Privacy Policy
Fengs Studio · Effective date: 23 July 2026 · Version 1.0
This Privacy Policy explains how personal data is collected, used, disclosed and protected when you use the Fengs Studio platform at https://www.fengstudio.app (the "Service"). It is drafted to meet the requirements of the Turkish Law No. 6698 on the Protection of Personal Data ("KVKK") and, where applicable, the EU/UK General Data Protection Regulation ("GDPR").
1. Data Controller
1.1 The data controller responsible for the processing described in this Policy is:
| Legal name | FENGS BİLİŞİM YAZILIM SANAYİ VE TİCARET LTD. ŞTİ. |
| Registered address | Çınarlı Mah. 1572 Sk. No: 33, Konak, İzmir, Türkiye |
| Trade Registry No. | 271857 |
| Tax office / Tax ID | Karşıyaka V.D. — 3852170856 |
| Contact | hello@fengs.ai |
1.2 Requests, questions and rights applications under this Policy should be addressed to hello@fengs.ai.
2. Scope and Our Role
2.1 This Policy applies to personal data processed in connection with your visit to our website, your registration and use of an Account, and your use of the Service's generative tools.
2.2 Controller role. We act as the data controller for your account, transaction, technical and communications data.
2.3 Processor role. Where you upload imagery depicting individuals other than yourself — for example, photographs of models engaged by your business — you act as the controller of that data and we act as your processor, processing it solely on your documented instructions as expressed through your use of the Service. A Data Processing Agreement governing that processing is available on request at hello@fengs.ai.
3. Categories of Personal Data
3.1 We process the following categories of data:
| Category | Examples | Source |
|---|---|---|
| Account data | Email address, hashed password, plan and credit balance | Provided by you at registration |
| Content data | Images, videos, prompts and reference materials you upload (which may include facial imagery — see Section 5) | Uploaded by you |
| Output data | Images and videos generated at your request, and associated generation settings | Generated by the Service |
| Transaction data | Purchase history, order references, billing country, invoice records | Provided by you / Dodo Payments |
| Technical data | IP address, browser and device information, access timestamps, server logs | Collected automatically |
| Communications data | Support correspondence and rights applications | Provided by you |
3.2 No payment card data. Payments are processed exclusively by Dodo Payments, Inc. as merchant of record. We do not receive, store or otherwise process your card number or other full payment credentials at any time.
4. Purposes and Legal Bases
4.1 We process personal data for the following purposes and on the following legal bases:
| Purpose | Data categories | Legal basis (GDPR / KVKK) |
|---|---|---|
| Providing the Service, operating your Account and generating Outputs | Account, Content, Output | Performance of a contract |
| Processing purchases, managing credits and maintaining billing records | Account, Transaction | Performance of a contract; compliance with a legal obligation |
| Securing the Service, preventing fraud and abuse, and enforcing our Terms | Account, Technical, Content | Legitimate interests |
| Providing support and responding to enquiries and rights applications | Account, Communications | Performance of a contract; legal obligation |
| Complying with tax, commercial and other statutory obligations | Transaction | Compliance with a legal obligation |
4.2 What we do not do. We do not use your Content data or Output data to train, fine-tune or develop generative models. We do not sell personal data. We do not use personal data for behavioural advertising or profiling for marketing purposes.
5. Facial and Personal Imagery
5.1 The Service is designed to work with imagery of people, and Content data will frequently include facial imagery. We treat such imagery with heightened safeguards.
5.2 We process facial imagery solely to render the generations you request. We do not extract faceprints or other biometric templates, do not perform biometric identification or matching against any database, and do not use facial imagery for identification purposes of any kind. The processing is image-to-image transformation, not biometric recognition.
5.3 Where you upload imagery of any individual other than yourself, you warrant that you have obtained that individual's informed consent (or hold another valid legal basis) covering the upload and the processing described in this Policy, and that you can evidence this on request.
6. Sub-processors and Recipients
6.1 We share personal data only with the following categories of recipients, and only to the extent necessary for the stated function:
| Recipient | Function | Data concerned |
|---|---|---|
| Dodo Payments, Inc. | Merchant of record; payment processing, invoicing, tax handling | Account (email), Transaction |
| Supabase | Database and object storage hosting | Account, Content, Output, Technical |
| Railway | Application hosting infrastructure | Technical; data in transit |
| Google (Gemini models) | Image generation processing | Content submitted for generation; prompts |
| Kling | Video generation processing | Content submitted for generation; prompts |
6.2 Content data is transmitted to model providers strictly to fulfil the specific generation you request and is processed by them as our sub-processors under contractual terms that restrict use to the provision of the service.
