
  • Method: Electronic records are deleted using methods that prevent recovery (database record deletion and storage object deletion). Copies in infrastructure backups are automatically purged within a maximum of 30 days thereafter.
  • Simulator data: Deleted at the instance, image, and snapshot level; once deleted, workspace data cannot be recovered.

8. Your Rights

Depending on your jurisdiction, you may have the following rights:

  • Access: Request a copy of your personal information
  • Correction: Request correction of inaccurate information
  • Deletion: Delete your account and personal data (see below)
  • Portability: Request your data in a portable format
  • Objection: Object to certain processing activities
  • Withdrawal of Consent: Withdraw consent where processing is based on consent

Account deletion (self-service): You can request deletion of your account directly in your account settings. Upon request, sign-in is blocked and any running simulator is stopped immediately. You may cancel the request by signing in again within 7 days; after the grace period, your account and personal data are permanently deleted in accordance with Sections 6 and 7.

To exercise your other rights, please contact us at support@physicar.ai. We respond without undue delay within the timeframes required by applicable law.

9. Children's Privacy

You may create an account only if you meet the minimum age for your jurisdiction (14 in the Republic of Korea), which you confirm during sign-up. We do not knowingly collect personal information from children below that age, and we do not collect or store dates of birth (see Section 1.1).

Use of the Services through a Classroom also requires meeting the minimum age for your jurisdiction. If we become aware that we have collected personal information from a child below the minimum age, we will delete that information without delay.

10. Security

We implement technical and organizational measures to protect your personal information, including:

  • Password hashing with PBKDF2 (100,000 iterations, SHA-256); plaintext passwords are never stored
  • Breached-password screening at sign-up and password change using a k-anonymity method (only the first 5 characters of a SHA-1 hash are sent to the Have I Been Pwned service; your password and email are never transmitted)
  • HTTPS/TLS encryption for all data in transit
  • Session-based authentication with secure tokens; API keys stored only as hashes
  • Rate limiting and abuse prevention
  • Regular security reviews

11. Operational Logs

Service logs generated during operation (sign-up, sign-in, email delivery, and similar events) may include your email address. These logs are retained for service operation, security monitoring, and abuse prevention. The internal operational alert store is automatically deleted after 90 days.

12. Cookies and Local Storage

We use browser local storage and a small number of first-party cookies for authentication only. We do not use tracking cookies or third-party advertising cookies.

Storage Item Type Purpose Duration
physicar_session Local storage Authentication token Until logout or expiration (7 days)
__sim_sess Cookie (HttpOnly) Simulator gateway authentication 12 hours

13. Data Protection Officer

The Company designates a Data Protection Officer (DPO/CPO) responsible for personal information processing and for handling related complaints and remedies:

  • Data Protection Officer: Jean-Young Kim (CEO)
  • Contact: +82 70-8080-3341
  • Email: support@physicar.ai

14. Remedies for Infringement of Rights

If you need to report or consult on a personal data infringement, you may contact the following organizations (Republic of Korea):

  • Personal Information Infringement Report Center (KISA): privacy.kisa.or.kr / 118 (no area code)
  • Personal Information Dispute Mediation Committee: kopico.go.kr / 1833-6972
  • Supreme Prosecutors' Office: spo.go.kr / 1301
  • National Police Agency (Cyber Bureau): ecrm.police.go.kr / 182

15. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the revised policy on this page with an updated effective date.

16. Contact Us

For privacy-related inquiries:

  • Email: support@physicar.ai
  • Company: AI Castle Inc.
  • Address: Gangnam-ro 9, Giheung-gu, Yongin-si, Gyeonggi-do, Republic of Korea (16977)

Jurisdiction-Specific Provisions

Republic of Korea

Users in the Republic of Korea have additional rights and protections under the Personal Information Protection Act (PIPA). Please review our consent documents:

European Economic Area (EEA)

For users in the EEA, we process your personal information based on the following legal bases: performance of a contract (providing the Services), legitimate interests (security, service improvement), and consent (where required). You have additional rights under the GDPR, including the right to lodge a complaint with a supervisory authority.


This Privacy Policy is available in multiple languages. In the event of any conflict between translated versions, the English version shall prevail.

AI