Privacy Policy

Last Updated: July 28, 2026

(In accordance with Personal Information Protection Act, Information Security Management Act, Consumer Protection Act and related regulations)

Article 1 - Policy Purpose

RockCam (hereinafter referred to as 'the Company') values user privacy and personal data protection. In accordance with the Personal Information Protection Act and related regulations, this policy explains how the Company collects, processes, and uses personal information, user rights and Company safeguards.

Article 2 - Purpose and Scope of Personal Data Collection

To provide SaaS software subscription services, AI photography and image generation functions, the Company may collect following types of data:

  • Basic Information: Name, email address, phone number, account information.
  • Payment Data: Transaction records (processed by third-party payment platforms, excluding complete credit card data).
  • Usage Data: Login times, operation records, IP address, device information, usage preferences, etc.
  • Image Data: User-uploaded or generated photos, videos, AI images (for service purposes only).

Collection purposes include:

  • Identity verification and account management;
  • Providing and maintaining cloud software and AI features;
  • Processing subscription payments and issuing invoices;
  • Improving service experience and feature analysis;
  • Data retention required by law or competent authorities.

Article 3 - Duration, Region, Parties and Methods of Personal Data Use

  • Duration: From user registration to maximum five years after account deletion or service termination (unless otherwise required by law).
  • Region: ROC and locations of Company or cloud servers (including offshore data centers).
  • Parties: Company and legally contracted payment, cloud or technical service providers.
  • Methods: Through electronic, network, cloud and other automated means for collection, processing, utilization and storage.

Article 4 - Third-Party Payment and Service Providers

Company's payment process is handled by legally authorized third-party payment platforms with security mechanisms to protect user transaction data. Company does not store complete credit card numbers or security codes. All transactions use secure encrypted transmission.

Company's servers and image generation systems may use domestic or offshore cloud services, implementing protective measures including encrypted transmission, access control, off-site backup and security audits to ensure user data integrity and security.

For cross-border data transfers, Company will handle according to Personal Information Protection Act Article 21 and relevant authority regulations, ensuring data confidentiality and lawful use during transmission and storage.

Article 5 - AI Images and Uploaded Content

  • User-uploaded or generated images, videos and AI content are for service operation and technical improvement purposes only.
  • Company will not use user images for advertising, commercial display or third-party cooperation without authorization.
  • With explicit user authorization, Company may use related materials in marketing, portfolio display or feature demonstrations.
  • If user-uploaded content involves illegal, infringing or violations of public order and morals, Company may immediately remove and terminate account.

Article 5-1 - Face Data

Certain optional AI photo effects in the Company's services (such as face style transfer and face swap) process photographs that contain users' or guests' faces. This article specifically explains how such face data is handled:

  • Collection: The Company's applications do not perform facial recognition and do not collect, generate or store facial geometry, faceprints, facial feature templates or any other biometric identifiers. The only face data processed consists of ordinary photographs taken or uploaded by users (and, for the face swap feature, a template photograph supplied by the user).
  • Use: Face-containing photographs are used solely to generate the photo effect the user requested at that moment. They are never used for identity recognition, authentication, tracking, profiling, advertising, or for training AI models.
  • Sharing: To render an AI effect, the photograph is transmitted over encrypted connections to the Company's server and processed by contracted third-party AI image processing providers, each acting solely as a data processor for that single request and bound not to use the content for any other purpose. Face data is never sold and never shared for any other purpose.
  • Storage and retention: Photographs submitted for AI processing are staged only temporarily on the Company's cloud infrastructure (Cloudflare) and are deleted immediately after processing completes, with an automatic 24-hour deletion rule as a safeguard; the Company does not retain AI input or output images on its servers. Photos shared through the optional QR download feature are stored for 14 days and then automatically deleted.
  • Deletion: Finished photos are stored on the user's own device under the user's control. Users may request deletion of any face data by contacting support@rock-cam.com ; the Company will comply within 15 working days in accordance with Article 7.

Article 6 - Data Security Management

Company establishes information security protection mechanisms according to Information Security Management Act, including:

  • Data encryption and access control;
  • Backup and disaster recovery mechanisms;
  • Regular security audits and anomaly detection;
  • Data protection and confidentiality training for internal personnel.

In case of data breach, Company will notify concerned parties according to Personal Information Protection Act Article 12 and authority requirements.

Article 7 - User Rights

According to Personal Information Protection Act Article 3, users may exercise following rights:

  • Inquire or request review of personal data;
  • Request copies;
  • Request supplementation or correction;
  • Request cessation of collection, processing or utilization;
  • Request data deletion.

To exercise above rights, please contact customer service at support@rock-cam.com. Company will respond within 15 working days.

Article 8 - Cookies and Tracking Technologies

  • Company may use Cookies, analytical tools or similar technologies to improve service experience.
  • Users can refuse or delete Cookies in browser settings, but may affect some features.
  • Company will not use Cookies for purposes unrelated to service.

Article 9 - Data Retention and Deletion

  • Users can delete uploaded images or videos in account.
  • After account deletion, Company will delete related data within reasonable time; however, transaction, tax or accounting records required by law will be retained for at least five years according to Business Accounting Act and Tax Collection Act.

Article 10 - Privacy Policy Amendment

Company may amend this policy due to legal changes, service adjustments or technical updates, announcing on website or notifying via email. If users continue using service after announcement, deemed as consent to amended policy content.

Article 11 - Contact Information

For any questions about this policy, to exercise data rights, or report security incidents, please contact:

RockCam Customer Service: support@rock-cam.com

Service Hours: Monday to Friday 10:00–18:00 (excluding holidays)