6.3 We may also disclose personal data where required by law, by a court order or by a competent public authority, and in connection with a merger, acquisition or sale of assets, subject to appropriate confidentiality protections.
7. International Transfers
7.1 Some of the recipients listed in Section 6 process data outside Türkiye and outside the European Economic Area. Where personal data is transferred internationally, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses and equivalent contractual mechanisms, together with supplementary technical measures such as encryption in transit and at rest.
7.2 Transfers from Türkiye are conducted in accordance with Article 9 of the KVKK and the decisions and guidance of the Turkish Personal Data Protection Board.
8. Retention
8.1 We retain personal data as follows:
- Account, Content and Output data — for as long as your Account remains active. Upon deletion of your Account, this data is deleted within thirty (30) days, subject to residual copies in encrypted backups which are overwritten on a rolling basis.
- Transaction and invoice records — for ten (10) years, as required by Turkish commercial and tax legislation.
- Technical logs — for no longer than twelve (12) months, unless a longer period is required for the investigation of a security incident.
- Communications data — for as long as necessary to handle the matter and to evidence compliance with our legal obligations.
9. Security
9.1 We implement appropriate technical and organisational measures to protect personal data, including encryption of data in transit (TLS) and at rest, access controls on a need-to-know basis, segregated storage with per-user access enforcement, hashed password storage, and logging and monitoring of administrative access.
9.2 In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority and, where required, the affected individuals without undue delay and, where feasible, within seventy-two (72) hours of becoming aware of the breach.
10. Your Rights
10.1 Subject to the conditions set out in the applicable law, you have the right to:
- learn whether your personal data is processed, and request information about that processing;
- access the personal data we hold about you and receive a copy;
- request rectification of inaccurate or incomplete data;
- request erasure of your data, including deletion of your Account;
- request restriction of processing, and object to processing based on legitimate interests;
- receive data you have provided in a structured, commonly used, machine-readable format (portability);
- learn the third parties to whom your data has been transferred, and request that corrections and erasures be notified to them;
- object to a result produced exclusively by automated processing that adversely affects you; and
- claim compensation for damage suffered as a result of unlawful processing.
10.2 Rights applications may be submitted to hello@fengs.ai. We respond without undue delay and in any event within the periods prescribed by the KVKK and, where applicable, the GDPR (generally thirty days).
10.3 You also have the right to lodge a complaint with the Turkish Personal Data Protection Authority (Kişisel Verileri Koruma Kurumu) and, if you are in the EEA or the United Kingdom, with your local supervisory authority.
11. Automated Decision-Making
11.1 We do not make decisions producing legal or similarly significant effects concerning you based solely on automated processing within the meaning of Article 22 GDPR. Automated systems may flag content for review under our Acceptable Use rules, but any decision to suspend or terminate an Account is subject to human review.
12. Cookies
12.1 The Service uses strictly necessary cookies only: a session cookie that keeps you signed in, and a preference cookie that stores your interface theme choice. We do not use analytics, advertising or tracking cookies, and no third-party cookies are set. Because only strictly necessary cookies are used, no consent banner is required.
13. Children
13.1 The Service is intended for persons aged 18 and over, and we do not knowingly collect personal data from minors as account holders. Where Content data uploaded by you depicts a minor, you warrant that you hold the informed consent of the minor's parent or legal guardian and that the depiction complies with our Acceptable Use rules.
14. Changes to this Policy
14.1 We may update this Policy from time to time. The current version is always available at https://www.fengstudio.app/privacy-policy. Material changes will be notified by email or by notice within the Service before they take effect.
15. Contact
| Entity | FENGS BİLİŞİM YAZILIM SANAYİ VE TİCARET LTD. ŞTİ. |
| Address | Çınarlı Mah. 1572 Sk. No: 33, Konak, İzmir, Türkiye |
| hello@fengs.ai | |
| Trade Registry No. | 271857 |
| Tax office / Tax ID | Karşıyaka V.D. — 3852170856 |
| Merchant of record | Dodo Payments, Inc. |